——————————————————————————-
KASPERSKY ON-LINE SCANNER REPORT
Friday, October 28, 2005 20:41:38
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 28/10/2005
Kaspersky Anti-Virus database records: 156920
——————————————————————————-
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\
K:\
Scan Statistics:
Total number of scanned objects: 96599
Number of viruses found: 25
Number of infected objects: 180
Number of suspicious objects: 0
Duration of the scan process: 4687 sec
Infected Object Name - Virus Name
C:\Documents and Settings\All Users\Application Data\Book Glue Surf Bleh\MapiChin.exe Infected: not-a-virus:AdWare.Win32.Lop.ag
C:\Documents and Settings\not rokit\Application Data\knobmeal\DART SHOW FORD.exe Infected: not-a-virus:AdWare.Win32.Lop.ag
C:\Documents and Settings\not rokit\Application Data\knobmeal\data load eggs.exe Infected: not-a-virus:AdWare.Win32.Lop.ag
C:\Documents and Settings\not rokit\Application Data\knobmeal\eltwasrh.exe Infected: Trojan-Downloader.Win32.Swizzor.de
C:\Documents and Settings\not rokit\Application Data\knobmeal\giqwvdct.exe Infected: not-a-virus:AdWare.Win32.Lop.ag
C:\Documents and Settings\not rokit\Application Data\knobmeal\PureWinGlobalDrive.exe Infected: not-a-virus:AdWare.Win32.Lop.ag
C:\Documents and Settings\not rokit\Application Data\knobmeal\qzsixyfd.exe Infected: not-a-virus:AdWare.Win32.Lop.ad
C:\Documents and Settings\not rokit\Application Data\knobmeal\rjwwaiht.exe Infected: not-a-virus:AdWare.Win32.Lop.z
C:\Documents and Settings\not rokit\Application Data\knobmeal\soeqcxir.exe Infected: not-a-virus:AdWare.Win32.Lop.ab
C:\Documents and Settings\not rokit\Application Data\knobmeal\wysqrakf.exe Infected: Trojan-Downloader.Win32.Swizzor.dr
C:\Documents and Settings\not rokit\Application Data\Lite This\burnace.exe Infected: not-a-virus:AdWare.Win32.Lop.ag
C:\Documents and Settings\not rokit\Local Settings\Temp\Inside Program.exe Infected: Trojan-Downloader.Win32.Swizzor.dj
C:\Documents and Settings\not rokit\Local Settings\Temp\nyiqbtpe.exe Infected: not-a-virus:AdWare.Win32.Lop.m
C:\Documents and Settings\not rokit\Local Settings\Temp\obuophio.exe Infected: not-a-virus:AdWare.Win32.Lop.m
C:\Documents and Settings\not rokit\Local Settings\Temp\sta256.exe Infected: not-a-virus:AdWare.Win32.Lop.ag
C:\Documents and Settings\not rokit\Local Settings\Temporary Internet Files\Content.IE5\0B7JY8P5\upAYB[1].int Infected: Trojan-Downloader.Win32.Swizzor.dj
C:\Documents and Settings\Owner\Application Data\knobmeal\atqqqlrl.exe Infected: not-a-virus:AdWare.Win32.Lop.ad
C:\Documents and Settings\Owner\Application Data\knobmeal\bzyhkjsj.exe Infected: not-a-virus:AdWare.Win32.Lop.z
C:\Documents and Settings\Owner\Application Data\knobmeal\ceuynvud.exe Infected: Trojan-Downloader.Win32.Swizzor.cr
C:\Documents and Settings\Owner\Application Data\knobmeal\cgigyfhz.exe Infected: Trojan-Downloader.Win32.Swizzor.de
C:\Documents and Settings\Owner\Application Data\knobmeal\cuqlgjsc.exe Infected: not-a-virus:AdWare.Win32.Lop.ab
C:\Documents and Settings\Owner\Application Data\knobmeal\DART SHOW FORD.exe Infected: not-a-virus:AdWare.Win32.Lop.ag
C:\Documents and Settings\Owner\Application Data\knobmeal\data load eggs.exe Infected: not-a-virus:AdWare.Win32.Lop.ag
C:\Documents and Settings\Owner\Application Data\knobmeal\djipjjwn.exe Infected: Trojan-Downloader.Win32.Swizzor.de
C:\Documents and Settings\Owner\Application Data\knobmeal\esohdidq.exe Infected: not-a-virus:AdWare.Win32.Lop.ad
C:\Documents and Settings\Owner\Application Data\knobmeal\fwdovbwq.exe Infected: Trojan-Downloader.Win32.Swizzor.de
C:\Documents and Settings\Owner\Application Data\knobmeal\hguhvybl.exe Infected: not-a-virus:AdWare.Win32.Lop.ad
C:\Documents and Settings\Owner\Application Data\knobmeal\hsswtjiz.exe Infected: Trojan-Downloader.Win32.Swizzor.dj
C:\Documents and Settings\Owner\Application Data\knobmeal\lrpgwzpy.exe Infected: Trojan-Downloader.Win32.Swizzor.de
C:\Documents and Settings\Owner\Application Data\knobmeal\ltyzpzqo.exe Infected: not-a-virus:AdWare.Win32.Lop.z
C:\Documents and Settings\Owner\Application Data\knobmeal\mznrgfhj.exe Infected: not-a-virus:AdWare.Win32.Lop.ab
C:\Documents and Settings\Owner\Application Data\knobmeal\nilcesxu.exe Infected: not-a-virus:AdWare.Win32.Lop.ad
C:\Documents and Settings\Owner\Application Data\knobmeal\nshgeppu.exe Infected: not-a-virus:AdWare.Win32.Lop.ad
C:\Documents and Settings\Owner\Application Data\knobmeal\oevmyicw.exe Infected: not-a-virus:AdWare.Win32.Lop.ad
C:\Documents and Settings\Owner\Application Data\knobmeal\onixhhvw.exe Infected: not-a-virus:AdWare.Win32.Lop.ad
C:\Documents and Settings\Owner\Application Data\knobmeal\oqtxaxlj.exe Infected: Trojan-Downloader.Win32.Swizzor.cr
C:\Documents and Settings\Owner\Application Data\knobmeal\ottrkdej.exe Infected: not-a-virus:AdWare.Win32.Lop.z
C:\Documents and Settings\Owner\Application Data\knobmeal\pbdtyuwr.exe Infected: Trojan-Downloader.Win32.Swizzor.de
C:\Documents and Settings\Owner\Application Data\knobmeal\pcergqqo.exe Infected: not-a-virus:AdWare.Win32.Lop.ab
C:\Documents and Settings\Owner\Application Data\knobmeal\pciwgozx.exe Infected: Trojan-Downloader.Win32.Swizzor.de
C:\Documents and Settings\Owner\Application Data\knobmeal\picbaqar.exe Infected: Trojan-Downloader.Win32.Swizzor.de
C:\Documents and Settings\Owner\Application Data\knobmeal\pnybgpsk.exe Infected: not-a-virus:AdWare.Win32.Lop.ad
C:\Documents and Settings\Owner\Application Data\knobmeal\ppbfzbwo.exe Infected: not-a-virus:AdWare.Win32.Lop.z
C:\Documents and Settings\Owner\Application Data\knobmeal\PureWinGlobalDrive.exe Infected: not-a-virus:AdWare.Win32.Lop.ag
C:\Documents and Settings\Owner\Application Data\knobmeal\rcglairl.exe Infected: Trojan-Downloader.Win32.Swizzor.de
C:\Documents and Settings\Owner\Application Data\knobmeal\rnjfumle.exe Infected: not-a-virus:AdWare.Win32.Lop.p
C:\Documents and Settings\Owner\Application Data\knobmeal\rupwczke.exe Infected: Trojan-Downloader.Win32.Swizzor.dr
C:\Documents and Settings\Owner\Application Data\knobmeal\rvmhzmhv.exe Infected: not-a-virus:AdWare.Win32.Lop.o
C:\Documents and Settings\Owner\Application Data\knobmeal\sduntnbl.exe Infected: Trojan-Downloader.Win32.Swizzor.de
C:\Documents and Settings\Owner\Application Data\knobmeal\vitrivnd.exe Infected: not-a-virus:AdWare.Win32.Lop.ag
C:\Documents and Settings\Owner\Application Data\knobmeal\wceccfiy.exe Infected: Trojan-Downloader.Win32.Swizzor.de
C:\Documents and Settings\Owner\Application Data\knobmeal\wojtjayk.exe Infected: not-a-virus:AdWare.Win32.Lop.z
C:\Documents and Settings\Owner\Application Data\knobmeal\xdwopntj.exe Infected: not-a-virus:AdWare.Win32.Lop.ad
C:\Documents and Settings\Owner\Application Data\knobmeal\xqcujnhu.exe Infected: not-a-virus:AdWare.Win32.Lop.ab
C:\Documents and Settings\Owner\Application Data\knobmeal\xygcxaov.exe Infected: Trojan-Downloader.Win32.Swizzor.de
C:\Documents and Settings\Owner\Application Data\knobmeal\yeoqxpug.exe Infected: Trojan-Downloader.Win32.Swizzor.cr
C:\Documents and Settings\Owner\Application Data\knobmeal\yjnyxoxb.exe Infected: not-a-virus:AdWare.Win32.Lop.ad
C:\Documents and Settings\Owner\Application Data\Lite This\burnace.exe Infected: not-a-virus:AdWare.Win32.Lop.ag
C:\Documents and Settings\Owner\Local Settings\Temp\1776c5.exe Infected: Trojan-Downloader.Win32.Swizzor.cs
C:\Documents and Settings\Owner\Local Settings\Temp\3fbeb2.exe Infected: not-a-virus:AdWare.Win32.Lop.ag
C:\Documents and Settings\Owner\Local Settings\Temp\425b52.exe Infected: Trojan-Downloader.Win32.Swizzor.cs
C:\Documents and Settings\Owner\Local Settings\Temp\425bbd.exe Infected: Trojan-Downloader.Win32.Swizzor.cs
C:\Documents and Settings\Owner\Local Settings\Temp\575a62.exe Infected: Trojan-Downloader.Win32.Swizzor.cs
C:\Documents and Settings\Owner\Local Settings\Temp\5ddd39.exe Infected: Trojan-Downloader.Win32.Swizzor.cs
C:\Documents and Settings\Owner\Local Settings\Temp\5e9d10.exe Infected: Trojan-Downloader.Win32.Swizzor.cs
C:\Documents and Settings\Owner\Local Settings\Temp\64a984.exe Infected: Trojan-Downloader.Win32.Swizzor.cs
C:\Documents and Settings\Owner\Local Settings\Temp\9d898d.exe Infected: Trojan-Downloader.Win32.Swizzor.dh
C:\Documents and Settings\Owner\Local Settings\Temp\afb647.exe Infected: Trojan-Downloader.Win32.Swizzor.cs
C:\Documents and Settings\Owner\Local Settings\Temp\cfzlgpuh.exe Infected: not-a-virus:AdWare.Win32.Lop.m
C:\Documents and Settings\Owner\Local Settings\Temp\cjpbfakg.exe Infected: not-a-virus:AdWare.Win32.Lop.m
C:\Documents and Settings\Owner\Local Settings\Temp\ec4d3224.exe Infected: Trojan-Downloader.Win32.Swizzor.cs
C:\Documents and Settings\Owner\Local Settings\Temp\fqthtifr.exe Infected: not-a-virus:AdWare.Win32.Lop
C:\Documents and Settings\Owner\Local Settings\Temp\gvhvjucw.exe Infected: not-a-virus:AdWare.Win32.Lop.m
C:\Documents and Settings\Owner\Local Settings\Temp\Inside Program.exe Infected: Trojan-Downloader.Win32.Swizzor.dr
C:\Documents and Settings\Owner\Local Settings\Temp\is-B2AB3.tmp\NNTRDA638.EXE Infected: not-a-virus:AdWare.Win32.NewDotNet
C:\Documents and Settings\Owner\Local Settings\Temp\New57.tmp\upgrade.exe Infected: not-a-virus:AdWare.Win32.NewDotNet
C:\Documents and Settings\Owner\Local Settings\Temp\oasgsfeg.exe Infected: not-a-virus:AdWare.Win32.Lop
C:\Documents and Settings\Owner\Local Settings\Temp\pjslgeva.exe Infected: not-a-virus:AdWare.Win32.Lop
C:\Documents and Settings\Owner\Local Settings\Temp\res209.tmp Infected: not-a-virus:AdWare.Win32.180Solutions.k
C:\Documents and Settings\Owner\Local Settings\Temp\sta26C.exe Infected: not-a-virus:AdWare.Win32.Lop.ag
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\UZERQXU7\upAYB_unk[1].int Infected: not-a-virus:AdWare.Win32.Lop.ag
C:\Program Files\BitComet\Downloads\3 Sexy Teen Sluts Experimenting [ porn xxx ].exe/data0004 Infected: not-a-virus:AdWare.Win32.NewDotNet
C:\Program Files\BitComet\Downloads\3 Sexy Teen Sluts Experimenting [ porn xxx ].exe Infected: not-a-virus:AdWare.Win32.NewDotNet
C:\Program Files\installcasino.exe Infected: not-a-virus:AdWare.Win32.Casino.m
C:\Program Files\Microsoft AntiSpyware\Quarantine\23B51397-C073-49BA-9233-402BA8\0424EA65-F354-402A-82E3-5F4D0A Infected: not-a-virus:AdWare.Win32.180Solutions.l
C:\Program Files\Microsoft AntiSpyware\Quarantine\23B51397-C073-49BA-9233-402BA8\9237108A-5B85-4610-B828-F95D5F Infected: not-a-virus:AdWare.Win32.180Solutions.k
C:\Program Files\Microsoft AntiSpyware\Quarantine\7AAC3C8C-BD4E-4BFC-85E9-AE2D06\763AF128-E8CD-4A8D-8412-DE0032 Infected: not-a-virus:AdWare.Win32.WinAD.bf
C:\Program Files\TopText\CHCON.dll.tcf Infected: not-a-virus:AdWare.Win32.EZula.ae
C:\Program Files\WarezP2P.exe/stream/data0029/Cabs.w1.cab/HyperbarSS3.dll Infected: not-a-virus:AdWare.Win32.HyperBar.b
C:\Program Files\WarezP2P.exe/stream/data0029/Cabs.w1.cab/Hyperbar.dll Infected: not-a-virus:AdWare.Win32.HyperBar.b
C:\Program Files\WarezP2P.exe/stream/data0029/Cabs.w1.cab Infected: not-a-virus:AdWare.Win32.HyperBar.b
C:\Program Files\WarezP2P.exe/stream/data0029 Infected: not-a-virus:AdWare.Win32.HyperBar.b
C:\Program Files\WarezP2P.exe/stream/data0030 Infected: not-a-virus:AdWare.Win32.NewDotNet
C:\Program Files\WarezP2P.exe/stream Infected: not-a-virus:AdWare.Win32.NewDotNet
C:\Program Files\WarezP2P.exe Infected: not-a-virus:AdWare.Win32.NewDotNet
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP23\A0005064.exe Infected: Trojan-Downloader.Win32.Swizzor.bo
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP24\A0005177.exe Infected: not-a-virus:AdWare.Win32.Lop.m
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP24\A0005178.exe Infected: Trojan-Downloader.Win32.Swizzor.cr
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP24\A0005179.exe Infected: not-a-virus:AdWare.Win32.Lop.ad
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP24\A0005180.exe Infected: Trojan-Downloader.Win32.Swizzor.de
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP24\A0005181.exe Infected: not-a-virus:AdWare.Win32.Lop.ad
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP24\A0005182.exe Infected: Trojan-Downloader.Win32.Swizzor.cr
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP24\A0005183.exe Infected: Trojan-Downloader.Win32.Swizzor.de
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP24\A0005184.exe Infected: not-a-virus:AdWare.Win32.Lop.ad
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP24\A0005185.exe Infected: Trojan-Downloader.Win32.Swizzor.de
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP24\A0005186.exe Infected: not-a-virus:AdWare.Win32.Lop.ab
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP24\A0005187.exe Infected: not-a-virus:AdWare.Win32.Lop.ad
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP24\A0005188.exe Infected: not-a-virus:AdWare.Win32.Lop.ab
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP24\A0005189.exe Infected: not-a-virus:AdWare.Win32.Lop.p
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP24\A0005190.exe Infected: not-a-virus:AdWare.Win32.Lop.z
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP24\A0005191.exe Infected: not-a-virus:AdWare.Win32.Lop.ab
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP24\A0005192.exe Infected: Trojan-Downloader.Win32.Swizzor.de
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP24\A0005193.exe Infected: not-a-virus:AdWare.Win32.Lop.ad
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP24\A0005194.exe Infected: Trojan-Downloader.Win32.Swizzor.de
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP24\A0005195.exe Infected: not-a-virus:AdWare.Win32.Lop.ab
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP24\A0005196.exe Infected: not-a-virus:AdWare.Win32.Lop.z
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP24\A0005197.exe Infected: Trojan-Downloader.Win32.Swizzor.de
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP24\A0005198.exe Infected: Trojan-Downloader.Win32.Swizzor.de
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP24\A0005199.exe Infected: not-a-virus:AdWare.Win32.Lop.ab
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP24\A0005200.exe Infected: Trojan-Downloader.Win32.Swizzor.de
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP24\A0005201.exe Infected: not-a-virus:AdWare.Win32.Lop.ad
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP24\A0005202.exe Infected: not-a-virus:AdWare.Win32.Lop.z
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP24\A0005203.exe Infected: Trojan-Downloader.Win32.Swizzor.de
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP24\A0005204.exe Infected: Trojan-Downloader.Win32.Swizzor.de
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP24\A0005205.exe Infected: not-a-virus:AdWare.Win32.Lop.z
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP24\A0005206.exe Infected: not-a-virus:AdWare.Win32.Lop.z
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP24\A0005207.exe Infected: not-a-virus:AdWare.Win32.Lop.ad
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP24\A0005208.exe Infected: not-a-virus:AdWare.Win32.Lop.z
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP24\A0005209.exe Infected: not-a-virus:AdWare.Win32.Lop.ad
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP24\A0005210.exe Infected: Trojan-Downloader.Win32.Swizzor.de
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP24\A0005211.exe Infected: not-a-virus:AdWare.Win32.Lop.ad
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP24\A0005212.exe Infected: not-a-virus:AdWare.Win32.Lop.ad
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP24\A0005213.exe Infected: Trojan-Downloader.Win32.Swizzor.de
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP24\A0005214.exe Infected: Trojan-Downloader.Win32.Swizzor.dr
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP24\A0005215.exe Infected: Trojan-Downloader.Win32.Swizzor.cb
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP36\A0008370.dll Infected: not-a-virus:AdWare.Win32.EZula.ae
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP36\A0008506.exe Infected: Trojan-Downloader.Win32.Swizzor.cr
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP36\A0008507.exe Infected: not-a-virus:AdWare.Win32.Lop.ad
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP36\A0008508.exe Infected: Trojan-Downloader.Win32.Swizzor.de
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP36\A0008509.exe Infected: not-a-virus:AdWare.Win32.Lop.ad
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP36\A0008510.exe Infected: Trojan-Downloader.Win32.Swizzor.cr
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP36\A0008511.exe Infected: Trojan-Downloader.Win32.Swizzor.de
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP36\A0008512.exe Infected: not-a-virus:AdWare.Win32.Lop.ad
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP36\A0008513.exe Infected: Trojan-Downloader.Win32.Swizzor.de
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP36\A0008514.exe Infected: not-a-virus:AdWare.Win32.Lop.ab
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP36\A0008515.exe Infected: not-a-virus:AdWare.Win32.Lop.ad
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP36\A0008516.exe Infected: not-a-virus:AdWare.Win32.Lop.ab
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP36\A0008517.exe Infected: not-a-virus:AdWare.Win32.Lop.p
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP36\A0008518.exe Infected: not-a-virus:AdWare.Win32.Lop.z
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP36\A0008519.exe Infected: not-a-virus:AdWare.Win32.Lop.ab
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP36\A0008520.exe Infected: Trojan-Downloader.Win32.Swizzor.de
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP36\A0008521.exe Infected: not-a-virus:AdWare.Win32.Lop.ad
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP36\A0008522.exe Infected: Trojan-Downloader.Win32.Swizzor.de
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP36\A0008523.exe Infected: not-a-virus:AdWare.Win32.Lop.ag
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP36\A0008524.exe Infected: not-a-virus:AdWare.Win32.Lop.ab
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP36\A0008525.exe Infected: not-a-virus:AdWare.Win32.Lop.z
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP36\A0008526.exe Infected: Trojan-Downloader.Win32.Swizzor.de
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP36\A0008527.exe Infected: Trojan-Downloader.Win32.Swizzor.de
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP36\A0008528.exe Infected: not-a-virus:AdWare.Win32.Lop.ad
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP36\A0008529.exe Infected: not-a-virus:AdWare.Win32.Lop.ab
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP36\A0008530.exe Infected: Trojan-Downloader.Win32.Swizzor.de
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP36\A0008531.exe Infected: not-a-virus:AdWare.Win32.Lop.ad
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP36\A0008532.exe Infected: not-a-virus:AdWare.Win32.Lop.z
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP36\A0008533.exe Infected: Trojan-Downloader.Win32.Swizzor.de
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP36\A0008534.exe Infected: Trojan-Downloader.Win32.Swizzor.de
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP36\A0008535.exe Infected: not-a-virus:AdWare.Win32.Lop.z
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP36\A0008536.exe Infected: not-a-virus:AdWare.Win32.Lop.z
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP36\A0008537.exe Infected: not-a-virus:AdWare.Win32.Lop.ad
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP36\A0008538.exe Infected: not-a-virus:AdWare.Win32.Lop.z
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP36\A0008539.exe Infected: not-a-virus:AdWare.Win32.Lop.ad
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP36\A0008540.exe Infected: Trojan-Downloader.Win32.Swizzor.de
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP36\A0008541.exe Infected: not-a-virus:AdWare.Win32.Lop.ad
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP36\A0008542.exe Infected: not-a-virus:AdWare.Win32.Lop.ad
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP36\A0008543.exe Infected: Trojan-Downloader.Win32.Swizzor.de
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP36\A0008697.exe Infected: not-a-virus:AdWare.Win32.Lop.m
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP36\A0008698.exe Infected: Trojan-Downloader.Win32.Swizzor.dr
C:\System Volume Information\_restore{8CB13E58-1931-4A1C-946C-BAC0623BF5DA}\RP36\A0008699.exe Infected: Trojan-Downloader.Win32.Swizzor.cb
C:\WINDOWS\system32\67m5ksm2.ini Infected: not-a-virus:AdWare.Win32.Sahat.ao
C:\WINDOWS\woinstall.exe/WISE0001.BIN Infected: not-a-virus:AdWare.Win32.EZula.ak
C:\WINDOWS\woinstall.exe Infected: not-a-virus:AdWare.Win32.EZula.ak
Scan process completed.
Logfile of HijackThis v1.99.1
Scan saved at 20:43:30, on 28/10/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\BT Voyager 105 ADSL Modem\dslstat.exe
C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Multimedia Card Reader\shwicon2k.exe
C:\Program Files\AOL 9.0\aoltray.exe
C:\Program Files\AOL 9.0\waol.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-gb\bin\WindowsSearch.exe
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-gb\bin\WindowsSearchIndexer.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\AOL 9.0\shellmon.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\Common Files\AOL\aoltpspd.exe
C:\Program Files\SpywareGuard\sgbhp.exe
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.co.uk
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: MSN Search Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1082\en-gb\msntb.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: MSN Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1082\en-gb\msntb.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [DSLSTATEXE] C:\Program Files\BT Voyager 105 ADSL Modem\dslstat.exe icon
O4 - HKLM\..\Run: [DSLAGENTEXE] C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe
O4 - HKLM\..\Run: [%FP%Friendly fts.exe] "C:\Program Files\VoyagerTest\fts.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P31 "EPSON Stylus Photo RX420 Series" /O6 "USB001" /M "Stylus Photo RX420"
O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series (Copy 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P40 "EPSON Stylus Photo RX420 Series (Copy 1)" /O5 "COM4:" /M "Stylus Photo RX420"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKLM\..\Run: [Surf Bleh Cake Active] C:\Documents and Settings\All Users\Application Data\Book Glue Surf Bleh\MapiChin.exe
O4 - HKCU\..\Run: [TrayGlue] C:\DOCUME~1\Owner\APPLIC~1\knobmeal\data load eggs.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AOL 9.0 Tray Icon.lnk = C:\Program Files\AOL 9.0\aoltray.exe
O4 - Global Startup: BlueSoleil.lnk = ?
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-gb\bin\WindowsSearch.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1082\en-gb\msntb.dll/search.htm
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-gb\msntabres.dll/229?1e6c9ed6565341f4877653cc6b9a2055
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-gb\msntabres.dll/230?1e6c9ed6565341f4877653cc6b9a2055
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) -
http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky.com/downloads/kws/kav…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) -
http://aolcc.aolsvc.aol.co.uk/computercheckup/qdiagcc.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://by22fd.bay22.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdat…b?1127756251281
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmesse…pdownloader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{78C19BE4-8D13-49B8-B9D0-309D5C184583}: NameServer = 205.188.146.145
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe