Hi
Following is my HJT log, then my Kaspersky scan log,,,any help would be much appreciated!
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:37:16 PM, on 5/19/2008
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\WINNT\system32\taskmgr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OW3B7DIL\HiJackThis[1].exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=6010&mid=MjI6Ojg5&lid=2
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.safewebnavigate2008.com/index.php?sid=0&pn=0&aid=725&said=7&pid=0
O2 - BHO: BurstWriting module - {18CB1A7B-94CD-4582-8022-ADA16851E44B} - C:\Program Files\BurstWriting\BurstWriting.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {BB90EAF5-B809-4C3C-A5B5-51550128F647} - C:\WINNT\system32\ddcArQkL.dll
O2 - BHO: (no name) - {CFC19E37-2C37-42BF-9DA6-71116F1A6E2C} - C:\WINNT\system32\awttutQh.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: mkrndofl - {4F6DD2F9-A353-484A-B35E-C4ED0211097F} - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ac8zt2\mkrndofl.dll (file missing)
O4 - HKLM\..\Run: [TrackPointSrv] tp4mon.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [6ce633bc] rundll32.exe "C:\WINNT\system32\whnbucpy.dll",b
O4 - HKLM\..\RunOnce: [SpybotDeletingA9360] command /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3095] cmd /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4782] command /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3739] cmd /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6880] command /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9338] cmd /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1226] command /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9122] cmd /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1771] command /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9811] cmd /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8311] command /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2920] cmd /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1235] command /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2401] cmd /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4659] command /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9395] cmd /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4982] command /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2537] cmd /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9575] command /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2252] cmd /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3019] command /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8879] cmd /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8554] command /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7217] cmd /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA478] command /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2097] cmd /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1675] command /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC975] cmd /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKCU\..\Run: [e©ùýùñûïèóÎ×øøÕøôþÊýÛñûëÞó] C:\Program Files\XP Antivirus\xpa.exe
O4 - HKCU\..\Run: [InetChk] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ms1210301710.exe work
O4 - HKCU\..\Run: [Antivirus] C:\Program Files\Antivirus 2008\Antvrs.exe
O4 - HKCU\..\Run: [MalWarrior] "C:\Documents and Settings\All Users\Application Data\Adsl Software Limited\MalWarrior 2008\Malwarrior.exe" /autorun
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingB5492] command /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4371] cmd /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB459] command /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6469] cmd /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3884] command /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6547] cmd /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9930] command /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD443] cmd /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8417] command /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD226] cmd /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7226] command /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7088] cmd /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB412] command /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1603] cmd /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6411] command /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD710] cmd /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1993] command /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7288] cmd /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3450] command /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6035] cmd /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7293] command /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD314] cmd /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8023] command /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2841] cmd /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7969] command /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1787] cmd /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9827] command /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9387] cmd /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9901] command /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7516] cmd /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4943] command /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9678] cmd /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab
O16 - DPF: {3BA4271E-5C1E-48E2-B432-D8BF420DD31D} - http://antivirus-scanner.com/AntvrsInstall.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1203851135588
O20 - Winlogon Notify: awttutQh - C:\WINNT\SYSTEM32\awttutQh.dll
O21 - SSODL: wetkadmr - {686CD3DA-14C3-44F9-A3B5-97CDD73B06EA} - C:\WINNT\wetkadmr.dll (file missing)
O21 - SSODL: tdomgafw - {B66100BA-AA83-44C1-8586-D79BA1852430} - C:\WINNT\tdomgafw.dll
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
--
End of file - 9513 bytes
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Saturday, May 17, 2008 3:59:50 PM
Operating System: Microsoft Windows 2000 Professional, Service Pack 4 (Build 2195)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 17/05/2008
Kaspersky Anti-Virus database records: 779981
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
Scan Statistics:
Total number of scanned objects: 12925
Number of viruses found: 9
Number of infected objects: 14
Number of suspicious objects: 0
Duration of the scan process: 01:07:24
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Administrator\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Desktop\Privacy Protector.url Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ICD1.tmp\AntvrsInstall.exe Infected: not-a-virus
ownloader.Win32.FraudLoad.ar skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ms1210301710.exe Infected: Trojan-Dropper.Win32.Agent.rky skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\printsrv32.exe Infected: Trojan.Win32.Agent.lsr skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\setup_526_1_.exe Infected: Trojan-Downloader.Win32.FraudLoad.ym skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\vifmykoc.exe Infected: Trojan.Win32.Agent.gmn skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Administrator\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\RECYCLER\S-1-5-21-1454471165-1563985344-1060284298-500\Dc49\Antvrs.exe Infected: not-a-virus:FraudTool.Win32.AntiVirus2008.w skipped
C:\WINNT\CSC\00000001 Object is locked skipped
C:\WINNT\Debug\ipsecpa.log Object is locked skipped
C:\WINNT\Debug\oakley.log Object is locked skipped
C:\WINNT\Debug\PASSWD.LOG Object is locked skipped
C:\WINNT\Downloaded Program Files\antvrs.exe Infected: not-a-virus:FraudTool.Win32.AntiVirus2008.w skipped
C:\WINNT\Downloaded Program Files\AntvrsInstall.exe Infected: not-a-virus
ownloader.Win32.FraudLoad.ar skipped
C:\WINNT\Downloaded Program Files\CONFLICT.1\AntvrsInstall.exe Infected: not-a-virus
ownloader.Win32.FraudLoad.ar skipped
C:\WINNT\knxsrgte.exe Infected: Trojan.Win32.Vapsup.eyk skipped
C:\WINNT\ModemLog_Lucent Win Modem.txt Object is locked skipped
C:\WINNT\qvlbodmnqse.dll Infected: Trojan.Win32.Vapsup.eyk skipped
C:\WINNT\SchedLgU.Txt Object is locked skipped
C:\WINNT\SoftwareDistribution\Download\c3e13424b5ca403dd00c8550d4b5fddd\BITC.tmp Object is locked skipped
C:\WINNT\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINNT\system32\awttutQh.dll Infected: Trojan.Win32.Monder.gen skipped
C:\WINNT\system32\CatRoot\SYSMAST.cbd Object is locked skipped
C:\WINNT\system32\CatRoot\SYSMAST.cbk Object is locked skipped
C:\WINNT\system32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\CATMAST.cbd Object is locked skipped
C:\WINNT\system32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\CATMAST.cbk Object is locked skipped
C:\WINNT\system32\config\AppEvent.Evt Object is locked skipped
C:\WINNT\system32\config\default Object is locked skipped
C:\WINNT\system32\config\default.LOG Object is locked skipped
C:\WINNT\system32\config\SAM Object is locked skipped
C:\WINNT\system32\config\SAM.LOG Object is locked skipped
C:\WINNT\system32\config\SecEvent.Evt Object is locked skipped
C:\WINNT\system32\config\SECURITY Object is locked skipped
C:\WINNT\system32\config\SECURITY.LOG Object is locked skipped
C:\WINNT\system32\config\software Object is locked skipped
C:\WINNT\system32\config\software.LOG Object is locked skipped
C:\WINNT\system32\config\SysEvent.Evt Object is locked skipped
C:\WINNT\system32\config\system Object is locked skipped
C:\WINNT\system32\config\SYSTEM.ALT Object is locked skipped
C:\WINNT\system32\ddcArQkL.dll Infected: Trojan.Win32.Zapchast.gr skipped
C:\WINNT\system32\ias\dnary.ldb Object is locked skipped
C:\WINNT\system32\ias\ias.ldb Object is locked skipped
C:\WINNT\system32\ias\ias.mdb Object is locked skipped
C:\WINNT\tdomgafw.dll Infected: Trojan.Win32.Vapsup.eyk skipped
C:\WINNT\Temp\JET6DEA.tmp Object is locked skipped
C:\WINNT\Temp\JETA816.tmp Object is locked skipped
C:\WINNT\WindowsUpdate.log Object is locked skipped
Scan process completed.
Following is my HJT log, then my Kaspersky scan log,,,any help would be much appreciated!
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:37:16 PM, on 5/19/2008
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\WINNT\system32\taskmgr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OW3B7DIL\HiJackThis[1].exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=6010&mid=MjI6Ojg5&lid=2
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.safewebnavigate2008.com/index.php?sid=0&pn=0&aid=725&said=7&pid=0
O2 - BHO: BurstWriting module - {18CB1A7B-94CD-4582-8022-ADA16851E44B} - C:\Program Files\BurstWriting\BurstWriting.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {BB90EAF5-B809-4C3C-A5B5-51550128F647} - C:\WINNT\system32\ddcArQkL.dll
O2 - BHO: (no name) - {CFC19E37-2C37-42BF-9DA6-71116F1A6E2C} - C:\WINNT\system32\awttutQh.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: mkrndofl - {4F6DD2F9-A353-484A-B35E-C4ED0211097F} - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ac8zt2\mkrndofl.dll (file missing)
O4 - HKLM\..\Run: [TrackPointSrv] tp4mon.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [6ce633bc] rundll32.exe "C:\WINNT\system32\whnbucpy.dll",b
O4 - HKLM\..\RunOnce: [SpybotDeletingA9360] command /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3095] cmd /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4782] command /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3739] cmd /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6880] command /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9338] cmd /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1226] command /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9122] cmd /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1771] command /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9811] cmd /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8311] command /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2920] cmd /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1235] command /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2401] cmd /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4659] command /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9395] cmd /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4982] command /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2537] cmd /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9575] command /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2252] cmd /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3019] command /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8879] cmd /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8554] command /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7217] cmd /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA478] command /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2097] cmd /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1675] command /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC975] cmd /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKCU\..\Run: [e©ùýùñûïèóÎ×øøÕøôþÊýÛñûëÞó] C:\Program Files\XP Antivirus\xpa.exe
O4 - HKCU\..\Run: [InetChk] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ms1210301710.exe work
O4 - HKCU\..\Run: [Antivirus] C:\Program Files\Antivirus 2008\Antvrs.exe
O4 - HKCU\..\Run: [MalWarrior] "C:\Documents and Settings\All Users\Application Data\Adsl Software Limited\MalWarrior 2008\Malwarrior.exe" /autorun
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingB5492] command /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4371] cmd /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB459] command /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6469] cmd /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3884] command /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6547] cmd /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9930] command /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD443] cmd /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8417] command /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD226] cmd /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7226] command /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7088] cmd /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB412] command /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1603] cmd /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6411] command /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD710] cmd /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1993] command /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7288] cmd /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3450] command /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6035] cmd /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7293] command /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD314] cmd /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8023] command /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2841] cmd /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7969] command /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1787] cmd /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9827] command /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9387] cmd /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9901] command /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7516] cmd /c del "C:\WINNT\system32\awttutQh.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4943] command /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9678] cmd /c del "C:\WINNT\system32\ddcArQkL.dll"
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab
O16 - DPF: {3BA4271E-5C1E-48E2-B432-D8BF420DD31D} - http://antivirus-scanner.com/AntvrsInstall.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1203851135588
O20 - Winlogon Notify: awttutQh - C:\WINNT\SYSTEM32\awttutQh.dll
O21 - SSODL: wetkadmr - {686CD3DA-14C3-44F9-A3B5-97CDD73B06EA} - C:\WINNT\wetkadmr.dll (file missing)
O21 - SSODL: tdomgafw - {B66100BA-AA83-44C1-8586-D79BA1852430} - C:\WINNT\tdomgafw.dll
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
--
End of file - 9513 bytes
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Saturday, May 17, 2008 3:59:50 PM
Operating System: Microsoft Windows 2000 Professional, Service Pack 4 (Build 2195)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 17/05/2008
Kaspersky Anti-Virus database records: 779981
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
Scan Statistics:
Total number of scanned objects: 12925
Number of viruses found: 9
Number of infected objects: 14
Number of suspicious objects: 0
Duration of the scan process: 01:07:24
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Administrator\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Desktop\Privacy Protector.url Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\ICD1.tmp\AntvrsInstall.exe Infected: not-a-virus

C:\Documents and Settings\Administrator\Local Settings\Temp\ms1210301710.exe Infected: Trojan-Dropper.Win32.Agent.rky skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\printsrv32.exe Infected: Trojan.Win32.Agent.lsr skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\setup_526_1_.exe Infected: Trojan-Downloader.Win32.FraudLoad.ym skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\vifmykoc.exe Infected: Trojan.Win32.Agent.gmn skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Administrator\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\RECYCLER\S-1-5-21-1454471165-1563985344-1060284298-500\Dc49\Antvrs.exe Infected: not-a-virus:FraudTool.Win32.AntiVirus2008.w skipped
C:\WINNT\CSC\00000001 Object is locked skipped
C:\WINNT\Debug\ipsecpa.log Object is locked skipped
C:\WINNT\Debug\oakley.log Object is locked skipped
C:\WINNT\Debug\PASSWD.LOG Object is locked skipped
C:\WINNT\Downloaded Program Files\antvrs.exe Infected: not-a-virus:FraudTool.Win32.AntiVirus2008.w skipped
C:\WINNT\Downloaded Program Files\AntvrsInstall.exe Infected: not-a-virus

C:\WINNT\Downloaded Program Files\CONFLICT.1\AntvrsInstall.exe Infected: not-a-virus

C:\WINNT\knxsrgte.exe Infected: Trojan.Win32.Vapsup.eyk skipped
C:\WINNT\ModemLog_Lucent Win Modem.txt Object is locked skipped
C:\WINNT\qvlbodmnqse.dll Infected: Trojan.Win32.Vapsup.eyk skipped
C:\WINNT\SchedLgU.Txt Object is locked skipped
C:\WINNT\SoftwareDistribution\Download\c3e13424b5ca403dd00c8550d4b5fddd\BITC.tmp Object is locked skipped
C:\WINNT\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINNT\system32\awttutQh.dll Infected: Trojan.Win32.Monder.gen skipped
C:\WINNT\system32\CatRoot\SYSMAST.cbd Object is locked skipped
C:\WINNT\system32\CatRoot\SYSMAST.cbk Object is locked skipped
C:\WINNT\system32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\CATMAST.cbd Object is locked skipped
C:\WINNT\system32\CatRoot\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\CATMAST.cbk Object is locked skipped
C:\WINNT\system32\config\AppEvent.Evt Object is locked skipped
C:\WINNT\system32\config\default Object is locked skipped
C:\WINNT\system32\config\default.LOG Object is locked skipped
C:\WINNT\system32\config\SAM Object is locked skipped
C:\WINNT\system32\config\SAM.LOG Object is locked skipped
C:\WINNT\system32\config\SecEvent.Evt Object is locked skipped
C:\WINNT\system32\config\SECURITY Object is locked skipped
C:\WINNT\system32\config\SECURITY.LOG Object is locked skipped
C:\WINNT\system32\config\software Object is locked skipped
C:\WINNT\system32\config\software.LOG Object is locked skipped
C:\WINNT\system32\config\SysEvent.Evt Object is locked skipped
C:\WINNT\system32\config\system Object is locked skipped
C:\WINNT\system32\config\SYSTEM.ALT Object is locked skipped
C:\WINNT\system32\ddcArQkL.dll Infected: Trojan.Win32.Zapchast.gr skipped
C:\WINNT\system32\ias\dnary.ldb Object is locked skipped
C:\WINNT\system32\ias\ias.ldb Object is locked skipped
C:\WINNT\system32\ias\ias.mdb Object is locked skipped
C:\WINNT\tdomgafw.dll Infected: Trojan.Win32.Vapsup.eyk skipped
C:\WINNT\Temp\JET6DEA.tmp Object is locked skipped
C:\WINNT\Temp\JETA816.tmp Object is locked skipped
C:\WINNT\WindowsUpdate.log Object is locked skipped
Scan process completed.