--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0: scan report
Sunday, February 28, 2010
Operating system: Microsoft Windows XP Home Edition Service Pack 2 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Sunday, February 28, 2010 03:31:05
Records in database: 3666803
--------------------------------------------------------------------------------
Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes
Scan area - My Computer:
C:\
D:\
E:\
Scan statistics:
Objects scanned: 128814
Threats found: 8
Infected objects found: 65
Suspicious objects found: 0
Scan duration: 03:10:46
File name / Threat / Threats count
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\4276317D.exe Infected: Trojan-Dropper.Win32.Agent.azn 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\53CF100A.exe Infected: Packed.Win32.Klone.t 1
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7E5623A4.tmp Infected: Trojan-Downloader.Win32.Small.dod 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\ahdjhc.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.nbz 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\alsbyl.dll.vir Infected: Trojan.Win32.Monder.arem 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\dfsldcpd.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.bdns 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\epvvxm.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.hut 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\gowegjdp.dll.vir Infected: Trojan.Win32.Monder.arem 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\hjkdjvce.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.nbz 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\npwtcerj.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.nbz 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\vbetia.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.nbz 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\vgpixcsl.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.hut 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP298\A0093942.sys Infected: Rootkit.Win32.ZAccess.b 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP299\A0093980.sys Infected: Rootkit.Win32.ZAccess.b 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP299\A0094000.sys Infected: Rootkit.Win32.ZAccess.b 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP300\A0094013.sys Infected: Rootkit.Win32.ZAccess.b 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP308\A0094483.sys Infected: Rootkit.Win32.ZAccess.b 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP309\A0095483.sys Infected: Rootkit.Win32.ZAccess.b 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP309\A0095492.sys Infected: Rootkit.Win32.ZAccess.b 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP309\A0096492.sys Infected: Rootkit.Win32.ZAccess.b 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP310\A0096763.sys Infected: Rootkit.Win32.ZAccess.b 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP311\A0096785.sys Infected: Rootkit.Win32.ZAccess.b 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP311\A0096796.sys Infected: Rootkit.Win32.ZAccess.b 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP311\A0096805.sys Infected: Rootkit.Win32.ZAccess.b 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP311\A0096815.sys Infected: Rootkit.Win32.ZAccess.b 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP312\A0096879.sys Infected: Rootkit.Win32.ZAccess.b 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP312\A0098896.sys Infected: Rootkit.Win32.ZAccess.b 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP312\A0098920.sys Infected: Rootkit.Win32.ZAccess.b 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP312\A0098929.sys Infected: Rootkit.Win32.ZAccess.b 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP313\A0099929.sys Infected: Rootkit.Win32.ZAccess.b 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP313\A0100929.sys Infected: Rootkit.Win32.ZAccess.b 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP313\A0101929.sys Infected: Rootkit.Win32.ZAccess.b 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP313\A0101943.sys Infected: Rootkit.Win32.ZAccess.b 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP314\A0101958.sys Infected: Rootkit.Win32.ZAccess.b 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP314\A0101973.sys Infected: Rootkit.Win32.ZAccess.b 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP315\A0102061.sys Infected: Rootkit.Win32.ZAccess.b 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP315\A0102215.sys Infected: Rootkit.Win32.ZAccess.b 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP316\A0102224.sys Infected: Rootkit.Win32.ZAccess.b 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP316\A0102270.sys Infected: Rootkit.Win32.ZAccess.b 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP316\A0102389.sys Infected: Rootkit.Win32.ZAccess.b 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP316\A0102394.sys Infected: Rootkit.Win32.ZAccess.b 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP316\A0102400.sys Infected: Rootkit.Win32.ZAccess.b 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP316\A0102405.sys Infected: Rootkit.Win32.ZAccess.b 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP316\A0103405.sys Infected: Rootkit.Win32.ZAccess.b 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP316\A0104405.sys Infected: Rootkit.Win32.ZAccess.b 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP317\A0105405.sys Infected: Rootkit.Win32.ZAccess.b 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP317\A0105420.sys Infected: Rootkit.Win32.ZAccess.b 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP317\A0105429.sys Infected: Rootkit.Win32.ZAccess.b 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP317\A0105433.sys Infected: Rootkit.Win32.ZAccess.b 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP317\A0105438.sys Infected: Rootkit.Win32.ZAccess.b 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP317\A0105442.sys Infected: Rootkit.Win32.ZAccess.b 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP318\A0105452.sys Infected: Rootkit.Win32.ZAccess.b 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP318\A0106452.sys Infected: Rootkit.Win32.ZAccess.b 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP318\A0106461.sys Infected: Rootkit.Win32.ZAccess.b 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP319\A0106590.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.nbz 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP319\A0106591.dll Infected: Trojan.Win32.Monder.arem 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP319\A0106592.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bdns 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP319\A0106593.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.hut 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP319\A0106594.dll Infected: Trojan.Win32.Monder.arem 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP319\A0106595.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.nbz 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP319\A0106596.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.nbz 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP319\A0106597.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.nbz 1
C:\System Volume Information\_restore{1368902D-6A36-4B35-812D-DDC763090AC0}\RP319\A0106598.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.hut 1
C:\WINDOWS\maxdriver\HSFHWAZL.sys Infected: Rootkit.Win32.ZAccess.b 1
C:\WINDOWS\system32\drivers\HSFHWAZL.sys.vir Infected: Rootkit.Win32.ZAccess.b 1
Selected area has been scanned.
DDS (Ver_09-12-01.01) - NTFSx86
Run by KDSN at 5:04:45.18 on Sun 02/28/2010
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_18
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2038.1265 [GMT -6:00]
AV: AVG Anti-Virus Free *On-access scanning disabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Pidgin\pidgin.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\Documents and Settings\KDSN.MATBOX\Desktop\dds.scr
============== Pseudo HJT Report ===============
uInternet Connection Wizard,ShellNext = hxxp://www.avg.com/ww.special-toolbar-first-run-tlbrf
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: AVG Security Toolbar: {a057a204-bacc-4d26-9990-79a187e2698e} - c:\progra~1\avg\avg8\AVGTOO~1.DLL
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\pidgin.lnk - c:\program files\pidgin\pidgin.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: igfxcui - igfxdev.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\kdsn~1.mat\applic~1\mozilla\firefox\profiles\h07v5jdv.default\
FF - prefs.js: browser.search.selectedEngine - Wowhead
FF - prefs.js: browser.startup.homepage -
www.google.com
FF - plugin: c:\documents and settings\kdsn.matbox\application data\mozilla\firefox\profiles\h07v5jdv.default\extensions\{190b412f-3273-4922-9954-56e8bcb5e113}\plugins\NPnsv.dll
FF - plugin: c:\documents and settings\kdsn.matbox\application data\mozilla\firefox\profiles\h07v5jdv.default\extensions\moveplayer@movenetworks.com\platform\winnt_x86-msvc\plugins\npmnqmp071101000055.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPTURNMED.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - truec:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
============= SERVICES / DRIVERS ===============
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-10-27 97928]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-10-27 26824]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2008-10-27 875288]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-10-31 231704]
R2 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-10-27 76040]
=============== Created Last 30 ================
2010-02-28 07:16:00 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-02-26 14:37:26 77312 ----a-w- c:\windows\MBR.exe
2010-02-26 14:37:26 261632 ----a-w- c:\windows\PEV.exe
2010-02-24 14:46:22 201600 ----a-w- c:\windows\system32\drivers\HSFHWAZL.sys.bak
2010-02-24 14:46:22 201600 ----a-w- c:\windows\system32\drivers\HSFHWAZL.sys
2010-02-24 06:51:54 0 d-----w- c:\program files\SecondLifeBetaViewer
2010-02-20 02:36:17 0 d-sha-r- C:\cmdcons
2010-02-20 02:36:17 0 d-----w- c:\windows\setup.pss
2010-02-20 02:36:05 0 d-----w- c:\windows\setupupd
2010-02-20 02:19:55 0 d-----w- c:\windows\maxdriver
2010-02-19 11:08:51 3482 ----a-w- c:\documents and settings\kdsn.matbox\.recently-used.xbel
2010-02-09 21:46:40 0 d-----w- c:\program files\VideoLAN
2010-02-05 05:42:27 1089601 ------w- c:\windows\system32\dllcache\ntprint.cat
2010-02-03 19:42:38 0 d-----w- c:\windows\system32\XPSViewer
2010-02-03 19:41:18 89088 ------w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-02-03 19:41:18 597504 ------w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-02-03 19:41:18 117760 ------w- c:\windows\system32\prntvpt.dll
2010-02-03 19:41:17 575488 ------w- c:\windows\system32\xpsshhdr.dll
2010-02-03 19:41:17 575488 ------w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-02-03 19:41:17 1676288 ------w- c:\windows\system32\xpssvcs.dll
2010-02-03 19:41:17 1676288 ------w- c:\windows\system32\dllcache\xpssvcs.dll
2010-02-03 19:41:17 0 d-----w- C:\76c9ad802ac1953bf118f71b08a990
2010-02-03 19:37:22 0 d-----w- c:\program files\MSXML 6.0
2010-02-03 19:32:56 0 d-----r- C:\AHCache
2010-01-30 02:04:50 0 d-----w- c:\docume~1\kdsn~1.mat\applic~1\CreeperWorldDEMO.BA6B793AB2C9FDD744493F22666C1F8DFA806A5E.1
2010-01-30 02:04:50 0 d-----w- c:\docume~1\kdsn~1.mat\applic~1\CreeperWorld
2010-01-30 02:04:41 0 d-----w- c:\program files\KnuckleCracker
==================== Find3M ====================
2010-02-28 07:15:37 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-01-07 22:07:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 22:07:04 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-31 16:14:12 352640 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-31 16:14:12 352640 ------w- c:\windows\system32\dllcache\srv.sys
2009-12-31 15:33:06 70656 ------w- c:\windows\system32\dllcache\ie4uinit.exe
2009-12-31 15:33:06 13824 ------w- c:\windows\system32\dllcache\ieudinit.exe
2009-12-18 13:05:43 634648 ------w- c:\windows\system32\dllcache\iexplore.exe
2009-12-18 13:04:09 161792 ------w- c:\windows\system32\dllcache\ieakui.dll
2009-12-16 12:58:04 343040 ----a-w- c:\windows\system32\mspaint.exe
2009-12-16 12:58:04 343040 ------w- c:\windows\system32\dllcache\mspaint.exe
2009-12-14 07:35:35 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-12-14 07:35:35 33280 ------w- c:\windows\system32\dllcache\csrsrv.dll
2009-12-08 18:14:02 2185984 ------w- c:\windows\system32\ntoskrnl.exe
2009-12-08 18:14:02 2185984 ------w- c:\windows\system32\dllcache\ntoskrnl.exe
2009-12-08 18:11:44 2142720 ------w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-12-08 17:35:25 2020864 ------w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-12-08 17:35:22 2063104 ------w- c:\windows\system32\ntkrnlpa.exe
2009-12-08 17:35:22 2063104 ------w- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-12-08 09:13:51 474112 ------w- c:\windows\system32\dllcache\shlwapi.dll
2009-12-04 14:41:55 453760 ------w- c:\windows\system32\dllcache\mrxsmb.sys
============= FINISH: 5:05:09.95 ===============