Hello. I have been a longtime user of Spybot SnD and recently came across a problem with maleware. I used Spybot SnD in conjunction with a lavasoft program to attempt to remove any and all problem. This did not work out entirely so I used Kaspersky. I have gotten rid of everything except this Tojan.win32.Agent.bck file that when I have Kaspersky try to delete it my comp reboots and it is there again everytime. I have tried to run these things in Safe mode but the same thing didnt turn up. Here is a HJT log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:49:00 PM, on 9/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\cmtdivwp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=1070302
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=1070302
O4 - HKLM\..\Run: [BootSkin Startup Jobs] "C:\Program Files\Stardock\WinCustomize\BootSkin\BootSkin.exe" /StartupJobs
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O4 - HKLM\..\Run: [AAWTray] C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
O4 - HKLM\..\Run: [SystemOptimizer] rundll32.exe "C:\WINDOWS\system32\ujgiyreq.dll",forkonce
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\cmtdivwp.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
--
End of file - 5109 bytes
This is the Kaspersky log
9/12/2007 1:37:49 PM File: c:\windows\system32\mljjh.dll ok iSwift
9/12/2007 1:37:49 PM File: c:\program files\flashget\getflash.dll ok iSwift
9/12/2007 1:37:49 PM File: c:\program files\adobe\acrobat 7.0\reader\acrord32.exe ok iSwift
9/12/2007 1:37:49 PM File: c:\program files\msn gaming zone\windows\bckgzm.exe ok iSwift
9/12/2007 1:37:49 PM File: c:\program files\msn gaming zone\windows\chkrzm.exe ok iSwift
9/12/2007 1:37:49 PM File: c:\windows\system32\cmcfg32.dll ok iSwift
9/12/2007 1:37:49 PM File: c:\program files\netmeeting\conf.exe ok iSwift
9/12/2007 1:37:49 PM File: c:\program files\windows nt\dialer.exe ok iSwift
9/12/2007 1:37:49 PM File: c:\program files\digital line detect\dlg.exe ok iSwift
9/12/2007 1:37:49 PM File: c:\program files\mozilla firefox\firefox.exe ok iSwift
9/12/2007 1:37:49 PM File: c:\windows\pchealth\helpctr\binaries\helpctr.exe ok iSwift
9/12/2007 1:37:50 PM File: c:\program files\msn gaming zone\windows\hrtzzm.exe ok iSwift
9/12/2007 1:37:50 PM File: c:\program files\internet explorer\connection wizard\icwconn1.exe ok iSwift
9/12/2007 1:37:50 PM File: c:\program files\internet explorer\connection wizard\icwconn2.exe ok iSwift
9/12/2007 1:37:50 PM File: c:\program files\internet explorer\connection wizard\inetwiz.exe ok iSwift
9/12/2007 1:37:50 PM File: c:\program files\internet explorer\connection wizard\isignup.exe ok iSwift
9/12/2007 1:37:50 PM File: c:\program files\dell\mediadirect\mdirect.exe ok iSwift
9/12/2007 1:37:50 PM File: C:\WINDOWS\system32\usmt\migwiz.exe ok iSwift
9/12/2007 1:37:50 PM File: c:\program files\movie maker\moviemk.exe ok iSwift
9/12/2007 1:37:50 PM File: c:\windows\pchealth\helpctr\binaries\msconfig.exe ok iSwift
9/12/2007 1:37:50 PM File: C:\Program Files\outlook express\msimn.exe ok iSwift
9/12/2007 1:37:50 PM File: c:\program files\common files\microsoft shared\msinfo\msinfo32.exe ok iSwift
9/12/2007 1:37:50 PM File: c:\program files\messenger\msmsgs.exe ok iSwift
9/12/2007 1:37:50 PM File: c:\progra~1\mi1933~1\office11\mspub.exe ok iSwift
9/12/2007 1:37:50 PM File: c:\progra~1\common~1\micros~1\modi\11.0\mspview.exe ok iSwift
9/12/2007 1:37:50 PM File: c:\progra~1\mi1933~1\office11\ois.exe ok iSwift
9/12/2007 1:37:50 PM File: C:\WINDOWS\system32\mspaint.exe ok iSwift
9/12/2007 1:37:50 PM File: c:\program files\windows nt\pinball\pinball.exe ok iSwift
9/12/2007 1:37:50 PM File: c:\progra~1\mi1933~1\office11\powerpnt.exe ok iSwift
9/12/2007 1:37:50 PM File: c:\progra~1\quickt~1\quicktimeplayer.exe ok iSwift
9/12/2007 1:37:50 PM File: c:\progra~1\quickt~1\quicktimeupdater.exe ok iSwift
9/12/2007 1:37:50 PM File: c:\program files\msn gaming zone\windows\rvsezm.exe ok iSwift
9/12/2007 1:37:50 PM File: c:\progra~1\mi1933~1\office11\1033\schdpl32.exe ok iSwift
9/12/2007 1:37:50 PM File: c:\program files\msn gaming zone\windows\shvlzm.exe ok iSwift
9/12/2007 1:37:52 PM File: C:\Program Files\outlook express\wab.exe ok iSwift
9/12/2007 1:37:52 PM File: C:\Program Files\outlook express\wabmig.exe ok iSwift
9/12/2007 1:37:52 PM File: c:\program files\winrar\winrar.exe ok iSwift
9/12/2007 1:37:52 PM File: c:\progra~1\mi1933~1\office11\winword.exe ok iSwift
9/12/2007 1:37:52 PM File: c:\program files\microsoft works\wkplmstp.exe ok iSwift
9/12/2007 1:37:52 PM File: c:\program files\microsoft works\wksab.exe ok iSwift
9/12/2007 1:37:52 PM File: c:\program files\common files\microsoft shared\works shared\wkscal.exe ok iSwift
9/12/2007 1:37:52 PM File: c:\program files\microsoft works\wksdb.exe ok iSwift
9/12/2007 1:37:52 PM File: c:\program files\microsoft works\wkssb.exe ok iSwift
9/12/2007 1:37:52 PM File: c:\program files\microsoft works\wksss.exe ok iSwift
9/12/2007 1:37:52 PM File: c:\program files\microsoft works\wkswp.exe ok iSwift
9/12/2007 1:37:52 PM File: c:\program files\microsoft works\wkwcestp.exe ok iSwift
9/12/2007 1:37:52 PM File: C:\Program Files\windows nt\accessories\wordpad.exe ok iSwift
9/12/2007 1:37:52 PM File: c:\windows\system32\ntsd.exe ok iSwift
9/12/2007 1:37:52 PM File: c:\windows\system32\java.exe ok iSwift
9/12/2007 1:37:52 PM File: c:\windows\system32\console.dll ok iSwift
9/12/2007 1:37:53 PM File: c:\program files\java\jre1.5.0_06\bin\npjpi150_06.dll ok iSwift
9/12/2007 1:37:53 PM File: c:\progra~1\mi1933~1\office11\refiebar.dll ok iSwift
9/12/2007 1:37:53 PM File: c:\progra~1\mi1933~1\office11\refbar.ico ok iSwift
9/12/2007 1:37:53 PM File: c:\progra~1\mi1933~1\office11\refbarh.ico ok iSwift
9/12/2007 1:37:53 PM File: c:\program files\flashget\flashget.exe ok iSwift
9/12/2007 1:37:53 PM File: c:\program files\uniblue\spyeraser\spyeraser.exe ok iSwift
9/12/2007 1:37:53 PM File: C:\WINDOWS\system32\rsvpsp.dll ok iSwift
9/12/2007 1:37:53 PM File: C:\WINDOWS\system32\winrnr.dll ok iSwift
9/12/2007 1:37:53 PM File: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini ok iSwift
9/12/2007 1:37:53 PM File: C:\Documents and Settings\user\Start Menu\Programs\Startup\desktop.ini ok iSwift
9/12/2007 1:37:53 PM File: C:\WINDOWS\ehome\ehSched.exe ok iSwift
9/12/2007 1:37:53 PM File: C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe ok iSwift
9/12/2007 1:37:53 PM File: C:\WINDOWS\ehome\ehrecvr.exe ok iSwift
9/12/2007 1:37:53 PM File: C:\WINDOWS\system32\smss.exe ok iSwift
9/12/2007 1:37:53 PM File: C:\WINDOWS\system32\WLTRYSVC.EXE ok iSwift
9/12/2007 1:37:53 PM File: C:\WINDOWS\system32\BCMWLTRY.EXE ok iSwift
9/12/2007 1:37:54 PM Logical disk sector: C ok scanned
9/12/2007 1:37:54 PM Logical disk sector: D ok scanned
9/12/2007 1:37:55 PM Physical disk sector: \Device\HarddiskVolume4 ok scanned
9/12/2007 1:37:55 PM Physical disk sector: \Device\HarddiskVolume3 ok scanned
9/12/2007 1:37:56 PM Physical disk sector: \Device\HarddiskVolume1 ok scanned
9/12/2007 1:37:56 PM Physical disk sector: \Device\Harddisk0\DR0 ok scanned
9/12/2007 1:37:56 PM File: c:\windows\system32\cmtdivwp.exe detected Trojan program 'Trojan.Win32.Agent.bck'
Any help at all would be appreciated.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:49:00 PM, on 9/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\cmtdivwp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=1070302
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=1070302
O4 - HKLM\..\Run: [BootSkin Startup Jobs] "C:\Program Files\Stardock\WinCustomize\BootSkin\BootSkin.exe" /StartupJobs
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O4 - HKLM\..\Run: [AAWTray] C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
O4 - HKLM\..\Run: [SystemOptimizer] rundll32.exe "C:\WINDOWS\system32\ujgiyreq.dll",forkonce
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\cmtdivwp.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
--
End of file - 5109 bytes
This is the Kaspersky log
9/12/2007 1:37:49 PM File: c:\windows\system32\mljjh.dll ok iSwift
9/12/2007 1:37:49 PM File: c:\program files\flashget\getflash.dll ok iSwift
9/12/2007 1:37:49 PM File: c:\program files\adobe\acrobat 7.0\reader\acrord32.exe ok iSwift
9/12/2007 1:37:49 PM File: c:\program files\msn gaming zone\windows\bckgzm.exe ok iSwift
9/12/2007 1:37:49 PM File: c:\program files\msn gaming zone\windows\chkrzm.exe ok iSwift
9/12/2007 1:37:49 PM File: c:\windows\system32\cmcfg32.dll ok iSwift
9/12/2007 1:37:49 PM File: c:\program files\netmeeting\conf.exe ok iSwift
9/12/2007 1:37:49 PM File: c:\program files\windows nt\dialer.exe ok iSwift
9/12/2007 1:37:49 PM File: c:\program files\digital line detect\dlg.exe ok iSwift
9/12/2007 1:37:49 PM File: c:\program files\mozilla firefox\firefox.exe ok iSwift
9/12/2007 1:37:49 PM File: c:\windows\pchealth\helpctr\binaries\helpctr.exe ok iSwift
9/12/2007 1:37:50 PM File: c:\program files\msn gaming zone\windows\hrtzzm.exe ok iSwift
9/12/2007 1:37:50 PM File: c:\program files\internet explorer\connection wizard\icwconn1.exe ok iSwift
9/12/2007 1:37:50 PM File: c:\program files\internet explorer\connection wizard\icwconn2.exe ok iSwift
9/12/2007 1:37:50 PM File: c:\program files\internet explorer\connection wizard\inetwiz.exe ok iSwift
9/12/2007 1:37:50 PM File: c:\program files\internet explorer\connection wizard\isignup.exe ok iSwift
9/12/2007 1:37:50 PM File: c:\program files\dell\mediadirect\mdirect.exe ok iSwift
9/12/2007 1:37:50 PM File: C:\WINDOWS\system32\usmt\migwiz.exe ok iSwift
9/12/2007 1:37:50 PM File: c:\program files\movie maker\moviemk.exe ok iSwift
9/12/2007 1:37:50 PM File: c:\windows\pchealth\helpctr\binaries\msconfig.exe ok iSwift
9/12/2007 1:37:50 PM File: C:\Program Files\outlook express\msimn.exe ok iSwift
9/12/2007 1:37:50 PM File: c:\program files\common files\microsoft shared\msinfo\msinfo32.exe ok iSwift
9/12/2007 1:37:50 PM File: c:\program files\messenger\msmsgs.exe ok iSwift
9/12/2007 1:37:50 PM File: c:\progra~1\mi1933~1\office11\mspub.exe ok iSwift
9/12/2007 1:37:50 PM File: c:\progra~1\common~1\micros~1\modi\11.0\mspview.exe ok iSwift
9/12/2007 1:37:50 PM File: c:\progra~1\mi1933~1\office11\ois.exe ok iSwift
9/12/2007 1:37:50 PM File: C:\WINDOWS\system32\mspaint.exe ok iSwift
9/12/2007 1:37:50 PM File: c:\program files\windows nt\pinball\pinball.exe ok iSwift
9/12/2007 1:37:50 PM File: c:\progra~1\mi1933~1\office11\powerpnt.exe ok iSwift
9/12/2007 1:37:50 PM File: c:\progra~1\quickt~1\quicktimeplayer.exe ok iSwift
9/12/2007 1:37:50 PM File: c:\progra~1\quickt~1\quicktimeupdater.exe ok iSwift
9/12/2007 1:37:50 PM File: c:\program files\msn gaming zone\windows\rvsezm.exe ok iSwift
9/12/2007 1:37:50 PM File: c:\progra~1\mi1933~1\office11\1033\schdpl32.exe ok iSwift
9/12/2007 1:37:50 PM File: c:\program files\msn gaming zone\windows\shvlzm.exe ok iSwift
9/12/2007 1:37:52 PM File: C:\Program Files\outlook express\wab.exe ok iSwift
9/12/2007 1:37:52 PM File: C:\Program Files\outlook express\wabmig.exe ok iSwift
9/12/2007 1:37:52 PM File: c:\program files\winrar\winrar.exe ok iSwift
9/12/2007 1:37:52 PM File: c:\progra~1\mi1933~1\office11\winword.exe ok iSwift
9/12/2007 1:37:52 PM File: c:\program files\microsoft works\wkplmstp.exe ok iSwift
9/12/2007 1:37:52 PM File: c:\program files\microsoft works\wksab.exe ok iSwift
9/12/2007 1:37:52 PM File: c:\program files\common files\microsoft shared\works shared\wkscal.exe ok iSwift
9/12/2007 1:37:52 PM File: c:\program files\microsoft works\wksdb.exe ok iSwift
9/12/2007 1:37:52 PM File: c:\program files\microsoft works\wkssb.exe ok iSwift
9/12/2007 1:37:52 PM File: c:\program files\microsoft works\wksss.exe ok iSwift
9/12/2007 1:37:52 PM File: c:\program files\microsoft works\wkswp.exe ok iSwift
9/12/2007 1:37:52 PM File: c:\program files\microsoft works\wkwcestp.exe ok iSwift
9/12/2007 1:37:52 PM File: C:\Program Files\windows nt\accessories\wordpad.exe ok iSwift
9/12/2007 1:37:52 PM File: c:\windows\system32\ntsd.exe ok iSwift
9/12/2007 1:37:52 PM File: c:\windows\system32\java.exe ok iSwift
9/12/2007 1:37:52 PM File: c:\windows\system32\console.dll ok iSwift
9/12/2007 1:37:53 PM File: c:\program files\java\jre1.5.0_06\bin\npjpi150_06.dll ok iSwift
9/12/2007 1:37:53 PM File: c:\progra~1\mi1933~1\office11\refiebar.dll ok iSwift
9/12/2007 1:37:53 PM File: c:\progra~1\mi1933~1\office11\refbar.ico ok iSwift
9/12/2007 1:37:53 PM File: c:\progra~1\mi1933~1\office11\refbarh.ico ok iSwift
9/12/2007 1:37:53 PM File: c:\program files\flashget\flashget.exe ok iSwift
9/12/2007 1:37:53 PM File: c:\program files\uniblue\spyeraser\spyeraser.exe ok iSwift
9/12/2007 1:37:53 PM File: C:\WINDOWS\system32\rsvpsp.dll ok iSwift
9/12/2007 1:37:53 PM File: C:\WINDOWS\system32\winrnr.dll ok iSwift
9/12/2007 1:37:53 PM File: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini ok iSwift
9/12/2007 1:37:53 PM File: C:\Documents and Settings\user\Start Menu\Programs\Startup\desktop.ini ok iSwift
9/12/2007 1:37:53 PM File: C:\WINDOWS\ehome\ehSched.exe ok iSwift
9/12/2007 1:37:53 PM File: C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe ok iSwift
9/12/2007 1:37:53 PM File: C:\WINDOWS\ehome\ehrecvr.exe ok iSwift
9/12/2007 1:37:53 PM File: C:\WINDOWS\system32\smss.exe ok iSwift
9/12/2007 1:37:53 PM File: C:\WINDOWS\system32\WLTRYSVC.EXE ok iSwift
9/12/2007 1:37:53 PM File: C:\WINDOWS\system32\BCMWLTRY.EXE ok iSwift
9/12/2007 1:37:54 PM Logical disk sector: C ok scanned
9/12/2007 1:37:54 PM Logical disk sector: D ok scanned
9/12/2007 1:37:55 PM Physical disk sector: \Device\HarddiskVolume4 ok scanned
9/12/2007 1:37:55 PM Physical disk sector: \Device\HarddiskVolume3 ok scanned
9/12/2007 1:37:56 PM Physical disk sector: \Device\HarddiskVolume1 ok scanned
9/12/2007 1:37:56 PM Physical disk sector: \Device\Harddisk0\DR0 ok scanned
9/12/2007 1:37:56 PM File: c:\windows\system32\cmtdivwp.exe detected Trojan program 'Trojan.Win32.Agent.bck'
Any help at all would be appreciated.