Hello,
I've just cleaned the first machine in my network, and now I'm posting the HJT and Kaspersky log for the other machine in my network.
(I have completed the steps in the "Readme first" section)
Can you please help me sort this mess out? I appreciate it.
Thanks!
**************
HJT Log
**************
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:21:14 PM, on 26/05/2008
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Safe mode
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\SYSTEM32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.EXE
C:\WINNT\SYSTEM32\taskmgr.exe
C:\Program Files\Trend Micro\HijackThis\HijackT.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {B3102264-D09D-4322-B625-503FBF18DD7E} - C:\WINNT\system32\khfCuSig.dll (file missing)
O2 - BHO: (no name) - {B3FA4FFF-85F1-4C0C-8FA2-1F6F98071091} - C:\WINNT\system32\ssqPhEVm.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [90d938f5] rundll32.exe "C:\WINNT\system32\kmvuobkn.dll",b
O4 - HKLM\..\Run: [BM93ea0b69] Rundll32.exe "C:\WINNT\system32\frcvkusn.dll",s
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [SpybotDeletingA3225] command /c del "C:\WINNT\system32\drqojpol.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5257] cmd /c del "C:\WINNT\system32\drqojpol.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5409] command /c del "C:\WINNT\system32\frcvkusn.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4477] cmd /c del "C:\WINNT\system32\frcvkusn.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1922] command /c del "C:\WINNT\system32\jwnldkcm.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4206] cmd /c del "C:\WINNT\system32\jwnldkcm.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6585] command /c del "C:\WINNT\system32\ssqPhEVm.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2584] cmd /c del "C:\WINNT\system32\ssqPhEVm.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1026] command /c del "C:\WINNT\system32\drqojpol.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7977] cmd /c del "C:\WINNT\system32\drqojpol.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA121] command /c del "C:\WINNT\system32\frcvkusn.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8182] cmd /c del "C:\WINNT\system32\frcvkusn.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA844] command /c del "C:\WINNT\system32\jwnldkcm.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4836] cmd /c del "C:\WINNT\system32\jwnldkcm.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2280] command /c del "C:\WINNT\system32\ssqPhEVm.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1862] cmd /c del "C:\WINNT\system32\ssqPhEVm.dll"
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [rebootex] C:\Program Files\RebootEx\rebootw.exe -s
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\RunOnce: [SpybotDeletingB5383] command /c del "C:\WINNT\system32\drqojpol.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7168] cmd /c del "C:\WINNT\system32\drqojpol.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5729] command /c del "C:\WINNT\system32\frcvkusn.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD14] cmd /c del "C:\WINNT\system32\frcvkusn.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4396] command /c del "C:\WINNT\system32\jwnldkcm.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7612] cmd /c del "C:\WINNT\system32\jwnldkcm.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6210] command /c del "C:\WINNT\system32\ssqPhEVm.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD66] cmd /c del "C:\WINNT\system32\ssqPhEVm.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9442] command /c del "C:\WINNT\system32\drqojpol.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6125] cmd /c del "C:\WINNT\system32\drqojpol.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB576] command /c del "C:\WINNT\system32\frcvkusn.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6052] cmd /c del "C:\WINNT\system32\frcvkusn.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6256] command /c del "C:\WINNT\system32\jwnldkcm.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5311] cmd /c del "C:\WINNT\system32\jwnldkcm.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4372] command /c del "C:\WINNT\system32\ssqPhEVm.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3931] cmd /c del "C:\WINNT\system32\ssqPhEVm.dll"
O4 - HKUS\.DEFAULT\..\Run: [internat.exe] internat.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Startup: VirtualExpander.lnk = C:\WINNT\system32\VirtualExpander\VirtualExpander.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O16 - DPF: TruePass EPF 7,0,100,717 - https://blrscr3.egs-seg.gc.ca/applets/entrusttruepassapplet-epf.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1132292444121
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1177881847056
O20 - Winlogon Notify: khfCuSig - khfCuSig.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Online Backup Service - Unknown owner - C:\Program Files\Data Deposit Box\Data Deposit Box\nts.exe (file missing)
--
End of file - 8416 bytes
**************
Kaspersky log
**************
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Monday, May 26, 2008 12:12:58 PM
Operating System: Microsoft Windows 2000 Professional, Service Pack 4 (Build 2195)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 26/05/2008
Kaspersky Anti-Virus database records: 800955
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
Scan Statistics:
Total number of scanned objects: 64362
Number of viruses found: 1
Number of infected objects: 6
Number of suspicious objects: 0
Duration of the scan process: 01:57:30
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\tamara\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\tamara\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\tamara\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\tamara\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\tamara\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\tamara\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\tamara\ntuser.dat.LOG Object is locked skipped
C:\RECYCLER\S-1-5-21-839522115-1580436667-1060284298-1000\Dc162\bitdefender_totalsecurity_2008_32b.exe/data0000.cab/is152564.exe Infected: Trojan.Win32.Monder.gen skipped
C:\RECYCLER\S-1-5-21-839522115-1580436667-1060284298-1000\Dc162\bitdefender_totalsecurity_2008_32b.exe/data0000.cab Infected: Trojan.Win32.Monder.gen skipped
C:\RECYCLER\S-1-5-21-839522115-1580436667-1060284298-1000\Dc162\bitdefender_totalsecurity_2008_32b.exe Rsrc-Package: infected - 2 skipped
C:\RECYCLER\S-1-5-21-839522115-1580436667-1060284298-1000\Dc162\Patch.exe/data0000.cab/is152564.exe Infected: Trojan.Win32.Monder.gen skipped
C:\RECYCLER\S-1-5-21-839522115-1580436667-1060284298-1000\Dc162\Patch.exe/data0000.cab Infected: Trojan.Win32.Monder.gen skipped
C:\RECYCLER\S-1-5-21-839522115-1580436667-1060284298-1000\Dc162\Patch.exe Rsrc-Package: infected - 2 skipped
C:\WINNT\CSC\00000001 Object is locked skipped
C:\WINNT\Debug\ipsecpa.log Object is locked skipped
C:\WINNT\Debug\oakley.log Object is locked skipped
C:\WINNT\Debug\PASSWD.LOG Object is locked skipped
C:\WINNT\SchedLgU.Txt Object is locked skipped
C:\WINNT\system32\config\AppEvent.Evt Object is locked skipped
C:\WINNT\system32\config\default Object is locked skipped
C:\WINNT\system32\config\default.LOG Object is locked skipped
C:\WINNT\system32\config\SAM Object is locked skipped
C:\WINNT\system32\config\SAM.LOG Object is locked skipped
C:\WINNT\system32\config\SecEvent.Evt Object is locked skipped
C:\WINNT\system32\config\SECURITY Object is locked skipped
C:\WINNT\system32\config\SECURITY.LOG Object is locked skipped
C:\WINNT\system32\config\software Object is locked skipped
C:\WINNT\system32\config\software.LOG Object is locked skipped
C:\WINNT\system32\config\SysEvent.Evt Object is locked skipped
C:\WINNT\system32\config\system Object is locked skipped
C:\WINNT\system32\config\SYSTEM.ALT Object is locked skipped
C:\WINNT\system32\Perflib_Perfdata_21c.dat Object is locked skipped
C:\WINNT\system32\Perflib_Perfdata_310.dat Object is locked skipped
Scan process completed.
I've just cleaned the first machine in my network, and now I'm posting the HJT and Kaspersky log for the other machine in my network.
(I have completed the steps in the "Readme first" section)
Can you please help me sort this mess out? I appreciate it.
Thanks!
**************
HJT Log
**************
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:21:14 PM, on 26/05/2008
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Safe mode
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\SYSTEM32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.EXE
C:\WINNT\SYSTEM32\taskmgr.exe
C:\Program Files\Trend Micro\HijackThis\HijackT.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {B3102264-D09D-4322-B625-503FBF18DD7E} - C:\WINNT\system32\khfCuSig.dll (file missing)
O2 - BHO: (no name) - {B3FA4FFF-85F1-4C0C-8FA2-1F6F98071091} - C:\WINNT\system32\ssqPhEVm.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [90d938f5] rundll32.exe "C:\WINNT\system32\kmvuobkn.dll",b
O4 - HKLM\..\Run: [BM93ea0b69] Rundll32.exe "C:\WINNT\system32\frcvkusn.dll",s
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [SpybotDeletingA3225] command /c del "C:\WINNT\system32\drqojpol.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5257] cmd /c del "C:\WINNT\system32\drqojpol.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5409] command /c del "C:\WINNT\system32\frcvkusn.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4477] cmd /c del "C:\WINNT\system32\frcvkusn.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1922] command /c del "C:\WINNT\system32\jwnldkcm.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4206] cmd /c del "C:\WINNT\system32\jwnldkcm.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6585] command /c del "C:\WINNT\system32\ssqPhEVm.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2584] cmd /c del "C:\WINNT\system32\ssqPhEVm.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1026] command /c del "C:\WINNT\system32\drqojpol.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7977] cmd /c del "C:\WINNT\system32\drqojpol.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA121] command /c del "C:\WINNT\system32\frcvkusn.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8182] cmd /c del "C:\WINNT\system32\frcvkusn.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA844] command /c del "C:\WINNT\system32\jwnldkcm.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4836] cmd /c del "C:\WINNT\system32\jwnldkcm.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2280] command /c del "C:\WINNT\system32\ssqPhEVm.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1862] cmd /c del "C:\WINNT\system32\ssqPhEVm.dll"
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [rebootex] C:\Program Files\RebootEx\rebootw.exe -s
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\RunOnce: [SpybotDeletingB5383] command /c del "C:\WINNT\system32\drqojpol.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7168] cmd /c del "C:\WINNT\system32\drqojpol.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5729] command /c del "C:\WINNT\system32\frcvkusn.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD14] cmd /c del "C:\WINNT\system32\frcvkusn.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4396] command /c del "C:\WINNT\system32\jwnldkcm.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7612] cmd /c del "C:\WINNT\system32\jwnldkcm.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6210] command /c del "C:\WINNT\system32\ssqPhEVm.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD66] cmd /c del "C:\WINNT\system32\ssqPhEVm.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9442] command /c del "C:\WINNT\system32\drqojpol.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6125] cmd /c del "C:\WINNT\system32\drqojpol.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB576] command /c del "C:\WINNT\system32\frcvkusn.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6052] cmd /c del "C:\WINNT\system32\frcvkusn.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6256] command /c del "C:\WINNT\system32\jwnldkcm.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5311] cmd /c del "C:\WINNT\system32\jwnldkcm.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4372] command /c del "C:\WINNT\system32\ssqPhEVm.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3931] cmd /c del "C:\WINNT\system32\ssqPhEVm.dll"
O4 - HKUS\.DEFAULT\..\Run: [internat.exe] internat.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Startup: VirtualExpander.lnk = C:\WINNT\system32\VirtualExpander\VirtualExpander.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O16 - DPF: TruePass EPF 7,0,100,717 - https://blrscr3.egs-seg.gc.ca/applets/entrusttruepassapplet-epf.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1132292444121
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1177881847056
O20 - Winlogon Notify: khfCuSig - khfCuSig.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Online Backup Service - Unknown owner - C:\Program Files\Data Deposit Box\Data Deposit Box\nts.exe (file missing)
--
End of file - 8416 bytes
**************
Kaspersky log
**************
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Monday, May 26, 2008 12:12:58 PM
Operating System: Microsoft Windows 2000 Professional, Service Pack 4 (Build 2195)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 26/05/2008
Kaspersky Anti-Virus database records: 800955
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
Scan Statistics:
Total number of scanned objects: 64362
Number of viruses found: 1
Number of infected objects: 6
Number of suspicious objects: 0
Duration of the scan process: 01:57:30
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\tamara\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\tamara\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\tamara\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\tamara\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\tamara\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\tamara\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\tamara\ntuser.dat.LOG Object is locked skipped
C:\RECYCLER\S-1-5-21-839522115-1580436667-1060284298-1000\Dc162\bitdefender_totalsecurity_2008_32b.exe/data0000.cab/is152564.exe Infected: Trojan.Win32.Monder.gen skipped
C:\RECYCLER\S-1-5-21-839522115-1580436667-1060284298-1000\Dc162\bitdefender_totalsecurity_2008_32b.exe/data0000.cab Infected: Trojan.Win32.Monder.gen skipped
C:\RECYCLER\S-1-5-21-839522115-1580436667-1060284298-1000\Dc162\bitdefender_totalsecurity_2008_32b.exe Rsrc-Package: infected - 2 skipped
C:\RECYCLER\S-1-5-21-839522115-1580436667-1060284298-1000\Dc162\Patch.exe/data0000.cab/is152564.exe Infected: Trojan.Win32.Monder.gen skipped
C:\RECYCLER\S-1-5-21-839522115-1580436667-1060284298-1000\Dc162\Patch.exe/data0000.cab Infected: Trojan.Win32.Monder.gen skipped
C:\RECYCLER\S-1-5-21-839522115-1580436667-1060284298-1000\Dc162\Patch.exe Rsrc-Package: infected - 2 skipped
C:\WINNT\CSC\00000001 Object is locked skipped
C:\WINNT\Debug\ipsecpa.log Object is locked skipped
C:\WINNT\Debug\oakley.log Object is locked skipped
C:\WINNT\Debug\PASSWD.LOG Object is locked skipped
C:\WINNT\SchedLgU.Txt Object is locked skipped
C:\WINNT\system32\config\AppEvent.Evt Object is locked skipped
C:\WINNT\system32\config\default Object is locked skipped
C:\WINNT\system32\config\default.LOG Object is locked skipped
C:\WINNT\system32\config\SAM Object is locked skipped
C:\WINNT\system32\config\SAM.LOG Object is locked skipped
C:\WINNT\system32\config\SecEvent.Evt Object is locked skipped
C:\WINNT\system32\config\SECURITY Object is locked skipped
C:\WINNT\system32\config\SECURITY.LOG Object is locked skipped
C:\WINNT\system32\config\software Object is locked skipped
C:\WINNT\system32\config\software.LOG Object is locked skipped
C:\WINNT\system32\config\SysEvent.Evt Object is locked skipped
C:\WINNT\system32\config\system Object is locked skipped
C:\WINNT\system32\config\SYSTEM.ALT Object is locked skipped
C:\WINNT\system32\Perflib_Perfdata_21c.dat Object is locked skipped
C:\WINNT\system32\Perflib_Perfdata_310.dat Object is locked skipped
Scan process completed.