Suspected virus featuring "Advanced XP Detector" and other fake Microsoft virus scans
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Tuesday, June 03, 2008 12:12:40 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 3/06/2008
Kaspersky Anti-Virus database records: 824795
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
Scan Statistics:
Total number of scanned objects: 38581
Number of viruses found: 11
Number of infected objects: 29
Number of suspicious objects: 0
Duration of the scan process: 00:55:43
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\avg8\emc\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgcore.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avglng.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgrs.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgsched.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgsrm.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgwd.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\commonpriv.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\mvictor\Local Settings\Temp\181390.tmp Infected: not-a-virus:AdWare.Win32.E404.bi skipped
C:\Documents and Settings\mvictor\Local Settings\Temp\printsrv32.exe Infected: not-a-virus:FraudTool.Win32.Agent.c skipped
C:\Documents and Settings\mvictor\Local Settings\Temp\tmp2012031.dll Infected: Trojan-Downloader.Win32.Small.wfd skipped
C:\Documents and Settings\mvictor\Local Settings\Temporary Internet Files\Content.IE5\EO6FTLA6\1212438378[1].exe/data0000/stream/data0007 Infected: not-a-virus:FraudTool.Win32.AdvancedXPFixer.a skipped
C:\Documents and Settings\mvictor\Local Settings\Temporary Internet Files\Content.IE5\EO6FTLA6\1212438378[1].exe/data0000/stream Infected: not-a-virus:FraudTool.Win32.AdvancedXPFixer.a skipped
C:\Documents and Settings\mvictor\Local Settings\Temporary Internet Files\Content.IE5\EO6FTLA6\1212438378[1].exe/data0000 Infected: not-a-virus:FraudTool.Win32.AdvancedXPFixer.a skipped
C:\Documents and Settings\mvictor\Local Settings\Temporary Internet Files\Content.IE5\EO6FTLA6\1212438378[1].exe EmbeddedEXE: infected - 3 skipped
C:\Documents and Settings\mvictor\Local Settings\Temporary Internet Files\Content.IE5\EO6FTLA6\1212438378[1].exe PECompact: infected - 3 skipped
C:\Documents and Settings\mvictor\Local Settings\Temporary Internet Files\Content.IE5\EO6FTLA6\1212438378[1].exe PecBundle: infected - 3 skipped
C:\Documents and Settings\mvictor\Local Settings\Temporary Internet Files\Content.IE5\EO6FTLA6\1212438378[1].exe PE_Patch.PECompact: infected - 3 skipped
C:\Documents and Settings\mvictor\My Documents\My Music\iTunes\iTunes Music\domino ghetto jam.mp3 Infected: Trojan-Downloader.WMA.Wimad.n skipped
C:\Documents and Settings\mvictor.KENTLAW\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\mvictor.KENTLAW\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\mvictor.KENTLAW\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\mvictor.KENTLAW\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\mvictor.KENTLAW\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\mvictor.KENTLAW\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\mvictor.KENTLAW\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\RECYCLER\S-1-5-21-1957994488-813497703-725345543-1003\Dc31.exe Infected: not-a-virus:AdTool.Win32.Zango.s skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP0\A0000019.dll Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP0\A0000023.exe Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP1\A0000046.dll Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP1\A0000050.exe Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP1\A0001046.dll Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP1\A0001057.exe Infected: SpamTool.Win32.Agent.kx skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP1\A0001060.dll Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP1\A0001065.exe Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP2\A0001108.exe Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP8\A0001445.dll Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP8\A0001464.exe Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP8\A0002445.dll Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP8\A0002513.dll Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002529.exe Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002530.exe Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002531.exe Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002532.exe Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002533.exe Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002534.exe Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002535.exe Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002536.dll Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002537.sys Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002538.sys Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002539.sys Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002540.sys Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002541.sys Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002542.sys Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002543.sys Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002544.sys Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002545.sys Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002546.sys Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002547.sys Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002548.sys Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002550.dll Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002551.dll Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002552.cpl Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002553.dll Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002584.exe Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002585.exe/data0000/stream/data0007 Infected: not-a-virus:FraudTool.Win32.AdvancedXPFixer.a skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002585.exe/data0000/stream Infected: not-a-virus:FraudTool.Win32.AdvancedXPFixer.a skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002585.exe/data0000 Infected: not-a-virus:FraudTool.Win32.AdvancedXPFixer.a skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002585.exe EmbeddedEXE: infected - 3 skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002585.exe PECompact: infected - 3 skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002585.exe PecBundle: infected - 3 skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002585.exe PE_Patch.PECompact: infected - 3 skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\change.log Object is locked skipped
C:\WINDOWS\CSC\00000001 Object is locked skipped
C:\WINDOWS\Debug\Netlogon.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\system32\905757\905757.dll Infected: not-a-virus:AdWare.Win32.E404.bw skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\pvC52.sys Object is locked skipped
C:\WINDOWS\system32\iifcCstq.dll Object is locked skipped
C:\WINDOWS\system32\iSecurity.cpl Infected: Trojan.Win32.Emgr.ad skipped
C:\WINDOWS\system32\qytcinqv.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.xmw skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\system32\WinCtrl32.dll Object is locked skipped
C:\WINDOWS\Temp\BN23.tmp Infected: Trojan.Win32.Buzus.fit skipped
C:\WINDOWS\Temp\BN3.tmp Infected: Trojan.Win32.Buzus.fit skipped
C:\WINDOWS\Temp\BN4.tmp Infected: Trojan.Win32.Buzus.fit skipped
C:\WINDOWS\Temp\BN6.tmp Infected: Trojan.Win32.Buzus.fit skipped
C:\WINDOWS\Temp\BN7.tmp Infected: Trojan.Win32.Buzus.fit skipped
C:\WINDOWS\Temp\BNA.tmp Infected: Trojan.Win32.Buzus.fit skipped
Scan process completed.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:47:36 AM, on 6/3/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Mozilla Firefox\firefox.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {4F26BEDB-D89B-44A1-948B-5D523292DADF} - C:\WINDOWS\system32\tuvTkhFY.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: 818646 helper - {54192079-8E8A-43D8-BCBC-3874916159AF} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: (no name) - {B5E3C772-F17A-4406-B127-F71448BA9357} - C:\WINDOWS\system32\sSMcAQKA.dll (file missing)
O2 - BHO: 905757 helper - {E28F671C-3D83-4149-BA2F-546A67702B49} - (no file)
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [advap32] C:\DOCUME~1\mvictor\LOCALS~1\Temp\rbnpsrv.exe/r
O4 - HKLM\..\Run: [d080e936] rundll32.exe "C:\WINDOWS\system32\qytcinqv.dll",b
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab
O16 - DPF: {B4A78D29-52B1-4A7B-BAC0-1471BEDF9836} - http://xscanner.shredderscan.com/setup/webinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = kentlaw.edu
O17 - HKLM\Software\..\Telephony: DomainName = kentlaw.edu
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: iSecurity.cpl
O20 - Winlogon Notify: tuvTkhFY - C:\WINDOWS\SYSTEM32\tuvTkhFY.dll
O20 - Winlogon Notify: WinCtrl32 - WinCtrl32.dll (file missing)
O21 - SSODL: StatAlrt - {429025d8-06a7-40c2-9a8a-83e7a9a0b528} - C:\WINDOWS\Resources\StatAlrt.dll (file missing)
O21 - SSODL: iSecurity - {A8311E8F-E459-4D22-89B4-CB9DCF10A425} - (no file)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
--
End of file - 7417 bytes
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Tuesday, June 03, 2008 12:12:40 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 3/06/2008
Kaspersky Anti-Virus database records: 824795
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
Scan Statistics:
Total number of scanned objects: 38581
Number of viruses found: 11
Number of infected objects: 29
Number of suspicious objects: 0
Duration of the scan process: 00:55:43
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\avg8\emc\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgcore.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avglng.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgrs.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgsched.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgsrm.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgwd.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\commonpriv.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\mvictor\Local Settings\Temp\181390.tmp Infected: not-a-virus:AdWare.Win32.E404.bi skipped
C:\Documents and Settings\mvictor\Local Settings\Temp\printsrv32.exe Infected: not-a-virus:FraudTool.Win32.Agent.c skipped
C:\Documents and Settings\mvictor\Local Settings\Temp\tmp2012031.dll Infected: Trojan-Downloader.Win32.Small.wfd skipped
C:\Documents and Settings\mvictor\Local Settings\Temporary Internet Files\Content.IE5\EO6FTLA6\1212438378[1].exe/data0000/stream/data0007 Infected: not-a-virus:FraudTool.Win32.AdvancedXPFixer.a skipped
C:\Documents and Settings\mvictor\Local Settings\Temporary Internet Files\Content.IE5\EO6FTLA6\1212438378[1].exe/data0000/stream Infected: not-a-virus:FraudTool.Win32.AdvancedXPFixer.a skipped
C:\Documents and Settings\mvictor\Local Settings\Temporary Internet Files\Content.IE5\EO6FTLA6\1212438378[1].exe/data0000 Infected: not-a-virus:FraudTool.Win32.AdvancedXPFixer.a skipped
C:\Documents and Settings\mvictor\Local Settings\Temporary Internet Files\Content.IE5\EO6FTLA6\1212438378[1].exe EmbeddedEXE: infected - 3 skipped
C:\Documents and Settings\mvictor\Local Settings\Temporary Internet Files\Content.IE5\EO6FTLA6\1212438378[1].exe PECompact: infected - 3 skipped
C:\Documents and Settings\mvictor\Local Settings\Temporary Internet Files\Content.IE5\EO6FTLA6\1212438378[1].exe PecBundle: infected - 3 skipped
C:\Documents and Settings\mvictor\Local Settings\Temporary Internet Files\Content.IE5\EO6FTLA6\1212438378[1].exe PE_Patch.PECompact: infected - 3 skipped
C:\Documents and Settings\mvictor\My Documents\My Music\iTunes\iTunes Music\domino ghetto jam.mp3 Infected: Trojan-Downloader.WMA.Wimad.n skipped
C:\Documents and Settings\mvictor.KENTLAW\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\mvictor.KENTLAW\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\mvictor.KENTLAW\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\mvictor.KENTLAW\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\mvictor.KENTLAW\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\mvictor.KENTLAW\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\mvictor.KENTLAW\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\RECYCLER\S-1-5-21-1957994488-813497703-725345543-1003\Dc31.exe Infected: not-a-virus:AdTool.Win32.Zango.s skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP0\A0000019.dll Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP0\A0000023.exe Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP1\A0000046.dll Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP1\A0000050.exe Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP1\A0001046.dll Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP1\A0001057.exe Infected: SpamTool.Win32.Agent.kx skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP1\A0001060.dll Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP1\A0001065.exe Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP2\A0001108.exe Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP8\A0001445.dll Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP8\A0001464.exe Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP8\A0002445.dll Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP8\A0002513.dll Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002529.exe Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002530.exe Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002531.exe Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002532.exe Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002533.exe Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002534.exe Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002535.exe Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002536.dll Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002537.sys Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002538.sys Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002539.sys Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002540.sys Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002541.sys Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002542.sys Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002543.sys Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002544.sys Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002545.sys Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002546.sys Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002547.sys Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002548.sys Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002550.dll Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002551.dll Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002552.cpl Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002553.dll Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002584.exe Object is locked skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002585.exe/data0000/stream/data0007 Infected: not-a-virus:FraudTool.Win32.AdvancedXPFixer.a skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002585.exe/data0000/stream Infected: not-a-virus:FraudTool.Win32.AdvancedXPFixer.a skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002585.exe/data0000 Infected: not-a-virus:FraudTool.Win32.AdvancedXPFixer.a skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002585.exe EmbeddedEXE: infected - 3 skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002585.exe PECompact: infected - 3 skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002585.exe PecBundle: infected - 3 skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\A0002585.exe PE_Patch.PECompact: infected - 3 skipped
C:\System Volume Information\_restore{D7BD4D7E-3CE6-4297-B81A-88060C6FB119}\RP9\change.log Object is locked skipped
C:\WINDOWS\CSC\00000001 Object is locked skipped
C:\WINDOWS\Debug\Netlogon.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\system32\905757\905757.dll Infected: not-a-virus:AdWare.Win32.E404.bw skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\pvC52.sys Object is locked skipped
C:\WINDOWS\system32\iifcCstq.dll Object is locked skipped
C:\WINDOWS\system32\iSecurity.cpl Infected: Trojan.Win32.Emgr.ad skipped
C:\WINDOWS\system32\qytcinqv.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.xmw skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\system32\WinCtrl32.dll Object is locked skipped
C:\WINDOWS\Temp\BN23.tmp Infected: Trojan.Win32.Buzus.fit skipped
C:\WINDOWS\Temp\BN3.tmp Infected: Trojan.Win32.Buzus.fit skipped
C:\WINDOWS\Temp\BN4.tmp Infected: Trojan.Win32.Buzus.fit skipped
C:\WINDOWS\Temp\BN6.tmp Infected: Trojan.Win32.Buzus.fit skipped
C:\WINDOWS\Temp\BN7.tmp Infected: Trojan.Win32.Buzus.fit skipped
C:\WINDOWS\Temp\BNA.tmp Infected: Trojan.Win32.Buzus.fit skipped
Scan process completed.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:47:36 AM, on 6/3/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Mozilla Firefox\firefox.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {4F26BEDB-D89B-44A1-948B-5D523292DADF} - C:\WINDOWS\system32\tuvTkhFY.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: 818646 helper - {54192079-8E8A-43D8-BCBC-3874916159AF} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: (no name) - {B5E3C772-F17A-4406-B127-F71448BA9357} - C:\WINDOWS\system32\sSMcAQKA.dll (file missing)
O2 - BHO: 905757 helper - {E28F671C-3D83-4149-BA2F-546A67702B49} - (no file)
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [advap32] C:\DOCUME~1\mvictor\LOCALS~1\Temp\rbnpsrv.exe/r
O4 - HKLM\..\Run: [d080e936] rundll32.exe "C:\WINDOWS\system32\qytcinqv.dll",b
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab
O16 - DPF: {B4A78D29-52B1-4A7B-BAC0-1471BEDF9836} - http://xscanner.shredderscan.com/setup/webinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = kentlaw.edu
O17 - HKLM\Software\..\Telephony: DomainName = kentlaw.edu
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: iSecurity.cpl
O20 - Winlogon Notify: tuvTkhFY - C:\WINDOWS\SYSTEM32\tuvTkhFY.dll
O20 - Winlogon Notify: WinCtrl32 - WinCtrl32.dll (file missing)
O21 - SSODL: StatAlrt - {429025d8-06a7-40c2-9a8a-83e7a9a0b528} - C:\WINDOWS\Resources\StatAlrt.dll (file missing)
O21 - SSODL: iSecurity - {A8311E8F-E459-4D22-89B4-CB9DCF10A425} - (no file)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
--
End of file - 7417 bytes