So I've run ad-aware, spybot in safe-mode, combofix and smitfraud fix after then reading i shouldn't have before posting a log (oops). here is the latest log...
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:43:06 AM, on 5/6/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\iPod Access for Windows\iPAHelper.exe
C:\Program Files\M-Audio MobilePre\Install\MPInst.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wshtcpip.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe
C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\WINDOWS\System32\Rundll32.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Svconr\Svconr.exe
C:\Documents and Settings\Owner\Application Data\SpeedRunner\SpeedRunner.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Owner\Application Data\Microsoft\Windows\nkkvvo.exe
C:\Program Files\Apoint2K\HidFind.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\M-Audio MobilePre\MPTask.exe
C:\Program Files\MOTU\FireWire Audio\MFWAKeys.exe
C:\WINDOWS\system32\kcntmkdm.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.whynotsearchhere.com/start.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = sas.we1.attbb.net:8000
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.we1.attbb.net;*.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: gooochi browser optimizer - {48ef2043-3396-10b3-0a15-9880fe3c93d9} - C:\WINDOWS\system32\{72709b0a-ee6f-ec75-72b6-de300b8c2a83}.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {62C21114-D4A8-499B-A15C-684FDB8B79B5} - C:\WINDOWS\system32\opnlKAro.dll (file missing)
O2 - BHO: (no name) - {70186681-442D-4D62-936D-E2B79089D6EB} - C:\WINDOWS\system32\qoMcyARl.dll (file missing)
O2 - BHO: (no name) - {87ed7406-1dca-4fab-ad56-37e4a6d893ca} - (no file)
O2 - BHO: (no name) - {A6C54318-5AC7-477D-B0A7-49AF5189300C} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O2 - BHO: DbarBHO - {CC11617C-259E-429c-9063-7D70B8355EBD} - C:\Program Files\dbar\Deskbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [IndicatorUtility] C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
O4 - HKLM\..\Run: [LoadFujitsuQuickTouch] C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe
O4 - HKLM\..\Run: [LoadBtnHnd] C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [H2O] C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [{D3-34-47-78-DW}] C:\WINDOWS\system32\cdTMP\cdrev132.exe DWram
O4 - HKLM\..\Run: [ec5d34d7] rundll32.exe "C:\WINDOWS\system32\istlpcuw.dll",b
O4 - HKLM\..\Run: [dbar_starter] C:\Documents and Settings\Owner\Application Data\Deskbar_{2498A92A-9F59-40c3-B5EA-244D3BBADA04}\starter.exe
O4 - HKLM\..\Run: [BMef6e074b] Rundll32.exe "C:\WINDOWS\system32\hfjdljfu.dll",s
O4 - HKLM\..\Run: [spa_start] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\{72709b0a-ee6f-ec75-72b6-de300b8c2a83}.dll" DllInit
O4 - HKCU\..\Run: [mprddm] C:\WINDOWS\System32\mprddm.exe
O4 - HKCU\..\Run: [196_150_ni] C:\WINDOWS\System32\196_150_ni.exe
O4 - HKCU\..\Run: [197_150_ni_4] C:\WINDOWS\System32\197_150_ni_4.exe
O4 - HKCU\..\Run: [198_150_ni_1] "C:\Documents and Settings\Owner\198_150_ni_1.exe"
O4 - HKCU\..\Run: [rsvpsp] "C:\WINDOWS\System32\rsvpsp.exe"
O4 - HKCU\..\Run: [avicap32] "C:\WINDOWS\System32\avicap32.exe"
O4 - HKCU\..\Run: [xpsp2res] "C:\WINDOWS\System32\xpsp2res.exe"
O4 - HKCU\..\Run: [rtm] "C:\WINDOWS\System32\rtm.exe"
O4 - HKCU\..\Run: [dgnet] "C:\WINDOWS\System32\dgnet.exe"
O4 - HKCU\..\Run: [oleacc] "C:\WINDOWS\System32\oleacc.exe"
O4 - HKCU\..\Run: [tapiperf] "C:\WINDOWS\System32\tapiperf.exe"
O4 - HKCU\..\Run: [mciseq] "C:\WINDOWS\System32\mciseq.exe"
O4 - HKCU\..\Run: [fsusd] "C:\WINDOWS\System32\fsusd.exe"
O4 - HKCU\..\Run: [query] "C:\WINDOWS\System32\query.exe"
O4 - HKCU\..\Run: [dskquoui] "C:\WINDOWS\System32\dskquoui.exe"
O4 - HKCU\..\Run: [wpdtrace] "C:\WINDOWS\System32\wpdtrace.exe"
O4 - HKCU\..\Run: [blackbox] "C:\WINDOWS\System32\blackbox.exe"
O4 - HKCU\..\Run: [odbccr32] "C:\WINDOWS\System32\odbccr32.exe"
O4 - HKCU\..\Run: [mswsock] "C:\WINDOWS\System32\mswsock.exe"
O4 - HKCU\..\Run: [shimeng] "C:\WINDOWS\System32\shimeng.exe"
O4 - HKCU\..\Run: [imagxpr5] "C:\WINDOWS\System32\imagxpr5.exe"
O4 - HKCU\..\Run: [netui2] "C:\WINDOWS\System32\netui2.exe"
O4 - HKCU\..\Run: [ir41_qc] "C:\WINDOWS\System32\ir41_qc.exe"
O4 - HKCU\..\Run: [cdfview] "C:\WINDOWS\System32\cdfview.exe"
O4 - HKCU\..\Run: [wmsdmoe2] "C:\WINDOWS\System32\wmsdmoe2.exe"
O4 - HKCU\..\Run: [msvcrt40] "C:\WINDOWS\System32\msvcrt40.exe"
O4 - HKCU\..\Run: [psnppagn] "C:\WINDOWS\System32\psnppagn.exe"
O4 - HKCU\..\Run: [imagehlp] "C:\WINDOWS\System32\imagehlp.exe"
O4 - HKCU\..\Run: [dbnmpntw] "C:\WINDOWS\System32\dbnmpntw.exe"
O4 - HKCU\..\Run: [msexcl40] "C:\WINDOWS\System32\msexcl40.exe"
O4 - HKCU\..\Run: [deskadp] "C:\WINDOWS\System32\deskadp.exe"
O4 - HKCU\..\Run: [browselc] "C:\WINDOWS\System32\browselc.exe"
O4 - HKCU\..\Run: [dssenh] "C:\WINDOWS\System32\dssenh.exe"
O4 - HKCU\..\Run: [licdll] "C:\WINDOWS\System32\licdll.exe"
O4 - HKCU\..\Run: [iasads] "C:\WINDOWS\System32\iasads.exe"
O4 - HKCU\..\Run: [cdmodem] "C:\WINDOWS\System32\cdmodem.exe"
O4 - HKCU\..\Run: [msr2cenu] "C:\WINDOWS\System32\msr2cenu.exe"
O4 - HKCU\..\Run: [iologmsg] "C:\WINDOWS\System32\iologmsg.exe"
O4 - HKCU\..\Run: [dinput8] "C:\WINDOWS\System32\dinput8.exe"
O4 - HKCU\..\Run: [stobject] "C:\WINDOWS\System32\stobject.exe"
O4 - HKCU\..\Run: [ipv6mon] "C:\WINDOWS\System32\ipv6mon.exe"
O4 - HKCU\..\Run: [mydocs] "C:\WINDOWS\System32\mydocs.exe"
O4 - HKCU\..\Run: [modemui] "C:\WINDOWS\System32\modemui.exe"
O4 - HKCU\..\Run: [eventcls] "C:\WINDOWS\System32\eventcls.exe"
O4 - HKCU\..\Run: [wmvsdecd] "C:\WINDOWS\system32\wmvsdecd.exe"
O4 - HKCU\..\Run: [msswch] "C:\WINDOWS\system32\msswch.exe"
O4 - HKCU\..\Run: [rdpcfgex] "C:\WINDOWS\system32\rdpcfgex.exe"
O4 - HKCU\..\Run: [glu32] "C:\WINDOWS\system32\glu32.exe"
O4 - HKCU\..\Run: [lfpsd11n] "C:\WINDOWS\system32\lfpsd11n.exe"
O4 - HKCU\..\Run: [kbdkyr] "C:\WINDOWS\system32\kbdkyr.exe"
O4 - HKCU\..\Run: [xactsrv] "C:\WINDOWS\system32\xactsrv.exe"
O4 - HKCU\..\Run: [jscript] "C:\WINDOWS\system32\jscript.exe"
O4 - HKCU\..\Run: [qasf] "C:\WINDOWS\system32\qasf.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [icmp] "C:\WINDOWS\system32\icmp.exe"
O4 - HKCU\..\Run: [dsprpres] "C:\WINDOWS\system32\dsprpres.exe"
O4 - HKCU\..\Run: [nddeapi] "C:\WINDOWS\system32\nddeapi.exe"
O4 - HKCU\..\Run: [hpovst08] "C:\WINDOWS\system32\hpovst08.exe"
O4 - HKCU\..\Run: [shdoclc] "C:\WINDOWS\system32\shdoclc.exe"
O4 - HKCU\..\Run: [rsvpmsg] "C:\WINDOWS\system32\rsvpmsg.exe"
O4 - HKCU\..\Run: [dmserver] "C:\WINDOWS\system32\dmserver.exe"
O4 - HKCU\..\Run: [usbmon] "C:\WINDOWS\system32\usbmon.exe"
O4 - HKCU\..\Run: [stclient] "C:\WINDOWS\system32\stclient.exe"
O4 - HKCU\..\Run: [ciodm] "C:\WINDOWS\system32\ciodm.exe"
O4 - HKCU\..\Run: [msprivs] "C:\WINDOWS\system32\msprivs.exe"
O4 - HKCU\..\Run: [wldap32] "C:\WINDOWS\system32\wldap32.exe"
O4 - HKCU\..\Run: [pncrt] "C:\WINDOWS\system32\pncrt.exe"
O4 - HKCU\..\Run: [vjoy] "C:\WINDOWS\system32\vjoy.exe"
O4 - HKCU\..\Run: [winsta] "C:\WINDOWS\system32\winsta.exe"
O4 - HKCU\..\Run: [WinUpdater] "C:\Program Files\winvi\update.exe" /background
O4 - HKCU\..\Run: [WebSUpdater] "C:\Program Files\winvi\wupda.exe" /background
O4 - HKCU\..\Run: [Svconr] C:\Program Files\Svconr\Svconr.exe
O4 - HKCU\..\Run: [SpeedRunner] C:\Documents and Settings\Owner\Application Data\SpeedRunner\SpeedRunner.exe
O4 - HKCU\..\Run: [SfKg6wIP] C:\Documents and Settings\Owner\Application Data\Microsoft\Windows\nkkvvo.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ir50_qcx] "C:\WINDOWS\system32\ir50_qcx.exe"
O4 - HKCU\..\Run: [svcpack] "C:\WINDOWS\system32\svcpack.exe"
O4 - S-1-5-18 Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (User 'SYSTEM')
O4 - S-1-5-18 Startup: Deewoo.lnk = C:\WINDOWS\system32\kcntmkdm.exe (User 'SYSTEM')
O4 - S-1-5-18 Startup: DW_Start.lnk = C:\WINDOWS\system32\cdTMP\cdrev132.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (User 'Default user')
O4 - .DEFAULT Startup: Deewoo.lnk = C:\WINDOWS\system32\kcntmkdm.exe (User 'Default user')
O4 - .DEFAULT Startup: DW_Start.lnk = C:\WINDOWS\system32\cdTMP\cdrev132.exe (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Deewoo.lnk = C:\WINDOWS\system32\kcntmkdm.exe
O4 - Startup: DW_Start.lnk = C:\WINDOWS\system32\cdTMP\cdrev132.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: M-Audio MobilePre Control Panel Launcher.lnk = C:\Program Files\M-Audio MobilePre\MPTask.exe
O4 - Global Startup: MFWAKeys.lnk = C:\Program Files\MOTU\FireWire Audio\MFWAKeys.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.fujitsupc.com/
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab
O20 - Winlogon Notify: efcDWNfc - efcDWNfc.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPAHelper.exe - Unknown owner - C:\Program Files\iPod Access for Windows\iPAHelper.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MobilePre Installer (MobilePreInstallerService) - M-Audio - C:\Program Files\M-Audio MobilePre\Install\MPInst.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2004\WinStylerThemeSvc.exe
O23 - Service: wshtcpip - Unknown owner - C:\WINDOWS\System32\wshtcpip.exe
--
End of file - 14626 bytes
KASPERSKY LOG:
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Tuesday, May 06, 2008 9:21:15 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 6/05/2008
Kaspersky Anti-Virus database records: 741846
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 108032
Number of viruses found: 26
Number of infected objects: 149
Number of suspicious objects: 0
Duration of the scan process: 02:03:26
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\PWMR8UHI\200_160_i_3[1].abc Infected: Trojan-Downloader.Win32.Agent.wd skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Owner\198_150_ni_1.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\Documents and Settings\Owner\Application Data\Microsoft\Windows\nkkvvo.exe Object is locked skipped
C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\uhq8xtir.default\cert8.db Object is locked skipped
C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\uhq8xtir.default\formhistory.dat Object is locked skipped
C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\uhq8xtir.default\history.dat Object is locked skipped
C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\uhq8xtir.default\key3.db Object is locked skipped
C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\uhq8xtir.default\parent.lock Object is locked skipped
C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\uhq8xtir.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\uhq8xtir.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Owner\Application Data\SpeedRunner\SpeedRunner.exe Infected: Trojan-Downloader.Win32.Agent.ndt skipped
C:\Documents and Settings\Owner\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\uhq8xtir.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\uhq8xtir.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\uhq8xtir.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\uhq8xtir.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\History\History.IE5\MSHist012008050620080507\index.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Temp\Perflib_Perfdata_25c.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Temp\~DF469A.tmp Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Owner\ntuser.dat Object is locked skipped
C:\Documents and Settings\Owner\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Owner\xJWIYFSHYHT.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\Documents and Settings\Owner\xVYDKKPLIKK.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.612 skipped
C:\Program Files\winvi\update.exe/stream/Script Infected: Trojan.NSIS.StartPage.c skipped
C:\Program Files\winvi\update.exe/stream Infected: Trojan.NSIS.StartPage.c skipped
C:\Program Files\winvi\update.exe NSIS: infected - 2 skipped
C:\QooBox\Quarantine\C\Program Files\JavaCore\JavaCore.exe.vir Infected: not-a-virus:AdWare.Win32.Insider.c skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\cbXRKBuu.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.qng skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\efcDWNfc.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.qng skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\test.bmp.vir Infected: Trojan-Downloader.Win32.Reqlook.d skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP463\A0070878.exe Infected: Trojan-Downloader.Win32.Agent.wd skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP464\A0070909.exe Infected: Trojan-Downloader.Win32.Agent.wd skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP466\A0070936.exe Infected: Trojan-Downloader.Win32.Agent.wd skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP466\A0070949.exe Infected: Trojan-Downloader.Win32.Agent.wd skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP467\A0070967.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP467\A0070968.exe Infected: Trojan-Downloader.Win32.Agent.wd skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP468\A0070984.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP468\A0070985.exe Infected: Trojan-Downloader.Win32.Agent.wd skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP469\A0071006.exe Infected: Trojan-Downloader.Win32.Agent.wd skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP471\A0071053.exe Infected: Trojan-Downloader.Win32.Agent.wd skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP472\A0071064.exe Infected: Trojan-Downloader.Win32.Agent.wd skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP473\A0071079.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP475\A0071123.exe Infected: Trojan-Downloader.Win32.Agent.wd skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP476\A0071138.exe Infected: Trojan-Downloader.Win32.Agent.wd skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP476\A0071146.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP477\A0071183.exe Infected: Trojan-Downloader.Win32.Agent.wd skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP478\A0071199.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP480\A0071216.exe Infected: Trojan-Downloader.Win32.Homles.bk skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP480\A0072247.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP480\A0072249.exe Infected: Trojan-Downloader.Win32.PurityScan.fj skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP480\A0072250.dll Infected: not-a-virus:AdWare.Win32.PurityScan.hk skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP480\A0072251.exe Infected: not-a-virus:AdWare.Win32.PurityScan.hl skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP480\A0072253.dll Infected: not-a-virus:AdWare.Win32.ZenoSearch.ad skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP480\A0072256.exe/data0001 Infected: not-a-virus:AdWare.Win32.PurityScan.gp skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP480\A0072256.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP480\A0072257.exe Infected: Trojan.Win32.Scapur.k skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP482\A0072305.exe Infected: Trojan-Downloader.Win32.Homles.bk skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP482\A0072308.exe Infected: Trojan-Downloader.Win32.Agent.ezc skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP482\A0072310.exe Infected: not-a-virus:AdWare.Win32.Insider.c skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP482\A0072311.exe Infected: Trojan.Win32.BHO.blh skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP482\A0072312.exe Infected: not-a-virus:AdWare.Win32.Insider.f skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP482\A0072313.exe Infected: Trojan-Downloader.Win32.Agent.jih skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP482\A0072314.exe Infected: Trojan-Downloader.Win32.Homles.bk skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP483\A0074388.exe Infected: not-a-virus:AdWare.Win32.Insider.c skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP483\A0074394.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qng skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP483\A0074395.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qng skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP483\A0074429.exe Infected: not-a-virus
ownloader.Win32.WinFixer.fs skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP483\A0074430.exe Infected: not-a-virus
ownloader.Win32.WinFixer.fs skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP484\A0074522.exe Infected: Trojan-Downloader.Win32.Agent.wd skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP484\change.log Object is locked skipped
C:\WINDOWS\b155.exe_old Infected: Trojan.Win32.BHO.blh skipped
C:\WINDOWS\b156.exe_old Infected: not-a-virus:AdWare.Win32.Insider.f skipped
C:\WINDOWS\b157.exe_old Infected: Trojan-Downloader.Win32.Agent.jih skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\ModemLog_Communications cable between two computers.txt Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\12033\cvserchka.exe Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\WINDOWS\system32\198_150_ni_1.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\adsldp.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\autodisc.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\avicap32.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\bkEur01\bkEur011065.exe Infected: Trojan-Downloader.Win32.VB.edw skipped
C:\WINDOWS\system32\blackbox.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\browselc.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\cdfview.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\cdmodem.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\cdTMP\cdrev132.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.am skipped
C:\WINDOWS\system32\ciodm.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\cNF\srkcont3.exe/stream/data0007/stream/Script Infected: Trojan.NSIS.StartPage.c skipped
C:\WINDOWS\system32\cNF\srkcont3.exe/stream/data0007/stream Infected: Trojan.NSIS.StartPage.c skipped
C:\WINDOWS\system32\cNF\srkcont3.exe/stream/data0007 Infected: Trojan.NSIS.StartPage.c skipped
C:\WINDOWS\system32\cNF\srkcont3.exe/stream Infected: Trojan.NSIS.StartPage.c skipped
C:\WINDOWS\system32\cNF\srkcont3.exe NSIS: infected - 4 skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\d3d9.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\d3dramp.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\d3dxof.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\davclnt.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\dbnmpntw.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\deskadp.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\dgnet.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\din3\is-setup03x.exe Infected: Trojan.Win32.Agent.lom skipped
C:\WINDOWS\system32\dinput8.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\dmserver.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\dplay.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\dskquoui.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\dsprpres.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\dssenh.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\eventcls.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\fsusd.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\glu32.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\hpovst08.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\iasads.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\icmp.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\icwdial.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\imagehlp.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\imagxpr5.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\inetcplc.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\iologmsg.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\ipv6mon.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\ir41_qc.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\ir50_qcx.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\jscript.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\kbdfr.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\kbdkyr.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\kcntmkdm.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.bc skipped
C:\WINDOWS\system32\langwrbk.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\ld.exe Infected: Trojan.Win32.Crypt.t skipped
C:\WINDOWS\system32\lfpsd11n.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\licdll.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINDOWS\system32\mciseq.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\modemui.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\msexcl40.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\msprivs.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\msr2cenu.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\msswch.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\msvcrt40.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\mswsock.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\mydocs.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\nddeapi.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\netui2.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\odbccr32.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\oleacc.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\pncrt.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\psnppagn.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\qasf.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\rdpcfgex.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\rsvpmsg.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\rsvpsp.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\rtm.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\rwwnw64d.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.am skipped
C:\WINDOWS\system32\shdoclc.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\shimeng.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\stclient.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\stobject.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\svcpack.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\swprv.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\tapiperf.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\tcntmkdm.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.bc skipped
C:\WINDOWS\system32\test.bmp Infected: Trojan-Downloader.Win32.Reqlook.d skipped
C:\WINDOWS\system32\usbmon.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\vjoy.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\system32\winsta.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\wldap32.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\wmsdmoe2.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\wmvsdecd.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\wpdtrace.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\wshtcpip.exe Infected: Trojan-Downloader.Win32.Reqlook.d skipped
C:\WINDOWS\system32\xactsrv.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\xenroll.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\xpsp2res.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:43:06 AM, on 5/6/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\iPod Access for Windows\iPAHelper.exe
C:\Program Files\M-Audio MobilePre\Install\MPInst.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wshtcpip.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe
C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\WINDOWS\System32\Rundll32.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Svconr\Svconr.exe
C:\Documents and Settings\Owner\Application Data\SpeedRunner\SpeedRunner.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Owner\Application Data\Microsoft\Windows\nkkvvo.exe
C:\Program Files\Apoint2K\HidFind.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\M-Audio MobilePre\MPTask.exe
C:\Program Files\MOTU\FireWire Audio\MFWAKeys.exe
C:\WINDOWS\system32\kcntmkdm.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.whynotsearchhere.com/start.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = sas.we1.attbb.net:8000
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.we1.attbb.net;*.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: gooochi browser optimizer - {48ef2043-3396-10b3-0a15-9880fe3c93d9} - C:\WINDOWS\system32\{72709b0a-ee6f-ec75-72b6-de300b8c2a83}.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {62C21114-D4A8-499B-A15C-684FDB8B79B5} - C:\WINDOWS\system32\opnlKAro.dll (file missing)
O2 - BHO: (no name) - {70186681-442D-4D62-936D-E2B79089D6EB} - C:\WINDOWS\system32\qoMcyARl.dll (file missing)
O2 - BHO: (no name) - {87ed7406-1dca-4fab-ad56-37e4a6d893ca} - (no file)
O2 - BHO: (no name) - {A6C54318-5AC7-477D-B0A7-49AF5189300C} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O2 - BHO: DbarBHO - {CC11617C-259E-429c-9063-7D70B8355EBD} - C:\Program Files\dbar\Deskbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [IndicatorUtility] C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
O4 - HKLM\..\Run: [LoadFujitsuQuickTouch] C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe
O4 - HKLM\..\Run: [LoadBtnHnd] C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [H2O] C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [{D3-34-47-78-DW}] C:\WINDOWS\system32\cdTMP\cdrev132.exe DWram
O4 - HKLM\..\Run: [ec5d34d7] rundll32.exe "C:\WINDOWS\system32\istlpcuw.dll",b
O4 - HKLM\..\Run: [dbar_starter] C:\Documents and Settings\Owner\Application Data\Deskbar_{2498A92A-9F59-40c3-B5EA-244D3BBADA04}\starter.exe
O4 - HKLM\..\Run: [BMef6e074b] Rundll32.exe "C:\WINDOWS\system32\hfjdljfu.dll",s
O4 - HKLM\..\Run: [spa_start] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\{72709b0a-ee6f-ec75-72b6-de300b8c2a83}.dll" DllInit
O4 - HKCU\..\Run: [mprddm] C:\WINDOWS\System32\mprddm.exe
O4 - HKCU\..\Run: [196_150_ni] C:\WINDOWS\System32\196_150_ni.exe
O4 - HKCU\..\Run: [197_150_ni_4] C:\WINDOWS\System32\197_150_ni_4.exe
O4 - HKCU\..\Run: [198_150_ni_1] "C:\Documents and Settings\Owner\198_150_ni_1.exe"
O4 - HKCU\..\Run: [rsvpsp] "C:\WINDOWS\System32\rsvpsp.exe"
O4 - HKCU\..\Run: [avicap32] "C:\WINDOWS\System32\avicap32.exe"
O4 - HKCU\..\Run: [xpsp2res] "C:\WINDOWS\System32\xpsp2res.exe"
O4 - HKCU\..\Run: [rtm] "C:\WINDOWS\System32\rtm.exe"
O4 - HKCU\..\Run: [dgnet] "C:\WINDOWS\System32\dgnet.exe"
O4 - HKCU\..\Run: [oleacc] "C:\WINDOWS\System32\oleacc.exe"
O4 - HKCU\..\Run: [tapiperf] "C:\WINDOWS\System32\tapiperf.exe"
O4 - HKCU\..\Run: [mciseq] "C:\WINDOWS\System32\mciseq.exe"
O4 - HKCU\..\Run: [fsusd] "C:\WINDOWS\System32\fsusd.exe"
O4 - HKCU\..\Run: [query] "C:\WINDOWS\System32\query.exe"
O4 - HKCU\..\Run: [dskquoui] "C:\WINDOWS\System32\dskquoui.exe"
O4 - HKCU\..\Run: [wpdtrace] "C:\WINDOWS\System32\wpdtrace.exe"
O4 - HKCU\..\Run: [blackbox] "C:\WINDOWS\System32\blackbox.exe"
O4 - HKCU\..\Run: [odbccr32] "C:\WINDOWS\System32\odbccr32.exe"
O4 - HKCU\..\Run: [mswsock] "C:\WINDOWS\System32\mswsock.exe"
O4 - HKCU\..\Run: [shimeng] "C:\WINDOWS\System32\shimeng.exe"
O4 - HKCU\..\Run: [imagxpr5] "C:\WINDOWS\System32\imagxpr5.exe"
O4 - HKCU\..\Run: [netui2] "C:\WINDOWS\System32\netui2.exe"
O4 - HKCU\..\Run: [ir41_qc] "C:\WINDOWS\System32\ir41_qc.exe"
O4 - HKCU\..\Run: [cdfview] "C:\WINDOWS\System32\cdfview.exe"
O4 - HKCU\..\Run: [wmsdmoe2] "C:\WINDOWS\System32\wmsdmoe2.exe"
O4 - HKCU\..\Run: [msvcrt40] "C:\WINDOWS\System32\msvcrt40.exe"
O4 - HKCU\..\Run: [psnppagn] "C:\WINDOWS\System32\psnppagn.exe"
O4 - HKCU\..\Run: [imagehlp] "C:\WINDOWS\System32\imagehlp.exe"
O4 - HKCU\..\Run: [dbnmpntw] "C:\WINDOWS\System32\dbnmpntw.exe"
O4 - HKCU\..\Run: [msexcl40] "C:\WINDOWS\System32\msexcl40.exe"
O4 - HKCU\..\Run: [deskadp] "C:\WINDOWS\System32\deskadp.exe"
O4 - HKCU\..\Run: [browselc] "C:\WINDOWS\System32\browselc.exe"
O4 - HKCU\..\Run: [dssenh] "C:\WINDOWS\System32\dssenh.exe"
O4 - HKCU\..\Run: [licdll] "C:\WINDOWS\System32\licdll.exe"
O4 - HKCU\..\Run: [iasads] "C:\WINDOWS\System32\iasads.exe"
O4 - HKCU\..\Run: [cdmodem] "C:\WINDOWS\System32\cdmodem.exe"
O4 - HKCU\..\Run: [msr2cenu] "C:\WINDOWS\System32\msr2cenu.exe"
O4 - HKCU\..\Run: [iologmsg] "C:\WINDOWS\System32\iologmsg.exe"
O4 - HKCU\..\Run: [dinput8] "C:\WINDOWS\System32\dinput8.exe"
O4 - HKCU\..\Run: [stobject] "C:\WINDOWS\System32\stobject.exe"
O4 - HKCU\..\Run: [ipv6mon] "C:\WINDOWS\System32\ipv6mon.exe"
O4 - HKCU\..\Run: [mydocs] "C:\WINDOWS\System32\mydocs.exe"
O4 - HKCU\..\Run: [modemui] "C:\WINDOWS\System32\modemui.exe"
O4 - HKCU\..\Run: [eventcls] "C:\WINDOWS\System32\eventcls.exe"
O4 - HKCU\..\Run: [wmvsdecd] "C:\WINDOWS\system32\wmvsdecd.exe"
O4 - HKCU\..\Run: [msswch] "C:\WINDOWS\system32\msswch.exe"
O4 - HKCU\..\Run: [rdpcfgex] "C:\WINDOWS\system32\rdpcfgex.exe"
O4 - HKCU\..\Run: [glu32] "C:\WINDOWS\system32\glu32.exe"
O4 - HKCU\..\Run: [lfpsd11n] "C:\WINDOWS\system32\lfpsd11n.exe"
O4 - HKCU\..\Run: [kbdkyr] "C:\WINDOWS\system32\kbdkyr.exe"
O4 - HKCU\..\Run: [xactsrv] "C:\WINDOWS\system32\xactsrv.exe"
O4 - HKCU\..\Run: [jscript] "C:\WINDOWS\system32\jscript.exe"
O4 - HKCU\..\Run: [qasf] "C:\WINDOWS\system32\qasf.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [icmp] "C:\WINDOWS\system32\icmp.exe"
O4 - HKCU\..\Run: [dsprpres] "C:\WINDOWS\system32\dsprpres.exe"
O4 - HKCU\..\Run: [nddeapi] "C:\WINDOWS\system32\nddeapi.exe"
O4 - HKCU\..\Run: [hpovst08] "C:\WINDOWS\system32\hpovst08.exe"
O4 - HKCU\..\Run: [shdoclc] "C:\WINDOWS\system32\shdoclc.exe"
O4 - HKCU\..\Run: [rsvpmsg] "C:\WINDOWS\system32\rsvpmsg.exe"
O4 - HKCU\..\Run: [dmserver] "C:\WINDOWS\system32\dmserver.exe"
O4 - HKCU\..\Run: [usbmon] "C:\WINDOWS\system32\usbmon.exe"
O4 - HKCU\..\Run: [stclient] "C:\WINDOWS\system32\stclient.exe"
O4 - HKCU\..\Run: [ciodm] "C:\WINDOWS\system32\ciodm.exe"
O4 - HKCU\..\Run: [msprivs] "C:\WINDOWS\system32\msprivs.exe"
O4 - HKCU\..\Run: [wldap32] "C:\WINDOWS\system32\wldap32.exe"
O4 - HKCU\..\Run: [pncrt] "C:\WINDOWS\system32\pncrt.exe"
O4 - HKCU\..\Run: [vjoy] "C:\WINDOWS\system32\vjoy.exe"
O4 - HKCU\..\Run: [winsta] "C:\WINDOWS\system32\winsta.exe"
O4 - HKCU\..\Run: [WinUpdater] "C:\Program Files\winvi\update.exe" /background
O4 - HKCU\..\Run: [WebSUpdater] "C:\Program Files\winvi\wupda.exe" /background
O4 - HKCU\..\Run: [Svconr] C:\Program Files\Svconr\Svconr.exe
O4 - HKCU\..\Run: [SpeedRunner] C:\Documents and Settings\Owner\Application Data\SpeedRunner\SpeedRunner.exe
O4 - HKCU\..\Run: [SfKg6wIP] C:\Documents and Settings\Owner\Application Data\Microsoft\Windows\nkkvvo.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ir50_qcx] "C:\WINDOWS\system32\ir50_qcx.exe"
O4 - HKCU\..\Run: [svcpack] "C:\WINDOWS\system32\svcpack.exe"
O4 - S-1-5-18 Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (User 'SYSTEM')
O4 - S-1-5-18 Startup: Deewoo.lnk = C:\WINDOWS\system32\kcntmkdm.exe (User 'SYSTEM')
O4 - S-1-5-18 Startup: DW_Start.lnk = C:\WINDOWS\system32\cdTMP\cdrev132.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (User 'Default user')
O4 - .DEFAULT Startup: Deewoo.lnk = C:\WINDOWS\system32\kcntmkdm.exe (User 'Default user')
O4 - .DEFAULT Startup: DW_Start.lnk = C:\WINDOWS\system32\cdTMP\cdrev132.exe (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Deewoo.lnk = C:\WINDOWS\system32\kcntmkdm.exe
O4 - Startup: DW_Start.lnk = C:\WINDOWS\system32\cdTMP\cdrev132.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: M-Audio MobilePre Control Panel Launcher.lnk = C:\Program Files\M-Audio MobilePre\MPTask.exe
O4 - Global Startup: MFWAKeys.lnk = C:\Program Files\MOTU\FireWire Audio\MFWAKeys.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.fujitsupc.com/
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab
O20 - Winlogon Notify: efcDWNfc - efcDWNfc.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPAHelper.exe - Unknown owner - C:\Program Files\iPod Access for Windows\iPAHelper.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MobilePre Installer (MobilePreInstallerService) - M-Audio - C:\Program Files\M-Audio MobilePre\Install\MPInst.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2004\WinStylerThemeSvc.exe
O23 - Service: wshtcpip - Unknown owner - C:\WINDOWS\System32\wshtcpip.exe
--
End of file - 14626 bytes
KASPERSKY LOG:
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Tuesday, May 06, 2008 9:21:15 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 6/05/2008
Kaspersky Anti-Virus database records: 741846
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 108032
Number of viruses found: 26
Number of infected objects: 149
Number of suspicious objects: 0
Duration of the scan process: 02:03:26
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\PWMR8UHI\200_160_i_3[1].abc Infected: Trojan-Downloader.Win32.Agent.wd skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Owner\198_150_ni_1.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\Documents and Settings\Owner\Application Data\Microsoft\Windows\nkkvvo.exe Object is locked skipped
C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\uhq8xtir.default\cert8.db Object is locked skipped
C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\uhq8xtir.default\formhistory.dat Object is locked skipped
C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\uhq8xtir.default\history.dat Object is locked skipped
C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\uhq8xtir.default\key3.db Object is locked skipped
C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\uhq8xtir.default\parent.lock Object is locked skipped
C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\uhq8xtir.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\uhq8xtir.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Owner\Application Data\SpeedRunner\SpeedRunner.exe Infected: Trojan-Downloader.Win32.Agent.ndt skipped
C:\Documents and Settings\Owner\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\uhq8xtir.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\uhq8xtir.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\uhq8xtir.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\uhq8xtir.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\History\History.IE5\MSHist012008050620080507\index.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Temp\Perflib_Perfdata_25c.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Temp\~DF469A.tmp Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Owner\ntuser.dat Object is locked skipped
C:\Documents and Settings\Owner\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Owner\xJWIYFSHYHT.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\Documents and Settings\Owner\xVYDKKPLIKK.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.612 skipped
C:\Program Files\winvi\update.exe/stream/Script Infected: Trojan.NSIS.StartPage.c skipped
C:\Program Files\winvi\update.exe/stream Infected: Trojan.NSIS.StartPage.c skipped
C:\Program Files\winvi\update.exe NSIS: infected - 2 skipped
C:\QooBox\Quarantine\C\Program Files\JavaCore\JavaCore.exe.vir Infected: not-a-virus:AdWare.Win32.Insider.c skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\cbXRKBuu.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.qng skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\efcDWNfc.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.qng skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\test.bmp.vir Infected: Trojan-Downloader.Win32.Reqlook.d skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP463\A0070878.exe Infected: Trojan-Downloader.Win32.Agent.wd skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP464\A0070909.exe Infected: Trojan-Downloader.Win32.Agent.wd skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP466\A0070936.exe Infected: Trojan-Downloader.Win32.Agent.wd skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP466\A0070949.exe Infected: Trojan-Downloader.Win32.Agent.wd skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP467\A0070967.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP467\A0070968.exe Infected: Trojan-Downloader.Win32.Agent.wd skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP468\A0070984.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP468\A0070985.exe Infected: Trojan-Downloader.Win32.Agent.wd skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP469\A0071006.exe Infected: Trojan-Downloader.Win32.Agent.wd skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP471\A0071053.exe Infected: Trojan-Downloader.Win32.Agent.wd skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP472\A0071064.exe Infected: Trojan-Downloader.Win32.Agent.wd skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP473\A0071079.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP475\A0071123.exe Infected: Trojan-Downloader.Win32.Agent.wd skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP476\A0071138.exe Infected: Trojan-Downloader.Win32.Agent.wd skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP476\A0071146.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP477\A0071183.exe Infected: Trojan-Downloader.Win32.Agent.wd skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP478\A0071199.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP480\A0071216.exe Infected: Trojan-Downloader.Win32.Homles.bk skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP480\A0072247.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP480\A0072249.exe Infected: Trojan-Downloader.Win32.PurityScan.fj skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP480\A0072250.dll Infected: not-a-virus:AdWare.Win32.PurityScan.hk skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP480\A0072251.exe Infected: not-a-virus:AdWare.Win32.PurityScan.hl skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP480\A0072253.dll Infected: not-a-virus:AdWare.Win32.ZenoSearch.ad skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP480\A0072256.exe/data0001 Infected: not-a-virus:AdWare.Win32.PurityScan.gp skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP480\A0072256.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP480\A0072257.exe Infected: Trojan.Win32.Scapur.k skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP482\A0072305.exe Infected: Trojan-Downloader.Win32.Homles.bk skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP482\A0072308.exe Infected: Trojan-Downloader.Win32.Agent.ezc skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP482\A0072310.exe Infected: not-a-virus:AdWare.Win32.Insider.c skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP482\A0072311.exe Infected: Trojan.Win32.BHO.blh skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP482\A0072312.exe Infected: not-a-virus:AdWare.Win32.Insider.f skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP482\A0072313.exe Infected: Trojan-Downloader.Win32.Agent.jih skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP482\A0072314.exe Infected: Trojan-Downloader.Win32.Homles.bk skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP483\A0074388.exe Infected: not-a-virus:AdWare.Win32.Insider.c skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP483\A0074394.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qng skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP483\A0074395.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.qng skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP483\A0074429.exe Infected: not-a-virus

C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP483\A0074430.exe Infected: not-a-virus

C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP484\A0074522.exe Infected: Trojan-Downloader.Win32.Agent.wd skipped
C:\System Volume Information\_restore{11827C99-88BA-4A82-B691-A920F3B1A44E}\RP484\change.log Object is locked skipped
C:\WINDOWS\b155.exe_old Infected: Trojan.Win32.BHO.blh skipped
C:\WINDOWS\b156.exe_old Infected: not-a-virus:AdWare.Win32.Insider.f skipped
C:\WINDOWS\b157.exe_old Infected: Trojan-Downloader.Win32.Agent.jih skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\ModemLog_Communications cable between two computers.txt Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\12033\cvserchka.exe Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\WINDOWS\system32\198_150_ni_1.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\adsldp.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\autodisc.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\avicap32.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\bkEur01\bkEur011065.exe Infected: Trojan-Downloader.Win32.VB.edw skipped
C:\WINDOWS\system32\blackbox.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\browselc.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\cdfview.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\cdmodem.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\cdTMP\cdrev132.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.am skipped
C:\WINDOWS\system32\ciodm.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\cNF\srkcont3.exe/stream/data0007/stream/Script Infected: Trojan.NSIS.StartPage.c skipped
C:\WINDOWS\system32\cNF\srkcont3.exe/stream/data0007/stream Infected: Trojan.NSIS.StartPage.c skipped
C:\WINDOWS\system32\cNF\srkcont3.exe/stream/data0007 Infected: Trojan.NSIS.StartPage.c skipped
C:\WINDOWS\system32\cNF\srkcont3.exe/stream Infected: Trojan.NSIS.StartPage.c skipped
C:\WINDOWS\system32\cNF\srkcont3.exe NSIS: infected - 4 skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\d3d9.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\d3dramp.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\d3dxof.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\davclnt.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\dbnmpntw.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\deskadp.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\dgnet.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\din3\is-setup03x.exe Infected: Trojan.Win32.Agent.lom skipped
C:\WINDOWS\system32\dinput8.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\dmserver.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\dplay.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\dskquoui.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\dsprpres.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\dssenh.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\eventcls.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\fsusd.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\glu32.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\hpovst08.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\iasads.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\icmp.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\icwdial.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\imagehlp.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\imagxpr5.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\inetcplc.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\iologmsg.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\ipv6mon.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\ir41_qc.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\ir50_qcx.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\jscript.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\kbdfr.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\kbdkyr.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\kcntmkdm.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.bc skipped
C:\WINDOWS\system32\langwrbk.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\ld.exe Infected: Trojan.Win32.Crypt.t skipped
C:\WINDOWS\system32\lfpsd11n.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\licdll.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINDOWS\system32\mciseq.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\modemui.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\msexcl40.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\msprivs.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\msr2cenu.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\msswch.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\msvcrt40.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\mswsock.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\mydocs.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\nddeapi.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\netui2.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\odbccr32.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\oleacc.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\pncrt.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\psnppagn.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\qasf.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\rdpcfgex.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\rsvpmsg.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\rsvpsp.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\rtm.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\rwwnw64d.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.am skipped
C:\WINDOWS\system32\shdoclc.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\shimeng.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\stclient.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\stobject.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\svcpack.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\swprv.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\tapiperf.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\tcntmkdm.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.bc skipped
C:\WINDOWS\system32\test.bmp Infected: Trojan-Downloader.Win32.Reqlook.d skipped
C:\WINDOWS\system32\usbmon.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\vjoy.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\system32\winsta.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\wldap32.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\wmsdmoe2.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\wmvsdecd.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\wpdtrace.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\wshtcpip.exe Infected: Trojan-Downloader.Win32.Reqlook.d skipped
C:\WINDOWS\system32\xactsrv.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\xenroll.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\system32\xpsp2res.exe Infected: Trojan-Downloader.Win32.Agent.am skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.