Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:08:43 AM, on 27/05/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\KeyboardSurrogate.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Comodo\CBOClean\BOCORE.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\TOSHIBA\TOSHIBA RAID\Service\kraidsvc.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Pen_Tablet.exe
C:\Program Files\TOSHIBA\TOSHIBA RAID\Service\krdevctl.exe
C:\WINDOWS\system32\ThpSrv.exe
C:\WINDOWS\SYSTEM32\WISPTIS.EXE
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\tabbtnu.exe
C:\WINDOWS\system32\WTablet\Pen_TabletUser.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\Pen_Tablet.exe
C:\WINDOWS\system32\conime.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\TCServer.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\TFNF5.exe
C:\WINDOWS\system32\TPSODDCtl.exe
C:\PROGRA~1\Comodo\CBOClean\BOC425.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\WINDOWS\system32\00THotkey.exe
C:\Program Files\Toshiba\CrossMenu\CrossMenu.exe
C:\Program Files\TOSHIBA\TOSHIBA Rotation Utility\TRot.exe
C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\LClock\lclock.exe
C:\Program Files\Launchy\Launchy.exe
C:\WINDOWS\system32\RAMASST.exe
C:\PROGRA~1\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
F3 - REG:win.ini: load=
F3 - REG:win.ini: run=
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [TPSODDCtl] TPSODDCtl.exe
O4 - HKLM\..\Run: [TOSDCR] TOSDCR.EXE
O4 - HKLM\..\Run: [BOC-425] C:\PROGRA~1\Comodo\CBOClean\BOC425.exe
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\system32\00THotkey.exe
O4 - HKLM\..\Run: [CrossMenu] C:\Program Files\Toshiba\CrossMenu\CrossMenu.exe
O4 - HKLM\..\Run: [TRot.exe] c:\Program Files\TOSHIBA\TOSHIBA Rotation Utility\TRot.exe
O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
O4 - HKLM\..\Run: [TabletWizard] C:\WINDOWS\help\SplshWrp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [BM8bd4b0d0] Rundll32.exe "C:\WINDOWS\system32\ddnpebes.dll",s
O4 - HKLM\..\Run: [88e7834c] rundll32.exe "C:\WINDOWS\system32\ixghqqlx.dll",b
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LClock] C:\Program Files\LClock\lclock.exe
O4 - HKUS\S-1-5-19\..\Run: [TabletWizard] %windir%\help\wizard.hta (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [TabletWizard] %windir%\help\wizard.hta (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - .DEFAULT User Startup: IEHOME.LNK = C:\Documents and Settings\Default User\Local Settings\Temp\iehome.bat (User 'Default user')
O4 - Global Startup: Launchy.lnk = C:\Program Files\Launchy\Launchy.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-CA/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1199781481968
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - https://secure.gopetslive.com/dev/GoPetsWeb.cab
O23 - Service: BOCore - COMODO - C:\Program Files\Comodo\CBOClean\BOCORE.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: TOSHIBA RAID Service (kraidsvc) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA RAID\Service\kraidsvc.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: TabletServicePen - Wacom Technology, Corp. - C:\WINDOWS\system32\Pen_Tablet.exe
O23 - Service: TOSHIBA HDD Protection (Thpsrv) - TOSHIBA Corporation - C:\WINDOWS\system32\ThpSrv.exe
O23 - Service: Tmesrv3 (Tmesrv) - Unknown owner - C:\Program Files\TOSHIBA\TME3\Tmesrv31.exe (file missing)
--
End of file - 8563 bytes
------------------------------------------------------------
Kaspersky scan is long, the files marked infected are:
Number of viruses found 23
Number of infected objects 95
Number of suspicious objects 0
C:\Documents and Settings\All Users\Application Data\BOC425\evidence.boc Infected: Trojan-Downloader.Win32.Injecter.li skipped
C:\Documents and Settings\boss\Local Settings\Temporary Internet Files\Content.IE5\BPH91119\kb516107[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.tsz skipped
C:\Documents and Settings\boss\Local Settings\Temporary Internet Files\Content.IE5\UDVJCIL4\kb516107[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.tsz skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP132\A0024166.exe/is153017.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.qij skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP132\A0024166.exe CAB: infected - 1 skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP132\A0024167.msi/is153017.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.qij skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP132\A0024167.msi CAB: infected - 1 skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP146\A0033497.exe/stream/data0010 Infected: not-a-virus:RiskTool.Win32.WFPDisabler.a skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP146\A0033497.exe/stream Infected: not-a-virus:RiskTool.Win32.WFPDisabler.a skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP146\A0033497.exe NSIS: infected - 2 skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP156\A0041542.dll Infected: Trojan-Downloader.Win32.Mutant.yq skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP156\A0041559.sys Infected: Trojan-Dropper.Win32.Agent.rek skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP156\A0041565.exe Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP157\A0041581.exe Infected: not-a-virus:AdWare.Win32.WebHancer.423 skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP157\A0041583.exe Infected: Trojan-Proxy.Win32.Small.oz skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP157\A0041584.sys Infected: Rootkit.Win32.Qandr.af skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP157\A0041586.exe Infected: Trojan.Win32.Agent.kwy skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP157\A0041587.exe Infected: Trojan-Downloader.Win32.Small.wab skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP157\A0041588.exe Infected: Trojan-Downloader.Win32.Homles.bp skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP157\A0041589.exe Infected: SpamTool.Win32.Agent.ip skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP157\A0041728.dll Infected: Trojan-Downloader.Win32.Mutant.yq skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP157\A0041729.dll Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP157\A0041730.dll Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP157\A0041731.exe Infected: Backdoor.Win32.Agent.ggk skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042033.exe Infected: Trojan-Downloader.Win32.Agent.plz skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042102.exe/data0000.cab/AUTOKE~1.EXE/data0000.cab/install.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.tsv skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042102.exe/data0000.cab/AUTOKE~1.EXE/data0000.cab Infected: not-a-virus:AdWare.Win32.Virtumonde.tsv skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042102.exe/data0000.cab/AUTOKE~1.EXE Infected: not-a-virus:AdWare.Win32.Virtumonde.tsv skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042102.exe/data0000.cab Infected: not-a-virus:AdWare.Win32.Virtumonde.tsv skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042102.exe Rsrc-Package: infected - 4 skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042111.exe/data0000.cab/TuneUp2008 Keymaker.exe Infected: Backdoor.Win32.Rbot.pfa skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042111.exe/data0000.cab/is154715.exe Infected: Trojan-Downloader.Win32.Injecter.li skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042111.exe/data0000.cab Infected: Trojan-Downloader.Win32.Injecter.li skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042111.exe Rsrc-Package: infected - 3 skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042112.exe/data0000.cab/is154715.exe Infected: Trojan-Downloader.Win32.Injecter.li skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042112.exe/data0000.cab Infected: Trojan-Downloader.Win32.Injecter.li skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042112.exe Rsrc-Package: infected - 2 skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042115.exe/data0000.cab/Keygen 2.exe Infected: Trojan-Downloader.Win32.Agent.ifq skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042115.exe/data0000.cab/is154715.exe Infected: Trojan-Downloader.Win32.Injecter.li skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042115.exe/data0000.cab Infected: Trojan-Downloader.Win32.Injecter.li skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042115.exe Rsrc-Package: infected - 3 skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042116.exe/data0000.cab/is154715.exe Infected: Trojan-Downloader.Win32.Injecter.li skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042116.exe/data0000.cab Infected: Trojan-Downloader.Win32.Injecter.li skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042116.exe Rsrc-Package: infected - 2 skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042117.exe/data0000.cab/is154715.exe Infected: Trojan-Downloader.Win32.Injecter.li skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042117.exe/data0000.cab Infected: Trojan-Downloader.Win32.Injecter.li skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042117.exe Rsrc-Package: infected - 2 skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042337.sys Infected: Trojan-Dropper.Win32.Agent.rek skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042339.sys Infected: Trojan-Dropper.Win32.Agent.rek skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042340.dll Infected: Trojan-Downloader.Win32.Mutant.yq skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042341.dll Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042342.dll Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042343.exe Infected: Trojan-Downloader.Win32.Homles.bp skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP165\A0042691.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.tsz skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP166\A0042723.exe/data0000.cab/is154715.exe Infected: Trojan-Downloader.Win32.Injecter.li skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP166\A0042723.exe/data0000.cab Infected: Trojan-Downloader.Win32.Injecter.li skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP166\A0042723.exe Rsrc-Package: infected - 2 skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP166\A0042730.msi/is153553.exe Infected: Trojan.Win32.Zapchast.gb skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP166\A0042730.msi CAB: infected - 1 skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP166\A0042733.msi/is153553.exe Infected: Trojan.Win32.Zapchast.gb skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP166\A0042733.msi CAB: infected - 1 skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP166\change.log Object is locked skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP63\A0015753.exe/stream/data0050 Infected: not-a-virus:AdWare.Win32.Shopper.r skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP63\A0015753.exe/stream Infected: not-a-virus:AdWare.Win32.Shopper.r skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP63\A0015753.exe NSIS: infected - 2 skipped
C:\WINDOWS\system32\ddnpebes.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.tsz skipped
C:\WINDOWS\system32\jkkKaArP.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.trz skipped
C:\WINDOWS\system32\jyyddvmw.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.tsz skipped
C:\WINDOWS\system32\rqRKefDU.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.trz skipped
C:\WINDOWS\system32\rwouygkl.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.tsz skipped
C:\WINDOWS\system32\svchost.ex Infected: Trojan.Win32.Obfuscated.arg skipped
C:\WINDOWS\system32\WinNt32.dl_ Infected: Trojan-Downloader.Win32.Mutant.yq skipped
-----------------------------------------------------
Help is sincerely appreciated! Thank you in advance.
Scan saved at 4:08:43 AM, on 27/05/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\KeyboardSurrogate.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Comodo\CBOClean\BOCORE.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\TOSHIBA\TOSHIBA RAID\Service\kraidsvc.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Pen_Tablet.exe
C:\Program Files\TOSHIBA\TOSHIBA RAID\Service\krdevctl.exe
C:\WINDOWS\system32\ThpSrv.exe
C:\WINDOWS\SYSTEM32\WISPTIS.EXE
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\tabbtnu.exe
C:\WINDOWS\system32\WTablet\Pen_TabletUser.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\Pen_Tablet.exe
C:\WINDOWS\system32\conime.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\TCServer.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\TFNF5.exe
C:\WINDOWS\system32\TPSODDCtl.exe
C:\PROGRA~1\Comodo\CBOClean\BOC425.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\WINDOWS\system32\00THotkey.exe
C:\Program Files\Toshiba\CrossMenu\CrossMenu.exe
C:\Program Files\TOSHIBA\TOSHIBA Rotation Utility\TRot.exe
C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\LClock\lclock.exe
C:\Program Files\Launchy\Launchy.exe
C:\WINDOWS\system32\RAMASST.exe
C:\PROGRA~1\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
F3 - REG:win.ini: load=
F3 - REG:win.ini: run=
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [TPSODDCtl] TPSODDCtl.exe
O4 - HKLM\..\Run: [TOSDCR] TOSDCR.EXE
O4 - HKLM\..\Run: [BOC-425] C:\PROGRA~1\Comodo\CBOClean\BOC425.exe
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\system32\00THotkey.exe
O4 - HKLM\..\Run: [CrossMenu] C:\Program Files\Toshiba\CrossMenu\CrossMenu.exe
O4 - HKLM\..\Run: [TRot.exe] c:\Program Files\TOSHIBA\TOSHIBA Rotation Utility\TRot.exe
O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
O4 - HKLM\..\Run: [TabletWizard] C:\WINDOWS\help\SplshWrp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [BM8bd4b0d0] Rundll32.exe "C:\WINDOWS\system32\ddnpebes.dll",s
O4 - HKLM\..\Run: [88e7834c] rundll32.exe "C:\WINDOWS\system32\ixghqqlx.dll",b
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LClock] C:\Program Files\LClock\lclock.exe
O4 - HKUS\S-1-5-19\..\Run: [TabletWizard] %windir%\help\wizard.hta (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [TabletWizard] %windir%\help\wizard.hta (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - .DEFAULT User Startup: IEHOME.LNK = C:\Documents and Settings\Default User\Local Settings\Temp\iehome.bat (User 'Default user')
O4 - Global Startup: Launchy.lnk = C:\Program Files\Launchy\Launchy.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-CA/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1199781481968
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - https://secure.gopetslive.com/dev/GoPetsWeb.cab
O23 - Service: BOCore - COMODO - C:\Program Files\Comodo\CBOClean\BOCORE.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: TOSHIBA RAID Service (kraidsvc) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA RAID\Service\kraidsvc.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: TabletServicePen - Wacom Technology, Corp. - C:\WINDOWS\system32\Pen_Tablet.exe
O23 - Service: TOSHIBA HDD Protection (Thpsrv) - TOSHIBA Corporation - C:\WINDOWS\system32\ThpSrv.exe
O23 - Service: Tmesrv3 (Tmesrv) - Unknown owner - C:\Program Files\TOSHIBA\TME3\Tmesrv31.exe (file missing)
--
End of file - 8563 bytes
------------------------------------------------------------
Kaspersky scan is long, the files marked infected are:
Number of viruses found 23
Number of infected objects 95
Number of suspicious objects 0
C:\Documents and Settings\All Users\Application Data\BOC425\evidence.boc Infected: Trojan-Downloader.Win32.Injecter.li skipped
C:\Documents and Settings\boss\Local Settings\Temporary Internet Files\Content.IE5\BPH91119\kb516107[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.tsz skipped
C:\Documents and Settings\boss\Local Settings\Temporary Internet Files\Content.IE5\UDVJCIL4\kb516107[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.tsz skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP132\A0024166.exe/is153017.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.qij skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP132\A0024166.exe CAB: infected - 1 skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP132\A0024167.msi/is153017.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.qij skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP132\A0024167.msi CAB: infected - 1 skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP146\A0033497.exe/stream/data0010 Infected: not-a-virus:RiskTool.Win32.WFPDisabler.a skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP146\A0033497.exe/stream Infected: not-a-virus:RiskTool.Win32.WFPDisabler.a skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP146\A0033497.exe NSIS: infected - 2 skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP156\A0041542.dll Infected: Trojan-Downloader.Win32.Mutant.yq skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP156\A0041559.sys Infected: Trojan-Dropper.Win32.Agent.rek skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP156\A0041565.exe Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP157\A0041581.exe Infected: not-a-virus:AdWare.Win32.WebHancer.423 skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP157\A0041583.exe Infected: Trojan-Proxy.Win32.Small.oz skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP157\A0041584.sys Infected: Rootkit.Win32.Qandr.af skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP157\A0041586.exe Infected: Trojan.Win32.Agent.kwy skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP157\A0041587.exe Infected: Trojan-Downloader.Win32.Small.wab skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP157\A0041588.exe Infected: Trojan-Downloader.Win32.Homles.bp skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP157\A0041589.exe Infected: SpamTool.Win32.Agent.ip skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP157\A0041728.dll Infected: Trojan-Downloader.Win32.Mutant.yq skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP157\A0041729.dll Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP157\A0041730.dll Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP157\A0041731.exe Infected: Backdoor.Win32.Agent.ggk skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042033.exe Infected: Trojan-Downloader.Win32.Agent.plz skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042102.exe/data0000.cab/AUTOKE~1.EXE/data0000.cab/install.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.tsv skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042102.exe/data0000.cab/AUTOKE~1.EXE/data0000.cab Infected: not-a-virus:AdWare.Win32.Virtumonde.tsv skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042102.exe/data0000.cab/AUTOKE~1.EXE Infected: not-a-virus:AdWare.Win32.Virtumonde.tsv skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042102.exe/data0000.cab Infected: not-a-virus:AdWare.Win32.Virtumonde.tsv skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042102.exe Rsrc-Package: infected - 4 skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042111.exe/data0000.cab/TuneUp2008 Keymaker.exe Infected: Backdoor.Win32.Rbot.pfa skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042111.exe/data0000.cab/is154715.exe Infected: Trojan-Downloader.Win32.Injecter.li skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042111.exe/data0000.cab Infected: Trojan-Downloader.Win32.Injecter.li skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042111.exe Rsrc-Package: infected - 3 skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042112.exe/data0000.cab/is154715.exe Infected: Trojan-Downloader.Win32.Injecter.li skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042112.exe/data0000.cab Infected: Trojan-Downloader.Win32.Injecter.li skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042112.exe Rsrc-Package: infected - 2 skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042115.exe/data0000.cab/Keygen 2.exe Infected: Trojan-Downloader.Win32.Agent.ifq skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042115.exe/data0000.cab/is154715.exe Infected: Trojan-Downloader.Win32.Injecter.li skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042115.exe/data0000.cab Infected: Trojan-Downloader.Win32.Injecter.li skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042115.exe Rsrc-Package: infected - 3 skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042116.exe/data0000.cab/is154715.exe Infected: Trojan-Downloader.Win32.Injecter.li skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042116.exe/data0000.cab Infected: Trojan-Downloader.Win32.Injecter.li skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042116.exe Rsrc-Package: infected - 2 skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042117.exe/data0000.cab/is154715.exe Infected: Trojan-Downloader.Win32.Injecter.li skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042117.exe/data0000.cab Infected: Trojan-Downloader.Win32.Injecter.li skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042117.exe Rsrc-Package: infected - 2 skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042337.sys Infected: Trojan-Dropper.Win32.Agent.rek skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042339.sys Infected: Trojan-Dropper.Win32.Agent.rek skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042340.dll Infected: Trojan-Downloader.Win32.Mutant.yq skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042341.dll Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042342.dll Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP161\A0042343.exe Infected: Trojan-Downloader.Win32.Homles.bp skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP165\A0042691.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.tsz skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP166\A0042723.exe/data0000.cab/is154715.exe Infected: Trojan-Downloader.Win32.Injecter.li skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP166\A0042723.exe/data0000.cab Infected: Trojan-Downloader.Win32.Injecter.li skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP166\A0042723.exe Rsrc-Package: infected - 2 skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP166\A0042730.msi/is153553.exe Infected: Trojan.Win32.Zapchast.gb skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP166\A0042730.msi CAB: infected - 1 skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP166\A0042733.msi/is153553.exe Infected: Trojan.Win32.Zapchast.gb skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP166\A0042733.msi CAB: infected - 1 skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP166\change.log Object is locked skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP63\A0015753.exe/stream/data0050 Infected: not-a-virus:AdWare.Win32.Shopper.r skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP63\A0015753.exe/stream Infected: not-a-virus:AdWare.Win32.Shopper.r skipped
C:\System Volume Information\_restore{0C16E88B-C8D3-4B88-A534-8D600B484EB3}\RP63\A0015753.exe NSIS: infected - 2 skipped
C:\WINDOWS\system32\ddnpebes.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.tsz skipped
C:\WINDOWS\system32\jkkKaArP.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.trz skipped
C:\WINDOWS\system32\jyyddvmw.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.tsz skipped
C:\WINDOWS\system32\rqRKefDU.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.trz skipped
C:\WINDOWS\system32\rwouygkl.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.tsz skipped
C:\WINDOWS\system32\svchost.ex Infected: Trojan.Win32.Obfuscated.arg skipped
C:\WINDOWS\system32\WinNt32.dl_ Infected: Trojan-Downloader.Win32.Mutant.yq skipped
-----------------------------------------------------
Help is sincerely appreciated! Thank you in advance.