The kids got a hold of my laptop and for about 2 weeks now I have been trying to clean this up - but it keeps coming back! ---
I've followed the procedures given prior to posting - here is my kaspersky -
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Thursday, May 08, 2008 4:06:20 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 8/05/2008
Kaspersky Anti-Virus database records: 747047
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 100962
Number of viruses found: 15
Number of infected objects: 57
Number of suspicious objects: 0
Duration of the scan process: 01:29:45
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Administrator\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{7CD8A59E-A208-4DF8-8124-1A24FB65EC8F} Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{C4A4844C-3BBF-4B80-8ABD-B017DC560A8C} Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\83WTA1OF\CAM7OLU7 Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\83WTA1OF\glas[2] Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\83WTA1OF\idkfa[1] Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\PHFGETIW\kriv[1] Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\WXE34T4P\idkfa[1] Infected: Trojan.Win32.Monder.an skipped
C:\Documents and Settings\Administrator\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Administrator\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-04272008-175532.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Network Associates\Common Framework\Db\Agent_TRICIA.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Network Associates\Common Framework\Db\PrdMgr_TRICIA.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Network Associates\VirusScan\OnAccessScanLog.txt Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\ntuser.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\ntuser.dat Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Mozilla Firefox\plugins\NPMyWebS.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.i skipped
C:\Program Files\Trend Micro\HijackThis\backups\backup-20080429-145420-674.dll Infected: not-a-virus
ownloader.Win32.PopCap.b skipped
C:\quarantine\media[1].htm.Vir Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP156\A0060645.old Infected: Trojan-Downloader.Win32.Small.ixt skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP157\A0060755.dll Infected: not-a-virus:AdWare.Win32.ZenoSearch.ad skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP157\A0060758.exe/data0001 Infected: not-a-virus:AdWare.Win32.PurityScan.gp skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP157\A0060758.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP157\A0060759.exe Infected: Trojan-Downloader.Win32.PurityScan.gb skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP157\A0060764.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP157\A0060767.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qrj skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP157\A0060768.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qri skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP157\A0060770.exe Infected: Trojan-Downloader.Win32.Agent.kwg skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP161\A0061143.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP161\A0061144.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qrj skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP161\A0061145.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP163\A0061404.old Infected: Trojan-Downloader.Win32.Agent.nua skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP165\A0063497.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP165\A0063498.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP165\A0063500.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP165\A0063501.dll Infected: Trojan.Win32.Monder.an skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP172\A0064894.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP172\A0064895.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP172\A0064897.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP172\A0064898.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP173\A0064919.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP173\A0064920.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP173\A0064922.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP173\A0064923.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP174\A0064944.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP174\A0064945.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP174\A0064947.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP174\A0064948.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP174\A0064961.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP174\A0064963.dll Infected: Trojan.Win32.Monder.db skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP174\A0064964.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP174\A0064965.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP174\A0064966.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP174\A0064967.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP174\A0064968.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP175\A0065100.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP175\A0065101.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP175\A0065109.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP175\change.log Object is locked skipped
C:\VundoFix Backups\pjdyeybb.dll.bad Infected: Trojan.Win32.Monder.gen skipped
C:\VundoFix Backups\xdifmcff.dll.bad Infected: Trojan.Win32.Monder.gen skipped
C:\WINDOWS\CSC\00000001 Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\000070.exe/data0002 Infected: Trojan-Downloader.Win32.PurityScan.gb skipped
C:\WINDOWS\system32\000070.exe NSIS: infected - 1 skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\Default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\Security Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\Software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\System Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\RP2IPTL1\1[1].exe Infected: not-a-virus:FraudTool.Win32.AntiSpySpider.c skipped
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\RP2IPTL1\update[1].upd Infected: Trojan-Downloader.Win32.Agent.nua skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\isrtidnd.dll Infected: Trojan.Win32.Monder.gen skipped
C:\WINDOWS\system32\mhgsdico.dll_old Infected: Trojan.Win32.Monder.gen skipped
C:\WINDOWS\system32\raofeatt.dll Infected: Trojan.Win32.Monder.gen skipped
C:\WINDOWS\system32\urqnMGXQ.dll Infected: Trojan.Win32.Monder.gen skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\system32\yejlluxk.dll Infected: Trojan.Win32.Monder.gen skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
Scan process completed.
Hijack this --
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:08:00 AM, on 5/9/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1D0B1B2F-4D44-48DC-AE5A-F4BBBAE2A83F} - (no file)
O2 - BHO: (no name) - {22883C80-3BD7-4718-B669-C5B8E47C7FE7} - C:\WINDOWS\system32\urqnMGXQ.dll (file missing)
O2 - BHO: (no name) - {42838FC0-55B5-426C-BA73-95B4CD255E8B} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {6390694C-7FCF-4EC7-91AB-109465996066} - (no file)
O2 - BHO: (no name) - {846b1c3b-900d-4ee3-b213-4127ef2681e6} - (no file)
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: (no name) - {E95CEE76-5A51-4452-A0F4-E62B45650039} - (no file)
O2 - BHO: (no name) - {EFD51596-6558-40C7-AB14-2FD2B0F2DBA6} - (no file)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [BM73dfdb0f] Rundll32.exe "C:\WINDOWS\system32\isrtidnd.dll",s
O4 - HKLM\..\RunOnce: [SpybotDeletingA6926] command /c del "C:\WINDOWS\system32\isrtidnd.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC174] cmd /c del "C:\WINDOWS\system32\isrtidnd.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5301] command /c del "C:\WINDOWS\system32\mhgsdico.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1795] cmd /c del "C:\WINDOWS\system32\mhgsdico.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9749] command /c del "C:\WINDOWS\system32\raofeatt.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4701] cmd /c del "C:\WINDOWS\system32\raofeatt.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4657] command /c del "C:\WINDOWS\system32\urqnMGXQ.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2413] cmd /c del "C:\WINDOWS\system32\urqnMGXQ.dll_old"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1125327898406
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1132850434593
O20 - Winlogon Notify: awturQhg - awturQhg.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
--
End of file - 7928 bytes
I've followed the procedures given prior to posting - here is my kaspersky -
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Thursday, May 08, 2008 4:06:20 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 8/05/2008
Kaspersky Anti-Virus database records: 747047
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 100962
Number of viruses found: 15
Number of infected objects: 57
Number of suspicious objects: 0
Duration of the scan process: 01:29:45
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Administrator\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{7CD8A59E-A208-4DF8-8124-1A24FB65EC8F} Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{C4A4844C-3BBF-4B80-8ABD-B017DC560A8C} Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\83WTA1OF\CAM7OLU7 Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\83WTA1OF\glas[2] Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\83WTA1OF\idkfa[1] Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\PHFGETIW\kriv[1] Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\WXE34T4P\idkfa[1] Infected: Trojan.Win32.Monder.an skipped
C:\Documents and Settings\Administrator\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Administrator\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-04272008-175532.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Network Associates\Common Framework\Db\Agent_TRICIA.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Network Associates\Common Framework\Db\PrdMgr_TRICIA.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Network Associates\VirusScan\OnAccessScanLog.txt Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\ntuser.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\ntuser.dat Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Mozilla Firefox\plugins\NPMyWebS.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.i skipped
C:\Program Files\Trend Micro\HijackThis\backups\backup-20080429-145420-674.dll Infected: not-a-virus

C:\quarantine\media[1].htm.Vir Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP156\A0060645.old Infected: Trojan-Downloader.Win32.Small.ixt skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP157\A0060755.dll Infected: not-a-virus:AdWare.Win32.ZenoSearch.ad skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP157\A0060758.exe/data0001 Infected: not-a-virus:AdWare.Win32.PurityScan.gp skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP157\A0060758.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP157\A0060759.exe Infected: Trojan-Downloader.Win32.PurityScan.gb skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP157\A0060764.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP157\A0060767.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qrj skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP157\A0060768.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qri skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP157\A0060770.exe Infected: Trojan-Downloader.Win32.Agent.kwg skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP161\A0061143.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP161\A0061144.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qrj skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP161\A0061145.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP163\A0061404.old Infected: Trojan-Downloader.Win32.Agent.nua skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP165\A0063497.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP165\A0063498.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP165\A0063500.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP165\A0063501.dll Infected: Trojan.Win32.Monder.an skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP172\A0064894.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP172\A0064895.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP172\A0064897.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP172\A0064898.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP173\A0064919.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP173\A0064920.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP173\A0064922.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP173\A0064923.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP174\A0064944.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP174\A0064945.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP174\A0064947.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP174\A0064948.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP174\A0064961.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP174\A0064963.dll Infected: Trojan.Win32.Monder.db skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP174\A0064964.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP174\A0064965.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP174\A0064966.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP174\A0064967.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP174\A0064968.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP175\A0065100.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP175\A0065101.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP175\A0065109.dll Infected: Trojan.Win32.Monder.gen skipped
C:\System Volume Information\_restore{8CA6E3C1-FF2E-4A85-8645-FC3B7376B604}\RP175\change.log Object is locked skipped
C:\VundoFix Backups\pjdyeybb.dll.bad Infected: Trojan.Win32.Monder.gen skipped
C:\VundoFix Backups\xdifmcff.dll.bad Infected: Trojan.Win32.Monder.gen skipped
C:\WINDOWS\CSC\00000001 Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\000070.exe/data0002 Infected: Trojan-Downloader.Win32.PurityScan.gb skipped
C:\WINDOWS\system32\000070.exe NSIS: infected - 1 skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\Default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\Security Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\Software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\System Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\RP2IPTL1\1[1].exe Infected: not-a-virus:FraudTool.Win32.AntiSpySpider.c skipped
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\RP2IPTL1\update[1].upd Infected: Trojan-Downloader.Win32.Agent.nua skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\isrtidnd.dll Infected: Trojan.Win32.Monder.gen skipped
C:\WINDOWS\system32\mhgsdico.dll_old Infected: Trojan.Win32.Monder.gen skipped
C:\WINDOWS\system32\raofeatt.dll Infected: Trojan.Win32.Monder.gen skipped
C:\WINDOWS\system32\urqnMGXQ.dll Infected: Trojan.Win32.Monder.gen skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\system32\yejlluxk.dll Infected: Trojan.Win32.Monder.gen skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
Scan process completed.
Hijack this --
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:08:00 AM, on 5/9/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1D0B1B2F-4D44-48DC-AE5A-F4BBBAE2A83F} - (no file)
O2 - BHO: (no name) - {22883C80-3BD7-4718-B669-C5B8E47C7FE7} - C:\WINDOWS\system32\urqnMGXQ.dll (file missing)
O2 - BHO: (no name) - {42838FC0-55B5-426C-BA73-95B4CD255E8B} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {6390694C-7FCF-4EC7-91AB-109465996066} - (no file)
O2 - BHO: (no name) - {846b1c3b-900d-4ee3-b213-4127ef2681e6} - (no file)
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: (no name) - {E95CEE76-5A51-4452-A0F4-E62B45650039} - (no file)
O2 - BHO: (no name) - {EFD51596-6558-40C7-AB14-2FD2B0F2DBA6} - (no file)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [BM73dfdb0f] Rundll32.exe "C:\WINDOWS\system32\isrtidnd.dll",s
O4 - HKLM\..\RunOnce: [SpybotDeletingA6926] command /c del "C:\WINDOWS\system32\isrtidnd.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC174] cmd /c del "C:\WINDOWS\system32\isrtidnd.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5301] command /c del "C:\WINDOWS\system32\mhgsdico.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1795] cmd /c del "C:\WINDOWS\system32\mhgsdico.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9749] command /c del "C:\WINDOWS\system32\raofeatt.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4701] cmd /c del "C:\WINDOWS\system32\raofeatt.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4657] command /c del "C:\WINDOWS\system32\urqnMGXQ.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2413] cmd /c del "C:\WINDOWS\system32\urqnMGXQ.dll_old"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1125327898406
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1132850434593
O20 - Winlogon Notify: awturQhg - awturQhg.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
--
End of file - 7928 bytes