This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Can't get rid of this "Pest trap" and "Virus Burst&

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

here are the files you requested.

Thank You!


KASPERSKY ONLINE SCANNER REPORT
Thursday, September 21, 2006 2:54:07 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 21/09/2006
Kaspersky Anti-Virus database records: 212214
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\

Scan Statistics:
Total number of scanned objects: 138717
Number of viruses found: 6
Number of infected objects: 37 / 0
Number of suspicious objects: 0
Duration of the scan process: 05:05:22

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\AOL\ACS\1.0\ph Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\ACS\1.0\variable Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\aolstderr.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\aolstdout.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\aoltsmon.lock Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\cache.db Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\server.lock Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\cls\common.cls Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Logs\OAS.Log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\mcafee.com personal firewall\data\IpRules.xdb Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Works\Portfolio\Collection 1.wsb Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\The Husar Computer\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Application Data\AOL\UserProfiles\All Users\cls\common.cls Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\History\History.IE5\MSHist012006092120060922\index.dat Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\k3e0fs8j.exe/data0007 Infected: Trojan-Downloader.Win32.Zlob.akb skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\k3e0fs8j.exe NSIS: infected - 1 skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\k3e0fs8j.exe UPX: infected - 1 skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_0FAiGpyuwKXCYBb Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_0SUHbaiyj8A2jYb Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_29KfUpx2eupms7l Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_2ACJ1EdIIzOBmTZ Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_35kx5QrcFM3Gp17 Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_3fqcVhiDFuIaokf Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_3JkKq5mI3wzQJVL Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_3m3s33txZDVcWDA Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_6QK4vm4bHNZ5fTL Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_8c6SoORWYi2Fggn Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_8RN9skH42bkb7k2 Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_8zOkM6vTJ0iEfdF Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_9cIz4NIwVN0LeyG Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_9IXKuhFB4PTI0Ht Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_9tC35kFRNACP8b5 Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_A5AMK2uPSQJ1xSV Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_AAOneIx5k8VmDPL Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_adBxQFuuSsQgRpA Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_ADjqmelycQaCkw8 Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_AociYxT9RCCBDWz Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_AtSGshERG048o7T Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_aWJelJX5dbLmPVO Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_AXNrDhN7Lmr8KxP Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_Cb4ZDZRo9sHRE9O Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_CXLQikbcy7rTgGt Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_DDHYFdfIs92hSTh Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_dZk1HYGDOBXFhje Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_Eg0HOtVjp3w5mMV Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_EHKQTA4YufeTEXo Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_eyvSFtX8ypqJVhp Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_fmBEpynlwzBGD90 Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_FOhorYIxQzi1bwH Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_GboGEhbg09iZz5h Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_ggOfB627DrVuEs6 Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_gJabChMRD3W4wnj Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_HAIy7b0GMCrrCb4 Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_heRdDDTOeazydMj Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_heUAHxaERdW0rxE Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_hfsZyqPjcw7OtbA Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_HMIITADmo7fwct1 Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_HREc2idb9fgsklA Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_Ic14D6GnGXfBxP9 Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_IHg4alb9KSln3SI Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_iINBx5bWJ0Uy4vi Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_IXBrGE2XLSgWuAm Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_j2wHkhH86X5kZTF Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_J5Q699LVh5ADSkJ Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_JfUce7ELwpdv8Se Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_JKEo4FxdrRBNAzF Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_JnOzFSzTEn5sql8 Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_JxMubpdthjnsFoe Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_jZ2a3HfKd6g6mjg Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_K2mcOeG3UodCK7z Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_kM1PfImhGVoqAtf Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_kNMw32szkJpIhZ4 Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_LDblx0G5Kc8fmAa Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_LGtIFxgEu1sBYIC Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_lNwHGRmOdU0PmAK Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_LPFlfdeCz2CJdOv Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_LQpj0XqEp9fQafc Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_LRlSdFxJiPvvEs4 Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_lUGHIxWBh3sy8oB Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_LXVMe1Bh3qMMAfk Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_m3zP6c7yck7utbY Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_maPAHNcayzL2290 Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_miZtB8l7u049HGt Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_mkDAgkipoLuuzzN Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_MPshQt8mY12Fesx Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_mziSkGWZHiL4rZ7 Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_n2natx4xn1hRQfX Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_n3PTAVCPNCZpaT0 Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_nG9QI4ZQHLSQvXP Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_orDCNI1cva1OlbF Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_OUOQsC8S0ICLxoF Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_P7blCRAbQZH3aCg Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_PkIUJgcgUOLSCBN Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_Q0vY5o1bCKG43oP Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_q1zm1aOwDJoOPdu Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_QyjzSuq4mqK57wN Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_T3xwiEgD03JIH92 Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_tNCabI1O6kboTsY Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_tQFhnwiP3VaWCmg Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_UgpMOlcDHWmlkP1 Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_V7emmLiwIplcCS7 Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_VQbYtZsIMhdJ8wI Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_Wng7deNtiCSKVdb Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_WqCZ1b3QalS2Qae Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_wuHVu1VtvjHyfFe Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_XjVXakPjB7x2QYB Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_XKYRTgZ8HraACxz Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_XQQeS2OGnBlKJRm Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_yY8n1s1UaI6XOLs Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_Z5CvfGbI2463p8F Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_zsSGofUa0fFzxtC Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_zwiul6U3uSWQtGO Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_zx70RWWUUosu2zw Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\~DFE087.tmp Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\The Husar Computer\ntuser.dat Object is locked skipped
C:\Documents and Settings\The Husar Computer\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Common Files\AOL\ACS\US\static Object is locked skipped
C:\Program Files\MSN Messenger\EZ-Emoticons.exe/stream/data0012 Infected: Trojan-Clicker.Win32.Agent.ff skipped
C:\Program Files\MSN Messenger\EZ-Emoticons.exe/stream Infected: Trojan-Clicker.Win32.Agent.ff skipped
C:\Program Files\MSN Messenger\EZ-Emoticons.exe NSIS: infected - 2 skipped
C:\Program Files\Steve Bass's Tips and utilities DL from Snipurl & Oreilly\Big Fix\__Data\Fixlet Central\__Local\Tmp\security-900.dat Object is locked skipped
C:\Program Files\Steve Bass's Tips and utilities DL from Snipurl & Oreilly\Big Fix\__Data\Fixlet Central\__Local\Tmp\shares-500.dat Object is locked skipped
C:\Program Files\Steve Bass's Tips and utilities DL from Snipurl & Oreilly\Big Fix\__Data\Fixlet Central\__Local\Tmp\survey.dat Object is locked skipped
C:\Program Files\Steve Bass's Tips and utilities DL from Snipurl & Oreilly\Big Fix\__Data\Fixlet Central\__Local\Tmp\updates-1000.dat Object is locked skipped
C:\Program Files\Steve Bass's Tips and utilities DL from Snipurl & Oreilly\Big Fix\__Data\Fixlet Central\__Local\Tmp\Urgent.dat Object is locked skipped
C:\Program Files\Steve Bass's Tips and utilities DL from Snipurl & Oreilly\Big Fix\__Data\Fixlet Central\__Local\Tmp\virus-300.dat Object is locked skipped
C:\Program Files\Steve Bass's Tips and utilities DL from Snipurl & Oreilly\Big Fix\__Data\Fixlet Central\__Local\Tmp\vscan-600.dat Object is locked skipped
C:\Program Files\Steve Bass's Tips and utilities DL from Snipurl & Oreilly\Big Fix\__Data\Fixlet Central\__Local\Tmp\warnings-200.dat Object is locked skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP144\A0021293.exe Infected: Trojan-Downloader.Win32.Zlob.akc skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP144\A0021294.dll Infected: Trojan-Downloader.Win32.Zlob.akp skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP144\A0021296.exe Infected: Trojan-Downloader.Win32.Zlob.ako skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0021504.dll Infected: Trojan-Downloader.Win32.Zlob.akp skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0021511.exe Infected: Trojan-Downloader.Win32.Zlob.akc skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0021513.exe Infected: Trojan-Downloader.Win32.Zlob.ako skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0021556.dll Infected: Trojan-Downloader.Win32.Zlob.akp skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0021557.exe Infected: Trojan-Downloader.Win32.Zlob.akc skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0021559.exe Infected: Trojan-Downloader.Win32.Zlob.ako skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0021592.dll Infected: Trojan-Downloader.Win32.Zlob.akp skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0021593.exe Infected: Trojan-Downloader.Win32.Zlob.akc skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0021594.exe Infected: Trojan-Downloader.Win32.Zlob.ako skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0021619.dll Infected: Trojan-Downloader.Win32.Zlob.akp skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0021620.exe Infected: Trojan-Downloader.Win32.Zlob.akc skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0021622.exe Infected: Trojan-Downloader.Win32.Zlob.ako skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0021648.exe Infected: Trojan-Downloader.Win32.Zlob.akc skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0021649.dll Infected: Trojan-Downloader.Win32.Zlob.akp skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0021651.exe Infected: Trojan-Downloader.Win32.Zlob.ako skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0022660.dll Infected: Trojan-Downloader.Win32.Zlob.akp skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0022661.exe Infected: Trojan-Downloader.Win32.Zlob.akc skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0022663.exe Infected: Trojan-Downloader.Win32.Zlob.ako skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0022687.dll Infected: Trojan-Downloader.Win32.Zlob.akp skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0022688.exe Infected: Trojan-Downloader.Win32.Zlob.akc skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0022689.exe Infected: Trojan-Downloader.Win32.Zlob.ako skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0022712.dll Infected: Trojan-Downloader.Win32.Zlob.akp skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0022713.exe Infected: Trojan-Downloader.Win32.Zlob.ako skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0022714.exe Infected: not-virus:Hoax.Win32.Renos.ev skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0022715.exe Infected: Trojan-Downloader.Win32.Zlob.akc skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP154\change.log Object is locked skipped
C:\WINNT\Debug\PASSWD.LOG Object is locked skipped
C:\WINNT\SchedLgU.Txt Object is locked skipped
C:\WINNT\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINNT\Sti_Trace.log Object is locked skipped
C:\WINNT\system32\CatRoot2\edb.log Object is locked skipped
C:\WINNT\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINNT\system32\config\AppEvent.Evt Object is locked skipped
C:\WINNT\system32\config\DEFAULT Object is locked skipped
C:\WINNT\system32\config\default.LOG Object is locked skipped
C:\WINNT\system32\config\SAM Object is locked skipped
C:\WINNT\system32\config\SAM.LOG Object is locked skipped
C:\WINNT\system32\config\SecEvent.Evt Object is locked skipped
C:\WINNT\system32\config\SECURITY Object is locked skipped
C:\WINNT\system32\config\SECURITY.LOG Object is locked skipped
C:\WINNT\system32\config\SOFTWARE Object is locked skipped
C:\WINNT\system32\config\software.LOG Object is locked skipped
C:\WINNT\system32\config\SysEvent.Evt Object is locked skipped
C:\WINNT\system32\config\SYSTEM Object is locked skipped
C:\WINNT\system32\config\system.LOG Object is locked skipped
C:\WINNT\system32\h323log.txt Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINNT\wiadebug.log Object is locked skipped
C:\WINNT\wiaservc.log Object is locked skipped
C:\WINNT\WindowsUpdate.log Object is locked skipped
E:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0021501.exe/data0007 Infected: Trojan-Downloader.Win32.Zlob.akb skipped
E:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0021501.exe NSIS: infected - 1 skipped
E:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0021501.exe UPX: infected - 1 skipped


Hijack This log file:
Logfile of HijackThis v1.99.1
Scan saved at 2:59:02 PM, on 09/21/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Common Files\AOL\1100827586\ee\AOLSoftware.exe
C:\Program Files\mcafee.com\antivirus\oasclnt.exe
C:\Program Files\mcafee.com\antivirus\mcvsescn.exe
C:\WINNT\System32\igfxtray.exe
C:\WINNT\System32\hkcmd.exe
C:\WINNT\StartupMonitor.exe
C:\WINNT\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Logitech camera\LogiTray.exe
C:\Program Files\Steve Bass's Tips and utilities DL from Snipurl & Oreilly\Big Fix\BigFix.exe
C:\Program Files\Common Files\AOL\1100827586\ee\services\sscFirewallPlugin\ver1_10_3_1\SSCEvtHdlr.exe
C:\Program Files\Logitech\Logitech camera\FxSvr2.exe
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
C:\WINNT\system32\PackethSvc.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\AOL\1100827586\ee\services\sscFirewallPlugin\ver1_10_3_1\aolavupd.exe
C:\Documents and Settings\The Husar Computer\Desktop\ewido\ewido anti-spyware 4.0\guard.exe
C:\PROGRA~1\mcafee.com\ANTIVI~1\mcshield.exe
E:\WEST DIGI SETTLE BACK-up\retrorun.exe
C:\WINNT\System32\ScsiAccess.EXE
C:\WINNT\System32\svchost.exe
C:\WINNT\wanmpsvc.exe
c:\program files\common files\aol\1100827586\ee\services\sscAntiSpywarePlugin\ver1_10_3_1\AOLSP Scheduler.exe
C:\Program Files\Microsoft Works\wkssb.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Steve Bass's Tips and utilities DL from Snipurl & Oreilly\PCBugDoctor\PCBugDoctor.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINNT\system32\NOTEPAD.EXE
C:\PROGRA~1\WINZIP\winzip32.exe
C:\unzipped\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://comcast.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1100827586\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\mcafee.com\antivirus\oasclnt.exe
O4 - HKLM\..\Run: [EmailScan] C:\Program Files\mcafee.com\antivirus\mcvsescn.exe
O4 - HKLM\..\Run: [MPFExe] C:\Program Files\mcafee.com\personal firewall\MPfTray.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
O4 - HKLM\..\Run: [tgcmd] C:\Program Files\Support.com\bin\tgcmd.exe /server /startmonitor /deaf
O4 - HKLM\..\Run: [LVCOMSX] C:\WINNT\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Logitech camera\LogiTray.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0c\AOL.EXE" -b
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\Steve Bass's Tips and utilities DL from Snipurl & Oreilly\Big Fix\BigFix.exe
O8 - Extra context menu item: &Define - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Look Up in &Encyclopedia - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra 'Tools' menuitem: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\WINNT\System32\shdocvw.dll
O9 - Extra button: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra 'Tools' menuitem: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O12 - Plugin for .UVR: C:\Program Files\Internet Explorer\Plugins\NPUPano.dll
O16 - DPF: Word Whomp Whackdown by pogo - http://whackdown.pogo.com/applet/whackdown…n-ob-assets.cab
O16 - DPF: Yahoo! Checkers - http://download.games.yahoo.com/games/clients/y/kt0_x.cab
O16 - DPF: Yahoo! Fleet - http://download.games.yahoo.com/games/clients/y/fltt1_x.cab
O16 - DPF: Yahoo! Freecell Solitaire - http://yog55.games.scd.yahoo.com/yog/y/fs10_x.cab
O16 - DPF: Yahoo! Hearts - http://download.games.yahoo.com/games/clients/y/ht0_x.cab
O16 - DPF: Yahoo! Word Racer - http://download.games.yahoo.com/games/clients/y/wt1_x.cab
O16 - DPF: {0122955E-1FB0-11D2-A238-006097FAEE8B} (CscClnt Class) - http://www.pollg.com/central/02030106/ccca…everContent.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://support.gateway.com/support/profiler/PCPitStop.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {10093E98-C073-4C75-8D0E-FB5CD3A71D33} (ZoneUpwords Object) - http://messenger.zone.msn.com/binary/Upwords.cab31267.cab
O16 - DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} (Controller Class) - https://www.windowsonecare.com/install/cli/…nSSWebAgent.CAB
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {17163BB4-107E-11D4-9B76-006097DF2317} (EABootStrap Class) - http://aol.ea.com/downloads/games/common/b…trap/iegils.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3CC943C7-3C99-11D4-8135-0050041A5144} (RunExeActiveX.UserControl1) - file://C:\Program Files\Gateway\HelpSpot\RunExeActiveX.CAB
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - https://objects.aol.com/mcafee/molbin/share…83/mcinsctl.cab
O16 - DPF: {525A15D0-4938-11D4-94C7-0050DA20189B} (SnoopyCtrl Class) - http://aol.ea.com/downloads/games/common/snoopy/iesnoopy.cab
O16 - DPF: {56393399-041A-4650-94C7-13DFCB1F4665} (PSFormX Control) - http://home3.ca.com/PestPatrol/uniblue/pestscan/pestscan.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1120185828141
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {76D90D08-EAB7-46D8-BF99-87445BF59E72} (SystemInfo Class) - http://orderdway.com/dwayready/dpcsysinfo.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
O16 - DPF: {93CEA8A4-6059-4E0B-ADDD-73848153DD5E} (CWebLaunchCtl Object) - http://gateway.cf1live.com/eSupport/static…h/weblaunch.cab
O16 - DPF: {99CDFD87-F97A-42E1-9C13-D18220D90AD1} (StartFirstControl.CheckFirst) - file://C:\Program Files\Gateway\HelpSpot\StartFirstControl.CAB
O16 - DPF: {9A57B18E-2F5D-11D5-8997-00104BD12D94} (compid Class) - http://www.gateway.com/support/serialharvest/gwCID.CAB
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/…/ymmapi_416.dll
O16 - DPF: {A1B09066-C95C-4EF6-8DFD-3DD0AFE610B6} - http://pak02.pictures.aol.com/ygp/aol/plug…ver.1.0.2.5.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real.com/gameconsole/Bundl…ArcadeRdxIE.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - https://objects.aol.com/mcafee/molbin/share…,20/McGDMgr.cab
O16 - DPF: {BDF9A7C7-F4DC-455D-B5C2-045D74788295} (AOLRegistrationWizard Control) - https://objects.aol.com/filebackup/AOLRegistrationWizard.cab
O16 - DPF: {CA797B15-445F-4AA9-9828-8A88502F560F} (Uninstall Control) - http://www.worldwinner.com/games/shared/uninstall.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O16 - DPF: {CE37E095-ACFF-4380-A856-A560D389E5E1} (XPLControlProject.XPLControl) - file://C:\Program Files\Gateway\HelpSpot\XPLControl.CAB
O16 - DPF: {DC187740-46A9-11D5-A815-00B0D0428C0C} - http://ds1.downloadtech.net/cn1060/pcpowerscan.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.games.yahoo.com/games/popc…aploader_v5.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/ac…/ActiveData.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…635/mcfscan.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Toolbar) - http://us.dl1.yimg.com/download.yahoo.com/…ebio5_1_2_0.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINNT\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINNT\system32\WPDShServiceObj.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AOL Antivirus Update Service (aolavupd) - America Online - C:\Program Files\Common Files\AOL\1100827586\ee\services\sscFirewallPlugin\ver1_10_3_1\aolavupd.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Documents and Settings\The Husar Computer\Desktop\ewido\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINNT\System32\ImapiRox.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINNT\system32\drivers\KodakCCS.exe
O23 - Service: McAfee McShield (McShield) - McAfee Inc. - C:\PROGRA~1\mcafee.com\ANTIVI~1\mcshield.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\Program Files\mcafee.com\personal firewall\MPFService.exe
O23 - Service: Virtual NIC Service (PackethSvc) - America Online, Inc. - C:\WINNT\system32\PackethSvc.exe
O23 - Service: Retrospect Launcher (RetroLauncher) - EMC Corporation - E:\WEST DIGI SETTLE BACK-up\retrorun.exe
O23 - Service: Retrospect Helper - EMC Corporation - E:\WEST DIGI SETTLE BACK-up\rthlpsvc.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINNT\System32\ScsiAccess.EXE
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINNT\wanmpsvc.exe
Hello mountainman,

You are making progress and near the end. We just need to get rid of a few infected files. Don't worry about the infected _restore files. We take care of those later in a different way.

Please set your system to show all files; please see here if you're unsure how to do this.

Reboot into Safe Mode: please see here if you are not sure how to do this.

Using Windows Explorer, locate the following files/folders, and delete them:
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\k3e0fs8j.exe<=file
C:\Program Files\MSN Messenger\EZ-Emoticons.exe<=file

Exit Explorer, and reboot as normal afterwards.


Now please run Kapersky again and post the results along with a hijackthis log.
Here are the files you requested.

Thank You!

KASPERSKY ONLINE SCANNER REPORT
Friday, September 22, 2006 8:11:44 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 22/09/2006
Kaspersky Anti-Virus database records: 212319
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\

Scan Statistics:
Total number of scanned objects: 138774
Number of viruses found: 6
Number of infected objects: 33 / 0
Number of suspicious objects: 0
Duration of the scan process: 06:51:14

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\AOL\ACS\1.0\ph Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\ACS\1.0\variable Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\aolstderr.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\aolstdout.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\aoltsmon.lock Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\cache.db Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\server.lock Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\cls\common.cls Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Logs\OAS.Log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\mcafee.com personal firewall\data\IpRules.xdb Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Works\Portfolio\Collection 1.wsb Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\The Husar Computer\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Application Data\AOL\UserProfiles\All Users\cls\common.cls Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\History\History.IE5\MSHist012006092220060923\index.dat Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_3Bneb2mW0fA4LdR Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_49Z3MAytMwR4NQB Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_5jrQAxVi9z9ONJ8 Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_7gvwCGCRuE8gFcj Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_aFFAgW1vJOlwJMY Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_BLStRE2EotWnGpu Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_cnT0ivAIAbRhJ6T Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_EFoWB9nJJQKcFL0 Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_FgW2yXK3mZdgAFe Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_glEcivI32zMFjZE Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_knTkXXYjfr4b8lD Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_OWkFQpaRpPo9y0E Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_ps0Qt7BLjgfk33c Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_pWcVZRs4JMGSVQc Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_Tw0OJTNMJxnyeB5 Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_UERW1cLy2vcpdsJ Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_wc6ezoeVWKA2rb7 Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temp\sqlite_zpy0cmSB6Lm9wun Object is locked skipped
C:\Documents and Settings\The Husar Computer\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\The Husar Computer\ntuser.dat Object is locked skipped
C:\Documents and Settings\The Husar Computer\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\The Husar Computer\UserData\index.dat Object is locked skipped
C:\Program Files\Common Files\AOL\ACS\US\static Object is locked skipped
C:\Program Files\Steve Bass's Tips and utilities DL from Snipurl & Oreilly\Big Fix\__Data\Fixlet Central\__Local\Tmp\Gateway-unsub.dat Object is locked skipped
C:\Program Files\Steve Bass's Tips and utilities DL from Snipurl & Oreilly\Big Fix\__Data\Fixlet Central\__Local\Tmp\Gateway.dat Object is locked skipped
C:\Program Files\Steve Bass's Tips and utilities DL from Snipurl & Oreilly\Big Fix\__Data\Fixlet Central\__Local\Tmp\general-800.dat Object is locked skipped
C:\Program Files\Steve Bass's Tips and utilities DL from Snipurl & Oreilly\Big Fix\__Data\Fixlet Central\__Local\Tmp\NewFixlets.dat Object is locked skipped
C:\Program Files\Steve Bass's Tips and utilities DL from Snipurl & Oreilly\Big Fix\__Data\Fixlet Central\__Local\Tmp\security-100.dat Object is locked skipped
C:\Program Files\Steve Bass's Tips and utilities DL from Snipurl & Oreilly\Big Fix\__Data\Fixlet Central\__Local\Tmp\Security-1000.dat Object is locked skipped
C:\Program Files\Steve Bass's Tips and utilities DL from Snipurl & Oreilly\Big Fix\__Data\Fixlet Central\__Local\Tmp\security-1200.dat Object is locked skipped
C:\Program Files\Steve Bass's Tips and utilities DL from Snipurl & Oreilly\Big Fix\__Data\Fixlet Central\__Local\Tmp\security-1300.dat Object is locked skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP144\A0021293.exe Infected: Trojan-Downloader.Win32.Zlob.akc skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP144\A0021294.dll Infected: Trojan-Downloader.Win32.Zlob.akp skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0021504.dll Infected: Trojan-Downloader.Win32.Zlob.akp skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0021511.exe Infected: Trojan-Downloader.Win32.Zlob.akc skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0021513.exe Infected: Trojan-Downloader.Win32.Zlob.ako skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0021556.dll Infected: Trojan-Downloader.Win32.Zlob.akp skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0021557.exe Infected: Trojan-Downloader.Win32.Zlob.akc skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0021559.exe Infected: Trojan-Downloader.Win32.Zlob.ako skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0021592.dll Infected: Trojan-Downloader.Win32.Zlob.akp skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0021593.exe Infected: Trojan-Downloader.Win32.Zlob.akc skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0021594.exe Infected: Trojan-Downloader.Win32.Zlob.ako skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0021619.dll Infected: Trojan-Downloader.Win32.Zlob.akp skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0021620.exe Infected: Trojan-Downloader.Win32.Zlob.akc skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0021622.exe Infected: Trojan-Downloader.Win32.Zlob.ako skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0021648.exe Infected: Trojan-Downloader.Win32.Zlob.akc skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0021649.dll Infected: Trojan-Downloader.Win32.Zlob.akp skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0021651.exe Infected: Trojan-Downloader.Win32.Zlob.ako skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0022660.dll Infected: Trojan-Downloader.Win32.Zlob.akp skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0022661.exe Infected: Trojan-Downloader.Win32.Zlob.akc skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0022663.exe Infected: Trojan-Downloader.Win32.Zlob.ako skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0022687.dll Infected: Trojan-Downloader.Win32.Zlob.akp skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0022688.exe Infected: Trojan-Downloader.Win32.Zlob.akc skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0022689.exe Infected: Trojan-Downloader.Win32.Zlob.ako skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0022712.dll Infected: Trojan-Downloader.Win32.Zlob.akp skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0022713.exe Infected: Trojan-Downloader.Win32.Zlob.ako skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0022714.exe Infected: not-virus:Hoax.Win32.Renos.ev skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0022715.exe Infected: Trojan-Downloader.Win32.Zlob.akc skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP154\A0023395.exe/stream/data0012 Infected: Trojan-Clicker.Win32.Agent.ff skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP154\A0023395.exe/stream Infected: Trojan-Clicker.Win32.Agent.ff skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP154\A0023395.exe NSIS: infected - 2 skipped
C:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP155\change.log Object is locked skipped
C:\WINNT\Debug\PASSWD.LOG Object is locked skipped
C:\WINNT\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{76DD7306-5E23-4A78-9EE4-620BCDC7AECF}.crmlog Object is locked skipped
C:\WINNT\SchedLgU.Txt Object is locked skipped
C:\WINNT\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINNT\Sti_Trace.log Object is locked skipped
C:\WINNT\system32\config\AppEvent.Evt Object is locked skipped
C:\WINNT\system32\config\DEFAULT Object is locked skipped
C:\WINNT\system32\config\default.LOG Object is locked skipped
C:\WINNT\system32\config\SAM Object is locked skipped
C:\WINNT\system32\config\SAM.LOG Object is locked skipped
C:\WINNT\system32\config\SecEvent.Evt Object is locked skipped
C:\WINNT\system32\config\SECURITY Object is locked skipped
C:\WINNT\system32\config\SECURITY.LOG Object is locked skipped
C:\WINNT\system32\config\SOFTWARE Object is locked skipped
C:\WINNT\system32\config\software.LOG Object is locked skipped
C:\WINNT\system32\config\SysEvent.Evt Object is locked skipped
C:\WINNT\system32\config\SYSTEM Object is locked skipped
C:\WINNT\system32\config\system.LOG Object is locked skipped
C:\WINNT\system32\h323log.txt Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINNT\wiadebug.log Object is locked skipped
C:\WINNT\wiaservc.log Object is locked skipped
C:\WINNT\WindowsUpdate.log Object is locked skipped
E:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0021501.exe/data0007 Infected: Trojan-Downloader.Win32.Zlob.akb skipped
E:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0021501.exe NSIS: infected - 1 skipped
E:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP145\A0021501.exe UPX: infected - 1 skipped
E:\System Volume Information\_restore{717DED14-B9DD-4C52-8322-6043B9687C5A}\RP155\change.log Object is locked skipped

Scan process completed.

Hijack This log file:
Logfile of HijackThis v1.99.1
Scan saved at 8:13:40 AM, on 09/22/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\1100827586\ee\AOLSoftware.exe
C:\Program Files\mcafee.com\antivirus\mcvsescn.exe
C:\WINNT\System32\igfxtray.exe
C:\WINNT\System32\hkcmd.exe
C:\WINNT\StartupMonitor.exe
C:\WINNT\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Logitech camera\LogiTray.exe
C:\Program Files\Steve Bass's Tips and utilities DL from Snipurl & Oreilly\Big Fix\BigFix.exe
C:\Program Files\Common Files\AOL\1100827586\ee\services\sscFirewallPlugin\ver1_10_3_1\SSCEvtHdlr.exe
C:\Program Files\Logitech\Logitech camera\FxSvr2.exe
c:\program files\common files\aol\1100827586\ee\services\sscAntiSpywarePlugin\ver1_10_3_1\AOLSP Scheduler.exe
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
C:\WINNT\system32\PackethSvc.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\AOL\1100827586\ee\services\sscFirewallPlugin\ver1_10_3_1\aolavupd.exe
C:\Documents and Settings\The Husar Computer\Desktop\ewido\ewido anti-spyware 4.0\guard.exe
C:\Program Files\mcafee.com\personal firewall\MPFService.exe
E:\WEST DIGI SETTLE BACK-up\retrorun.exe
C:\WINNT\System32\ScsiAccess.EXE
C:\WINNT\System32\svchost.exe
C:\WINNT\wanmpsvc.exe
C:\Program Files\Microsoft Works\wkssb.exe
C:\WINNT\explorer.exe
C:\WINNT\system32\DllHost.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINNT\System32\dllhost.exe
c:\program files\common files\aol\1100827586\ee\aolssc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINNT\system32\NOTEPAD.EXE
C:\PROGRA~1\WINZIP\winzip32.exe
C:\unzipped\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://comcast.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1100827586\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\mcafee.com\antivirus\oasclnt.exe
O4 - HKLM\..\Run: [EmailScan] C:\Program Files\mcafee.com\antivirus\mcvsescn.exe
O4 - HKLM\..\Run: [MPFExe] C:\Program Files\mcafee.com\personal firewall\MPfTray.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
O4 - HKLM\..\Run: [tgcmd] C:\Program Files\Support.com\bin\tgcmd.exe /server /startmonitor /deaf
O4 - HKLM\..\Run: [LVCOMSX] C:\WINNT\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Logitech camera\LogiTray.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0c\AOL.EXE" -b
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\Steve Bass's Tips and utilities DL from Snipurl & Oreilly\Big Fix\BigFix.exe
O8 - Extra context menu item: &Define - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Look Up in &Encyclopedia - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra 'Tools' menuitem: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\WINNT\System32\shdocvw.dll
O9 - Extra button: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra 'Tools' menuitem: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O12 - Plugin for .UVR: C:\Program Files\Internet Explorer\Plugins\NPUPano.dll
O16 - DPF: Word Whomp Whackdown by pogo - http://whackdown.pogo.com/applet/whackdown…n-ob-assets.cab
O16 - DPF: Yahoo! Checkers - http://download.games.yahoo.com/games/clients/y/kt0_x.cab
O16 - DPF: Yahoo! Fleet - http://download.games.yahoo.com/games/clients/y/fltt1_x.cab
O16 - DPF: Yahoo! Freecell Solitaire - http://yog55.games.scd.yahoo.com/yog/y/fs10_x.cab
O16 - DPF: Yahoo! Hearts - http://download.games.yahoo.com/games/clients/y/ht0_x.cab
O16 - DPF: Yahoo! Word Racer - http://download.games.yahoo.com/games/clients/y/wt1_x.cab
O16 - DPF: {0122955E-1FB0-11D2-A238-006097FAEE8B} (CscClnt Class) - http://www.pollg.com/central/02030106/ccca…everContent.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://support.gateway.com/support/profiler/PCPitStop.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {10093E98-C073-4C75-8D0E-FB5CD3A71D33} (ZoneUpwords Object) - http://messenger.zone.msn.com/binary/Upwords.cab31267.cab
O16 - DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} (Controller Class) - https://www.windowsonecare.com/install/cli/…nSSWebAgent.CAB
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {17163BB4-107E-11D4-9B76-006097DF2317} (EABootStrap Class) - http://aol.ea.com/downloads/games/common/b…trap/iegils.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3CC943C7-3C99-11D4-8135-0050041A5144} (RunExeActiveX.UserControl1) - file://C:\Program Files\Gateway\HelpSpot\RunExeActiveX.CAB
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - https://objects.aol.com/mcafee/molbin/share…83/mcinsctl.cab
O16 - DPF: {525A15D0-4938-11D4-94C7-0050DA20189B} (SnoopyCtrl Class) - http://aol.ea.com/downloads/games/common/snoopy/iesnoopy.cab
O16 - DPF: {56393399-041A-4650-94C7-13DFCB1F4665} (PSFormX Control) - http://home3.ca.com/PestPatrol/uniblue/pestscan/pestscan.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1120185828141
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {76D90D08-EAB7-46D8-BF99-87445BF59E72} (SystemInfo Class) - http://orderdway.com/dwayready/dpcsysinfo.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
O16 - DPF: {93CEA8A4-6059-4E0B-ADDD-73848153DD5E} (CWebLaunchCtl Object) - http://gateway.cf1live.com/eSupport/static…h/weblaunch.cab
O16 - DPF: {99CDFD87-F97A-42E1-9C13-D18220D90AD1} (StartFirstControl.CheckFirst) - file://C:\Program Files\Gateway\HelpSpot\StartFirstControl.CAB
O16 - DPF: {9A57B18E-2F5D-11D5-8997-00104BD12D94} (compid Class) - http://www.gateway.com/support/serialharvest/gwCID.CAB
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/…/ymmapi_416.dll
O16 - DPF: {A1B09066-C95C-4EF6-8DFD-3DD0AFE610B6} - http://pak02.pictures.aol.com/ygp/aol/plug…ver.1.0.2.5.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real.com/gameconsole/Bundl…ArcadeRdxIE.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - https://objects.aol.com/mcafee/molbin/share…,20/McGDMgr.cab
O16 - DPF: {BDF9A7C7-F4DC-455D-B5C2-045D74788295} (AOLRegistrationWizard Control) - https://objects.aol.com/filebackup/AOLRegistrationWizard.cab
O16 - DPF: {CA797B15-445F-4AA9-9828-8A88502F560F} (Uninstall Control) - http://www.worldwinner.com/games/shared/uninstall.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O16 - DPF: {CE37E095-ACFF-4380-A856-A560D389E5E1} (XPLControlProject.XPLControl) - file://C:\Program Files\Gateway\HelpSpot\XPLControl.CAB
O16 - DPF: {DC187740-46A9-11D5-A815-00B0D0428C0C} - http://ds1.downloadtech.net/cn1060/pcpowerscan.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.games.yahoo.com/games/popc…aploader_v5.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/ac…/ActiveData.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…635/mcfscan.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Toolbar) - http://us.dl1.yimg.com/download.yahoo.com/…ebio5_1_2_0.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINNT\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINNT\system32\WPDShServiceObj.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AOL Antivirus Update Service (aolavupd) - America Online - C:\Program Files\Common Files\AOL\1100827586\ee\services\sscFirewallPlugin\ver1_10_3_1\aolavupd.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Documents and Settings\The Husar Computer\Desktop\ewido\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINNT\System32\ImapiRox.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINNT\system32\drivers\KodakCCS.exe
O23 - Service: McAfee McShield (McShield) - McAfee Inc. - C:\PROGRA~1\mcafee.com\ANTIVI~1\mcshield.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\Program Files\mcafee.com\personal firewall\MPFService.exe
O23 - Service: Virtual NIC Service (PackethSvc) - America Online, Inc. - C:\WINNT\system32\PackethSvc.exe
O23 - Service: Retrospect Launcher (RetroLauncher) - EMC Corporation - E:\WEST DIGI SETTLE BACK-up\retrorun.exe
O23 - Service: Retrospect Helper - EMC Corporation - E:\WEST DIGI SETTLE BACK-up\rthlpsvc.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINNT\System32\ScsiAccess.EXE
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINNT\wanmpsvc.exe
Hi mountainman,

Good work! Kapersky is almost clean! All you have is the infected _restore files and we will clean those up now.

Turn off System Restore.
  • On the Desktop, right-click My Computer.
  • Click Properties.
  • Click the System Restore tab.
  • Check Turn off System Restore.
  • Click Apply, and then click OK.
Reboot.

Turn ON System Restore.
  • On the Desktop, right-click My Computer.
  • Click Properties.
  • Click the System Restore tab.
  • UN-Check *Turn off System Restore*.
  • Click Apply, and then click OK.
Please review the following to help prevent malware troubles.

STEP 1.
======
DON’T BECOME OVERCONFIDENT WITH ANTIVIRUS APPLICATIONS INSTALLED!!!

http://forum.malwareremoval.com/viewtopic….39eba6ea0b5e8ee

Stay up to date on security patches and be extremely wary of clicking on links and attachments that arrive unbidden in instant messages and e-mail.

"The number one thing the majority of the malicious code we're seeing now does is disable or delete anti-virus and other security software," Dunham said. "In a lot of cases, once the user clicks on that attachment, it's already too late."


Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
  • Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Visit Microsoft's Update Site Frequently - It is important that you visit Windows Updates regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

  • Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option. This will provide realtime spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an antivirus software.
    A tutorial on installing & using this product can be found here:
    Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers

  • Install Ad-Aware - Install and download Ad-Aware. ou should also scan your computer with program on a regular basis just as you would an antivirus software in conjunction with Spybot.
    A tutorial on installing & using this product can be found here:
    Using Ad-aware to remove Spyware, Malware, & Hijackers from Your Computer

  • Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.
    A tutorial on installing & using this product can be found here:
    Using SpywareBlaster to protect your computer from Spyware and Malware

  • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.

  • More info on how to prevent malware you can also find here (By Tony Klein)
Follow this list and your potential for being infected again will reduce dramatically.

Thank you for allowing me to assist you.

Susan
Thank You so much Susan, for all of your hard work helping me. Thank You for all the leg-work you did in helping me get rid of the problems I had. I have used Tom Coyote in the past and have donated to him and will do so again. This is the best website for those who need help with these kind of issues. Keep up the good work! Thank You!! The Mountainman
You are very welcome. :) Glad we could help. Thanks for the compliments concerning TomCoyote and supporting the site.
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI