piratenews
New member
Spybot was unable to remove this RED item in SAFE mode, it just came back twice on reboot:
Product: Win32.Soundmix
Threat: Trojan
Win32.Soundmix copies itself as soundmix.exe into the system directory and pretends to be a soundmixer. It starts itself in autorun as "soundmix" without user consent. It also adds itself to the exefile shell open command so that it will be started synchronously with every other exe file.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:45:20 PM, on 5/29/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Tall Emu\Online Armor\oasrv.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\igfxtray.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\Tall Emu\Online Armor\oaui.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
file:///E:/September911surprise%20CTV/PirateNews-org/Homepage/index2.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
F2 - REG:system.ini: Shell=Explorer.exe
N2 - Netscape 6: user_pref("browser.startup.homepage", "http://home.netscape.com/"); (C:\Documents and Settings\JOHN
LEE\Application Data\Mozilla\Profiles\default\f5sn9q7e.slt\prefs.js)
N2 - Netscape 6: user_pref("browser.search.defaultengine", "http://www.google.com/"); (C:\Documents and Settings\JOHN
LEE\Application Data\Mozilla\Profiles\default\f5sn9q7e.slt\prefs.js)
O2 - BHO: (no name) - {344B7EF2-9819-299E-51CB-018EEAA2D736} - C:\WINDOWS\system32\admdsc.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autofix
O4 - HKLM\..\Run: [OnlineArmor GUI] "C:\Program Files\Tall Emu\Online Armor\oaui.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKLM\..\Policies\Explorer\Run: [dhprthpl] rundll32.exe "C:\WINDOWS\system32\rdpthj.sys" WLEntryPoint
O4 - HKUS\S-1-5-21-1420582129-1497244195-3520757181-1006\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &
Destroy\TeaTimer.exe (User '?')
O8 - Extra context menu item: Save Flash with Flash Catcher - res://C:\Program Files\Common
Files\Justdo\IECatcher.DLL/FlashCatcher.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} -
C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\torapcfm.dll
O15 - Trusted Zone: http://www.archive.org
O15 - Trusted Zone: http://tvplanner.comcast.net
O15 - Trusted Zone: http://www.comcast.net
O15 - Trusted Zone: http://www.disabilityforms.com
O15 - Trusted Zone: http://www.fireflyfans.net
O15 - Trusted Zone: http://www.infowars.com
O15 - Trusted Zone: http://www.infowars.net
O15 - Trusted Zone: http://*.infowars.net
O15 - Trusted Zone: http://*.myspace.com
O15 - Trusted Zone: http://ww2.nero.com
O15 - Trusted Zone: http://vhost.oddcast.com
O15 - Trusted Zone: http://flash.picturetail.com
O15 - Trusted Zone: http://www.picturetrail.com
O15 - Trusted Zone: *.picturetrail.com
O15 - Trusted Zone: http://forums.spybot.info
O15 - Trusted Zone: http://www.tallemu.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {8436FE12-31DB-48BF-83BF-FE682F9160B4} (NanoInstaller Class) - http://www.nanoscan.com/cabs/nanoinst.cab
O20 - Winlogon Notify: hgnid - C:\WINDOWS\
O20 - Winlogon Notify: WLCtrl32 - C:\WINDOWS\SYSTEM32\WLCtrl32.dll
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common
Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Online Armor (SvcOnlineArmor) - Tall Emu - C:\Program Files\Tall Emu\Online Armor\oasrv.exe
--
End of file - 4947 bytes
===========================================
KASPERSKY ONLINE SCANNER REPORT
Thursday, May 29, 2008 4:14:00 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 29/05/2008
Kaspersky Anti-Virus database records: 812154
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 185169
Number of viruses found: 93
Number of infected objects: 719
Number of suspicious objects: 4
Duration of the scan process: 02:09:28
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\bspefqpk\tufmlwnu.exe Infected: Trojan.Win32.Obfuscated.gx skipped
C:\Documents and Settings\All Users\Application Data\cnifshqp\uzqpkbcb.exe Infected: Trojan.Win32.Obfuscated.gx skipped
C:\Documents and Settings\All Users\Application Data\danwhoha\fmhurabo.exe Infected: Trojan.Win32.Obfuscated.gx skipped
C:\Documents and Settings\All Users\Application Data\dgxwxyjw\xqvkngze.exe Infected: Trojan.Win32.Obfuscated.gx skipped
C:\Documents and Settings\All Users\Application Data\dsxmtkvi\vijcnshy.exe Infected: Trojan.Win32.Obfuscated.gx skipped
C:\Documents and Settings\All Users\Application Data\dunwjghm\jmdifsvi.exe Infected: Trojan.Win32.Obfuscated.gx skipped
C:\Documents and Settings\All Users\Application Data\fmpkrczw\bajylylq.exe Infected: Trojan.Win32.Obfuscated.gx skipped
C:\Documents and Settings\All Users\Application Data\fspmjgfy\tibatqzc.exe Infected: Trojan.Win32.Obfuscated.gx skipped
C:\Documents and Settings\All Users\Application Data\fyvgtytu\jobkzwry.exe Infected: Trojan.Win32.Obfuscated.gx skipped
C:\Documents and Settings\All Users\Application Data\hydmhcby\rmxodsla.exe Infected: Trojan.Win32.Obfuscated.gx skipped
C:\Documents and Settings\All Users\Application Data\izgtgbct\qbetelyx.exe Infected: Trojan.Win32.Obfuscated.gx skipped
C:\Documents and Settings\All Users\Application Data\jahihoxw\fqpajude.exe Infected: Trojan.Win32.Obfuscated.gx skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\mlqdwxef.dll Infected: Trojan.Win32.Obfuscated.sc skipped
C:\Documents and Settings\All Users\Application Data\obunarah.dll Infected: Trojan.Win32.Obfuscated.sc skipped
C:\Documents and Settings\All Users\Application Data\parifcpm\jkhsvujc.exe Infected: Trojan.Win32.Obfuscated.gx skipped
C:\Documents and Settings\All Users\Application Data\qtglohyd\qpuxgzan.exe Infected: Trojan.Win32.Obfuscated.gx skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\PWSLDPinchIE5.zip/partnership.dll Infected: Trojan-Proxy.Win32.Xorpix.dg skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\PWSLDPinchIE5.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC.zip/vedxga1me4t1.exe Infected: Trojan-Downloader.Win32.Tibs.wh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC1.zip/vedxg4am1et2.exe Infected: Trojan-Downloader.Win32.Tibs.wh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC1.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC14.zip/dllgh8jkd1q2.exe Infected: Trojan-Downloader.Win32.Tibs.wh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC14.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC15.zip/dllgh8jkd1q6.exe Infected: Trojan-Downloader.Win32.Tibs.wh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC15.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC16.zip/dllgh8jkd1q7.exe Infected: Trojan-Downloader.Win32.Tibs.wh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC16.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC2.zip/vedxga3me2.exe Infected: Trojan-Downloader.Win32.VB.ded skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC2.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC3.zip/vedxga4me1.exe Infected: Trojan-Downloader.Win32.Small.cxx skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC3.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC4.zip/vedxg6ame4.exe Infected: Trojan-Downloader.Win32.Tibs.wh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC4.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC5.zip/wind32.exe Infected: Trojan-Downloader.Win32.Tibs.vz skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC5.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC7.zip/desktop.html Infected: not-virus:Hoax.Win32.Renos.cy skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC7.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC9.zip/BraveSentry0.dll Infected: not-a-virus:FraudTool.Win32.BraveSentry.f skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC9.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric.zip/autorun.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric1.zip/svchost.exe Infected: Trojan-Downloader.Win32.Small.svi skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric1.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric2.zip/autorun.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric2.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SpySheriff1.zip/SpySheriff.exe Infected: not-a-virus:FraudTool.Win32.SpySheriff.a skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SpySheriff1.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SpySheriff6.zip/heur000.dll Infected: not-a-virus:FraudTool.Win32.SpySheriff.a skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SpySheriff6.zip/heur001.dll Infected: not-a-virus:FraudTool.Win32.SpySheriff.a skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SpySheriff6.zip/heur002.dll Infected: not-a-virus:FraudTool.Win32.SpySheriff.a skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SpySheriff6.zip/heur003.dll Infected: not-a-virus:FraudTool.Win32.SpySheriff.a skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SpySheriff6.zip ZIP: infected - 4 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde10.zip/syslook.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde10.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde11.zip/sys16.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde11.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde12.zip/synsv.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde12.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde13.zip/powersys.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde13.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde14.zip/poweragent.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde14.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde15.zip/hostwin.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde15.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde17.zip/shift.exe.exe Infected: Email-Worm.Win32.Zhelatin.vg skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde17.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde4.zip/mljgh.dll Infected: Trojan-Spy.Win32.Agent.hn skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde4.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde5.zip/syssys.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde5.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde55.zip/printer.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde55.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde6.zip/monpower.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde6.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde64.zip/printer.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde64.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde8.zip/avp.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde8.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde82.zip/printer.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde82.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde85.zip/printer.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde85.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde99.zip/printer.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde99.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack.zip/shell.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack1.zip/spoolvs.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack1.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack10.zip/spoolvs.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack10.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack11.zip/findfast.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack11.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack12.zip/printer.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack12.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack15.zip/printer.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack15.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack16.zip/findfast.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack16.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack17.zip/spoolvs.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack17.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack18.zip/shell.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack18.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack19.zip/printer.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack19.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack2.zip/printer.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack2.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack20.zip/spoolvs.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack20.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack21.zip/shell.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack21.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack22.zip/printer.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack22.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack23.zip/spoolvs.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack23.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack24.zip/shell.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack24.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack26.zip/printer.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack26.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack27.zip/findfast.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack27.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack28.zip/spoolvs.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack28.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack29.zip/xloader30029.exe Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack29.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack30.zip/shell.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack30.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack4.zip/shell.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack4.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack5.zip/spoolvs.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack5.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack6.zip/findfast.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack6.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack7.zip/printer.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack7.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack9.zip/shell.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack9.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbid4.zip/winlogon.exe Infected: Trojan-Proxy.Win32.Small.kx skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbid4.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinBHOje10.zip/1205424199.dll Infected: not-a-virus:AdWare.Win32.E404.f skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinBHOje10.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinBHOje6.zip/1205424199.dll Infected: not-a-virus:AdWare.Win32.E404.f skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinBHOje6.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinGBDialerj.zip/npdl.exe Infected: not-a-virus
orn-Dialer.Win32.GBDialer.j skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinGBDialerj.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinLoadAdvh.zip/hlpsrv.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinLoadAdvh.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh10.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh10.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh13.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh13.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh16.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh16.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh19.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh19.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh2.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh2.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh21.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh21.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh25.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh25.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh28.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh28.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh30.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh30.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh33.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh33.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh36.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh36.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh39.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh39.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh4.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh4.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh41.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh41.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh43.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh43.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh46.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh46.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh48.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh48.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh51.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh51.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh53.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh53.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh56.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh56.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh58.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh58.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh60.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh60.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh63.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh63.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh66.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh66.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh68.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh68.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh7.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh7.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinSmallazl2.zip/mrofinu27.exe Infected: Trojan-Downloader.Win32.Agent.lbx skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinSmallazl2.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Zlockuc.zip/onuxuped.dll Infected: not-a-virus:AdWare.Win32.Agent.wk skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Zlockuc.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\stwjkzmz\qvkfkfej.exe Infected: Trojan.Win32.Obfuscated.gx skipped
C:\Documents and Settings\All Users\Application Data\vmxkzufk\jevmxazo.exe Infected: Trojan.Win32.Obfuscated.gx skipped
C:\Documents and Settings\All Users\Application Data\whulahat\ynehglit.exe Infected: Trojan.Win32.Obfuscated.gx skipped
C:\Documents and Settings\All Users\Application Data\yvktobmb\yjolabel.exe Infected: Trojan-Dropper.Win32.Agent.amm skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/Documents and Settings/John Lee/Local Settings/Temp/0.EXE Infected: Trojan-Downloader.Win32.Small.ius skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/Documents and Settings/John Lee/Local Settings/Temp/1922.tmp Infected: Trojan-Downloader.Win32.Agent.lcx skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/Documents and Settings/John Lee/Local Settings/Temp/csrssc.exe Infected: Trojan-Downloader.Win32.Suurch.dw skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/Documents and Settings/John Lee/Local Settings/Temp/file834.exe Infected: Trojan-Spy.Win32.Zbot.amb skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/WINDOWS/temp/1.dllb Infected: Trojan-Downloader.Win32.Tibs.wh skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/WINDOWS/temp/2.dllb Infected: Trojan-Downloader.Win32.Tibs.wh skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/WINDOWS/temp/238A.tmp Infected: Trojan-Downloader.Win32.Zlob.jbe skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/WINDOWS/temp/5.dllb Infected: Trojan-Downloader.Win32.Tibs.wh skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/WINDOWS/temp/6.dllb Infected: Trojan-Downloader.Win32.Tibs.wh skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/WINDOWS/temp/63.tmp Infected: Trojan.Win32.Pakes.cix skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/WINDOWS/temp/7.dllb Infected: Trojan-Downloader.Win32.Tibs.wh skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/WINDOWS/temp/A984.tmp Infected: Trojan-Downloader.Win32.Agent.lcx skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/WINDOWS/temp/codec.exe Infected: Trojan-Downloader.Win32.Zlob.jhh skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/WINDOWS/temp/D5.tmp Infected: Trojan-Downloader.Win32.Flux.eh skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/WINDOWS/temp/dpdbjf.drv Infected: Email-Worm.Win32.Locksky.cm skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/WINDOWS/temp/G5F-tmp.exe Infected: Trojan-Downloader.Win32.Flux.eh skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/WINDOWS/temp/iframestat.exe Infected: Trojan-Downloader.Win32.Tibs.vz skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/WINDOWS/temp/kfmtonetcrm.drv Infected: Email-Worm.Win32.Locksky.cm skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/WINDOWS/temp/lebsbord.exe Infected: Email-Worm.Win32.Locksky.da skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/WINDOWS/temp/lhdtpp.dll Infected: Email-Worm.Win32.Locksky.cm skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/WINDOWS/temp/sh.exe Infected: Trojan-Downloader.Win32.Agent.lab skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/WINDOWS/temp/tmp.exe Infected: Backdoor.Win32.Agent.fnb skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/Program Files/WinBudget/bin/crap.1165507431.old/data0000 Infected: Trojan-Clicker.Win32.BHO.r skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/Program Files/WinBudget/bin/crap.1165507431.old Infected: Trojan-Clicker.Win32.BHO.r skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/Program Files/WinBudget/bin/matrix.dll.1165951424.old Infected: Trojan-Clicker.Win32.BHO.r skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/Program Files/WinBudget/bin/matrix.dll.1166051149.old Infected: Trojan-Clicker.Win32.BHO.r skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/Program Files/WinBudget/bin/matrix.dll.1166073115.old Infected: Trojan-Clicker.Win32.BHO.r skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/Program Files/WinBudget/bin/matrix.dll.1166394446.old Infected: Trojan-Clicker.Win32.BHO.r skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/Program Files/WinBudget/bin/matrix.dll.1167002879.old Infected: Trojan-Clicker.Win32.BHO.r skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/Program Files/WinBudget/bin/matrix.dll.1167199060.old Infected: Trojan-Clicker.Win32.BHO.r skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/Program Files/WinBudget/bin/matrix.dll.1167455550.old Infected: Trojan-Clicker.Win32.BHO.r skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/Program Files/WinBudget/bin/matrix.dll.1167715835.old Infected: Trojan-Clicker.Win32.BHO.r skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/Program Files/WinBudget/bin/matrix.dll.1168035795.old Infected: Trojan-Clicker.Win32.BHO.r skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/Program Files/WinBudget/bin/matrix.dll.1168242245.old Infected: Trojan-Clicker.Win32.BHO.r skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/Program Files/WinBudget/bin/matrix.dll.1168519775.old Infected: Trojan-Clicker.Win32.BHO.r skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/Program Files/WinBudget/bin/matrix.dll.1168936518.old Infected: Trojan-Clicker.Win32.BHO.r skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU ZIP: infected - 36 skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/WINDOWS/TEMP/BN1.tmp Infected: Backdoor.Win32.Agobot.pbq skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/WINDOWS/TEMP/BN2.tmp Infected: Backdoor.Win32.Agobot.pbq skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/WINDOWS/TEMP/BN6A.tmp Infected: Backdoor.Win32.Agobot.pbq skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/WINDOWS/TEMP/BND.tmp Infected: Backdoor.Win32.Agobot.pbq skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/WINDOWS/TEMP/ldlddpldttt.nls Infected: Email-Worm.Win32.Locksky.cm skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/WINDOWS/TEMP/nhphhhtlpht.nls Infected: Email-Worm.Win32.Locksky.cm skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/WINDOWS/TEMP/sjapcrahsjq.dll Infected: Email-Worm.Win32.Locksky.cm skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/WINDOWS/TEMP/ttnhtlpp.drv Infected: Email-Worm.Win32.Locksky.cm skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/10.tmp Infected: Trojan-Spy.Win32.Zbot.arw skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/13.tmp Infected: Trojan-Spy.Win32.Zbot.arw skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/14.tmp Infected: Trojan-Spy.Win32.Zbot.arw skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/1A.tmp Infected: Trojan-Spy.Win32.Zbot.arw skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/1D.tmp Infected: Trojan-Spy.Win32.Zbot.arw skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/1E.tmp Infected: Trojan-Spy.Win32.Zbot.arw skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/1F.tmp Infected: Trojan-Spy.Win32.Zbot.arw skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/22D7.tmp Infected: Trojan-Spy.Win32.Zbot.arw skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/22D8.tmp Infected: Trojan-Spy.Win32.Zbot.arw skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/25.tmp Infected: Trojan-Spy.Win32.Zbot.arw skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/27.tmp Infected: Trojan-Spy.Win32.Zbot.arw skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/2A.tmp Infected: Trojan-Spy.Win32.Zbot.arw skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/2B.tmp Infected: Trojan-Spy.Win32.Zbot.arw skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/2D.tmp Infected: Trojan-Spy.Win32.Zbot.arw skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/30.tmp Infected: Trojan-Spy.Win32.Zbot.arw skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/39.tmp Infected: Trojan-Spy.Win32.Zbot.arw skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/5.tmp Infected: Trojan-Spy.Win32.Zbot.arw skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/6.tmp Infected: Trojan-Spy.Win32.Zbot.arw skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/8.tmp Infected: Trojan-Spy.Win32.Zbot.arw skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/9.tmp Infected: Trojan-Spy.Win32.Zbot.arw skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/B.tmp Infected: Trojan-Spy.Win32.Zbot.arw skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/F.tmp Infected: Trojan-Spy.Win32.Zbot.arw skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU ZIP: infected - 30 skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39554.6742069907.WCU/C:/WINDOWS/TEMP/hltpdhtdlhd.dll Infected: Email-Worm.Win32.Locksky.cm skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39554.6742069907.WCU/C:/WINDOWS/TEMP/thpldt.drv Infected: Email-Worm.Win32.Locksky.cm skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39554.6742069907.WCU/C:/WINDOWS/TEMP/ttpddptp.dll Infected: Email-Worm.Win32.Locksky.cm skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39554.6742069907.WCU ZIP: infected - 3 skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39563.1994920023.WCU/C:/WINDOWS/TEMP/bpnfbnhtdnp.dll Infected: Email-Worm.Win32.Locksky.cm skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39563.1994920023.WCU/C:/WINDOWS/TEMP/hhfpplbfth.sys Infected: Email-Worm.Win32.Locksky.cm skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39563.1994920023.WCU/C:/WINDOWS/TEMP/ltprflbnhjf.sys Infected: Email-Worm.Win32.Locksky.cm skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39563.1994920023.WCU ZIP: infected - 3 skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39564.1587857986.WCU/C:/WINDOWS/TEMP/ddhnlnthpl.nls Infected: Email-Worm.Win32.Locksky.cm skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39564.1587857986.WCU/C:/WINDOWS/TEMP/dhtjdlpt.sys Infected: Email-Worm.Win32.Locksky.cm skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39564.1587857986.WCU/C:/WINDOWS/TEMP/pppjlh.sys Infected: Email-Worm.Win32.Locksky.cm skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39564.1587857986.WCU ZIP: infected - 3 skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39573.9436123727.WCU/C:/WINDOWS/TEMP/ffjdhf.nls Infected: Email-Worm.Win32.Locksky.cm skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39573.9436123727.WCU/C:/WINDOWS/TEMP/nfhtpddpdjf.dll Infected: Email-Worm.Win32.Locksky.cm skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39573.9436123727.WCU/C:/WINDOWS/TEMP/rprpdlfr.sys Infected: Email-Worm.Win32.Locksky.cm skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39573.9436123727.WCU ZIP: infected - 3 skipped
C:\Documents and Settings\John Lee\Application Data\OnlineArmor\client.dat Object is locked skipped
C:\Documents and Settings\John Lee\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\John Lee\Desktop\Unused Desktop Shortcuts\cool-speech-59mary-sap14.exe/Realtime.dll Infected: Trojan-Spy.Win32.Delf.fk skipped
C:\Documents and Settings\John Lee\Desktop\Unused Desktop Shortcuts\cool-speech-59mary-sap14.exe CreateInstall: infected - 1 skipped
C:\Documents and Settings\John Lee\Desktop\Unused Desktop Shortcuts\cool-speech59peter-sap14.exe/Realtime.dll Infected: Trojan-Spy.Win32.Delf.fk skipped
C:\Documents and Settings\John Lee\Desktop\Unused Desktop Shortcuts\cool-speech59peter-sap14.exe CreateInstall: infected - 1 skipped
C:\Documents and Settings\John Lee\Desktop\Unused Desktop Shortcuts\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\John Lee\ftpdll.dll Infected: Trojan-Dropper.Win32.Small.bgx skipped
C:\Documents and Settings\John Lee\ie_updates3r.exe Infected: Trojan-Downloader.Win32.Winlagons.al skipped
C:\Documents and Settings\John Lee\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\John Lee\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\John Lee\Local Settings\Application Data\windowsupdate.exe Infected: Worm.Win32.Socks.jf skipped
C:\Documents and Settings\John Lee\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\John Lee\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\John Lee\nax.exe Infected: Trojan-Dropper.Win32.Small.bgl skipped
C:\Documents and Settings\John Lee\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\John Lee\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\ftpdll.dll Infected: Trojan-Dropper.Win32.Small.bgx skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\windowsupdate.exe Infected: Worm.Win32.Socks.jf skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\backups\backup-20061219-025422-705.dll Infected: Trojan-Clicker.Win32.BHO.r skipped
C:\Program Files\Bat\Bat.dll Infected: not-a-virus:AdWare.Win32.Rabio.m skipped
C:\Program Files\Bat\Info.dll Infected: not-a-virus:AdWare.Win32.Rabio.m skipped
C:\Program Files\Cmkkhknc\qitpxpww.exe Suspicious: Type_Win32 skipped
C:\Program Files\CuteComp.exe/file21 Infected: not-a-virus:AdTool.Win32.WhenU.a skipped
C:\Program Files\CuteComp.exe Inno: infected - 1 skipped
C:\Program Files\IE Extensions\cj.v2.dll Infected: Trojan-Clicker.Win32.Agent.xs skipped
C:\Program Files\Lpxiesdk\bpmqzonk.exe Infected: Trojan.Win32.Obfuscated.gx skipped
C:\Program Files\Orffrake\fucghrpz.exe Infected: Trojan.Win32.Obfuscated.gx skipped
C:\Program Files\Robot Voices\male-voice-american.exe/Realtime.dll Infected: Trojan-Spy.Win32.Delf.fk skipped
C:\Program Files\Robot Voices\male-voice-american.exe CreateInstall: infected - 1 skipped
C:\Program Files\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
Product: Win32.Soundmix
Threat: Trojan
Win32.Soundmix copies itself as soundmix.exe into the system directory and pretends to be a soundmixer. It starts itself in autorun as "soundmix" without user consent. It also adds itself to the exefile shell open command so that it will be started synchronously with every other exe file.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:45:20 PM, on 5/29/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Tall Emu\Online Armor\oasrv.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\igfxtray.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\Tall Emu\Online Armor\oaui.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
file:///E:/September911surprise%20CTV/PirateNews-org/Homepage/index2.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
F2 - REG:system.ini: Shell=Explorer.exe
N2 - Netscape 6: user_pref("browser.startup.homepage", "http://home.netscape.com/"); (C:\Documents and Settings\JOHN
LEE\Application Data\Mozilla\Profiles\default\f5sn9q7e.slt\prefs.js)
N2 - Netscape 6: user_pref("browser.search.defaultengine", "http://www.google.com/"); (C:\Documents and Settings\JOHN
LEE\Application Data\Mozilla\Profiles\default\f5sn9q7e.slt\prefs.js)
O2 - BHO: (no name) - {344B7EF2-9819-299E-51CB-018EEAA2D736} - C:\WINDOWS\system32\admdsc.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autofix
O4 - HKLM\..\Run: [OnlineArmor GUI] "C:\Program Files\Tall Emu\Online Armor\oaui.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKLM\..\Policies\Explorer\Run: [dhprthpl] rundll32.exe "C:\WINDOWS\system32\rdpthj.sys" WLEntryPoint
O4 - HKUS\S-1-5-21-1420582129-1497244195-3520757181-1006\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &
Destroy\TeaTimer.exe (User '?')
O8 - Extra context menu item: Save Flash with Flash Catcher - res://C:\Program Files\Common
Files\Justdo\IECatcher.DLL/FlashCatcher.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} -
C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\torapcfm.dll
O15 - Trusted Zone: http://www.archive.org
O15 - Trusted Zone: http://tvplanner.comcast.net
O15 - Trusted Zone: http://www.comcast.net
O15 - Trusted Zone: http://www.disabilityforms.com
O15 - Trusted Zone: http://www.fireflyfans.net
O15 - Trusted Zone: http://www.infowars.com
O15 - Trusted Zone: http://www.infowars.net
O15 - Trusted Zone: http://*.infowars.net
O15 - Trusted Zone: http://*.myspace.com
O15 - Trusted Zone: http://ww2.nero.com
O15 - Trusted Zone: http://vhost.oddcast.com
O15 - Trusted Zone: http://flash.picturetail.com
O15 - Trusted Zone: http://www.picturetrail.com
O15 - Trusted Zone: *.picturetrail.com
O15 - Trusted Zone: http://forums.spybot.info
O15 - Trusted Zone: http://www.tallemu.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {8436FE12-31DB-48BF-83BF-FE682F9160B4} (NanoInstaller Class) - http://www.nanoscan.com/cabs/nanoinst.cab
O20 - Winlogon Notify: hgnid - C:\WINDOWS\
O20 - Winlogon Notify: WLCtrl32 - C:\WINDOWS\SYSTEM32\WLCtrl32.dll
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common
Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Online Armor (SvcOnlineArmor) - Tall Emu - C:\Program Files\Tall Emu\Online Armor\oasrv.exe
--
End of file - 4947 bytes
===========================================
KASPERSKY ONLINE SCANNER REPORT
Thursday, May 29, 2008 4:14:00 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 29/05/2008
Kaspersky Anti-Virus database records: 812154
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 185169
Number of viruses found: 93
Number of infected objects: 719
Number of suspicious objects: 4
Duration of the scan process: 02:09:28
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\bspefqpk\tufmlwnu.exe Infected: Trojan.Win32.Obfuscated.gx skipped
C:\Documents and Settings\All Users\Application Data\cnifshqp\uzqpkbcb.exe Infected: Trojan.Win32.Obfuscated.gx skipped
C:\Documents and Settings\All Users\Application Data\danwhoha\fmhurabo.exe Infected: Trojan.Win32.Obfuscated.gx skipped
C:\Documents and Settings\All Users\Application Data\dgxwxyjw\xqvkngze.exe Infected: Trojan.Win32.Obfuscated.gx skipped
C:\Documents and Settings\All Users\Application Data\dsxmtkvi\vijcnshy.exe Infected: Trojan.Win32.Obfuscated.gx skipped
C:\Documents and Settings\All Users\Application Data\dunwjghm\jmdifsvi.exe Infected: Trojan.Win32.Obfuscated.gx skipped
C:\Documents and Settings\All Users\Application Data\fmpkrczw\bajylylq.exe Infected: Trojan.Win32.Obfuscated.gx skipped
C:\Documents and Settings\All Users\Application Data\fspmjgfy\tibatqzc.exe Infected: Trojan.Win32.Obfuscated.gx skipped
C:\Documents and Settings\All Users\Application Data\fyvgtytu\jobkzwry.exe Infected: Trojan.Win32.Obfuscated.gx skipped
C:\Documents and Settings\All Users\Application Data\hydmhcby\rmxodsla.exe Infected: Trojan.Win32.Obfuscated.gx skipped
C:\Documents and Settings\All Users\Application Data\izgtgbct\qbetelyx.exe Infected: Trojan.Win32.Obfuscated.gx skipped
C:\Documents and Settings\All Users\Application Data\jahihoxw\fqpajude.exe Infected: Trojan.Win32.Obfuscated.gx skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\mlqdwxef.dll Infected: Trojan.Win32.Obfuscated.sc skipped
C:\Documents and Settings\All Users\Application Data\obunarah.dll Infected: Trojan.Win32.Obfuscated.sc skipped
C:\Documents and Settings\All Users\Application Data\parifcpm\jkhsvujc.exe Infected: Trojan.Win32.Obfuscated.gx skipped
C:\Documents and Settings\All Users\Application Data\qtglohyd\qpuxgzan.exe Infected: Trojan.Win32.Obfuscated.gx skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\PWSLDPinchIE5.zip/partnership.dll Infected: Trojan-Proxy.Win32.Xorpix.dg skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\PWSLDPinchIE5.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC.zip/vedxga1me4t1.exe Infected: Trojan-Downloader.Win32.Tibs.wh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC1.zip/vedxg4am1et2.exe Infected: Trojan-Downloader.Win32.Tibs.wh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC1.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC14.zip/dllgh8jkd1q2.exe Infected: Trojan-Downloader.Win32.Tibs.wh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC14.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC15.zip/dllgh8jkd1q6.exe Infected: Trojan-Downloader.Win32.Tibs.wh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC15.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC16.zip/dllgh8jkd1q7.exe Infected: Trojan-Downloader.Win32.Tibs.wh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC16.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC2.zip/vedxga3me2.exe Infected: Trojan-Downloader.Win32.VB.ded skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC2.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC3.zip/vedxga4me1.exe Infected: Trojan-Downloader.Win32.Small.cxx skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC3.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC4.zip/vedxg6ame4.exe Infected: Trojan-Downloader.Win32.Tibs.wh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC4.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC5.zip/wind32.exe Infected: Trojan-Downloader.Win32.Tibs.vz skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC5.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC7.zip/desktop.html Infected: not-virus:Hoax.Win32.Renos.cy skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC7.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC9.zip/BraveSentry0.dll Infected: not-a-virus:FraudTool.Win32.BraveSentry.f skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC9.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric.zip/autorun.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric1.zip/svchost.exe Infected: Trojan-Downloader.Win32.Small.svi skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric1.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric2.zip/autorun.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgeneric2.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SpySheriff1.zip/SpySheriff.exe Infected: not-a-virus:FraudTool.Win32.SpySheriff.a skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SpySheriff1.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SpySheriff6.zip/heur000.dll Infected: not-a-virus:FraudTool.Win32.SpySheriff.a skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SpySheriff6.zip/heur001.dll Infected: not-a-virus:FraudTool.Win32.SpySheriff.a skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SpySheriff6.zip/heur002.dll Infected: not-a-virus:FraudTool.Win32.SpySheriff.a skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SpySheriff6.zip/heur003.dll Infected: not-a-virus:FraudTool.Win32.SpySheriff.a skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SpySheriff6.zip ZIP: infected - 4 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde10.zip/syslook.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde10.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde11.zip/sys16.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde11.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde12.zip/synsv.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde12.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde13.zip/powersys.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde13.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde14.zip/poweragent.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde14.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde15.zip/hostwin.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde15.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde17.zip/shift.exe.exe Infected: Email-Worm.Win32.Zhelatin.vg skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde17.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde4.zip/mljgh.dll Infected: Trojan-Spy.Win32.Agent.hn skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde4.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde5.zip/syssys.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde5.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde55.zip/printer.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde55.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde6.zip/monpower.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde6.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde64.zip/printer.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde64.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde8.zip/avp.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde8.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde82.zip/printer.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde82.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde85.zip/printer.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde85.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde99.zip/printer.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde99.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack.zip/shell.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack1.zip/spoolvs.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack1.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack10.zip/spoolvs.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack10.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack11.zip/findfast.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack11.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack12.zip/printer.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack12.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack15.zip/printer.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack15.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack16.zip/findfast.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack16.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack17.zip/spoolvs.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack17.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack18.zip/shell.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack18.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack19.zip/printer.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack19.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack2.zip/printer.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack2.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack20.zip/spoolvs.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack20.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack21.zip/shell.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack21.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack22.zip/printer.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack22.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack23.zip/spoolvs.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack23.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack24.zip/shell.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack24.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack26.zip/printer.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack26.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack27.zip/findfast.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack27.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack28.zip/spoolvs.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack28.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack29.zip/xloader30029.exe Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack29.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack30.zip/shell.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack30.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack4.zip/shell.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack4.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack5.zip/spoolvs.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack5.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack6.zip/findfast.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack6.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack7.zip/printer.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack7.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack9.zip/shell.exe Infected: Trojan.Win32.Qhost.aes skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack9.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbid4.zip/winlogon.exe Infected: Trojan-Proxy.Win32.Small.kx skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbid4.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinBHOje10.zip/1205424199.dll Infected: not-a-virus:AdWare.Win32.E404.f skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinBHOje10.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinBHOje6.zip/1205424199.dll Infected: not-a-virus:AdWare.Win32.E404.f skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinBHOje6.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinGBDialerj.zip/npdl.exe Infected: not-a-virus

C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinGBDialerj.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinLoadAdvh.zip/hlpsrv.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinLoadAdvh.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh10.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh10.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh13.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh13.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh16.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh16.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh19.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh19.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh2.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh2.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh21.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh21.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh25.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh25.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh28.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh28.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh30.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh30.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh33.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh33.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh36.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh36.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh39.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh39.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh4.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh4.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh41.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh41.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh43.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh43.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh46.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh46.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh48.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh48.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh51.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh51.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh53.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh53.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh56.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh56.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh58.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh58.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh60.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh60.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh63.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh63.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh66.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh66.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh68.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh68.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh7.zip/wowfx.dll Infected: Trojan.Win32.Qhost.abh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh7.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinSmallazl2.zip/mrofinu27.exe Infected: Trojan-Downloader.Win32.Agent.lbx skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinSmallazl2.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Zlockuc.zip/onuxuped.dll Infected: not-a-virus:AdWare.Win32.Agent.wk skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Zlockuc.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\stwjkzmz\qvkfkfej.exe Infected: Trojan.Win32.Obfuscated.gx skipped
C:\Documents and Settings\All Users\Application Data\vmxkzufk\jevmxazo.exe Infected: Trojan.Win32.Obfuscated.gx skipped
C:\Documents and Settings\All Users\Application Data\whulahat\ynehglit.exe Infected: Trojan.Win32.Obfuscated.gx skipped
C:\Documents and Settings\All Users\Application Data\yvktobmb\yjolabel.exe Infected: Trojan-Dropper.Win32.Agent.amm skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/Documents and Settings/John Lee/Local Settings/Temp/0.EXE Infected: Trojan-Downloader.Win32.Small.ius skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/Documents and Settings/John Lee/Local Settings/Temp/1922.tmp Infected: Trojan-Downloader.Win32.Agent.lcx skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/Documents and Settings/John Lee/Local Settings/Temp/csrssc.exe Infected: Trojan-Downloader.Win32.Suurch.dw skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/Documents and Settings/John Lee/Local Settings/Temp/file834.exe Infected: Trojan-Spy.Win32.Zbot.amb skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/WINDOWS/temp/1.dllb Infected: Trojan-Downloader.Win32.Tibs.wh skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/WINDOWS/temp/2.dllb Infected: Trojan-Downloader.Win32.Tibs.wh skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/WINDOWS/temp/238A.tmp Infected: Trojan-Downloader.Win32.Zlob.jbe skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/WINDOWS/temp/5.dllb Infected: Trojan-Downloader.Win32.Tibs.wh skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/WINDOWS/temp/6.dllb Infected: Trojan-Downloader.Win32.Tibs.wh skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/WINDOWS/temp/63.tmp Infected: Trojan.Win32.Pakes.cix skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/WINDOWS/temp/7.dllb Infected: Trojan-Downloader.Win32.Tibs.wh skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/WINDOWS/temp/A984.tmp Infected: Trojan-Downloader.Win32.Agent.lcx skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/WINDOWS/temp/codec.exe Infected: Trojan-Downloader.Win32.Zlob.jhh skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/WINDOWS/temp/D5.tmp Infected: Trojan-Downloader.Win32.Flux.eh skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/WINDOWS/temp/dpdbjf.drv Infected: Email-Worm.Win32.Locksky.cm skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/WINDOWS/temp/G5F-tmp.exe Infected: Trojan-Downloader.Win32.Flux.eh skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/WINDOWS/temp/iframestat.exe Infected: Trojan-Downloader.Win32.Tibs.vz skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/WINDOWS/temp/kfmtonetcrm.drv Infected: Email-Worm.Win32.Locksky.cm skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/WINDOWS/temp/lebsbord.exe Infected: Email-Worm.Win32.Locksky.da skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/WINDOWS/temp/lhdtpp.dll Infected: Email-Worm.Win32.Locksky.cm skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/WINDOWS/temp/sh.exe Infected: Trojan-Downloader.Win32.Agent.lab skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/WINDOWS/temp/tmp.exe Infected: Backdoor.Win32.Agent.fnb skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/Program Files/WinBudget/bin/crap.1165507431.old/data0000 Infected: Trojan-Clicker.Win32.BHO.r skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/Program Files/WinBudget/bin/crap.1165507431.old Infected: Trojan-Clicker.Win32.BHO.r skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/Program Files/WinBudget/bin/matrix.dll.1165951424.old Infected: Trojan-Clicker.Win32.BHO.r skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/Program Files/WinBudget/bin/matrix.dll.1166051149.old Infected: Trojan-Clicker.Win32.BHO.r skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/Program Files/WinBudget/bin/matrix.dll.1166073115.old Infected: Trojan-Clicker.Win32.BHO.r skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/Program Files/WinBudget/bin/matrix.dll.1166394446.old Infected: Trojan-Clicker.Win32.BHO.r skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/Program Files/WinBudget/bin/matrix.dll.1167002879.old Infected: Trojan-Clicker.Win32.BHO.r skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/Program Files/WinBudget/bin/matrix.dll.1167199060.old Infected: Trojan-Clicker.Win32.BHO.r skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/Program Files/WinBudget/bin/matrix.dll.1167455550.old Infected: Trojan-Clicker.Win32.BHO.r skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/Program Files/WinBudget/bin/matrix.dll.1167715835.old Infected: Trojan-Clicker.Win32.BHO.r skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/Program Files/WinBudget/bin/matrix.dll.1168035795.old Infected: Trojan-Clicker.Win32.BHO.r skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/Program Files/WinBudget/bin/matrix.dll.1168242245.old Infected: Trojan-Clicker.Win32.BHO.r skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/Program Files/WinBudget/bin/matrix.dll.1168519775.old Infected: Trojan-Clicker.Win32.BHO.r skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU/C:/Program Files/WinBudget/bin/matrix.dll.1168936518.old Infected: Trojan-Clicker.Win32.BHO.r skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39524.0746234722.WCU ZIP: infected - 36 skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/WINDOWS/TEMP/BN1.tmp Infected: Backdoor.Win32.Agobot.pbq skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/WINDOWS/TEMP/BN2.tmp Infected: Backdoor.Win32.Agobot.pbq skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/WINDOWS/TEMP/BN6A.tmp Infected: Backdoor.Win32.Agobot.pbq skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/WINDOWS/TEMP/BND.tmp Infected: Backdoor.Win32.Agobot.pbq skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/WINDOWS/TEMP/ldlddpldttt.nls Infected: Email-Worm.Win32.Locksky.cm skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/WINDOWS/TEMP/nhphhhtlpht.nls Infected: Email-Worm.Win32.Locksky.cm skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/WINDOWS/TEMP/sjapcrahsjq.dll Infected: Email-Worm.Win32.Locksky.cm skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/WINDOWS/TEMP/ttnhtlpp.drv Infected: Email-Worm.Win32.Locksky.cm skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/10.tmp Infected: Trojan-Spy.Win32.Zbot.arw skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/13.tmp Infected: Trojan-Spy.Win32.Zbot.arw skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/14.tmp Infected: Trojan-Spy.Win32.Zbot.arw skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/1A.tmp Infected: Trojan-Spy.Win32.Zbot.arw skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/1D.tmp Infected: Trojan-Spy.Win32.Zbot.arw skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/1E.tmp Infected: Trojan-Spy.Win32.Zbot.arw skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/1F.tmp Infected: Trojan-Spy.Win32.Zbot.arw skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/22D7.tmp Infected: Trojan-Spy.Win32.Zbot.arw skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/22D8.tmp Infected: Trojan-Spy.Win32.Zbot.arw skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/25.tmp Infected: Trojan-Spy.Win32.Zbot.arw skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/27.tmp Infected: Trojan-Spy.Win32.Zbot.arw skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/2A.tmp Infected: Trojan-Spy.Win32.Zbot.arw skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/2B.tmp Infected: Trojan-Spy.Win32.Zbot.arw skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/2D.tmp Infected: Trojan-Spy.Win32.Zbot.arw skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/30.tmp Infected: Trojan-Spy.Win32.Zbot.arw skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/39.tmp Infected: Trojan-Spy.Win32.Zbot.arw skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/5.tmp Infected: Trojan-Spy.Win32.Zbot.arw skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/6.tmp Infected: Trojan-Spy.Win32.Zbot.arw skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/8.tmp Infected: Trojan-Spy.Win32.Zbot.arw skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/9.tmp Infected: Trojan-Spy.Win32.Zbot.arw skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/B.tmp Infected: Trojan-Spy.Win32.Zbot.arw skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU/C:/F.tmp Infected: Trojan-Spy.Win32.Zbot.arw skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39539.8254425231.WCU ZIP: infected - 30 skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39554.6742069907.WCU/C:/WINDOWS/TEMP/hltpdhtdlhd.dll Infected: Email-Worm.Win32.Locksky.cm skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39554.6742069907.WCU/C:/WINDOWS/TEMP/thpldt.drv Infected: Email-Worm.Win32.Locksky.cm skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39554.6742069907.WCU/C:/WINDOWS/TEMP/ttpddptp.dll Infected: Email-Worm.Win32.Locksky.cm skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39554.6742069907.WCU ZIP: infected - 3 skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39563.1994920023.WCU/C:/WINDOWS/TEMP/bpnfbnhtdnp.dll Infected: Email-Worm.Win32.Locksky.cm skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39563.1994920023.WCU/C:/WINDOWS/TEMP/hhfpplbfth.sys Infected: Email-Worm.Win32.Locksky.cm skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39563.1994920023.WCU/C:/WINDOWS/TEMP/ltprflbnhjf.sys Infected: Email-Worm.Win32.Locksky.cm skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39563.1994920023.WCU ZIP: infected - 3 skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39564.1587857986.WCU/C:/WINDOWS/TEMP/ddhnlnthpl.nls Infected: Email-Worm.Win32.Locksky.cm skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39564.1587857986.WCU/C:/WINDOWS/TEMP/dhtjdlpt.sys Infected: Email-Worm.Win32.Locksky.cm skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39564.1587857986.WCU/C:/WINDOWS/TEMP/pppjlh.sys Infected: Email-Worm.Win32.Locksky.cm skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39564.1587857986.WCU ZIP: infected - 3 skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39573.9436123727.WCU/C:/WINDOWS/TEMP/ffjdhf.nls Infected: Email-Worm.Win32.Locksky.cm skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39573.9436123727.WCU/C:/WINDOWS/TEMP/nfhtpddpdjf.dll Infected: Email-Worm.Win32.Locksky.cm skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39573.9436123727.WCU/C:/WINDOWS/TEMP/rprpdlfr.sys Infected: Email-Worm.Win32.Locksky.cm skipped
C:\Documents and Settings\John Lee\Application Data\Business Logic\UWC\Backup\J39573.9436123727.WCU ZIP: infected - 3 skipped
C:\Documents and Settings\John Lee\Application Data\OnlineArmor\client.dat Object is locked skipped
C:\Documents and Settings\John Lee\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\John Lee\Desktop\Unused Desktop Shortcuts\cool-speech-59mary-sap14.exe/Realtime.dll Infected: Trojan-Spy.Win32.Delf.fk skipped
C:\Documents and Settings\John Lee\Desktop\Unused Desktop Shortcuts\cool-speech-59mary-sap14.exe CreateInstall: infected - 1 skipped
C:\Documents and Settings\John Lee\Desktop\Unused Desktop Shortcuts\cool-speech59peter-sap14.exe/Realtime.dll Infected: Trojan-Spy.Win32.Delf.fk skipped
C:\Documents and Settings\John Lee\Desktop\Unused Desktop Shortcuts\cool-speech59peter-sap14.exe CreateInstall: infected - 1 skipped
C:\Documents and Settings\John Lee\Desktop\Unused Desktop Shortcuts\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\John Lee\ftpdll.dll Infected: Trojan-Dropper.Win32.Small.bgx skipped
C:\Documents and Settings\John Lee\ie_updates3r.exe Infected: Trojan-Downloader.Win32.Winlagons.al skipped
C:\Documents and Settings\John Lee\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\John Lee\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\John Lee\Local Settings\Application Data\windowsupdate.exe Infected: Worm.Win32.Socks.jf skipped
C:\Documents and Settings\John Lee\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\John Lee\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\John Lee\nax.exe Infected: Trojan-Dropper.Win32.Small.bgl skipped
C:\Documents and Settings\John Lee\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\John Lee\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\ftpdll.dll Infected: Trojan-Dropper.Win32.Small.bgx skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\windowsupdate.exe Infected: Worm.Win32.Socks.jf skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\backups\backup-20061219-025422-705.dll Infected: Trojan-Clicker.Win32.BHO.r skipped
C:\Program Files\Bat\Bat.dll Infected: not-a-virus:AdWare.Win32.Rabio.m skipped
C:\Program Files\Bat\Info.dll Infected: not-a-virus:AdWare.Win32.Rabio.m skipped
C:\Program Files\Cmkkhknc\qitpxpww.exe Suspicious: Type_Win32 skipped
C:\Program Files\CuteComp.exe/file21 Infected: not-a-virus:AdTool.Win32.WhenU.a skipped
C:\Program Files\CuteComp.exe Inno: infected - 1 skipped
C:\Program Files\IE Extensions\cj.v2.dll Infected: Trojan-Clicker.Win32.Agent.xs skipped
C:\Program Files\Lpxiesdk\bpmqzonk.exe Infected: Trojan.Win32.Obfuscated.gx skipped
C:\Program Files\Orffrake\fucghrpz.exe Infected: Trojan.Win32.Obfuscated.gx skipped
C:\Program Files\Robot Voices\male-voice-american.exe/Realtime.dll Infected: Trojan-Spy.Win32.Delf.fk skipped
C:\Program Files\Robot Voices\male-voice-american.exe CreateInstall: infected - 1 skipped
C:\Program Files\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped