Logfile of HijackThis v1.99.1
Scan saved at 10:59:43 PM, on 9/8/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\TPSrv.exe
C:\Program Files\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\pavsrv51.exe
C:\Program Files\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\AVENGINE.EXE
C:\WINDOWS\System32\svchost.exe
c:\program files\panda software\panda titanium 2006 antivirus + antispyware\firewall\PNMSRV.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\PavFnSvr.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
C:\Program Files\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\PsImSvc.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Documents and Settings\Cliff Smith\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://cnn.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com
R3 - URLSearchHook: (no name) - {EA584250-A9B2-4814-8767-D6BDC7D4AB31} - (no file)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%206%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Cliff Smith\Application Data\Mozilla\Profiles\default\rw44y7lt.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [ppfw] "C:\Program Files\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\Firewall\PPFW.exe" /cmd:allowpandarules /mod:3 /prod:titanium /dest:"C:\Program Files\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\Firewall" /flg:2 /ver:5.03.00
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AnimatedWallpaper] "C:\Program Files\3d Animated Wallpaper\AnimWallpaper.exe"
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.6\THGuard.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\RunOnce: [] "C:\Program Files\compaq\Compaq Advisor\bin\compaq-rba.exe" -z
O4 - HKCU\..\Run: [AxisBin] C:\DOCUME~1\CLIFFS~1\APPLIC~1\INTERN~1\Date bags tool.exe
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot
O4 - HKCU\..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [MySpaceIM] "C:\Program Files\MySpace\IM\MySpaceIM.exe"
O4 - Global Startup: 3d Animated Wallpaper.lnk = ?
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O8 - Extra context menu item: -
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=consumerfav&c=2c02&lc=0409
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab31267.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = +s
O17 - HKLM\Software\..\Telephony: DomainName = +s
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = +s
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: avldr - C:\WINDOWS\SYSTEM32\avldr.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WBSrv - C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Compaq Advisor (Compaq_RBA) - NeoPlanet - C:\Program Files\compaq\Compaq Advisor\bin\compaq-rba.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Panda Function Service (PAVFNSVR) - Panda Software International - C:\Program Files\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\PavFnSvr.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program Files\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\pavsrv51.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\System32\HPHipm11.exe
O23 - Service: Panda Network Manager (PNMSRV) - Panda Software - c:\program files\panda software\panda titanium 2006 antivirus + antispyware\firewall\PNMSRV.EXE
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software - C:\Program Files\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\PsImSvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SpyDetectorWatcher - Unknown owner - C:\Program Files\SpyDetector\spywatcher.exe (file missing)
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Panda TPSrv (TPSrv) - Panda Software - C:\Program Files\Panda Software\Panda Titanium 2006 Antivirus + Antispyware\TPSrv.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
Spy Sweeper -
7:53 PM: Removal process completed. Elapsed time 01:26:01
7:53 PM: Preparing to restart your computer. Please wait…
6:36 PM: Quarantining All Traces: gain - common components
6:36 PM: Quarantining All Traces: security toolbar
6:36 PM: Quarantining All Traces: dialerplatform
6:36 PM: Quarantining All Traces: startnow startnow hijack
6:36 PM: Quarantining All Traces: nocreditcard dialer
6:36 PM: Quarantining All Traces: spyware quake
6:36 PM: Quarantining All Traces: moneytree
6:36 PM: Quarantining All Traces: mojo toolbar
6:36 PM: Quarantining All Traces: startnow
6:36 PM: potentially rootkit-masked files is in use. It will be removed on reboot.
6:28 PM: Quarantining All Traces: potentially rootkit-masked files
6:28 PM: Quarantining All Traces: lopdotcom
6:28 PM: Quarantining All Traces: spyware quake fakealert
6:28 PM: Quarantining All Traces: directrevenue-abetterinternet
6:28 PM: Quarantining All Traces: trojan-downloader-zlob
6:28 PM: Quarantining All Traces: personal inspector
6:28 PM: Quarantining All Traces: trojan-downloader-rmass
6:28 PM: Quarantining All Traces: trojan agent winlogonhook
6:28 PM: Quarantining All Traces: metakodix stealth keylogger
6:28 PM: Quarantining All Traces: popuper
6:28 PM: Quarantining All Traces: security2k hijacker
6:27 PM: Removal process initiated
5:49 PM: Traces Found: 129
5:49 PM: Full Sweep has completed. Elapsed time 00:53:54
5:49 PM: File Sweep Complete, Elapsed Time: 00:51:00
5:46 PM: Warning: Stream read error
5:44 PM: Warning: Stream read error
5:44 PM: Warning: Stream read error
5:42 PM: Found System Monitor: potentially rootkit-masked files
5:42 PM: Warning: Failed to access drive I:
5:42 PM: Warning: Failed to access drive H:
5:42 PM: Warning: Failed to access drive G:
5:42 PM: Warning: Failed to access drive F:
5:42 PM: Warning: Failed to access drive E:
5:42 PM: Warning: Failed to access drive D:
5:42 PM: C:\WINDOWS\inf\Belt.inf (ID = 83154)
5:42 PM: C:\System Volume Information\_restore{cd45504f-d983-486e-9c46-f5c3e4adcbd7}\RP703\A0247060.bat (ID = 202688)
5:42 PM: Found Adware: security toolbar
5:42 PM: C:\System Volume Information\_restore{cd45504f-d983-486e-9c46-f5c3e4adcbd7}\RP711\A0249537.inf (ID = 83199)
5:39 PM: Warning: Failed to open file "c:\documents and settings\cliff smith\local settings\temporary internet files\content.ie5\2widfsll\;type=iframe;id=101683;size=468x80;rnd=521625;setid=17506[1].". The operation completed successfully
5:37 PM: C:\System Volume Information\_restore{cd45504f-d983-486e-9c46-f5c3e4adcbd7}\RP716\A0253358.exe (ID = 460)
5:37 PM: C:\System Volume Information\_restore{cd45504f-d983-486e-9c46-f5c3e4adcbd7}\RP716\A0253357.exe (ID = 465)
5:37 PM: C:\System Volume Information\_restore{cd45504f-d983-486e-9c46-f5c3e4adcbd7}\RP716\A0253356.exe (ID = 458)
5:37 PM: C:\System Volume Information\_restore{cd45504f-d983-486e-9c46-f5c3e4adcbd7}\RP716\A0253354.exe (ID = 465)
5:36 PM: C:\System Volume Information\_restore{cd45504f-d983-486e-9c46-f5c3e4adcbd7}\RP716\A0251794.exe (ID = 285163)
5:36 PM: C:\System Volume Information\_restore{cd45504f-d983-486e-9c46-f5c3e4adcbd7}\RP716\A0253447.exe (ID = 285164)
5:36 PM: C:\System Volume Information\_restore{cd45504f-d983-486e-9c46-f5c3e4adcbd7}\RP716\A0253355.exe (ID = 459)
5:36 PM: c:\windows\downloaded program files\conflict.14\gdnus2218.exe (ID = 322697)
5:36 PM: c:\windows\downloaded program files\conflict.5\gdnus2218.exe (ID = 322697)
5:36 PM: c:\windows\downloaded program files\conflict.2\gdnus2218.exe (ID = 322697)
5:36 PM: c:\windows\downloaded program files\conflict.6\gdnus2218.exe (ID = 322697)
5:36 PM: c:\windows\downloaded program files\conflict.7\gdnus2218.exe (ID = 322697)
5:36 PM: c:\windows\downloaded program files\conflict.1\gdnus2218.exe (ID = 322697)
5:36 PM: c:\windows\downloaded program files\conflict.9\gdnus2218.exe (ID = 322697)
5:36 PM: c:\windows\downloaded program files\conflict.10\gdnus2218.exe (ID = 322697)
5:36 PM: c:\windows\downloaded program files\conflict.4\gdnus2218.exe (ID = 322697)
5:36 PM: c:\windows\downloaded program files\conflict.12\gdnus2218.exe (ID = 322697)
5:36 PM: c:\windows\downloaded program files\conflict.13\gdnus2218.exe (ID = 322697)
5:36 PM: c:\windows\downloaded program files\conflict.3\gdnus2218.exe (ID = 322697)
5:36 PM: c:\windows\downloaded program files\conflict.11\gdnus2218.exe (ID = 322697)
5:36 PM: c:\windows\downloaded program files\conflict.8\gdnus2218.exe (ID = 322697)
5:35 PM: Found Adware: dialerplatform
5:29 PM: C:\System Volume Information\_restore{cd45504f-d983-486e-9c46-f5c3e4adcbd7}\RP701\A0246018.exe (ID = 328203)
5:25 PM: C:\System Volume Information\_restore{cd45504f-d983-486e-9c46-f5c3e4adcbd7}\RP716\A0251745.exe (ID = 465)
5:25 PM: Found Adware: lopdotcom
5:22 PM: C:\System Volume Information\_restore{cd45504f-d983-486e-9c46-f5c3e4adcbd7}\RP711\A0249534.exe (ID = 285164)
5:21 PM: C:\System Volume Information\_restore{cd45504f-d983-486e-9c46-f5c3e4adcbd7}\RP709\A0249254.dll (ID = 319805)
5:21 PM: Found Adware: spyware quake fakealert
5:20 PM: C:\System Volume Information\_restore{cd45504f-d983-486e-9c46-f5c3e4adcbd7}\RP701\A0245033.lnk (ID = 288513)
5:17 PM: C:\System Volume Information\_restore{cd45504f-d983-486e-9c46-f5c3e4adcbd7}\RP701\A0245047.inf (ID = 83179)
5:17 PM: Found Adware: directrevenue-abetterinternet
5:14 PM: C:\Program Files\MSK\license.txt (ID = 285492)
5:14 PM: C:\Program Files\MSK\readme.txt (ID = 285491)
5:08 PM: C:\System Volume Information\_restore{cd45504f-d983-486e-9c46-f5c3e4adcbd7}\RP774\A0258664.ini (ID = 298068)
5:08 PM: C:\System Volume Information\_restore{cd45504f-d983-486e-9c46-f5c3e4adcbd7}\RP701\A0245029.exe (ID = 298057)
5:06 PM: C:\System Volume Information\_restore{cd45504f-d983-486e-9c46-f5c3e4adcbd7}\RP701\A0245030.ini (ID = 298068)
5:06 PM: C:\System Volume Information\_restore{cd45504f-d983-486e-9c46-f5c3e4adcbd7}\RP701\A0245038.exe (ID = 315742)
5:01 PM: C:\WINDOWS\system32\components\flx6.dll (ID = 338616)
5:01 PM: Found Trojan Horse: trojan-downloader-zlob
5:01 PM: C:\System Volume Information\_restore{cd45504f-d983-486e-9c46-f5c3e4adcbd7}\RP711\A0249533.dll (ID = 283361)
4:59 PM: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\StartupFaster\GStartup.lnk (ID = 61450)
4:59 PM: Found Adware: gain - common components
4:59 PM: C:\WINDOWS\system32\PIN (1 subtraces) (ID = 2147486823)
4:59 PM: Found System Monitor: personal inspector
4:58 PM: Starting File Sweep
4:58 PM: Warning: Failed to access drive A:
4:58 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00
4:58 PM: Starting Cookie Sweep
4:58 PM: Registry Sweep Complete, Elapsed Time:00:00:44
4:58 PM: HKU\S-1-5-21-173008773-919082819-4212676017-1007\software\microsoft\internet explorer\search\ || local page (ID = 142622)
4:58 PM: Found Adware: startnow startnow hijack
4:58 PM: HKU\S-1-5-21-173008773-919082819-4212676017-1007\software\microsoft\installer\products\b5890ede256d37548ae908c32b952774\ (ID = 142596)
4:58 PM: HKU\S-1-5-21-173008773-919082819-4212676017-1007\software\microsoft\installer\features\b5890ede256d37548ae908c32b952774\ (ID = 142595)
4:58 PM: HKU\S-1-5-21-173008773-919082819-4212676017-1007\software\microsoft\windows\currentversion\internet settings\connections\ || minidialer (ID = 136243)
4:58 PM: Found Adware: nocreditcard dialer
4:58 PM: HKLM\software\classes\mezziacodec.chl\ (ID = 1588798)
4:58 PM: HKCR\mezziacodec.chl\ (ID = 1588797)
4:58 PM: Found Trojan Horse: trojan-downloader-rmass
4:58 PM: HKLM\software\microsoft\windows\currentversion\policies\explorer\run\ || ishost.exe (ID = 1572302)
4:58 PM: HKLM\software\classes\clsid\{5b55c4e3-c179-ba0b-b4fd-f2db862d6202}\ (ID = 1218857)
4:58 PM: HKCR\clsid\{5b55c4e3-c179-ba0b-b4fd-f2db862d6202}\ (ID = 1218826)
4:58 PM: Found Adware: spyware quake
4:58 PM: HKLM\software\microsoft\mssmgr\ (ID = 937101)
4:58 PM: Found Trojan Horse: trojan agent winlogonhook
4:58 PM: HKLM\software\gensrv\ (ID = 860688)
4:58 PM: Found System Monitor: metakodix stealth keylogger
4:58 PM: HKLM\software\microsoft\windows\currentversion\explorer\browser helper objecta\ (ID = 735573)
4:58 PM: Found Adware: popuper
4:58 PM: HKLM\software\microsoft\windows\currentversion\uninstall\{ede0985b-d652-4573-a89e-803cb2597247}\ (ID = 142617)
4:58 PM: Found Adware: startnow
4:58 PM: HKLM\software\classes\interface\{da9a0b1f-9b7b-11d3-b8a4-00c04f79641c}\ (ID = 135197)
4:58 PM: HKCR\interface\{da9a0b1f-9b7b-11d3-b8a4-00c04f79641c}\ (ID = 135183)
4:58 PM: Found Adware: moneytree
4:58 PM: HKCR\typelib\{282147c5-5258-4a62-92ba-b82dd895f6ef}\ (ID = 135148)
4:58 PM: Found Adware: mojo toolbar
4:57 PM: Starting Registry Sweep
4:57 PM: Memory Sweep Complete, Elapsed Time: 00:01:54
4:56 PM: Starting Memory Sweep
4:56 PM: HKLM\software\microsoft\windows\currentversion\policies\explorer\run\ || ishost.exe (ID = 1572185)
4:55 PM: Found Adware: security2k hijacker
4:55 PM: Sweep initiated using definitions version 757
4:55 PM: Spy Sweeper 5.0.5.1286 started
4:55 PM: | Start of Session, Friday, September 08, 2006 |
********
4:55 PM: | End of Session, Friday, September 08, 2006 |
4:54 PM: Your spyware definitions have been updated.
Keylogger Shield: On
BHO Shield: On
IE Security Shield: On
Alternate Data Stream (ADS) Execution Shield: On
Startup Shield: On
Common Ad Sites Shield: Off
Hosts File Shield: On
Spy Communication Shield: On
ActiveX Shield: On
Windows Messenger Service Shield: On
IE Favorites Shield: On
Spy Installation Shield: On
Memory Shield: On
IE Hijack Shield: On
IE Tracking Cookies Shield: Off
4:53 PM: Shield States
4:53 PM: Spyware Definitions: 691
4:53 PM: Spy Sweeper 5.0.5.1286 started
4:53 PM: Spy Sweeper 5.0.5.1286 started
4:53 PM: | Start of Session, Friday, September 08, 2006 |
Kaspersky -
Friday, September 08, 2006 10:55:48 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 9/09/2006
Kaspersky Anti-Virus database records: 209003
Scan Settings
Scan using the following antivirus database standard
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
A:\
C:\
D:\
E:\
F:\
G:\
H:\
I:\
Scan Statistics
Total number of scanned objects 106650
Number of viruses found 15
Number of infected objects 34 / 0
Number of suspicious objects 2
Duration of the scan process 02:23:36
Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BlazeFindBridge7.zip/a.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BlazeFindBridge7.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\Cliff Smith\.jpi_cache\jar\1.0\archive.jar-2fe7a1a6-34360547.zip/binny/binny.class Infected: Trojan.Java.Binny.a skipped
C:\Documents and Settings\Cliff Smith\.jpi_cache\jar\1.0\archive.jar-2fe7a1a6-34360547.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Cliff Smith\Application Data\Mozilla\Firefox\Profiles\oixf3oxe.default\flashgot.log Object is locked skipped
C:\Documents and Settings\Cliff Smith\Application Data\Mozilla\Firefox\Profiles\oixf3oxe.default\history.dat Object is locked skipped
C:\Documents and Settings\Cliff Smith\Application Data\Mozilla\Firefox\Profiles\oixf3oxe.default\parent.lock Object is locked skipped
C:\Documents and Settings\Cliff Smith\Application Data\Webroot\Spy Sweeper\Logs\060908165302.ses Object is locked skipped
C:\Documents and Settings\Cliff Smith\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Cliff Smith\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Cliff Smith\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Cliff Smith\Local Settings\Application Data\Mozilla\Firefox\Profiles\oixf3oxe.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Cliff Smith\Local Settings\Application Data\Mozilla\Firefox\Profiles\oixf3oxe.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Cliff Smith\Local Settings\Application Data\Mozilla\Firefox\Profiles\oixf3oxe.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Cliff Smith\Local Settings\Application Data\Mozilla\Firefox\Profiles\oixf3oxe.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Cliff Smith\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Cliff Smith\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Cliff Smith\ntuser.dat Object is locked skipped
C:\Documents and Settings\Cliff Smith\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Data\settings.dat Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS038EDCBB-EB63-4865-9532-1163EEBE1D8E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS07F290C3-3727-4FA1-8BE4-FA4B3DA5F9E6.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS08079444-57DC-431B-A597-778E47E037D6.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS09C8A675-A73B-414B-B8D4-2D05762D8E56.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS0ACE145D-D73F-4811-8B98-3CAAC8F26974.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1047A840-EE80-4D92-BD60-A9D49E17F85B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1057956E-C793-4E16-98C8-025C696BF738.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS10D3FBF7-8092-4746-A78B-B166D89E983B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS10D66FD6-ED10-4674-BBE2-241C40D90867.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS11034287-CB92-4055-9D4C-75952B6056DF.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS125D079E-E819-4B2A-AC4F-58626B890EEB.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS13BA15E3-5C92-4072-9E7B-314CB864C729.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS14150165-83E4-436D-80EA-48B6CA05619C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS142CC0FF-AE85-4145-9693-BB58DBC9E023.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS199DAFF2-B62E-4822-BBC6-3ED13EA1EF3A.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1F375296-EFF8-4E22-9131-B572B7BAD1A2.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS20F96D5F-5A8E-4A09-B6B9-CA77FB8E9255.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS23420BDF-F196-4F7A-9255-1285AD9664B9.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS2481672E-1AA8-4BC6-91A0-63D66DC74F09.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS29F72FB5-17F1-428D-84E7-FCB91B4325DB.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS2A372584-B093-4651-9C72-8DBBB93F9841.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS33E9D9F2-12A2-4F7C-9FD4-676EEE174F9B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS3601E0B5-246B-48F2-ADAE-0AC72543D348.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS36F6694B-BEC3-44D1-AA63-ACD71BD3D296.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4036FC4C-9887-48E7-896B-9887D8C92E8F.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4B43BC2F-8B51-44BE-825D-4AA02C318F84.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4B4A8E58-A2FC-4E81-974A-874A69AEAB0C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4D14596A-686A-4B8E-AC4B-9877A1B8D6F8.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4FE7EE4B-99F8-447C-98C8-02C16FB0BAAB.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS528693BE-AA2E-4C6A-B348-975BDA274097.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS53B254ED-5423-4C35-B537-DA4F9D374B74.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS5416B1D3-5D28-4E0D-8B9C-14F453AE25CE.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS56BDBE01-51AC-423A-9419-B5359C9A21A5.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS592009EA-CCC3-44C9-82FA-A760BB864505.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS5D836B70-3DF5-4270-89FD-A4403D6E522A.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS5E4FB7D1-5557-45C2-B88B-521CCCA48631.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS5FEEA58F-0231-4F10-A69D-E316D95EE6CA.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS60A0E464-27D8-4C7B-8988-04F23C91F92D.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS60AD2EC8-6ABA-4EB9-83A0-AD3500D3A49F.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS611E395B-9D67-4E54-8CAC-09D7FD2EB24A.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS62761C42-0DCB-4545-85E6-7F470AB11DD8.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS62DD3562-FE28-40AB-A97C-06B5D66624CB.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS69BEF862-B775-4A4B-BE31-A9785CC23117.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS6A2DC810-2E42-47A2-9F58-CC07FD015F59.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS6A38532E-172C-41A0-AA65-594F94E8FB60.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS700AE1C0-AE93-40FA-B3A8-F82ECE29C615.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS744B8C94-CEAB-4CEC-8F19-4F82C1C24731.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS77D970BD-1EE1-4DAF-8088-75E3EFEA45FA.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS79198B60-673B-4465-923A-96B7ABEB0756.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS7A55C78D-F55B-466E-84AF-41C9B458EE95.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS7ABF1E7F-64A7-49BC-8C61-1AAF260357BC.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS7F08B561-F0C0-41D1-925C-D89E7D62A96F.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS842EB6E8-BE57-4086-AF0F-C3AAE1B43FFE.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8C9F3BC3-0163-4B9D-9133-CD2C23B66A3E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8F4A58EA-DC74-4E3F-9737-51E94800DD9A.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS95AC80F9-8D64-4CA4-B24D-D1AA40676BC6.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS96D5F481-A0C9-40B4-81BE-2C80895C6FD1.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS979E2081-E693-4CA8-8EC2-CB0313D83287.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS9DA94DCD-9A50-472F-9016-F0D84A32151D.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS9E694A0C-4B85-4B5D-A36F-01DE6637C2BE.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS9EF4C594-C2EE-4D27-956E-61367A27F5EB.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS9F2DDFF6-4F26-4CF2-86BC-30826C0FE63B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA113A465-C4A0-4210-AE68-7B7C53540002.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA3292249-D761-4978-93A3-5D1B0C5CC3B4.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA4114F12-B761-454D-BBFE-839CF9A155B9.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA60F8E31-253F-418F-AF2F-D38D453FDABE.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA887BE22-322F-4471-A4C6-D508672C0882.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA8CB43CD-68A5-44C3-8FC5-EAD6DD82FE3C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSAE3A10DA-9F73-415C-B933-EE4C0F68ECFE.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB164BB6D-E116-4095-99E3-C1AEFC8F14C8.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB24FE3C9-06AA-402E-8619-06686A3A3760.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB2E85B20-7B8C-4632-8342-7FCADFF858A8.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB3CA0962-3E9F-4179-BBA2-12283CCFF6CB.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB3D7AADF-AB50-416C-B327-EBAA7C415D51.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB49CEA8E-849C-4D05-BCFE-F12566A290F3.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB96EF4B3-26B0-4E51-AB6A-BA0E4BB9A2F8.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSBA6A832B-C623-4430-9FF7-F50B60CE187B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSBAD82746-1054-46A7-9CB1-930EAB17034F.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSBB8DD985-348E-477E-8215-6D0B73BD4FD8.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSBC17B069-3E86-4AEB-8125-B99E16D95F01.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSBC6D077D-2080-49DE-B8B2-7989F546A350.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSBDB9AF08-45D2-4544-A728-3327AC5968E9.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSBDF9706C-D631-41E9-86C0-3DD83CFE2E6D.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSBDFED1EA-E3C3-4053-A0BB-B541DDD6B240.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSBF4B7A87-88AF-429F-A7CA-60832512A2B5.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC09C242E-6059-4DB5-8FE7-9B356ABEC7B1.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC416B234-F66C-4AB9-AB95-5BAC5114FDC2.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC5D2DDA0-2A3D-4B15-8216-39A4BE035270.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC70A2108-FCB0-4F17-82DE-7E90866FE146.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSCDE38174-F7F8-4785-B268-52E1CEB70DD4.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD100C8B8-1A96-4DC6-B50F-D7E42556D3ED.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD1679915-52E9-4BF1-926E-94F23170BEBD.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD390A5CC-DF43-469B-9B29-5D7F9FDF5E84.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD4C0C0A7-B101-485C-9E2F-4B3C7B801CA0.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD588C79E-CD47-4BFA-BA71-FD47B7691FDE.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD81F650A-4D0F-47DD-A173-D3949F85EAF5.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD956624A-9268-46A1-91F5-D01DB218287A.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD9CB28D4-8576-40EA-B68C-14E6E819C4E1.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSDDEDE64F-320C-46E3-978B-929130EEBE20.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSE02B7FFE-5E98-4B49-86B1-11AE9A1D6FCD.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSE444D62A-0271-4105-96A6-1C2C7788947B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSE49C667D-9D00-4125-97EB-4350ED0B4D77.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSE8B15D4C-264B-4FC7-AD5E-151BFA180228.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSEA99D6A6-4237-4796-8149-F2C516EDC734.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSF3C0E5D6-42A0-4312-BFA1-33B2CE880726.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSF81D26C3-288B-4C12-9188-CC96417CE976.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSFB206CA5-FD45-441F-9756-91323B491CF1.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSFB890740-6D49-4EA6-AD2E-E72355304FAF.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSFD72B798-1494-4D60-8751-07A7911FC467.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\logs\starwind.2006-09-08.19-59-05.log Object is locked skipped
C:\Program Files\Webroot\Spy Sweeper\Masters\masters.bak Object is locked skipped
C:\Program Files\Webroot\Spy Sweeper\Masters\Masters.const Object is locked skipped
C:\Program Files\Webroot\Spy Sweeper\Masters\masters.mst Object is locked skipped
C:\Program Files\Webroot\Spy Sweeper\Masters.base Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{CD45504F-D983-486E-9C46-F5C3E4ADCBD7}\RP701\A0245022.tlb Infected: Trojan-Downloader.Win32.Zlob.wd skipped
C:\System Volume Information\_restore{CD45504F-D983-486E-9C46-F5C3E4ADCBD7}\RP701\A0245023.exe Infected: Trojan-Downloader.Win32.Obfuscated.n skipped
C:\System Volume Information\_restore{CD45504F-D983-486E-9C46-F5C3E4ADCBD7}\RP701\A0245039.exe/data0007 Infected: Trojan-Downloader.Win32.Zlob.we skipped
C:\System Volume Information\_restore{CD45504F-D983-486E-9C46-F5C3E4ADCBD7}\RP701\A0245039.exe/data0008 Infected: Trojan-Downloader.Win32.Zlob.we skipped
C:\System Volume Information\_restore{CD45504F-D983-486E-9C46-F5C3E4ADCBD7}\RP701\A0245039.exe NSIS: infected - 2 skipped
C:\System Volume Information\_restore{CD45504F-D983-486E-9C46-F5C3E4ADCBD7}\RP701\A0245039.exe UPX: infected - 2 skipped
C:\System Volume Information\_restore{CD45504F-D983-486E-9C46-F5C3E4ADCBD7}\RP701\A0245039.exe PE_Patch.UPX: infected - 2 skipped
C:\System Volume Information\_restore{CD45504F-D983-486E-9C46-F5C3E4ADCBD7}\RP701\A0246016.exe Infected: Trojan-Downloader.Win32.Zlob.wi skipped
C:\System Volume Information\_restore{CD45504F-D983-486E-9C46-F5C3E4ADCBD7}\RP701\A0246017.exe Infected: Trojan-Downloader.Win32.Zlob.wd skipped
C:\System Volume Information\_restore{CD45504F-D983-486E-9C46-F5C3E4ADCBD7}\RP709\A0249301.exe Infected: Trojan-Downloader.Win32.Swizzor.co skipped
C:\System Volume Information\_restore{CD45504F-D983-486E-9C46-F5C3E4ADCBD7}\RP709\A0249304.exe Infected: Trojan-Downloader.Win32.Swizzor.dv skipped
C:\System Volume Information\_restore{CD45504F-D983-486E-9C46-F5C3E4ADCBD7}\RP709\A0249310.exe Infected: Trojan-Downloader.Win32.Swizzor.co skipped
C:\System Volume Information\_restore{CD45504F-D983-486E-9C46-F5C3E4ADCBD7}\RP709\A0249312.exe Infected: Trojan-Downloader.Win32.Swizzor.co skipped
C:\System Volume Information\_restore{CD45504F-D983-486E-9C46-F5C3E4ADCBD7}\RP709\A0249313.exe Infected: Trojan-Downloader.Win32.Swizzor.fg skipped
C:\System Volume Information\_restore{CD45504F-D983-486E-9C46-F5C3E4ADCBD7}\RP709\A0249319.exe Infected: Trojan-Downloader.Win32.Swizzor.fg skipped
C:\System Volume Information\_restore{CD45504F-D983-486E-9C46-F5C3E4ADCBD7}\RP709\A0249320.exe Infected: Trojan-Downloader.Win32.Swizzor.fg skipped
C:\System Volume Information\_restore{CD45504F-D983-486E-9C46-F5C3E4ADCBD7}\RP711\A0249530.exe Infected: Trojan-Downloader.Win32.Swizzor.co skipped
C:\System Volume Information\_restore{CD45504F-D983-486E-9C46-F5C3E4ADCBD7}\RP716\A0253359.exe Infected: Trojan-Downloader.Win32.Obfuscated.n skipped
C:\System Volume Information\_restore{CD45504F-D983-486E-9C46-F5C3E4ADCBD7}\RP716\A0253452.exe Infected: Trojan-Downloader.Win32.Obfuscated.n skipped
C:\System Volume Information\_restore{CD45504F-D983-486E-9C46-F5C3E4ADCBD7}\RP774\A0258659.exe Infected: Trojan-Downloader.Win32.Zlob.adt skipped
C:\System Volume Information\_restore{CD45504F-D983-486E-9C46-F5C3E4ADCBD7}\RP774\A0258660.dll Infected: Trojan-Downloader.Win32.Zlob.aiq skipped
C:\System Volume Information\_restore{CD45504F-D983-486E-9C46-F5C3E4ADCBD7}\RP774\A0258674.dll Infected: not-virus:Hoax.Win32.Renos.ds skipped
C:\System Volume Information\_restore{CD45504F-D983-486E-9C46-F5C3E4ADCBD7}\RP774\A0258798.exe Infected: Trojan-Downloader.Win32.Zlob.adt skipped
C:\System Volume Information\_restore{CD45504F-D983-486E-9C46-F5C3E4ADCBD7}\RP774\A0258800.exe Infected: Trojan-Downloader.Win32.Zlob.aiq skipped
C:\System Volume Information\_restore{CD45504F-D983-486E-9C46-F5C3E4ADCBD7}\RP774\A0258801.dll Infected: Trojan-Downloader.Win32.Zlob.aiq skipped
C:\System Volume Information\_restore{CD45504F-D983-486E-9C46-F5C3E4ADCBD7}\RP774\A0258802.dll Infected: Trojan-Downloader.Win32.Zlob.aiq skipped
C:\System Volume Information\_restore{CD45504F-D983-486E-9C46-F5C3E4ADCBD7}\RP775\A0258859.dll Infected: Packed.Win32.Klone.g skipped
C:\System Volume Information\_restore{CD45504F-D983-486E-9C46-F5C3E4ADCBD7}\RP776\A0258875.dll Infected: Trojan-Downloader.Win32.Zlob.aix skipped
C:\System Volume Information\_restore{CD45504F-D983-486E-9C46-F5C3E4ADCBD7}\RP777\A0258928.dll Infected: not-virus:Hoax.Win32.Renos.ds skipped
C:\System Volume Information\_restore{CD45504F-D983-486E-9C46-F5C3E4ADCBD7}\RP777\change.log Object is locked skipped
C:\WINDOWS\$NtUninstallQ828026$\msdxm.ocx Object is locked skipped
C:\WINDOWS\$NtUninstallQ828026$\msdxm.ocx.000 Object is locked skipped
C:\WINDOWS\$NtUninstallQ828026$\wmp.dll Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\g154948968.dll Infected: Trojan-Downloader.Win32.Delf.aeo skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{A82A696D-2EFC-49E0-8D87-CEFA97193920}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\ismini.exe Infected: Trojan-Downloader.Win32.Zlob.adt skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\system32\winzdn32.txt Infected: Packed.Win32.Klone.g skipped
C:\WINDOWS\temp\Perflib_Perfdata_2a8.dat Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped