here is the kaspersky and HJT log
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Tuesday, April 15, 2008 12:47:49 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 15/04/2008
Kaspersky Anti-Virus database records: 705072
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
Scan Statistics:
Total number of scanned objects: 86142
Number of viruses found: 27
Number of infected objects: 163
Number of suspicious objects: 0
Duration of the scan process: 01:16:26
Infected Object Name / Virus Name / Last Action
C:\1weicxa.com Infected: Trojan-PSW.Win32.OnLineGames.woo skipped
C:\autorun.inf Infected: Worm.Win32.AutoRun.dcz skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\PC Tools\PC Tools AntiVirus\Report Logs\Report39552.855995370373.xml Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Confid.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Content.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Privacy.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Restrict.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\WebHist.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2008-04-14_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped
C:\Documents and Settings\allan\cftmon.exe Infected: Worm.Win32.Socks.by skipped
C:\Documents and Settings\allan\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\allan\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\allan\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\allan\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\allan\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\allan\Local Settings\History\History.IE5\MSHist012008041420080415\index.dat Object is locked skipped
C:\Documents and Settings\allan\Local Settings\Temp\1312.tmp Infected: Trojan-Downloader.Win32.Delf.dke skipped
C:\Documents and Settings\allan\Local Settings\Temp\aajc.dll Infected: Trojan-PSW.Win32.OnLineGames.xlx skipped
C:\Documents and Settings\allan\Local Settings\Temp\BNBF.tmp Infected: Trojan-Downloader.Win32.Agent.mkb skipped
C:\Documents and Settings\allan\Local Settings\Temp\BNC1.tmp Infected: Trojan-Downloader.Win32.Agent.mkb skipped
C:\Documents and Settings\allan\Local Settings\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\allan\Local Settings\Temp\ee77xdv.dll Infected: Worm.Win32.AutoRun.cvy skipped
C:\Documents and Settings\allan\Local Settings\Temp\f.dll Infected: Trojan-PSW.Win32.OnLineGames.ulc skipped
C:\Documents and Settings\allan\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\allan\Local Settings\Temp\k2fvpt.dll Infected: Trojan-PSW.Win32.OnLineGames.tdc skipped
C:\Documents and Settings\allan\Local Settings\Temp\MediaBar.exe/stream/data0005 Infected: not-a-virus:AdWare.Win32.Mostofate.aa skipped
C:\Documents and Settings\allan\Local Settings\Temp\MediaBar.exe/stream Infected: not-a-virus:AdWare.Win32.Mostofate.aa skipped
C:\Documents and Settings\allan\Local Settings\Temp\MediaBar.exe NSIS: infected - 2 skipped
C:\Documents and Settings\allan\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\allan\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\allan\Local Settings\Temporary Internet Files\Content.IE5\81D78T0X\lmmqrv[1].htm Infected: not-a-virus:AdWare.Win32.Virtumonde.mcg skipped
C:\Documents and Settings\allan\Local Settings\Temporary Internet Files\Content.IE5\81D78T0X\us[1].exe Infected: Trojan-Spy.Win32.Zbot.avh skipped
C:\Documents and Settings\allan\Local Settings\Temporary Internet Files\Content.IE5\81D78T0X\vsskkopgtx[1].htm Infected: Worm.Win32.Socks.by skipped
C:\Documents and Settings\allan\Local Settings\Temporary Internet Files\Content.IE5\F3OL5S8Y\ddos[1].htm Infected: Trojan-Downloader.Win32.Mutant.jz skipped
C:\Documents and Settings\allan\Local Settings\Temporary Internet Files\Content.IE5\F3OL5S8Y\nwabo[1].txt Infected: Trojan-Downloader.Win32.Agent.mws skipped
C:\Documents and Settings\allan\Local Settings\Temporary Internet Files\Content.IE5\F3OL5S8Y\sgxllcqhhy[1].htm Infected: Trojan-Clicker.Win32.Costrat.fl skipped
C:\Documents and Settings\allan\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\allan\Local Settings\Temporary Internet Files\Content.IE5\LSW5XE76\AccessMediaSetup[1].exe Infected: Trojan-Downloader.Win32.Delf.dke skipped
C:\Documents and Settings\allan\Local Settings\Temporary Internet Files\Content.IE5\LSW5XE76\drv32[1].data Infected: Trojan-Downloader.Win32.Peregar.bs skipped
C:\Documents and Settings\allan\Local Settings\Temporary Internet Files\Content.IE5\LSW5XE76\iftkk[1].htm Infected: Trojan-Downloader.Win32.Agent.lxt skipped
C:\Documents and Settings\allan\Local Settings\Temporary Internet Files\Content.IE5\LSW5XE76\us[1].exe Infected: Trojan-Spy.Win32.Zbot.avh skipped
C:\Documents and Settings\allan\Local Settings\Temporary Internet Files\Content.IE5\YWQPHH3P\ddos1[1].htm Infected: Trojan-Downloader.Win32.Mutant.jz skipped
C:\Documents and Settings\allan\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\allan\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\cftmon.exe Infected: Worm.Win32.Socks.by skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsys.dll Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDALRT.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDCON.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDDBG.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDFW.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDIDS.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDSYS.log Object is locked skipped
C:\Program Files\PC Tools AntiVirus\PCTAVService.txt Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP325\A0039632.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jad skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP328\A0040702.exe/AntiSpywareApp/Launcher.exe Infected: not-a-virus:FraudTool.Win32.AntiSpyware.j skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP328\A0040702.exe 7-Zip: infected - 1 skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP328\A0040702.exe UPX: infected - 1 skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP328\A0040702.exe PE_Patch.UPX: infected - 1 skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP328\A0040710.exe Infected: not-a-virus:FraudTool.Win32.AntiSpyware.j skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP330\A0040795.inf Infected: Worm.Win32.AutoRun.cnw skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP330\A0040870.inf Infected: Worm.Win32.AutoRun.cnw skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP330\A0040882.inf Infected: Worm.Win32.AutoRun.cnw skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP331\A0040940.inf Infected: Trojan-PSW.Win32.OnLineGames.ssx skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP332\A0040961.inf Infected: Trojan-PSW.Win32.OnLineGames.ssx skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP332\A0041349.inf Infected: Trojan-PSW.Win32.OnLineGames.ssx skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP333\A0041363.exe Infected: Worm.Win32.AutoRun.cvy skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP333\A0041364.inf Infected: Worm.Win32.AutoRun.cvy skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP334\A0041519.exe Infected: Worm.Win32.AutoRun.cvy skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP334\A0041520.inf Infected: Worm.Win32.AutoRun.cvy skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP335\A0041540.exe Infected: Worm.Win32.AutoRun.cvy skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP335\A0041541.inf Infected: Worm.Win32.AutoRun.cvy skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP336\A0041558.exe Infected: Worm.Win32.AutoRun.cvy skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP336\A0041559.inf Infected: Worm.Win32.AutoRun.cvy skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP337\A0041608.exe Infected: Worm.Win32.AutoRun.cvy skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP337\A0041609.inf Infected: Worm.Win32.AutoRun.cvy skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP338\A0041632.exe Infected: Worm.Win32.AutoRun.cvy skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP338\A0041633.inf Infected: Worm.Win32.AutoRun.cvy skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP339\A0041718.exe Infected: Worm.Win32.AutoRun.cvy skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP339\A0041719.inf Infected: Worm.Win32.AutoRun.cvy skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP339\A0041721.exe Infected: Worm.Win32.AutoRun.cvy skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP339\A0041732.dll Infected: Worm.Win32.AutoRun.cvy skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP339\A0041733.exe Infected: Worm.Win32.AutoRun.cvy skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP339\A0041734.dll Infected: Worm.Win32.AutoRun.cvy skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP339\A0041738.inf Infected: Worm.Win32.AutoRun.cvy skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP339\A0041767.inf Infected: Trojan-PSW.Win32.OnLineGames.uhv skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP340\A0041778.inf Infected: Trojan-PSW.Win32.OnLineGames.uhv skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP341\A0041800.inf Infected: Trojan-PSW.Win32.OnLineGames.uhv skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP342\A0041807.inf Infected: Trojan-PSW.Win32.OnLineGames.uhv skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP343\A0041816.inf Infected: Trojan-PSW.Win32.OnLineGames.uhv skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP344\A0041857.inf Infected: Trojan-PSW.Win32.OnLineGames.uhv skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP345\A0041903.inf Infected: Trojan-PSW.Win32.OnLineGames.uhv skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP346\A0041905.inf Infected: Trojan-PSW.Win32.OnLineGames.uhv skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP346\A0042083.inf Infected: Trojan-PSW.Win32.OnLineGames.uhv skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP346\A0042102.com Infected: Trojan-PSW.Win32.OnLineGames.woo skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP346\A0042103.inf Infected: Worm.Win32.AutoRun.dcz skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP347\A0042124.com Infected: Trojan-PSW.Win32.OnLineGames.woo skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP347\A0042125.inf Infected: Worm.Win32.AutoRun.dcz skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP348\A0042318.com Infected: Trojan-PSW.Win32.OnLineGames.woo skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP348\A0042319.inf Infected: Worm.Win32.AutoRun.dcz skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP349\A0042372.com Infected: Trojan-PSW.Win32.OnLineGames.woo skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP349\A0042373.inf Infected: Worm.Win32.AutoRun.dcz skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP350\A0042383.com Infected: Trojan-PSW.Win32.OnLineGames.woo skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP350\A0042384.inf Infected: Worm.Win32.AutoRun.dcz skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP351\A0042392.com Infected: Trojan-PSW.Win32.OnLineGames.woo skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP351\A0042393.inf Infected: Worm.Win32.AutoRun.dcz skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP352\A0042421.com Infected: Trojan-PSW.Win32.OnLineGames.woo skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP352\A0042422.inf Infected: Worm.Win32.AutoRun.dcz skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP352\A0042824.dll Infected: Trojan-PSW.Win32.OnLineGames.won skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP352\A0042825.com Infected: Trojan-PSW.Win32.OnLineGames.woo skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP352\A0042826.inf Infected: Worm.Win32.AutoRun.dcz skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP353\A0042836.com Infected: Trojan-PSW.Win32.OnLineGames.woo skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP353\A0042837.inf Infected: Worm.Win32.AutoRun.dcz skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP354\A0042845.com Infected: Trojan-PSW.Win32.OnLineGames.woo skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP354\A0042846.inf Infected: Worm.Win32.AutoRun.dcz skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP354\A0042989.dll Infected: Trojan-PSW.Win32.OnLineGames.won skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP354\A0042991.com Infected: Trojan-PSW.Win32.OnLineGames.woo skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP354\A0042992.inf Infected: Worm.Win32.AutoRun.dcz skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP355\A0043013.com Infected: Trojan-PSW.Win32.OnLineGames.woo skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP355\A0043014.inf Infected: Worm.Win32.AutoRun.dcz skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP356\A0043109.com Infected: Trojan-PSW.Win32.OnLineGames.woo skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP356\A0043110.inf Infected: Worm.Win32.AutoRun.dcz skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP356\A0043396.dll Infected: Trojan-PSW.Win32.OnLineGames.won skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP356\A0043397.com Infected: Trojan-PSW.Win32.OnLineGames.woo skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP356\A0043398.inf Infected: Worm.Win32.AutoRun.dcz skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0043414.com Infected: Trojan-PSW.Win32.OnLineGames.woo skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0043415.inf Infected: Worm.Win32.AutoRun.dcz skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0044389.dll Infected: Trojan-Downloader.Win32.Mutant.lb skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0044393.exe Infected: Worm.Win32.Socks.by skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0044394.dll Infected: Trojan-PSW.Win32.OnLineGames.won skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0044395.com Infected: Trojan-PSW.Win32.OnLineGames.woo skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0044396.inf Infected: Worm.Win32.AutoRun.dcz skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0044404.sys Infected: Trojan-Downloader.Win32.Agent.lxa skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045389.dll Infected: Trojan-Downloader.Win32.Mutant.lb skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045393.exe Infected: Worm.Win32.Socks.by skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045394.dll Infected: Trojan-PSW.Win32.OnLineGames.won skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045396.com Infected: Trojan-PSW.Win32.OnLineGames.woo skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045397.inf Infected: Worm.Win32.AutoRun.dcz skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045404.exe Infected: Worm.Win32.Socks.by skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045405.exe Infected: Trojan-Downloader.Win32.Agent.mws skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045407.exe Infected: Trojan-Clicker.Win32.Costrat.fl skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045409.exe Infected: Worm.Win32.Socks.by skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045569.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mcg skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045575.dll Infected: Trojan-Downloader.Win32.Mutant.lb skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045584.dll Infected: Trojan-PSW.Win32.OnLineGames.won skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045585.com Infected: Trojan-PSW.Win32.OnLineGames.woo skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045586.inf Infected: Worm.Win32.AutoRun.dcz skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045596.exe Infected: Worm.Win32.Socks.by skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045598.sys Infected: Trojan-Downloader.Win32.Agent.lxa skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045602.dll Infected: Trojan-Downloader.Win32.Mutant.lb skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045606.sys Infected: Trojan-Downloader.Win32.Agent.lxa skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045612.dll Infected: Trojan-Downloader.Win32.Mutant.lb skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045616.sys Infected: Trojan-Downloader.Win32.Agent.lxa skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045618.dll Infected: Trojan-PSW.Win32.OnLineGames.won skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045619.com Infected: Trojan-PSW.Win32.OnLineGames.woo skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045620.inf Infected: Worm.Win32.AutoRun.dcz skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045637.dll Infected: Trojan-Downloader.Win32.Mutant.lb skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045641.sys Infected: Trojan-Downloader.Win32.Agent.lxa skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045644.exe Infected: Worm.Win32.Socks.by skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045645.exe Infected: Worm.Win32.Socks.by skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045652.dll Infected: Trojan-Downloader.Win32.Mutant.lr skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045657.sys Infected: Trojan-Downloader.Win32.Agent.lxa skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045660.dll Infected: Trojan-Downloader.Win32.Mutant.lr skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045664.sys Infected: Trojan-Downloader.Win32.Agent.lxa skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045668.dll Infected: Trojan-PSW.Win32.OnLineGames.won skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045675.com Infected: Trojan-PSW.Win32.OnLineGames.woo skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045676.inf Infected: Worm.Win32.AutoRun.dcz skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045679.exe Infected: Worm.Win32.Socks.by skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045687.exe Infected: Worm.Win32.Socks.by skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045736.dll Infected: Trojan-Downloader.Win32.Mutant.hx skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045742.sys Infected: Trojan-Downloader.Win32.Agent.lxa skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045746.dll Infected: Trojan-Downloader.Win32.Mutant.lr skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045750.sys Infected: Trojan-Downloader.Win32.Agent.lxa skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045754.dll Infected: Trojan-PSW.Win32.OnLineGames.won skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045755.com Infected: Trojan-PSW.Win32.OnLineGames.woo skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045756.inf Infected: Worm.Win32.AutoRun.dcz skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045760.exe Infected: Worm.Win32.Socks.by skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045768.exe Infected: Worm.Win32.Socks.by skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045773.dll Infected: Trojan-Downloader.Win32.Mutant.lr skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045778.sys Infected: Trojan-Downloader.Win32.Agent.lxa skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045785.dll Infected: Trojan-Downloader.Win32.Mutant.lr skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045789.sys Infected: Trojan-Downloader.Win32.Agent.lxa skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045795.dll Infected: Trojan-PSW.Win32.OnLineGames.won skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045796.com Infected: Trojan-PSW.Win32.OnLineGames.woo skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045797.inf Infected: Worm.Win32.AutoRun.dcz skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\change.log Object is locked skipped
C:\uisvkqr.exe Infected: Worm.Win32.AutoRun.cvy skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\ModemLog_Motorola SM56 Data Fax Modem.txt Object is locked skipped
C:\WINDOWS\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{27278167-C094-41C9-8015-37AEC9C015D0}.crmlog Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{7C429D16-CF5E-4A72-9F9C-15DA3ACA648A}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\amvo.exe Infected: Trojan-PSW.Win32.OnLineGames.woo skipped
C:\WINDOWS\system32\amvo0.dll Infected: Trojan-PSW.Win32.OnLineGames.won skipped
C:\WINDOWS\system32\amvo1.dll Infected: Trojan-PSW.Win32.OnLineGames.won skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\Media Ce.evt Object is locked skipped
C:\WINDOWS\system32\config\ODiag.evt Object is locked skipped
C:\WINDOWS\system32\config\OSession.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008041420080415\index.dat Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\FP9I1C84\fl8_ATT%20Wireless%20BrideBar01%20-%20300x270-600[1].flv Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\WINDOWS\system32\drivers\spools.exe Infected: Worm.Win32.Socks.by skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\system32\WLCtrl32.dll Infected: Trojan-Downloader.Win32.Mutant.lr skipped
C:\WINDOWS\system32\WLCtrl32.dl_ Infected: Trojan-Downloader.Win32.Mutant.lr skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
HJT log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:50:52 PM, on 4/14/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\ATK0100\HControl.exe
C:\WINDOWS\sm56hlpr.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\allan\cftmon.exe
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\FileOpen\plug_ins\FileOpenAPI.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\PC Tools AntiVirus\PCTAV.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.2.7:11
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\ntos.exe,
O2 - BHO: C:\WINDOWS\system32\jfiehayd.dll - {c5af49a2-94f3-42bd-f434-2604812c897d} - C:\WINDOWS\system32\jfiehayd.dll (file missing)
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [EOUApp] "C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [jdgf894jrghoiiskd] C:\DOCUME~1\allan\LOCALS~1\Temp\winlogan.exe
O4 - HKLM\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe
O4 - HKLM\..\Run: [PCTAVApp] "C:\Program Files\PC Tools AntiVirus\PCTAV.exe" /MONITORSCAN
O4 - HKLM\..\Run: [autoload] C:\Documents and Settings\allan\cftmon.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AntiSpyware] C:\Program Files\AntiSpywareApp\Antispyware.exe -boot
O4 - HKCU\..\Run: [amva] C:\WINDOWS\system32\amvo.exe
O4 - HKCU\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe
O4 - HKCU\..\Run: [jdgf894jrghoiiskd] C:\DOCUME~1\allan\LOCALS~1\Temp\winlogan.exe
O4 - HKCU\..\Run: [Jnskdfmf9eldfd] C:\DOCUME~1\allan\LOCALS~1\Temp\csrssc.exe
O4 - HKCU\..\Run: [autoload] C:\Documents and Settings\allan\cftmon.exe
O4 - HKUS\S-1-5-18\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Jnskdfmf9eldfd] C:\WINDOWS\TEMP\csrssc.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [autoload] C:\Documents and Settings\LocalService\cftmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe (User 'Default user')
O4 - Startup: FileOpenAPI.exe.lnk = C:\Program Files\FileOpen\plug_ins\FileOpenAPI.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {0eb0e74a-2a76-4ab3-a7fb-9bd8c29f7f75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {B991DA79-51F7-4011-98D2-1F2592E82A56} (ACNPlayer2 Class) - http://drm1.reelsurvey.com/ePlayer/V3_2_0_0/ACNePlayer.cab
O16 - DPF: {CE8267C2-D41A-4A50-A69D-F32B5C289F14} (FileOpenInstaller) - http://plugin.fileopen.com/current/FileOpen.CAB
O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} (Facebook Photo Uploader 4) - http://upload.facebook.com/controls/FacebookPhotoUploader4_5.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O20 - Winlogon Notify: hlphiaby - hlphiaby.dll (file missing)
O20 - Winlogon Notify: tuvwvur - tuvwvur.dll (file missing)
O20 - Winlogon Notify: wlctrl32 - C:\WINDOWS\SYSTEM32\WLCtrl32.dll
O22 - SharedTaskScheduler: jhsf8d984jief8dsfus98jkefn - {C5AF49A2-94F3-42BD-F434-2604812C897D} - C:\WINDOWS\system32\jfiehayd.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: PC Tools AntiVirus Engine (pctavsvc) - PC Tools Research Pty Ltd - C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Task Scheduler (Schedule) - Unknown owner - C:\WINDOWS\system32\drivers\spools.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
--
End of file - 12896 bytes
I appreciate the help with this issue.
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Tuesday, April 15, 2008 12:47:49 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 15/04/2008
Kaspersky Anti-Virus database records: 705072
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
Scan Statistics:
Total number of scanned objects: 86142
Number of viruses found: 27
Number of infected objects: 163
Number of suspicious objects: 0
Duration of the scan process: 01:16:26
Infected Object Name / Virus Name / Last Action
C:\1weicxa.com Infected: Trojan-PSW.Win32.OnLineGames.woo skipped
C:\autorun.inf Infected: Worm.Win32.AutoRun.dcz skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\PC Tools\PC Tools AntiVirus\Report Logs\Report39552.855995370373.xml Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Confid.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Content.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Privacy.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Restrict.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\WebHist.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2008-04-14_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped
C:\Documents and Settings\allan\cftmon.exe Infected: Worm.Win32.Socks.by skipped
C:\Documents and Settings\allan\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\allan\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\allan\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\allan\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\allan\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\allan\Local Settings\History\History.IE5\MSHist012008041420080415\index.dat Object is locked skipped
C:\Documents and Settings\allan\Local Settings\Temp\1312.tmp Infected: Trojan-Downloader.Win32.Delf.dke skipped
C:\Documents and Settings\allan\Local Settings\Temp\aajc.dll Infected: Trojan-PSW.Win32.OnLineGames.xlx skipped
C:\Documents and Settings\allan\Local Settings\Temp\BNBF.tmp Infected: Trojan-Downloader.Win32.Agent.mkb skipped
C:\Documents and Settings\allan\Local Settings\Temp\BNC1.tmp Infected: Trojan-Downloader.Win32.Agent.mkb skipped
C:\Documents and Settings\allan\Local Settings\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\allan\Local Settings\Temp\ee77xdv.dll Infected: Worm.Win32.AutoRun.cvy skipped
C:\Documents and Settings\allan\Local Settings\Temp\f.dll Infected: Trojan-PSW.Win32.OnLineGames.ulc skipped
C:\Documents and Settings\allan\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\allan\Local Settings\Temp\k2fvpt.dll Infected: Trojan-PSW.Win32.OnLineGames.tdc skipped
C:\Documents and Settings\allan\Local Settings\Temp\MediaBar.exe/stream/data0005 Infected: not-a-virus:AdWare.Win32.Mostofate.aa skipped
C:\Documents and Settings\allan\Local Settings\Temp\MediaBar.exe/stream Infected: not-a-virus:AdWare.Win32.Mostofate.aa skipped
C:\Documents and Settings\allan\Local Settings\Temp\MediaBar.exe NSIS: infected - 2 skipped
C:\Documents and Settings\allan\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\allan\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\allan\Local Settings\Temporary Internet Files\Content.IE5\81D78T0X\lmmqrv[1].htm Infected: not-a-virus:AdWare.Win32.Virtumonde.mcg skipped
C:\Documents and Settings\allan\Local Settings\Temporary Internet Files\Content.IE5\81D78T0X\us[1].exe Infected: Trojan-Spy.Win32.Zbot.avh skipped
C:\Documents and Settings\allan\Local Settings\Temporary Internet Files\Content.IE5\81D78T0X\vsskkopgtx[1].htm Infected: Worm.Win32.Socks.by skipped
C:\Documents and Settings\allan\Local Settings\Temporary Internet Files\Content.IE5\F3OL5S8Y\ddos[1].htm Infected: Trojan-Downloader.Win32.Mutant.jz skipped
C:\Documents and Settings\allan\Local Settings\Temporary Internet Files\Content.IE5\F3OL5S8Y\nwabo[1].txt Infected: Trojan-Downloader.Win32.Agent.mws skipped
C:\Documents and Settings\allan\Local Settings\Temporary Internet Files\Content.IE5\F3OL5S8Y\sgxllcqhhy[1].htm Infected: Trojan-Clicker.Win32.Costrat.fl skipped
C:\Documents and Settings\allan\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\allan\Local Settings\Temporary Internet Files\Content.IE5\LSW5XE76\AccessMediaSetup[1].exe Infected: Trojan-Downloader.Win32.Delf.dke skipped
C:\Documents and Settings\allan\Local Settings\Temporary Internet Files\Content.IE5\LSW5XE76\drv32[1].data Infected: Trojan-Downloader.Win32.Peregar.bs skipped
C:\Documents and Settings\allan\Local Settings\Temporary Internet Files\Content.IE5\LSW5XE76\iftkk[1].htm Infected: Trojan-Downloader.Win32.Agent.lxt skipped
C:\Documents and Settings\allan\Local Settings\Temporary Internet Files\Content.IE5\LSW5XE76\us[1].exe Infected: Trojan-Spy.Win32.Zbot.avh skipped
C:\Documents and Settings\allan\Local Settings\Temporary Internet Files\Content.IE5\YWQPHH3P\ddos1[1].htm Infected: Trojan-Downloader.Win32.Mutant.jz skipped
C:\Documents and Settings\allan\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\allan\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\cftmon.exe Infected: Worm.Win32.Socks.by skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsys.dll Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDALRT.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDCON.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDDBG.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDFW.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDIDS.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDSYS.log Object is locked skipped
C:\Program Files\PC Tools AntiVirus\PCTAVService.txt Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP325\A0039632.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jad skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP328\A0040702.exe/AntiSpywareApp/Launcher.exe Infected: not-a-virus:FraudTool.Win32.AntiSpyware.j skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP328\A0040702.exe 7-Zip: infected - 1 skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP328\A0040702.exe UPX: infected - 1 skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP328\A0040702.exe PE_Patch.UPX: infected - 1 skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP328\A0040710.exe Infected: not-a-virus:FraudTool.Win32.AntiSpyware.j skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP330\A0040795.inf Infected: Worm.Win32.AutoRun.cnw skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP330\A0040870.inf Infected: Worm.Win32.AutoRun.cnw skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP330\A0040882.inf Infected: Worm.Win32.AutoRun.cnw skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP331\A0040940.inf Infected: Trojan-PSW.Win32.OnLineGames.ssx skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP332\A0040961.inf Infected: Trojan-PSW.Win32.OnLineGames.ssx skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP332\A0041349.inf Infected: Trojan-PSW.Win32.OnLineGames.ssx skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP333\A0041363.exe Infected: Worm.Win32.AutoRun.cvy skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP333\A0041364.inf Infected: Worm.Win32.AutoRun.cvy skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP334\A0041519.exe Infected: Worm.Win32.AutoRun.cvy skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP334\A0041520.inf Infected: Worm.Win32.AutoRun.cvy skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP335\A0041540.exe Infected: Worm.Win32.AutoRun.cvy skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP335\A0041541.inf Infected: Worm.Win32.AutoRun.cvy skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP336\A0041558.exe Infected: Worm.Win32.AutoRun.cvy skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP336\A0041559.inf Infected: Worm.Win32.AutoRun.cvy skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP337\A0041608.exe Infected: Worm.Win32.AutoRun.cvy skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP337\A0041609.inf Infected: Worm.Win32.AutoRun.cvy skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP338\A0041632.exe Infected: Worm.Win32.AutoRun.cvy skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP338\A0041633.inf Infected: Worm.Win32.AutoRun.cvy skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP339\A0041718.exe Infected: Worm.Win32.AutoRun.cvy skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP339\A0041719.inf Infected: Worm.Win32.AutoRun.cvy skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP339\A0041721.exe Infected: Worm.Win32.AutoRun.cvy skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP339\A0041732.dll Infected: Worm.Win32.AutoRun.cvy skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP339\A0041733.exe Infected: Worm.Win32.AutoRun.cvy skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP339\A0041734.dll Infected: Worm.Win32.AutoRun.cvy skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP339\A0041738.inf Infected: Worm.Win32.AutoRun.cvy skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP339\A0041767.inf Infected: Trojan-PSW.Win32.OnLineGames.uhv skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP340\A0041778.inf Infected: Trojan-PSW.Win32.OnLineGames.uhv skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP341\A0041800.inf Infected: Trojan-PSW.Win32.OnLineGames.uhv skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP342\A0041807.inf Infected: Trojan-PSW.Win32.OnLineGames.uhv skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP343\A0041816.inf Infected: Trojan-PSW.Win32.OnLineGames.uhv skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP344\A0041857.inf Infected: Trojan-PSW.Win32.OnLineGames.uhv skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP345\A0041903.inf Infected: Trojan-PSW.Win32.OnLineGames.uhv skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP346\A0041905.inf Infected: Trojan-PSW.Win32.OnLineGames.uhv skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP346\A0042083.inf Infected: Trojan-PSW.Win32.OnLineGames.uhv skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP346\A0042102.com Infected: Trojan-PSW.Win32.OnLineGames.woo skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP346\A0042103.inf Infected: Worm.Win32.AutoRun.dcz skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP347\A0042124.com Infected: Trojan-PSW.Win32.OnLineGames.woo skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP347\A0042125.inf Infected: Worm.Win32.AutoRun.dcz skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP348\A0042318.com Infected: Trojan-PSW.Win32.OnLineGames.woo skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP348\A0042319.inf Infected: Worm.Win32.AutoRun.dcz skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP349\A0042372.com Infected: Trojan-PSW.Win32.OnLineGames.woo skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP349\A0042373.inf Infected: Worm.Win32.AutoRun.dcz skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP350\A0042383.com Infected: Trojan-PSW.Win32.OnLineGames.woo skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP350\A0042384.inf Infected: Worm.Win32.AutoRun.dcz skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP351\A0042392.com Infected: Trojan-PSW.Win32.OnLineGames.woo skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP351\A0042393.inf Infected: Worm.Win32.AutoRun.dcz skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP352\A0042421.com Infected: Trojan-PSW.Win32.OnLineGames.woo skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP352\A0042422.inf Infected: Worm.Win32.AutoRun.dcz skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP352\A0042824.dll Infected: Trojan-PSW.Win32.OnLineGames.won skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP352\A0042825.com Infected: Trojan-PSW.Win32.OnLineGames.woo skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP352\A0042826.inf Infected: Worm.Win32.AutoRun.dcz skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP353\A0042836.com Infected: Trojan-PSW.Win32.OnLineGames.woo skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP353\A0042837.inf Infected: Worm.Win32.AutoRun.dcz skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP354\A0042845.com Infected: Trojan-PSW.Win32.OnLineGames.woo skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP354\A0042846.inf Infected: Worm.Win32.AutoRun.dcz skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP354\A0042989.dll Infected: Trojan-PSW.Win32.OnLineGames.won skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP354\A0042991.com Infected: Trojan-PSW.Win32.OnLineGames.woo skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP354\A0042992.inf Infected: Worm.Win32.AutoRun.dcz skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP355\A0043013.com Infected: Trojan-PSW.Win32.OnLineGames.woo skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP355\A0043014.inf Infected: Worm.Win32.AutoRun.dcz skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP356\A0043109.com Infected: Trojan-PSW.Win32.OnLineGames.woo skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP356\A0043110.inf Infected: Worm.Win32.AutoRun.dcz skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP356\A0043396.dll Infected: Trojan-PSW.Win32.OnLineGames.won skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP356\A0043397.com Infected: Trojan-PSW.Win32.OnLineGames.woo skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP356\A0043398.inf Infected: Worm.Win32.AutoRun.dcz skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0043414.com Infected: Trojan-PSW.Win32.OnLineGames.woo skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0043415.inf Infected: Worm.Win32.AutoRun.dcz skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0044389.dll Infected: Trojan-Downloader.Win32.Mutant.lb skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0044393.exe Infected: Worm.Win32.Socks.by skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0044394.dll Infected: Trojan-PSW.Win32.OnLineGames.won skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0044395.com Infected: Trojan-PSW.Win32.OnLineGames.woo skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0044396.inf Infected: Worm.Win32.AutoRun.dcz skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0044404.sys Infected: Trojan-Downloader.Win32.Agent.lxa skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045389.dll Infected: Trojan-Downloader.Win32.Mutant.lb skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045393.exe Infected: Worm.Win32.Socks.by skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045394.dll Infected: Trojan-PSW.Win32.OnLineGames.won skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045396.com Infected: Trojan-PSW.Win32.OnLineGames.woo skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045397.inf Infected: Worm.Win32.AutoRun.dcz skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045404.exe Infected: Worm.Win32.Socks.by skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045405.exe Infected: Trojan-Downloader.Win32.Agent.mws skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045407.exe Infected: Trojan-Clicker.Win32.Costrat.fl skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045409.exe Infected: Worm.Win32.Socks.by skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045569.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mcg skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045575.dll Infected: Trojan-Downloader.Win32.Mutant.lb skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045584.dll Infected: Trojan-PSW.Win32.OnLineGames.won skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045585.com Infected: Trojan-PSW.Win32.OnLineGames.woo skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045586.inf Infected: Worm.Win32.AutoRun.dcz skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045596.exe Infected: Worm.Win32.Socks.by skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045598.sys Infected: Trojan-Downloader.Win32.Agent.lxa skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045602.dll Infected: Trojan-Downloader.Win32.Mutant.lb skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045606.sys Infected: Trojan-Downloader.Win32.Agent.lxa skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045612.dll Infected: Trojan-Downloader.Win32.Mutant.lb skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045616.sys Infected: Trojan-Downloader.Win32.Agent.lxa skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045618.dll Infected: Trojan-PSW.Win32.OnLineGames.won skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045619.com Infected: Trojan-PSW.Win32.OnLineGames.woo skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045620.inf Infected: Worm.Win32.AutoRun.dcz skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045637.dll Infected: Trojan-Downloader.Win32.Mutant.lb skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045641.sys Infected: Trojan-Downloader.Win32.Agent.lxa skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045644.exe Infected: Worm.Win32.Socks.by skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045645.exe Infected: Worm.Win32.Socks.by skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045652.dll Infected: Trojan-Downloader.Win32.Mutant.lr skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045657.sys Infected: Trojan-Downloader.Win32.Agent.lxa skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045660.dll Infected: Trojan-Downloader.Win32.Mutant.lr skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045664.sys Infected: Trojan-Downloader.Win32.Agent.lxa skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045668.dll Infected: Trojan-PSW.Win32.OnLineGames.won skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045675.com Infected: Trojan-PSW.Win32.OnLineGames.woo skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045676.inf Infected: Worm.Win32.AutoRun.dcz skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045679.exe Infected: Worm.Win32.Socks.by skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045687.exe Infected: Worm.Win32.Socks.by skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045736.dll Infected: Trojan-Downloader.Win32.Mutant.hx skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045742.sys Infected: Trojan-Downloader.Win32.Agent.lxa skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045746.dll Infected: Trojan-Downloader.Win32.Mutant.lr skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045750.sys Infected: Trojan-Downloader.Win32.Agent.lxa skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045754.dll Infected: Trojan-PSW.Win32.OnLineGames.won skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045755.com Infected: Trojan-PSW.Win32.OnLineGames.woo skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045756.inf Infected: Worm.Win32.AutoRun.dcz skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045760.exe Infected: Worm.Win32.Socks.by skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045768.exe Infected: Worm.Win32.Socks.by skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045773.dll Infected: Trojan-Downloader.Win32.Mutant.lr skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045778.sys Infected: Trojan-Downloader.Win32.Agent.lxa skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045785.dll Infected: Trojan-Downloader.Win32.Mutant.lr skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045789.sys Infected: Trojan-Downloader.Win32.Agent.lxa skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045795.dll Infected: Trojan-PSW.Win32.OnLineGames.won skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045796.com Infected: Trojan-PSW.Win32.OnLineGames.woo skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\A0045797.inf Infected: Worm.Win32.AutoRun.dcz skipped
C:\System Volume Information\_restore{8DC34318-AC3B-40ED-B6BB-FA6679A29239}\RP357\change.log Object is locked skipped
C:\uisvkqr.exe Infected: Worm.Win32.AutoRun.cvy skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\ModemLog_Motorola SM56 Data Fax Modem.txt Object is locked skipped
C:\WINDOWS\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{27278167-C094-41C9-8015-37AEC9C015D0}.crmlog Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{7C429D16-CF5E-4A72-9F9C-15DA3ACA648A}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\amvo.exe Infected: Trojan-PSW.Win32.OnLineGames.woo skipped
C:\WINDOWS\system32\amvo0.dll Infected: Trojan-PSW.Win32.OnLineGames.won skipped
C:\WINDOWS\system32\amvo1.dll Infected: Trojan-PSW.Win32.OnLineGames.won skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\Media Ce.evt Object is locked skipped
C:\WINDOWS\system32\config\ODiag.evt Object is locked skipped
C:\WINDOWS\system32\config\OSession.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008041420080415\index.dat Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\FP9I1C84\fl8_ATT%20Wireless%20BrideBar01%20-%20300x270-600[1].flv Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\WINDOWS\system32\drivers\spools.exe Infected: Worm.Win32.Socks.by skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\system32\WLCtrl32.dll Infected: Trojan-Downloader.Win32.Mutant.lr skipped
C:\WINDOWS\system32\WLCtrl32.dl_ Infected: Trojan-Downloader.Win32.Mutant.lr skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
HJT log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:50:52 PM, on 4/14/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\ATK0100\HControl.exe
C:\WINDOWS\sm56hlpr.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\allan\cftmon.exe
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\FileOpen\plug_ins\FileOpenAPI.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\PC Tools AntiVirus\PCTAV.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.2.7:11
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\ntos.exe,
O2 - BHO: C:\WINDOWS\system32\jfiehayd.dll - {c5af49a2-94f3-42bd-f434-2604812c897d} - C:\WINDOWS\system32\jfiehayd.dll (file missing)
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [EOUApp] "C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [jdgf894jrghoiiskd] C:\DOCUME~1\allan\LOCALS~1\Temp\winlogan.exe
O4 - HKLM\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe
O4 - HKLM\..\Run: [PCTAVApp] "C:\Program Files\PC Tools AntiVirus\PCTAV.exe" /MONITORSCAN
O4 - HKLM\..\Run: [autoload] C:\Documents and Settings\allan\cftmon.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AntiSpyware] C:\Program Files\AntiSpywareApp\Antispyware.exe -boot
O4 - HKCU\..\Run: [amva] C:\WINDOWS\system32\amvo.exe
O4 - HKCU\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe
O4 - HKCU\..\Run: [jdgf894jrghoiiskd] C:\DOCUME~1\allan\LOCALS~1\Temp\winlogan.exe
O4 - HKCU\..\Run: [Jnskdfmf9eldfd] C:\DOCUME~1\allan\LOCALS~1\Temp\csrssc.exe
O4 - HKCU\..\Run: [autoload] C:\Documents and Settings\allan\cftmon.exe
O4 - HKUS\S-1-5-18\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Jnskdfmf9eldfd] C:\WINDOWS\TEMP\csrssc.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [autoload] C:\Documents and Settings\LocalService\cftmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe (User 'Default user')
O4 - Startup: FileOpenAPI.exe.lnk = C:\Program Files\FileOpen\plug_ins\FileOpenAPI.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {0eb0e74a-2a76-4ab3-a7fb-9bd8c29f7f75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {B991DA79-51F7-4011-98D2-1F2592E82A56} (ACNPlayer2 Class) - http://drm1.reelsurvey.com/ePlayer/V3_2_0_0/ACNePlayer.cab
O16 - DPF: {CE8267C2-D41A-4A50-A69D-F32B5C289F14} (FileOpenInstaller) - http://plugin.fileopen.com/current/FileOpen.CAB
O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} (Facebook Photo Uploader 4) - http://upload.facebook.com/controls/FacebookPhotoUploader4_5.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O20 - Winlogon Notify: hlphiaby - hlphiaby.dll (file missing)
O20 - Winlogon Notify: tuvwvur - tuvwvur.dll (file missing)
O20 - Winlogon Notify: wlctrl32 - C:\WINDOWS\SYSTEM32\WLCtrl32.dll
O22 - SharedTaskScheduler: jhsf8d984jief8dsfus98jkefn - {C5AF49A2-94F3-42BD-F434-2604812C897D} - C:\WINDOWS\system32\jfiehayd.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: PC Tools AntiVirus Engine (pctavsvc) - PC Tools Research Pty Ltd - C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Task Scheduler (Schedule) - Unknown owner - C:\WINDOWS\system32\drivers\spools.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
--
End of file - 12896 bytes
I appreciate the help with this issue.