This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

It's back...AVG warning of trojan clicker.fr

33 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Posted last week and got lots of great help and thought everything was kosher. Appears as though I was wrong. Yesterday, got an AVG virus warning concerning a certain little nasty that we tried to kill already. I immediately updated my Ewido, Spybot S&D, AdAware SE Personal, and AVG 7.1 Professional. Rebooted in Safe Mode, ran all four programs, followed their recommendations for removal of nasties. Ran Fixwareout.exe and rebooted. Here is the report.txt, followed by the latest HijackThis log. Please help if you can!


Fixwareout ver 1.003
Last edited 8/11/2006
Post this report in the forums please

Reg Entries that were deleted
…

Microsoft ® Windows Script Host Version 5.6
Random Runs removed from HKLM
…

PLEASE NOTE, There WILL be LEGITIMATE FILES LISTED. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.

»»»»» Searching by size/names…

»»»»»
Search five digit cs, dm and jb files.
This WILL/CAN also list Legit Files, Submit them at Virustotal

Other suspects.
Directory of C:\WINDOWS\system32

»»»»» Misc files.

»»»»» Checking for older varients covered by the Rem3 tool.


Logfile of HijackThis v1.99.1
Scan saved at 7:57:47 AM, on 8/22/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\LEXBCES.EXE
F:\WINDOWS\system32\spoolsv.exe
F:\WINDOWS\system32\LEXPPS.EXE
F:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
F:\WINDOWS\system32\drivers\KodakCCS.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\wscntfy.exe
F:\WINDOWS\system32\NOTEPAD.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
F:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\program files\support.com\bin\tgcmd.exe
C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe
C:\Program Files\Lexmark X5100 Series\lxbabmon.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
C:\PROGRA~1\Grisoft\AVG7\avgw.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
F:\WINDOWS\System32\tbctray.exe
C:\PROGRA~1\AWS\WEATHE~1\WEATHER.EXE
F:\Program Files\Free History Eraser\HistoryEraser.exe
F:\Documents and Settings\Eddie\Desktop\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.findin.org/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://yahoo.sbc.com/dsl
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\en-us\msntb.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O4 - HKLM\..\Run: [tgcmd] "F:\Program Files\support.com\bin\tgcmd.exe" /server
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [iTunesHelper] "F:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MSConfig] F:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [tgcmdprovidersbc] "c:\program files\support.com\bin\tgcmd.exe" /server /startmonitor /deaf /nosystray
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Lexmark X5100 Series] "C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [TraySantaCruz] F:\WINDOWS\System32\tbctray.exe
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\WEATHER.EXE 1
O4 - HKCU\..\Run: [SPSTEALT] "F:\Program Files\Free History Eraser\HistoryEraser.exe" /stealt
O8 - Extra context menu item: &Define - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Look Up in &Encyclopedia - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\npjpi150_08.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\npjpi150_08.dll
O9 - Extra button: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra 'Tools' menuitem: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll (file missing)
O9 - Extra button: Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - http://www.net2phone.com/ (file missing)
O9 - Extra 'Tools' menuitem: Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - http://www.net2phone.com/ (file missing)
O9 - Extra button: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra 'Tools' menuitem: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Dell Home - {08DCFC6C-B6E4-480C-95A4-FC64F37B787E} - http://www.dellnet.com (file missing) (HKCU)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O12 - Plugin for .bcf: C:\Program Files\Internet Explorer\Plugins\NPBelv32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall-beta.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200312…meInstaller.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O16 - DPF: {F72BC3F0-6C20-4793-9DDA-258589D8A907} - http://akamai.downloadv3.com/binaries/IA/netslv32_EN_XP.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - F:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - F:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - F:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: STOPzilla Local Service - Unknown owner - C:\Program Files\STOPzilla!\szntsvc.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe

THANKS…
Hello egates,

You have some things disabled for startup. Please do the following:

Step 1.

Go to Start >Run and type "Notepad" without the quotes
Copy the contents of this next code box to Notepad.
Go to the menu at the top of the Notepad file and Save as:
  • Name the file inspect.bat
  • Save as Type: All files
  • Select the desktop icon on the left to save it on the desktop.
Double click on inspect.bat and let it run.
When finished it will open a file in Notepad.
That file will be named startup.txt
Please post the contents of startup.txt into your next reply here.

If not exist Files MkDir Files 

regedit /e peek1.txt "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg"
regedit /e peek2.txt "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder"
type peek1.txt >> startup.txt
type peek2.txt >> startup.txt
del peek*.txt
start notepad startup.txt

Copy files\*.txt = startup.txt 
rmdir /s /q files 
Start Notepad startup.txt

Step 2.

Now run this online scan using Internet Explorer:
Kaspersky Online Scanner from http://www.kaspersky.com/virusscanner

Next Click on Launch Kaspersky Online Scanner

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
  • Scan using the following Anti-Virus database:
  • Standard
  • Scan Options:
  • Scan Archives
  • Scan Mail Bases
  • Click OK
  • Now under select a target to scan:
  • Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button:
  • Save the file to your desktop.
Copy and paste that information from Kapersky in your next post.

Step 3.

Let's check for rootkits:
Blacklight

Download Blacklight trial from here:
http://www.f-secure.com/blacklight/
  • Hit I accept. It will take you to download page.
  • Download blbeta.exe and save it to the Desktop.
  • Once saved… double click blbeta.exe to install the program.
  • Click accept agreement and Click scan
    This app too may fire off a warning from antivirus. Let the driver load.
    Wait for it to finish.
  • If it displays any items…don't do anything with them yet. Just hit exit (close)
  • It will drop a log on Desktop that starts with fsbl….big number
Please post contents of log.

So please reply with the startup.txt, the results from Kapersky, and the Blacklight Beta log that begins with the fslb… big number.
Here's the scoop: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\MSMsgSvc] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="" "hkey"="HKCU" "command"="" "inimapping"="0" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Run] "key"="SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Windows" "item"="dxsty" "hkey"="HKCU" "command"="c:\\windows\\system32\\dxsty.exe" "inimapping"="1" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Yahoo! Pager] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="1" "hkey"="HKCU" "command"="1" "inimapping"="0" Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\F:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk] "path"="F:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Adobe Reader Speed Launch.lnk" "backup"="F:\\WINDOWS\\pss\\Adobe Reader Speed Launch.lnkCommon Startup" "location"="Common Startup" "command"="F:\\PROGRA~1\\Adobe\\ACROBA~2.0\\Reader\\READER~1.EXE " "item"="Adobe Reader Speed Launch" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\F:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk] "path"="F:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Kodak EasyShare software.lnk" "backup"="F:\\WINDOWS\\pss\\Kodak EasyShare software.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\Kodak\\KODAKE~1\\bin\\EASYSH~1.EXE -h" "item"="Kodak EasyShare software" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\F:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk] "path"="F:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Microsoft Office.lnk" "backup"="F:\\WINDOWS\\pss\\Microsoft Office.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\MICROS~1\\Office10\\OSA.EXE -b -l" "item"="Microsoft Office" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\F:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Works Calendar Reminders.lnk] "path"="F:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Microsoft Works Calendar Reminders.lnk" "backup"="F:\\WINDOWS\\pss\\Microsoft Works Calendar Reminders.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\COMMON~1\\MICROS~1\\WORKSS~1\\wkcalrem.exe " "item"="Microsoft Works Calendar Reminders" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\F:^Documents and Settings^All Users^Start Menu^Programs^Startup^SBC Self Support Tool.lnk] "path"="F:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\SBC Self Support Tool.lnk" "backup"="F:\\WINDOWS\\pss\\SBC Self Support Tool.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\SBCSEL~1\\bin\\matcli.exe -boot" "item"="SBC Self Support Tool" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\F:^Documents and Settings^Eddie^Start Menu^Programs^Startup^Connection Manager.lnk] "path"="F:\\Documents and Settings\\Eddie\\Start Menu\\Programs\\Startup\\Connection Manager.lnk" "backup"="F:\\WINDOWS\\pss\\Connection Manager.lnkStartup" "location"="Startup" "command"="F:\\PROGRA~1\\SBC\\CONNEC~1\\CManager.exe " "item"="Connection Manager" KASPERSKY ONLINE SCANNER REPORT Wednesday, August 23, 2006 9:42:38 AM Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.83.0 Kaspersky Anti-Virus database last update: 23/08/2006 Kaspersky Anti-Virus database records: 204568 Scan Settings Scan using the following antivirus database standard Scan Archives true Scan Mail Bases true Scan Target My Computer A:\ C:\ D:\ E:\ F:\ Scan Statistics Total number of scanned objects 226320 Number of viruses found 9 Number of infected objects 51 / 0 Number of suspicious objects 6 Duration of the scan process 06:58:19 Infected Object Name Virus Name Last Action C:\WINDOWS\WindowsUpdate.log Object is locked skipped C:\Program Files\memo option nurb\CityWma.exe Infected: Trojan-Downloader.Win32.Swizzor.fg skipped C:\Program Files\Open ford\mtrxxaek.exe Infected: Trojan-Downloader.Win32.Swizzor.bw skipped C:\Program Files\Open ford\Vc axis shim.exe Infected: Trojan-Downloader.Win32.Swizzor.fg skipped C:\Documents and Settings\All Users\Application Data\funk mail plus anti\MEMO LOAD.exe Infected: Trojan.Win32.Krepper.ab skipped C:\Documents and Settings\Eddie\Local Settings\Temp\Rem4D6.exe Infected: Trojan-Downloader.Win32.Swizzor.br skipped C:\Documents and Settings\Eddie\Local Settings\Temp\sta1FCC.exe Infected: Trojan-Downloader.Win32.Swizzor.br skipped C:\Documents and Settings\Eddie\Local Settings\Temp\6ec1325a.exe Infected: Trojan-Downloader.Win32.Swizzor.bn skipped C:\Documents and Settings\Eddie\Local Settings\Temp\sta2242.exe Infected: Trojan-Downloader.Win32.Swizzor.br skipped C:\Documents and Settings\Eddie\Local Settings\Temp\Rem38CB.exe Infected: Trojan-Downloader.Win32.Swizzor.br skipped C:\Documents and Settings\Eddie\Local Settings\Temp\6c1077a4.exe Infected: Trojan-Downloader.Win32.Swizzor.bn skipped C:\Documents and Settings\Eddie\Local Settings\Temp\66f9e81b.exe Infected: Trojan-Downloader.Win32.Swizzor.bn skipped C:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP529\A0023419.exe Infected: Trojan.Win32.Krepper.ab skipped C:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP542\change.log Object is locked skipped F:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped F:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped F:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped F:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped F:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SecondThoughtSTCLoader2.zip/stcloader.exe Suspicious: Password-protected-EXE skipped F:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SecondThoughtSTCLoader2.zip ZIP: suspicious - 1 skipped F:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\TIBS2.zip/125439.exe Suspicious: Password-protected-EXE skipped F:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\TIBS2.zip ZIP: suspicious - 1 skipped F:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\TIBS6.zip/125439.exe Suspicious: Password-protected-EXE skipped F:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\TIBS6.zip ZIP: suspicious - 1 skipped F:\Documents and Settings\Eddie\.housecall\Quarantine\migksftl.exe.bac_a02848 Infected: Trojan.Win32.Krepper.ab skipped F:\Documents and Settings\Eddie\Application Data\AVG7\Log\emc.log Object is locked skipped F:\Documents and Settings\Eddie\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped F:\Documents and Settings\Eddie\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped F:\Documents and Settings\Eddie\Application Data\Sun\Java\Deployment\log\plugin150_08.trace Object is locked skipped F:\Documents and Settings\Eddie\Cookies\index.dat Object is locked skipped F:\Documents and Settings\Eddie\Local Settings\History\History.IE5\index.dat Object is locked skipped F:\Documents and Settings\Eddie\Local Settings\Temp\AcrF6C.tmp Object is locked skipped F:\Documents and Settings\Eddie\Local Settings\Temp\Cookies\index.dat Object is locked skipped F:\Documents and Settings\Eddie\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped F:\Documents and Settings\Eddie\Local Settings\Temp\History\History.IE5\MSHist012006082220060823\index.dat Object is locked skipped F:\Documents and Settings\Eddie\Local Settings\Temp\hpotdd009.log Object is locked skipped F:\Documents and Settings\Eddie\Local Settings\Temp\hsperfdata_Eddie\3080 Object is locked skipped F:\Documents and Settings\Eddie\Local Settings\Temp\msn3080.fdr Object is locked skipped F:\Documents and Settings\Eddie\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped F:\Documents and Settings\Eddie\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped F:\Documents and Settings\Eddie\ntuser.dat Object is locked skipped F:\Documents and Settings\Eddie\ntuser.dat.LOG Object is locked skipped F:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped F:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped F:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped F:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped F:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped F:\Documents and Settings\LocalService\ntuser.dat Object is locked skipped F:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped F:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped F:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped F:\Documents and Settings\NetworkService\ntuser.dat Object is locked skipped F:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped F:\Program Files\MSN\MSNCoreFiles\market.mar Object is locked skipped F:\Program Files\MSN\MSNCoreFiles\market32.mar Object is locked skipped F:\Program Files\MSN\MSNCoreFiles\themedef32.mar Object is locked skipped F:\Program Files\MSN\MSNCoreFiles\ui.mar Object is locked skipped F:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP528\A0021973.exe Infected: Trojan.Win32.Small.fb skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP528\A0021974.exe Infected: Trojan.Win32.DNSChanger.ef skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP529\A0023516.exe Infected: Trojan.Win32.Small.fb skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP529\A0023517.exe Infected: Trojan.Win32.DNSChanger.ef skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP529\A0023582.exe Infected: Trojan.Win32.Small.fb skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP529\A0023583.exe Infected: Trojan.Win32.DNSChanger.ef skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP533\A0023908.exe Infected: Trojan.Win32.Small.fb skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP533\A0023909.exe Infected: Trojan.Win32.DNSChanger.ef skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024429.exe Infected: Trojan.Win32.Small.fb skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024430.exe Infected: Trojan.Win32.DNSChanger.ef skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024443.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024444.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024446.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024447.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024448.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024449.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024451.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024452.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024455.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024458.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024459.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024460.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024461.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024462.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024464.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024465.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024466.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP535\A0024477.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP535\A0024478.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP535\A0024481.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP535\A0024482.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP535\A0024483.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP535\A0024484.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024501.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024504.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024505.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024508.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024509.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024510.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024512.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024514.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024515.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024517.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024519.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024520.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024522.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024523.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024524.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024525.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024526.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024528.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024529.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024531.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024533.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024536.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024537.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024538.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024539.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024540.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024541.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024542.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024543.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024544.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024546.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024547.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024548.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024573.exe Infected: Trojan.Win32.Small.fb skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024593.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024595.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024596.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024598.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024600.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024601.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024603.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024606.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024607.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024626.exe Infected: Trojan.Win32.Small.fb skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024628.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024629.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024630.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024631.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024632.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024633.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024634.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024635.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024636.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024637.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024638.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024639.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024640.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024641.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024642.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024643.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024644.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024645.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024646.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024647.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024648.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024649.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024650.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024651.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024652.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024653.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024654.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024655.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024656.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024657.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024658.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024659.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024660.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024661.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024662.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024663.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024664.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024665.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024666.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024667.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024668.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024669.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024670.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024671.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024672.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024673.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024674.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024675.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024676.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024677.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024678.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024679.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024680.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024681.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024682.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024683.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024684.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024685.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024686.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024687.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024688.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024689.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024690.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024691.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024692.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024693.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024694.exe Object is locked skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024755.exe Infected: Trojan.Win32.DNSChanger.ef skipped F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP542\change.log Object is locked skipped F:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped F:\WINDOWS\fffd0eff_{4FB9B3DC-E454-40F8-A6AC-7D85218BF41D}.tmp:ropaup:$DATA/data0001.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped F:\WINDOWS\fffd0eff_{4FB9B3DC-E454-40F8-A6AC-7D85218BF41D}.tmp:ropaup:$DATA/data0002.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped F:\WINDOWS\fffd0eff_{4FB9B3DC-E454-40F8-A6AC-7D85218BF41D}.tmp:ropaup:$DATA/data0003.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped F:\WINDOWS\fffd0eff_{4FB9B3DC-E454-40F8-A6AC-7D85218BF41D}.tmp:ropaup:$DATA/data0004.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped F:\WINDOWS\fffd0eff_{4FB9B3DC-E454-40F8-A6AC-7D85218BF41D}.tmp:ropaup:$DATA/data0005.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped F:\WINDOWS\fffd0eff_{4FB9B3DC-E454-40F8-A6AC-7D85218BF41D}.tmp:ropaup:$DATA Embedded HTML: infected - 5 skipped F:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped F:\WINDOWS\KB823559.log:qmtix:$DATA/data0001.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped F:\WINDOWS\KB823559.log:qmtix:$DATA/data0002.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped F:\WINDOWS\KB823559.log:qmtix:$DATA/data0003.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped F:\WINDOWS\KB823559.log:qmtix:$DATA/data0004.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped F:\WINDOWS\KB823559.log:qmtix:$DATA/data0005.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped F:\WINDOWS\KB823559.log:qmtix:$DATA Embedded HTML: infected - 5 skipped F:\WINDOWS\SchedLgU.Txt Object is locked skipped F:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped F:\WINDOWS\Sti_Trace.log Object is locked skipped F:\WINDOWS\SYSTEM32\CatRoot2\edb.log Object is locked skipped F:\WINDOWS\SYSTEM32\CatRoot2\tmp.edb Object is locked skipped F:\WINDOWS\SYSTEM32\config\AppEvent.Evt Object is locked skipped F:\WINDOWS\SYSTEM32\config\DEFAULT Object is locked skipped F:\WINDOWS\SYSTEM32\config\default.LOG Object is locked skipped F:\WINDOWS\SYSTEM32\config\SAM Object is locked skipped F:\WINDOWS\SYSTEM32\config\SAM.LOG Object is locked skipped F:\WINDOWS\SYSTEM32\config\SecEvent.Evt Object is locked skipped F:\WINDOWS\SYSTEM32\config\SECURITY Object is locked skipped F:\WINDOWS\SYSTEM32\config\SECURITY.LOG Object is locked skipped F:\WINDOWS\SYSTEM32\config\SOFTWARE Object is locked skipped F:\WINDOWS\SYSTEM32\config\software.LOG Object is locked skipped F:\WINDOWS\SYSTEM32\config\SysEvent.Evt Object is locked skipped F:\WINDOWS\SYSTEM32\config\SYSTEM Object is locked skipped F:\WINDOWS\SYSTEM32\config\system.LOG Object is locked skipped F:\WINDOWS\SYSTEM32\dmloq.exe Infected: Trojan.Win32.Small.fb skipped F:\WINDOWS\SYSTEM32\h323log.txt Object is locked skipped F:\WINDOWS\SYSTEM32\wbem\Repository\FS\INDEX.BTR Object is locked skipped F:\WINDOWS\SYSTEM32\wbem\Repository\FS\INDEX.MAP Object is locked skipped F:\WINDOWS\SYSTEM32\wbem\Repository\FS\MAPPING.VER Object is locked skipped F:\WINDOWS\SYSTEM32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped F:\WINDOWS\SYSTEM32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped F:\WINDOWS\SYSTEM32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped F:\WINDOWS\SYSTEM32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped F:\WINDOWS\VideoSetup.exe:ucxkt:$DATA/data0001.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped F:\WINDOWS\VideoSetup.exe:ucxkt:$DATA/data0002.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped F:\WINDOWS\VideoSetup.exe:ucxkt:$DATA/data0003.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped F:\WINDOWS\VideoSetup.exe:ucxkt:$DATA/data0004.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped F:\WINDOWS\VideoSetup.exe:ucxkt:$DATA/data0005.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped F:\WINDOWS\VideoSetup.exe:ucxkt:$DATA Embedded HTML: infected - 5 skipped F:\WINDOWS\wiadebug.log Object is locked skipped F:\WINDOWS\wiaservc.log Object is locked skipped F:\WINDOWS\wininit.tmp:qssrku:$DATA/data0001.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped F:\WINDOWS\wininit.tmp:qssrku:$DATA/data0002.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped F:\WINDOWS\wininit.tmp:qssrku:$DATA/data0003.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped F:\WINDOWS\wininit.tmp:qssrku:$DATA/data0004.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped F:\WINDOWS\wininit.tmp:qssrku:$DATA/data0005.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped F:\WINDOWS\wininit.tmp:qssrku:$DATA Embedded HTML: infected - 5 skipped Scan process completed. 08/23/06 09:44:17 [Info]: BlackLight Engine 1.0.46 initialized 08/23/06 09:44:17 [Info]: OS: 5.1 build 2600 (Service Pack 2) 08/23/06 09:44:18 [Note]: 7019 4 08/23/06 09:44:18 [Note]: 7005 0 08/23/06 09:44:37 [Note]: 7006 0 08/23/06 09:44:37 [Note]: 7011 1132 08/23/06 09:44:37 [Note]: 7026 0 08/23/06 09:44:37 [Note]: 7026 0 08/23/06 09:44:56 [Note]: FSRAW library version 1.7.1019 08/23/06 09:45:34 [Info]: Hidden file: f:\WINDOWS\VideoSetup.exe:ucxkt 08/23/06 09:45:37 [Info]: Hidden file: f:\WINDOWS\fffd0eff_{4FB9B3DC-E454-40F8-A6AC-7D85218BF41D}.tmp:ropaup 08/23/06 09:45:53 [Info]: Hidden file: f:\WINDOWS\wininit.tmp:qssrku 08/23/06 09:45:57 [Info]: Hidden file: f:\WINDOWS\KB823559.log:qmtix 08/23/06 09:52:00 [Note]: 7007 0 Thanks again. That Kaspersky scan took forever…that's why I'm so long getting back to you. Hope this tells you more and I appreciate your efforts!
STEP 1.
======
Delete Files with Killbox

Download Pocket Killbox from http://www.downloads.subratam.org/KillBox.zip and unzip it; save it to your Desktop. DO NOT RUN IT YET.
==========
Double-click on KillBox.exe to launch the program. It is the red circle with a large white X in it
- Highlight the files in bold RED below and press the Ctrl key and the C key at the same time to copy them to the clipboard
C:\Program Files\memo option nurb\CityWma.exe
C:\Program Files\Open ford\mtrxxaek.exe
C:\Program Files\Open ford\Vc axis shim.exe
C:\Documents and Settings\All Users\Application Data\funk mail plus anti\MEMO LOAD.exe
C:\Documents and Settings\Eddie\Local Settings\Temp\Rem4D6.exe
C:\Documents and Settings\Eddie\Local Settings\Temp\sta1FCC.exe
C:\Documents and Settings\Eddie\Local Settings\Temp\6ec1325a.exe
C:\Documents and Settings\Eddie\Local Settings\Temp\sta2242.exe
C:\Documents and Settings\Eddie\Local Settings\Temp\Rem38CB.exe
C:\Documents and Settings\Eddie\Local Settings\Temp\6c1077a4.exe
C:\Documents and Settings\Eddie\Local Settings\Temp\66f9e81b.exe
F:\WINDOWS\fffd0eff_{4FB9B3DC-E454-40F8-A6AC-7D85218BF41D}.tmp:ropaup:$DATA
F:\WINDOWS\KB823559.log:qmtix:$DATA
F:\WINDOWS\VideoSetup.exe:ucxkt:$DATA
F:\WINDOWS\wininit.tmp:qssrku:$DATA


In Killbox click on the File menu and then the Paste from Clipboard item
in the Full Path of File to Delete field drop down the arrow and make sure that all of the files are listed
(Please note that the tool checks your computer for the presence of the files pasted into the box so if files are not present, it is possible that you might not see all files you pasted into the box.)
Click the option to Delete on Reboot
- If not greyed out click the checkbox for Unregister .dll Before Deleting
- click End Explorer Shell while Killing File
- Now click on the red button with a white 'X' in the middle to delete the files
- Click Yes when it says all files will be deleted on the next reboot
- Click Yes when it asks if you want to reboot now
(Note: If you get a "PendingFileRenameOperations Registry Data has been Removed by External Process!" message then just reboot manually)

Note: Killbox will let you know if a file does not exist. If that happens, just continue on.

If you have any issues with this method you can copy and paste the lines one at a time into the killbox top box. Then click the "Single File" button. Then click the Red X …and for the confirmation message that will appear, you will need to click Yes. A second message will ask to Reboot now? you will need to click No until the last one at which time you click yes to allow the reboot.
_________________


Please download ATF Cleaner by Atribune.

This program is for XP and Windows 2000 only
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
If you use Firefox browser
  • Click Firefox at the top and choose:Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click
  • No at the prompt.
If you use Opera browser
  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE:If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

Scan with HijackThis. Place a check against each of the following (if it still exists):
O16 - DPF: {F72BC3F0-6C20-4793-9DDA-258589D8A907} - http://akamai.downloadv3.com/binaries/IA/netslv32_EN_XP.cab
Close all windows or browsers except for Hijackthis. Click on Fix Checked.
ok…
that was relatively painless…
it seems to be running smoothly and no virus warnings popping up
was there anything else i should do? idk if you need another HJT log, but here is the most recent

Logfile of HijackThis v1.99.1
Scan saved at 12:42:40 PM, on 8/23/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\LEXBCES.EXE
F:\WINDOWS\system32\spoolsv.exe
F:\WINDOWS\Explorer.EXE
F:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
F:\Program Files\iTunes\iTunesHelper.exe
C:\program files\support.com\bin\tgcmd.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
C:\Program Files\Lexmark X5100 Series\lxbabmon.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
F:\WINDOWS\System32\tbctray.exe
C:\PROGRA~1\AWS\WEATHE~1\WEATHER.EXE
F:\WINDOWS\system32\drivers\KodakCCS.exe
F:\Program Files\Free History Eraser\HistoryEraser.exe
F:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
F:\WINDOWS\system32\wscntfy.exe
F:\Program Files\MSN\MSNCoreFiles\msn6.exe
C:\PROGRA~1\MSNMES~1\msnmsgr.exe
F:\Documents and Settings\Eddie\Desktop\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.findin.org/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://yahoo.sbc.com/dsl
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\en-us\msntb.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O4 - HKLM\..\Run: [tgcmd] "F:\Program Files\support.com\bin\tgcmd.exe" /server
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [iTunesHelper] "F:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MSConfig] F:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [tgcmdprovidersbc] "c:\program files\support.com\bin\tgcmd.exe" /server /startmonitor /deaf /nosystray
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Lexmark X5100 Series] "C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [TraySantaCruz] F:\WINDOWS\System32\tbctray.exe
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\WEATHER.EXE 1
O4 - HKCU\..\Run: [SPSTEALT] "F:\Program Files\Free History Eraser\HistoryEraser.exe" /stealt
O8 - Extra context menu item: &Define - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Look Up in &Encyclopedia - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\npjpi150_08.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\npjpi150_08.dll
O9 - Extra button: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra 'Tools' menuitem: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll (file missing)
O9 - Extra button: Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - http://www.net2phone.com/ (file missing)
O9 - Extra 'Tools' menuitem: Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - http://www.net2phone.com/ (file missing)
O9 - Extra button: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra 'Tools' menuitem: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Dell Home - {08DCFC6C-B6E4-480C-95A4-FC64F37B787E} - http://www.dellnet.com (file missing) (HKCU)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O12 - Plugin for .bcf: C:\Program Files\Internet Explorer\Plugins\NPBelv32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall-beta.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200312…meInstaller.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - F:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - F:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - F:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: STOPzilla Local Service - Unknown owner - C:\Program Files\STOPzilla!\szntsvc.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
Please run Kapersky again and post the results. Let's see how we did. Also don't be alarmed about the infected _restore files. We will take care of those later.


STEP 1.
======
Backup Your Registry with ERUNT
  • Please use the following link and scroll down to ERUNT and download it.
    http://aumha.org/freeware/freeware.php
  • For version with the Installer:
    Use the setup program to install ERUNT on your computer
  • For the zipped version:
    Unzip all the files into a folder of your choice.
Click Erunt.exe to backup your registry to the folder of your choice.

Note: to restore your registry, go to the folder and start ERDNT.exe

Then, go to start–>run

and type this in:
notepad

Paste this into the box:

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Run]
"item"=-
"command"=-

Then click on the FILE menu and select save as
Save the file as regfix.reg. Save the file to the desktop.
IMPORTANT: make sure to save the file as "all types" and NOT as a text file
**

Now double click on regfix.reg and insert it into the registry.

Step 2
Please go to Start>Run>type 'msconfig' (no quotes) and select the "Startup tab" and Enable all and run Hijackthis. Then post a new HijackThis log.
4.5 hours into Kaspersky scan and it's 80% complete. Should I wait until it's done before I do the registry fix and msconfig changes, or just do that now while I'm waiting?
while we're waiting, may i ask you a few questions? firstly, right now i'm only using the windows firewall (which i'm sure is not adequate protection) and i was wondering what you would recommend…i've had zone labs' zoneAlarm in the past and had issues with it when i was doing battle with a friend of mine in tampa via peer-to-peer, so i ditched it. i've heard good things about peer guardian, what do you think? secondly, up until a few weeks ago, i was pleased (perhaps comfortably wrapped in ignorance) with AVG anti-virus…again, any suggestions?
96 % complete and all of sudden AVG resident shield is going BANANAS! F:\System Volume Information\_restore{BA…long hex number}…\…\24593.exe It has popped up with at least 30 warnings just while trying to post this…
ok. did the kaspersky scan, downloaded and ran ERUNT, did the regfix thing, enabled all the choices on the startup tab in the msconfig window, and ran a HJT…here's the log

Logfile of HijackThis v1.99.1
Scan saved at 11:06:17 PM, on 8/23/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\LEXBCES.EXE
F:\WINDOWS\system32\spoolsv.exe
F:\WINDOWS\Explorer.EXE
F:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
F:\Program Files\iTunes\iTunesHelper.exe
C:\program files\support.com\bin\tgcmd.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
C:\Program Files\Lexmark X5100 Series\lxbabmon.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
F:\WINDOWS\System32\tbctray.exe
C:\PROGRA~1\AWS\WEATHE~1\WEATHER.EXE
F:\WINDOWS\system32\drivers\KodakCCS.exe
F:\Program Files\Free History Eraser\HistoryEraser.exe
F:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
F:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\MSNMES~1\msnmsgr.exe
F:\Program Files\MSN\MSNCoreFiles\msn6.exe
F:\Documents and Settings\Eddie\Desktop\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.findin.org/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://yahoo.sbc.com/dsl
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\en-us\msntb.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O4 - HKLM\..\Run: [tgcmd] "F:\Program Files\support.com\bin\tgcmd.exe" /server
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [iTunesHelper] "F:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MSConfig] F:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [tgcmdprovidersbc] "c:\program files\support.com\bin\tgcmd.exe" /server /startmonitor /deaf /nosystray
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Lexmark X5100 Series] "C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [TraySantaCruz] F:\WINDOWS\System32\tbctray.exe
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\WEATHER.EXE 1
O4 - HKCU\..\Run: [SPSTEALT] "F:\Program Files\Free History Eraser\HistoryEraser.exe" /stealt
O4 - HKCU\..\Run: [Yahoo! Pager] 1
O4 - Startup: Connection Manager.lnk = F:\Program Files\SBC\Connection Manager\CManager.exe
O4 - Startup: ERUNT AutoBackup.lnk = F:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = F:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O8 - Extra context menu item: &Define - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Look Up in &Encyclopedia - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\npjpi150_08.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\npjpi150_08.dll
O9 - Extra button: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra 'Tools' menuitem: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll (file missing)
O9 - Extra button: Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - http://www.net2phone.com/ (file missing)
O9 - Extra 'Tools' menuitem: Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - http://www.net2phone.com/ (file missing)
O9 - Extra button: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra 'Tools' menuitem: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Dell Home - {08DCFC6C-B6E4-480C-95A4-FC64F37B787E} - http://www.dellnet.com (file missing) (HKCU)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O12 - Plugin for .bcf: C:\Program Files\Internet Explorer\Plugins\NPBelv32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall-beta.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200312…meInstaller.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - F:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - F:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - F:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: STOPzilla Local Service - Unknown owner - C:\Program Files\STOPzilla!\szntsvc.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe



here's the kaspersky scan report
KASPERSKY ONLINE SCANNER REPORT
Wednesday, August 23, 2006 11:11:06 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 23/08/2006
Kaspersky Anti-Virus database records: 204940


Scan Settings
Scan using the following antivirus database standard
Scan Archives true
Scan Mail Bases true

Scan Target My Computer
A:\
C:\
D:\
E:\
F:\

Scan Statistics
Total number of scanned objects 211489
Number of viruses found 9
Number of infected objects 62 / 0
Number of suspicious objects 6
Duration of the scan process 06:37:42

Infected Object Name Virus Name Last Action
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

C:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP529\A0023419.exe Infected: Trojan.Win32.Krepper.ab skipped

C:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP542\A0025311.exe Infected: Trojan-Downloader.Win32.Swizzor.fg skipped

C:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP542\A0025322.exe Infected: Trojan-Downloader.Win32.Swizzor.bw skipped

C:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP542\A0025323.exe Infected: Trojan-Downloader.Win32.Swizzor.fg skipped

C:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP542\A0025324.exe Infected: Trojan.Win32.Krepper.ab skipped

C:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP542\A0025325.exe Infected: Trojan-Downloader.Win32.Swizzor.br skipped

C:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP542\A0025326.exe Infected: Trojan-Downloader.Win32.Swizzor.br skipped

C:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP542\A0025327.exe Infected: Trojan-Downloader.Win32.Swizzor.bn skipped

C:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP542\A0025328.exe Infected: Trojan-Downloader.Win32.Swizzor.br skipped

C:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP542\A0025329.exe Infected: Trojan-Downloader.Win32.Swizzor.br skipped

C:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP542\A0025330.exe Infected: Trojan-Downloader.Win32.Swizzor.bn skipped

C:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP542\A0025331.exe Infected: Trojan-Downloader.Win32.Swizzor.bn skipped

F:\!KillBox\66f9e81b.exe Infected: Trojan-Downloader.Win32.Swizzor.bn skipped

F:\!KillBox\6c1077a4.exe Infected: Trojan-Downloader.Win32.Swizzor.bn skipped

F:\!KillBox\6ec1325a.exe Infected: Trojan-Downloader.Win32.Swizzor.bn skipped

F:\!KillBox\CityWma.exe Infected: Trojan-Downloader.Win32.Swizzor.fg skipped

F:\!KillBox\MEMO LOAD.exe Infected: Trojan.Win32.Krepper.ab skipped

F:\!KillBox\mtrxxaek.exe Infected: Trojan-Downloader.Win32.Swizzor.bw skipped

F:\!KillBox\Rem38CB.exe Infected: Trojan-Downloader.Win32.Swizzor.br skipped

F:\!KillBox\Rem4D6.exe Infected: Trojan-Downloader.Win32.Swizzor.br skipped

F:\!KillBox\sta1FCC.exe Infected: Trojan-Downloader.Win32.Swizzor.br skipped

F:\!KillBox\sta2242.exe Infected: Trojan-Downloader.Win32.Swizzor.br skipped

F:\!KillBox\Vc axis shim.exe Infected: Trojan-Downloader.Win32.Swizzor.fg skipped

F:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped

F:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped

F:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped

F:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped

F:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SecondThoughtSTCLoader2.zip/stcloader.exe Suspicious: Password-protected-EXE skipped

F:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SecondThoughtSTCLoader2.zip ZIP: suspicious - 1 skipped

F:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\TIBS2.zip/125439.exe Suspicious: Password-protected-EXE skipped

F:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\TIBS2.zip ZIP: suspicious - 1 skipped

F:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\TIBS6.zip/125439.exe Suspicious: Password-protected-EXE skipped

F:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\TIBS6.zip ZIP: suspicious - 1 skipped

F:\Documents and Settings\Eddie\.housecall\Quarantine\migksftl.exe.bac_a02848 Infected: Trojan.Win32.Krepper.ab skipped

F:\Documents and Settings\Eddie\Application Data\AVG7\Log\emc.log Object is locked skipped

F:\Documents and Settings\Eddie\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

F:\Documents and Settings\Eddie\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

F:\Documents and Settings\Eddie\Cookies\index.dat Object is locked skipped

F:\Documents and Settings\Eddie\Local Settings\History\History.IE5\index.dat Object is locked skipped

F:\Documents and Settings\Eddie\Local Settings\Temp\Cookies\index.dat Object is locked skipped

F:\Documents and Settings\Eddie\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped

F:\Documents and Settings\Eddie\Local Settings\Temp\hpotdd011.log Object is locked skipped

F:\Documents and Settings\Eddie\Local Settings\Temp\msn1276.fdr Object is locked skipped

F:\Documents and Settings\Eddie\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

F:\Documents and Settings\Eddie\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

F:\Documents and Settings\Eddie\ntuser.dat Object is locked skipped

F:\Documents and Settings\Eddie\ntuser.dat.LOG Object is locked skipped

F:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

F:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

F:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped

F:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped

F:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

F:\Documents and Settings\LocalService\ntuser.dat Object is locked skipped

F:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

F:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

F:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

F:\Documents and Settings\NetworkService\ntuser.dat Object is locked skipped

F:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

F:\Program Files\MSN\MSNCoreFiles\mail.mar Object is locked skipped

F:\Program Files\MSN\MSNCoreFiles\market.mar Object is locked skipped

F:\Program Files\MSN\MSNCoreFiles\market32.mar Object is locked skipped

F:\Program Files\MSN\MSNCoreFiles\themedef32.mar Object is locked skipped

F:\Program Files\MSN\MSNCoreFiles\ui.mar Object is locked skipped

F:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP528\A0021973.exe Infected: Trojan.Win32.Small.fb skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP528\A0021974.exe Infected: Trojan.Win32.DNSChanger.ef skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP529\A0023516.exe Infected: Trojan.Win32.Small.fb skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP529\A0023517.exe Infected: Trojan.Win32.DNSChanger.ef skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP529\A0023582.exe Infected: Trojan.Win32.Small.fb skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP529\A0023583.exe Infected: Trojan.Win32.DNSChanger.ef skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP533\A0023908.exe Infected: Trojan.Win32.Small.fb skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP533\A0023909.exe Infected: Trojan.Win32.DNSChanger.ef skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024429.exe Infected: Trojan.Win32.Small.fb skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024430.exe Infected: Trojan.Win32.DNSChanger.ef skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024443.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024444.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024446.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024447.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024448.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024449.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024451.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024452.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024455.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024458.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024459.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024460.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024461.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024462.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024464.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024465.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024466.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP535\A0024477.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP535\A0024478.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP535\A0024481.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP535\A0024482.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP535\A0024483.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP535\A0024484.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024501.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024504.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024505.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024508.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024509.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024510.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024512.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024514.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024515.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024517.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024519.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024520.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024522.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024523.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024524.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024525.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024526.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024528.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024529.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024531.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024533.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024536.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024537.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024538.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024539.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024540.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024541.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024542.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024543.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024544.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024546.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024547.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP536\A0024548.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024573.exe Infected: Trojan.Win32.Small.fb skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024593.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024595.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024596.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024598.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024600.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024601.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024603.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024606.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024607.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024626.exe Infected: Trojan.Win32.Small.fb skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024628.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024629.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024630.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024631.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024632.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024633.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024634.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024635.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024636.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024637.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024638.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024639.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024640.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024641.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024642.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024643.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024644.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024645.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024646.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024647.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024648.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024649.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024650.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024651.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024652.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024653.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024654.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024655.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024656.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024657.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024658.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024659.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024660.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024661.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024662.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024663.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024664.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024665.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024666.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024667.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024668.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024669.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024670.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024671.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024672.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024673.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024674.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024675.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024676.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024677.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024678.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024679.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024680.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024681.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024682.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024683.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024684.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024685.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024686.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024687.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024688.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024689.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024690.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024691.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024692.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024693.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024694.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024755.exe Infected: Trojan.Win32.DNSChanger.ef skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP543\change.log Object is locked skipped

F:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

F:\WINDOWS\fffd0eff_{4FB9B3DC-E454-40F8-A6AC-7D85218BF41D}.tmp:ropaup:$DATA/data0001.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped

F:\WINDOWS\fffd0eff_{4FB9B3DC-E454-40F8-A6AC-7D85218BF41D}.tmp:ropaup:$DATA/data0002.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped

F:\WINDOWS\fffd0eff_{4FB9B3DC-E454-40F8-A6AC-7D85218BF41D}.tmp:ropaup:$DATA/data0003.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped

F:\WINDOWS\fffd0eff_{4FB9B3DC-E454-40F8-A6AC-7D85218BF41D}.tmp:ropaup:$DATA/data0004.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped

F:\WINDOWS\fffd0eff_{4FB9B3DC-E454-40F8-A6AC-7D85218BF41D}.tmp:ropaup:$DATA/data0005.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped

F:\WINDOWS\fffd0eff_{4FB9B3DC-E454-40F8-A6AC-7D85218BF41D}.tmp:ropaup:$DATA Embedded HTML: infected - 5 skipped

F:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped

F:\WINDOWS\KB823559.log:qmtix:$DATA/data0001.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped

F:\WINDOWS\KB823559.log:qmtix:$DATA/data0002.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped

F:\WINDOWS\KB823559.log:qmtix:$DATA/data0003.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped

F:\WINDOWS\KB823559.log:qmtix:$DATA/data0004.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped

F:\WINDOWS\KB823559.log:qmtix:$DATA/data0005.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped

F:\WINDOWS\KB823559.log:qmtix:$DATA Embedded HTML: infected - 5 skipped

F:\WINDOWS\SchedLgU.Txt Object is locked skipped

F:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped

F:\WINDOWS\Sti_Trace.log Object is locked skipped

F:\WINDOWS\SYSTEM32\config\AppEvent.Evt Object is locked skipped

F:\WINDOWS\SYSTEM32\config\DEFAULT Object is locked skipped

F:\WINDOWS\SYSTEM32\config\default.LOG Object is locked skipped

F:\WINDOWS\SYSTEM32\config\SAM Object is locked skipped

F:\WINDOWS\SYSTEM32\config\SAM.LOG Object is locked skipped

F:\WINDOWS\SYSTEM32\config\SecEvent.Evt Object is locked skipped

F:\WINDOWS\SYSTEM32\config\SECURITY Object is locked skipped

F:\WINDOWS\SYSTEM32\config\SECURITY.LOG Object is locked skipped

F:\WINDOWS\SYSTEM32\config\SOFTWARE Object is locked skipped

F:\WINDOWS\SYSTEM32\config\software.LOG Object is locked skipped

F:\WINDOWS\SYSTEM32\config\SysEvent.Evt Object is locked skipped

F:\WINDOWS\SYSTEM32\config\SYSTEM Object is locked skipped

F:\WINDOWS\SYSTEM32\config\system.LOG Object is locked skipped

F:\WINDOWS\SYSTEM32\dmloq.exe Infected: Trojan.Win32.Small.fb skipped

F:\WINDOWS\SYSTEM32\h323log.txt Object is locked skipped

F:\WINDOWS\SYSTEM32\wbem\Repository\FS\INDEX.BTR Object is locked skipped

F:\WINDOWS\SYSTEM32\wbem\Repository\FS\INDEX.MAP Object is locked skipped

F:\WINDOWS\SYSTEM32\wbem\Repository\FS\MAPPING.VER Object is locked skipped

F:\WINDOWS\SYSTEM32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped

F:\WINDOWS\SYSTEM32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped

F:\WINDOWS\SYSTEM32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped

F:\WINDOWS\SYSTEM32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

F:\WINDOWS\VideoSetup.exe:ucxkt:$DATA/data0001.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped

F:\WINDOWS\VideoSetup.exe:ucxkt:$DATA/data0002.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped

F:\WINDOWS\VideoSetup.exe:ucxkt:$DATA/data0003.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped

F:\WINDOWS\VideoSetup.exe:ucxkt:$DATA/data0004.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped

F:\WINDOWS\VideoSetup.exe:ucxkt:$DATA/data0005.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped

F:\WINDOWS\VideoSetup.exe:ucxkt:$DATA Embedded HTML: infected - 5 skipped

F:\WINDOWS\wiadebug.log Object is locked skipped

F:\WINDOWS\wiaservc.log Object is locked skipped

F:\WINDOWS\wininit.tmp:qssrku:$DATA/data0001.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped

F:\WINDOWS\wininit.tmp:qssrku:$DATA/data0002.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped

F:\WINDOWS\wininit.tmp:qssrku:$DATA/data0003.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped

F:\WINDOWS\wininit.tmp:qssrku:$DATA/data0004.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped

F:\WINDOWS\wininit.tmp:qssrku:$DATA/data0005.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped

F:\WINDOWS\wininit.tmp:qssrku:$DATA Embedded HTML: infected - 5 skipped

Scan process completed.
Hi egates,

Thanks for your patience.

Navigate to the F:\!KillBox\ folder and delete all the files within !KillBox but not the folder itself.

Then empty your recycle bin.

We will not do anything about the infected _restore files yet. We do that step when the computer appears to be all clean. If something terrible would happen (which it rarely does) we can restore back with an infected restore point but with no restore points, we would be up a creek without a paddle!

======
Trojan Hunter
  • Download the free trial version of TrojanHunter
  • Install (allow registry entry to be changed if necessary – THGuard) and update. You will get an evaluation notice – choose “Continue Evaluation”.
  • You will see window titled “TrojanHunter – UNLICENSED EVALUATION COPY”
    Click icon “Full Scan” and let it scan- this may take awhile
  • If you have Trojans then a window titled “Clean Trojans” will open after the scan.
  • Be sure the entries are checked and click the “Clean” button.
  • Go to the window “TrojanHunter – UNLICENSED EVALUATION COPY”
    Go the “File” on the top menu =>Save Scan Report”.
Please copy and paste the Scan Report in your reply. Please let me know if all items were cleaned. I do not think the Scan Report will show me.
Yes, all the items were cleaned… Registry scan Registry key exists: HKEY_CLASSES_ROOT\Interface\{851F86C9-D3CC-4574-93F5-40E2D65159E4} (matches Adware.WildMedia.OverPro.100) (Regedit Jump) Inifile scan No suspicious entries found Port scan No suspicious open ports found Memory scan No trojans found in memory File scan Error: Directory not found: C:\Program Files\?ystem Found adware file: C:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP538\A0024810.exe (Adware.WebRebates.113) Found trojan file: F:\WINDOWS\SYSTEM32\dmloq.exe (Small.259) Error: Directory not found: F:\WINDOWS\SYSTEM32\s?curity 2 files identified

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI