:sad
lease help my pc is infected with lots of problems
I have run spybot but they keep coming back.
Thanking you in advance.
Please find attached the hjt log and the kaspersky report
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:23:14, on 15/04/2008
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\BT\ISecP\App\syssvcnt.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Norton GoBack\GBPoll.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\BT\ISecP\app\Console.exe
C:\WINDOWS\system32\mcntklwd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Norton GoBack\GBTray.exe
C:\Program Files\RABCO\X_RABCOse.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sbwltbxa.exe,
O2 - BHO: (no name) - {00000250-0320-4dd4-be4f-7566d2314352} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {13197ace-6851-45c3-a7ff-c281324d5489} - (no file)
O2 - BHO: (no name) - {15651c7c-e812-44a2-a9ac-b467a2233e7d} - (no file)
O2 - BHO: AuthPopupBHO01.cBHO - {3C7195F6-D788-4D50-BA72-2EE212EDAC78} - C:\Program Files\BT\ISecP\App\popupbho01.dll
O2 - BHO: (no name) - {40659EC0-507E-7DAD-5713-5800B8C281BC} - C:\WINDOWS\System32\rxbws.dll (file missing)
O2 - BHO: (no name) - {4D63CDCD-5174-78A8-0413-5800B8C28BB7} - C:\WINDOWS\System32\sun.dll (file missing)
O2 - BHO: (no name) - {4e1075f4-eec4-4a86-add7-cd5f52858c31} - (no file)
O2 - BHO: (no name) - {4e7bd74f-2b8d-469e-92c6-ce7eb590a94d} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5929cd6e-2062-44a4-b2c5-2c7e78fbab38} - (no file)
O2 - BHO: (no name) - {5dafd089-24b1-4c5e-bd42-8ca72550717b} - (no file)
O2 - BHO: (no name) - {5fa6752a-c4a0-4222-88c2-928ae5ab4966} - (no file)
O2 - BHO: (no name) - {622cc208-b014-4fe0-801b-874a5e5e403a} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {8674aea0-9d3d-11d9-99dc-00600f9a01f1} - (no file)
O2 - BHO: (no name) - {8FD2108D-6D0A-4D19-BF5F-E93480873774} - C:\WINDOWS\System32\awvtr.dll (file missing)
O2 - BHO: (no name) - {965a592f-8efa-4250-8630-7960230792f1} - (no file)
O2 - BHO: (no name) - {9c5b2f29-1f46-4639-a6b4-828942301d3e} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-717765728274} - (no file)
O2 - BHO: (no name) - {ED120D76-BF31-412C-A99B-783C6676E128} - C:\WINDOWS\System32\cbxuttq.dll (file missing)
O2 - BHO: (no name) - {fc3a74e5-f281-4f10-ae1e-733078684f3c} - (no file)
O2 - BHO: {c368bf3d-36bf-84ab-a494-608bcf4417ff} - {ff7144fc-b806-494a-ba48-fb63d3fb863c} - C:\WINDOWS\System32\onwugvyd.dll (file missing)
O2 - BHO: (no name) - {ffff0001-0002-101a-a3c9-08002b2f49fb} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: BT Internet Security Pack Popup Blocker - {2C0A5F28-48D8-408B-9172-9C6121025BCE} - C:\Program Files\BT\ISecP\App\popupbho01.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ESP] C:\Program Files\BT\ISecP\app\start.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\mcntklwd.exe DWram
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [BM97687271] Rundll32.exe "C:\WINDOWS\System32\bymglxns.dll",s
O4 - HKLM\..\Run: [945b41ed] rundll32.exe "C:\WINDOWS\System32\wvitisnv.dll",b
O4 - HKLM\..\Run: [WMDM PMSP Service] C:\WINDOWS\system32\cssrss.exe
O4 - HKCU\..\Run: [Swso] "C:\PROGRA~1\COMMON~1\WNSXS~1\arpa.exe" -vt ndrv
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Jcwkaqb] C:\WINDOWS\s?mbols\d?xplore.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Deewoo.lnk = C:\WINDOWS\system32\mcntklwd.exe
O4 - Startup: DW_Start.lnk = C:\WINDOWS\system32\kjwnw64j.exe
O4 - Startup: RABCO - Auto Update.lnk = C:\Program Files\RABCO\RABCOse.exe
O4 - Global Startup: Norton GoBack.lnk = C:\Program Files\Norton GoBack\GBTray.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {1B4F9DD7-2D7C-44B5-9126-73206DA0AE75} (CNavigationManager Object) - http://www.btsecurity.bt.com/bt/bin/wizard.exe
O16 - DPF: {50BD5CDA-4BA8-4048-8FAA-763F222E41D8} - ms-its:mhtml:file://c:\\nores.mht!http://adxanet.net/code/chm/xpre.chm::/xpreload.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.adobe.com/pub/shockwave/cabs/flash/swflash.cab
O23 - Service: BT Internet Security Pack System Service (AuthSysSvc) - Authentium, Inc. - c:\Program Files\BT\ISecP\App\syssvcnt.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
O23 - Service: GoBack Polling Service (GBPoll) - Symantec Corporation - C:\Program Files\Norton GoBack\GBPoll.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hpdj - Unknown owner - C:\DOCUME~1\Kerr\LOCALS~1\Temp\hpdj.exe (file missing)
O23 - Service: Remote Registry RemoteRegistryWZCSVC (RemoteRegistryWZCSVC) - Unknown owner - C:\WINDOWS\System32\actxprxyc.exe
O23 - Service: Smart Card SCardSvrVSS (SCardSvrVSS) - Unknown owner - C:\WINDOWS\System32\advapi32k.exe
--
End of file - 8669 bytes-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Tuesday, April 15, 2008 1:14:42 PM
Operating System: Microsoft Windows XP Professional, (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 15/04/2008
Kaspersky Anti-Virus database records: 706125
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 25640
Number of viruses found: 16
Number of infected objects: 40
Number of suspicious objects: 18
Duration of the scan process: 01:06:26
Infected Object Name / Virus Name / Last Action
C:\94.tmp Infected: Trojan-PSW.Win32.Agent.afg skipped
C:\Documents and Settings\All Users\Application Data\Authentium\ESPC\prf\imdb.bin Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Authentium\ESPC\prf\{D2F5620D-8DB3-427d-9356-04AB08B907CB} Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Bluebeam Software\Brewery\V4\Printer Support\BBPDFPortMon.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SecondThoughtSTCLoader7.zip/stcloader.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SecondThoughtSTCLoader7.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC22.zip/bokja.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC22.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC33.zip/bokja.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC33.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SolutionsSearchAssistant12.zip/180ax.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SolutionsSearchAssistant12.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SolutionsSearchAssistant16.zip/180ax.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SolutionsSearchAssistant16.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SolutionsSearchAssistant22.zip/saap.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SolutionsSearchAssistant22.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SolutionsSearchAssistant9.zip/sais.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SolutionsSearchAssistant9.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Zango14.zip/zango.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Zango14.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Zango8.zip/zango.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Zango8.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\Kerr\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Kerr\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Kerr\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Kerr\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Kerr\Local Settings\Temp\.tt3.tmp/stream/data0007 Infected: not-a-virus:FraudTool.Win32.WinFixer.c skipped
C:\Documents and Settings\Kerr\Local Settings\Temp\.tt3.tmp/stream Infected: not-a-virus:FraudTool.Win32.WinFixer.c skipped
C:\Documents and Settings\Kerr\Local Settings\Temp\.tt3.tmp NSIS: infected - 2 skipped
C:\Documents and Settings\Kerr\Local Settings\Temp\.tt4.tmp/stream/data0007 Infected: not-a-virus:FraudTool.Win32.WinFixer.c skipped
C:\Documents and Settings\Kerr\Local Settings\Temp\.tt4.tmp/stream Infected: not-a-virus:FraudTool.Win32.WinFixer.c skipped
C:\Documents and Settings\Kerr\Local Settings\Temp\.tt4.tmp NSIS: infected - 2 skipped
C:\Documents and Settings\Kerr\Local Settings\Temp\.tt9D.tmp/stream/data0007 Infected: not-a-virus:FraudTool.Win32.WinFixer.c skipped
C:\Documents and Settings\Kerr\Local Settings\Temp\.tt9D.tmp/stream Infected: not-a-virus:FraudTool.Win32.WinFixer.c skipped
C:\Documents and Settings\Kerr\Local Settings\Temp\.tt9D.tmp NSIS: infected - 2 skipped
C:\Documents and Settings\Kerr\Local Settings\Temp\IjlVlclY.exe Infected: not-virus:Hoax.Win32.Renos.bhz skipped
C:\Documents and Settings\Kerr\Local Settings\Temp\~DF40A0.tmp Object is locked skipped
C:\Documents and Settings\Kerr\Local Settings\Temp\~DF7A44.tmp Object is locked skipped
C:\Documents and Settings\Kerr\Local Settings\Temporary Internet Files\Content.IE5\8RA3AT6X\file2[1].exe Infected: Trojan-PSW.Win32.Agent.afg skipped
C:\Documents and Settings\Kerr\Local Settings\Temporary Internet Files\Content.IE5\8RA3AT6X\file4[1].exe Object is locked skipped
C:\Documents and Settings\Kerr\Local Settings\Temporary Internet Files\Content.IE5\8RA3AT6X\mail[1] Object is locked skipped
C:\Documents and Settings\Kerr\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Kerr\Local Settings\Temporary Internet Files\Content.IE5\L4QUDBRA\index[1].html Object is locked skipped
C:\Documents and Settings\Kerr\Local Settings\Temporary Internet Files\Content.IE5\MQ07NFPQ\file1[1].exe Object is locked skipped
C:\Documents and Settings\Kerr\Local Settings\Temporary Internet Files\Content.IE5\QPEHKPCH\img[1] Object is locked skipped
C:\Documents and Settings\Kerr\Local Settings\Temporary Internet Files\Content.IE5\QPEHKPCH\index[2].html Infected: Trojan-Downloader.JS.Psyme.adn skipped
C:\Documents and Settings\Kerr\ntuser.dat Object is locked skipped
C:\Documents and Settings\Kerr\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\gobackio.bin Object is locked skipped
C:\Program Files\Outerinfo\OiUninstaller.exe/data0002 Infected: not-a-virus:AdWare.Win32.PurityScan.hh skipped
C:\Program Files\Outerinfo\OiUninstaller.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP209\A0016124.exe Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP209\A0016126.exe Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP209\A0016148.exe Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP209\A0016150.exe Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP209\A0016177.exe Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP209\A0016179.exe Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP209\A0016188.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP209\A0016190.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP209\A0016191.exe Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP209\A0016192.exe Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP209\A0016193.exe Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP238\A0020828.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP239\A0021909.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP239\A0021910.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP239\A0021911.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP239\A0021913.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP239\A0021919.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP239\A0021920.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP239\A0021923.exe/data0002 Infected: not-a-virus:AdWare.Win32.PurityScan.hh skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP239\A0021923.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP239\A0021926.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.at skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP239\A0025930.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP240\A0028986.exe Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP240\A0028988.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP240\A0028989.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP240\A0028991.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP240\A0028992.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.at skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP240\A0028996.exe Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP240\A0028997.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.at skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP240\A0029001.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP240\A0029005.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP240\A0030071.exe/data0002 Infected: not-a-virus:AdWare.Win32.PurityScan.hh skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP240\A0030071.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP241\A0032106.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP241\A0033159.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP241\A0033174.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP242\A0034174.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP243\A0036211.exe Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP243\A0036212.exe Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP243\A0036214.exe Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP243\A0036215.exe Infected: not-a-virus:AdWare.Win32.PurityScan.gw skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP243\A0036216.dll Infected: not-a-virus:AdWare.Win32.PurityScan.gv skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP243\A0036217.dll Infected: not-a-virus:AdWare.Win32.PurityScan.gv skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP243\A0036218.dll Infected: not-a-virus:AdWare.Win32.Rabio.h skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP243\A0036219.exe/data0002 Infected: not-a-virus:AdWare.Win32.TTC.d skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP243\A0036219.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP243\A0037284.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP243\A0037285.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP243\A0037287.exe Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP243\A0037289.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP243\A0037291.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP245\A0037374.exe Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP247\A0038418.exe Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP249\A0039455.dll Infected: Backdoor.Win32.Agent.frr skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP249\A0041465.exe Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP249\A0041485.ocx Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP249\A0041486.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP249\A0041487.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP249\A0041488.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP249\A0041489.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP249\A0041490.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP249\A0041491.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP249\A0041492.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP249\A0041493.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP249\A0041494.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP249\A0041495.exe Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP249\A0041496.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP249\A0041497.exe Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP249\A0041498.exe Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP250\A0043494.exe Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP250\A0043495.dll Infected: Packed.Win32.Monder.gen skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP250\A0043498.exe Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP250\A0043499.dll Object is locked skipped
C:\WINDOWS\Debug\oakley.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\default.htm Infected: not-virus:Hoax.HTML.Secureinvites.b skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\system32\3465282683.dat Object is locked skipped
C:\WINDOWS\system32\5FaNbu.syz Infected: Rootkit.Win32.Agent.ahs skipped
C:\WINDOWS\system32\9k72rW.syz Infected: Rootkit.Win32.Agent.ahs skipped
C:\WINDOWS\system32\actxprxyc.exe Object is locked skipped
C:\WINDOWS\system32\buRiCu.syz Infected: Rootkit.Win32.Agent.ahs skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\WINDOWS\system32\DaQs2X.syz Infected: Rootkit.Win32.Agent.ahs skipped
C:\WINDOWS\system32\GBh2KF.syz Infected: Rootkit.Win32.Agent.ahs skipped
C:\WINDOWS\system32\mcntklwb.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.aj skipped
C:\WINDOWS\system32\mcntklwd.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.at skipped
C:\WINDOWS\system32\nMBlAh.syz Infected: Rootkit.Win32.Agent.ahs skipped
C:\WINDOWS\system32\sncmpJ.syz Infected: Rootkit.Win32.Agent.ahs skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
Scan process completed.

I have run spybot but they keep coming back.
Thanking you in advance.
Please find attached the hjt log and the kaspersky report
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:23:14, on 15/04/2008
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\BT\ISecP\App\syssvcnt.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Norton GoBack\GBPoll.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\BT\ISecP\app\Console.exe
C:\WINDOWS\system32\mcntklwd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Norton GoBack\GBTray.exe
C:\Program Files\RABCO\X_RABCOse.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sbwltbxa.exe,
O2 - BHO: (no name) - {00000250-0320-4dd4-be4f-7566d2314352} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {13197ace-6851-45c3-a7ff-c281324d5489} - (no file)
O2 - BHO: (no name) - {15651c7c-e812-44a2-a9ac-b467a2233e7d} - (no file)
O2 - BHO: AuthPopupBHO01.cBHO - {3C7195F6-D788-4D50-BA72-2EE212EDAC78} - C:\Program Files\BT\ISecP\App\popupbho01.dll
O2 - BHO: (no name) - {40659EC0-507E-7DAD-5713-5800B8C281BC} - C:\WINDOWS\System32\rxbws.dll (file missing)
O2 - BHO: (no name) - {4D63CDCD-5174-78A8-0413-5800B8C28BB7} - C:\WINDOWS\System32\sun.dll (file missing)
O2 - BHO: (no name) - {4e1075f4-eec4-4a86-add7-cd5f52858c31} - (no file)
O2 - BHO: (no name) - {4e7bd74f-2b8d-469e-92c6-ce7eb590a94d} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5929cd6e-2062-44a4-b2c5-2c7e78fbab38} - (no file)
O2 - BHO: (no name) - {5dafd089-24b1-4c5e-bd42-8ca72550717b} - (no file)
O2 - BHO: (no name) - {5fa6752a-c4a0-4222-88c2-928ae5ab4966} - (no file)
O2 - BHO: (no name) - {622cc208-b014-4fe0-801b-874a5e5e403a} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {8674aea0-9d3d-11d9-99dc-00600f9a01f1} - (no file)
O2 - BHO: (no name) - {8FD2108D-6D0A-4D19-BF5F-E93480873774} - C:\WINDOWS\System32\awvtr.dll (file missing)
O2 - BHO: (no name) - {965a592f-8efa-4250-8630-7960230792f1} - (no file)
O2 - BHO: (no name) - {9c5b2f29-1f46-4639-a6b4-828942301d3e} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-717765728274} - (no file)
O2 - BHO: (no name) - {ED120D76-BF31-412C-A99B-783C6676E128} - C:\WINDOWS\System32\cbxuttq.dll (file missing)
O2 - BHO: (no name) - {fc3a74e5-f281-4f10-ae1e-733078684f3c} - (no file)
O2 - BHO: {c368bf3d-36bf-84ab-a494-608bcf4417ff} - {ff7144fc-b806-494a-ba48-fb63d3fb863c} - C:\WINDOWS\System32\onwugvyd.dll (file missing)
O2 - BHO: (no name) - {ffff0001-0002-101a-a3c9-08002b2f49fb} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: BT Internet Security Pack Popup Blocker - {2C0A5F28-48D8-408B-9172-9C6121025BCE} - C:\Program Files\BT\ISecP\App\popupbho01.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ESP] C:\Program Files\BT\ISecP\app\start.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\mcntklwd.exe DWram
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [BM97687271] Rundll32.exe "C:\WINDOWS\System32\bymglxns.dll",s
O4 - HKLM\..\Run: [945b41ed] rundll32.exe "C:\WINDOWS\System32\wvitisnv.dll",b
O4 - HKLM\..\Run: [WMDM PMSP Service] C:\WINDOWS\system32\cssrss.exe
O4 - HKCU\..\Run: [Swso] "C:\PROGRA~1\COMMON~1\WNSXS~1\arpa.exe" -vt ndrv
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Jcwkaqb] C:\WINDOWS\s?mbols\d?xplore.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Deewoo.lnk = C:\WINDOWS\system32\mcntklwd.exe
O4 - Startup: DW_Start.lnk = C:\WINDOWS\system32\kjwnw64j.exe
O4 - Startup: RABCO - Auto Update.lnk = C:\Program Files\RABCO\RABCOse.exe
O4 - Global Startup: Norton GoBack.lnk = C:\Program Files\Norton GoBack\GBTray.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {1B4F9DD7-2D7C-44B5-9126-73206DA0AE75} (CNavigationManager Object) - http://www.btsecurity.bt.com/bt/bin/wizard.exe
O16 - DPF: {50BD5CDA-4BA8-4048-8FAA-763F222E41D8} - ms-its:mhtml:file://c:\\nores.mht!http://adxanet.net/code/chm/xpre.chm::/xpreload.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.adobe.com/pub/shockwave/cabs/flash/swflash.cab
O23 - Service: BT Internet Security Pack System Service (AuthSysSvc) - Authentium, Inc. - c:\Program Files\BT\ISecP\App\syssvcnt.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
O23 - Service: GoBack Polling Service (GBPoll) - Symantec Corporation - C:\Program Files\Norton GoBack\GBPoll.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hpdj - Unknown owner - C:\DOCUME~1\Kerr\LOCALS~1\Temp\hpdj.exe (file missing)
O23 - Service: Remote Registry RemoteRegistryWZCSVC (RemoteRegistryWZCSVC) - Unknown owner - C:\WINDOWS\System32\actxprxyc.exe
O23 - Service: Smart Card SCardSvrVSS (SCardSvrVSS) - Unknown owner - C:\WINDOWS\System32\advapi32k.exe
--
End of file - 8669 bytes-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Tuesday, April 15, 2008 1:14:42 PM
Operating System: Microsoft Windows XP Professional, (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 15/04/2008
Kaspersky Anti-Virus database records: 706125
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 25640
Number of viruses found: 16
Number of infected objects: 40
Number of suspicious objects: 18
Duration of the scan process: 01:06:26
Infected Object Name / Virus Name / Last Action
C:\94.tmp Infected: Trojan-PSW.Win32.Agent.afg skipped
C:\Documents and Settings\All Users\Application Data\Authentium\ESPC\prf\imdb.bin Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Authentium\ESPC\prf\{D2F5620D-8DB3-427d-9356-04AB08B907CB} Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Bluebeam Software\Brewery\V4\Printer Support\BBPDFPortMon.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SecondThoughtSTCLoader7.zip/stcloader.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SecondThoughtSTCLoader7.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC22.zip/bokja.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC22.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC33.zip/bokja.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC33.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SolutionsSearchAssistant12.zip/180ax.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SolutionsSearchAssistant12.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SolutionsSearchAssistant16.zip/180ax.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SolutionsSearchAssistant16.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SolutionsSearchAssistant22.zip/saap.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SolutionsSearchAssistant22.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SolutionsSearchAssistant9.zip/sais.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SolutionsSearchAssistant9.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Zango14.zip/zango.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Zango14.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Zango8.zip/zango.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Zango8.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\Kerr\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Kerr\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Kerr\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Kerr\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Kerr\Local Settings\Temp\.tt3.tmp/stream/data0007 Infected: not-a-virus:FraudTool.Win32.WinFixer.c skipped
C:\Documents and Settings\Kerr\Local Settings\Temp\.tt3.tmp/stream Infected: not-a-virus:FraudTool.Win32.WinFixer.c skipped
C:\Documents and Settings\Kerr\Local Settings\Temp\.tt3.tmp NSIS: infected - 2 skipped
C:\Documents and Settings\Kerr\Local Settings\Temp\.tt4.tmp/stream/data0007 Infected: not-a-virus:FraudTool.Win32.WinFixer.c skipped
C:\Documents and Settings\Kerr\Local Settings\Temp\.tt4.tmp/stream Infected: not-a-virus:FraudTool.Win32.WinFixer.c skipped
C:\Documents and Settings\Kerr\Local Settings\Temp\.tt4.tmp NSIS: infected - 2 skipped
C:\Documents and Settings\Kerr\Local Settings\Temp\.tt9D.tmp/stream/data0007 Infected: not-a-virus:FraudTool.Win32.WinFixer.c skipped
C:\Documents and Settings\Kerr\Local Settings\Temp\.tt9D.tmp/stream Infected: not-a-virus:FraudTool.Win32.WinFixer.c skipped
C:\Documents and Settings\Kerr\Local Settings\Temp\.tt9D.tmp NSIS: infected - 2 skipped
C:\Documents and Settings\Kerr\Local Settings\Temp\IjlVlclY.exe Infected: not-virus:Hoax.Win32.Renos.bhz skipped
C:\Documents and Settings\Kerr\Local Settings\Temp\~DF40A0.tmp Object is locked skipped
C:\Documents and Settings\Kerr\Local Settings\Temp\~DF7A44.tmp Object is locked skipped
C:\Documents and Settings\Kerr\Local Settings\Temporary Internet Files\Content.IE5\8RA3AT6X\file2[1].exe Infected: Trojan-PSW.Win32.Agent.afg skipped
C:\Documents and Settings\Kerr\Local Settings\Temporary Internet Files\Content.IE5\8RA3AT6X\file4[1].exe Object is locked skipped
C:\Documents and Settings\Kerr\Local Settings\Temporary Internet Files\Content.IE5\8RA3AT6X\mail[1] Object is locked skipped
C:\Documents and Settings\Kerr\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Kerr\Local Settings\Temporary Internet Files\Content.IE5\L4QUDBRA\index[1].html Object is locked skipped
C:\Documents and Settings\Kerr\Local Settings\Temporary Internet Files\Content.IE5\MQ07NFPQ\file1[1].exe Object is locked skipped
C:\Documents and Settings\Kerr\Local Settings\Temporary Internet Files\Content.IE5\QPEHKPCH\img[1] Object is locked skipped
C:\Documents and Settings\Kerr\Local Settings\Temporary Internet Files\Content.IE5\QPEHKPCH\index[2].html Infected: Trojan-Downloader.JS.Psyme.adn skipped
C:\Documents and Settings\Kerr\ntuser.dat Object is locked skipped
C:\Documents and Settings\Kerr\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\gobackio.bin Object is locked skipped
C:\Program Files\Outerinfo\OiUninstaller.exe/data0002 Infected: not-a-virus:AdWare.Win32.PurityScan.hh skipped
C:\Program Files\Outerinfo\OiUninstaller.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP209\A0016124.exe Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP209\A0016126.exe Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP209\A0016148.exe Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP209\A0016150.exe Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP209\A0016177.exe Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP209\A0016179.exe Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP209\A0016188.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP209\A0016190.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP209\A0016191.exe Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP209\A0016192.exe Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP209\A0016193.exe Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP238\A0020828.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP239\A0021909.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP239\A0021910.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP239\A0021911.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP239\A0021913.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP239\A0021919.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP239\A0021920.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP239\A0021923.exe/data0002 Infected: not-a-virus:AdWare.Win32.PurityScan.hh skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP239\A0021923.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP239\A0021926.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.at skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP239\A0025930.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP240\A0028986.exe Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP240\A0028988.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP240\A0028989.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP240\A0028991.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP240\A0028992.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.at skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP240\A0028996.exe Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP240\A0028997.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.at skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP240\A0029001.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP240\A0029005.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP240\A0030071.exe/data0002 Infected: not-a-virus:AdWare.Win32.PurityScan.hh skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP240\A0030071.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP241\A0032106.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP241\A0033159.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP241\A0033174.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP242\A0034174.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP243\A0036211.exe Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP243\A0036212.exe Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP243\A0036214.exe Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP243\A0036215.exe Infected: not-a-virus:AdWare.Win32.PurityScan.gw skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP243\A0036216.dll Infected: not-a-virus:AdWare.Win32.PurityScan.gv skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP243\A0036217.dll Infected: not-a-virus:AdWare.Win32.PurityScan.gv skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP243\A0036218.dll Infected: not-a-virus:AdWare.Win32.Rabio.h skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP243\A0036219.exe/data0002 Infected: not-a-virus:AdWare.Win32.TTC.d skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP243\A0036219.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP243\A0037284.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP243\A0037285.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP243\A0037287.exe Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP243\A0037289.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP243\A0037291.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP245\A0037374.exe Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP247\A0038418.exe Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP249\A0039455.dll Infected: Backdoor.Win32.Agent.frr skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP249\A0041465.exe Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP249\A0041485.ocx Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP249\A0041486.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP249\A0041487.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP249\A0041488.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP249\A0041489.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP249\A0041490.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP249\A0041491.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP249\A0041492.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP249\A0041493.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP249\A0041494.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP249\A0041495.exe Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP249\A0041496.dll Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP249\A0041497.exe Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP249\A0041498.exe Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP250\A0043494.exe Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP250\A0043495.dll Infected: Packed.Win32.Monder.gen skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP250\A0043498.exe Object is locked skipped
C:\System Volume Information\_restore{7487559D-6B8D-43D3-BF31-93E843FD5092}\RP250\A0043499.dll Object is locked skipped
C:\WINDOWS\Debug\oakley.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\default.htm Infected: not-virus:Hoax.HTML.Secureinvites.b skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\system32\3465282683.dat Object is locked skipped
C:\WINDOWS\system32\5FaNbu.syz Infected: Rootkit.Win32.Agent.ahs skipped
C:\WINDOWS\system32\9k72rW.syz Infected: Rootkit.Win32.Agent.ahs skipped
C:\WINDOWS\system32\actxprxyc.exe Object is locked skipped
C:\WINDOWS\system32\buRiCu.syz Infected: Rootkit.Win32.Agent.ahs skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\WINDOWS\system32\DaQs2X.syz Infected: Rootkit.Win32.Agent.ahs skipped
C:\WINDOWS\system32\GBh2KF.syz Infected: Rootkit.Win32.Agent.ahs skipped
C:\WINDOWS\system32\mcntklwb.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.aj skipped
C:\WINDOWS\system32\mcntklwd.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.at skipped
C:\WINDOWS\system32\nMBlAh.syz Infected: Rootkit.Win32.Agent.ahs skipped
C:\WINDOWS\system32\sncmpJ.syz Infected: Rootkit.Win32.Agent.ahs skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
Scan process completed.