This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Browser Hijack After Clicking On Google Search Links

128 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey Dan Sorry for the long delay, finding time to do these things is difficult. thanks for staying with me tho, i should be able to get to it next week (i hope) :unsure: uE
Hi Dan

finally got around to doing the scan.

a couple of notes to recap

Yes I did the clear temp files. I've uninstalled nortons and am running avg purch copy, I removed the symantec directory containing all the quaranteen files.

in the hijack this log these entries say "file missing but after checking it appears they arn't missing at all. these files are still there.

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

Here's the kaspersky log. Ive not included all the locked files from the other account (jason) as the post would be too big (like previously). I've gone through them and these are what was found.




Friday, June 22, 2007 4:39:37 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 22/06/2007
Kaspersky Anti-Virus database records: 350779


Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true

Scan Target My Computer
A:\
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\

Scan Statistics
Total number of scanned objects 56760
Number of viruses found 26
Number of infected objects 225 / 0
Number of suspicious objects 2
Duration of the scan process 01:19:28

Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC.zip/ishost.exe Suspicious: Password-protected-EXE skipped

C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC.zip ZIP: suspicious - 1 skipped

C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\SANDY CAUST\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\SANDY CAUST\Desktop\security\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped

C:\Documents and Settings\SANDY CAUST\Desktop\security\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped

C:\Documents and Settings\SANDY CAUST\Desktop\security\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped

C:\Documents and Settings\SANDY CAUST\Desktop\security\SmitfraudFix.exe RarSFX: infected - 2 skipped

C:\Documents and Settings\SANDY CAUST\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped

C:\Documents and Settings\SANDY CAUST\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\SANDY CAUST\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\SANDY CAUST\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\SANDY CAUST\Local Settings\Temp\vurjxoly.dll Infected: Trojan.Win32.BHO.g skipped

C:\Documents and Settings\SANDY CAUST\Local Settings\Temp\~DF8E31.tmp Object is locked skipped

C:\Documents and Settings\SANDY CAUST\Local Settings\Temp\~DFA7E.tmp Object is locked skipped

C:\Documents and Settings\SANDY CAUST\Local Settings\Temp\~DFB17.tmp Object is locked skipped

C:\Documents and Settings\SANDY CAUST\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped

C:\Documents and Settings\SANDY CAUST\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\SANDY CAUST\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\SANDY CAUST\ntuser.dat.LOG Object is locked skipped

C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003235.exe Infected: Trojan-Downloader.Win32.Tiny.eg skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003236.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003237.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003238.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003239.exe Infected: Trojan-Downloader.Win32.Small.cqf skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003240.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003241.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003242.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003243.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003244.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003245.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003246.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003247.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003248.exe Infected: Trojan-Downloader.Win32.Small.dam skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003249.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003250.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003251.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003252.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003253.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003254.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003255.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003256.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003257.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003258.exe Infected: Trojan-Dropper.Win32.Agent.ayl skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003259.dll Infected: Rootkit.Win32.Agent.cg skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003260.exe Infected: Trojan.Win32.VB.abv skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003261.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003262.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003263.dll Infected: Rootkit.Win32.Agent.cg skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003264.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003265.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003266.exe Infected: Backdoor.Win32.Agent.vk skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003267.exe Infected: Trojan-Downloader.Win32.Small.dam skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003268.exe Infected: Trojan.Win32.VB.abv skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003269.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003270.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003271.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003272.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003273.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003274.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003275.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003276.exe Infected: Trojan-Downloader.Win32.Small.dam skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003277.exe Infected: Trojan-Clicker.Win32.Agent.hz skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003278.exe Infected: Trojan-Clicker.Win32.Agent.hz skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003279.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003280.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003281.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003282.exe Infected: Trojan-Downloader.Win32.Small.dam skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003283.dll Infected: Rootkit.Win32.Agent.cg skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003284.dll Infected: Trojan-Downloader.Win32.Tibs.gc skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003285.dll Infected: Trojan-Downloader.Win32.Tibs.gc skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003286.dll Infected: Trojan-Downloader.Win32.Tibs.gc skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003287.dll Infected: Trojan-Downloader.Win32.Tibs.gc skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003288.dll Infected: Trojan-Downloader.Win32.Tibs.gc skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003289.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003290.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003291.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003292.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003293.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003294.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003295.exe Infected: Virus.Win32.Hidrag.a skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003296.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003297.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003298.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003299.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003300.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003301.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003302.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003303.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003304.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003305.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003306.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003307.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003308.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003309.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003310.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003311.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003312.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003313.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003314.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003315.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003316.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003317.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003318.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003319.exe Infected: Trojan-Dropper.Win32.Agent.ayl skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003320.exe Infected: Trojan-Downloader.Win32.Small.ccm skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003321.exe Infected: Trojan-Downloader.Win32.Small.ccm skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003322.exe Infected: Trojan-Downloader.Win32.Small.ccm skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003323.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003324.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003325.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003326.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003327.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003328.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003329.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003330.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003331.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003332.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003333.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003334.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003335.exe Infected: Backdoor.Win32.Agent.vk skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003336.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003337.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003338.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003339.dll Infected: Trojan.Win32.Obfuscated.ar skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003340.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003341.exe Infected: Email-Worm.Win32.Zhelatin.o skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003342.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003343.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003344.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003345.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003346.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003347.exe Infected: Trojan-Downloader.Win32.Small.cqf skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003348.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003349.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003350.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003351.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003352.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003353.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003354.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003355.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003356.dll Infected: Rootkit.Win32.Agent.cg skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003357.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003358.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003359.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003360.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003361.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003362.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003363.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003364.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003365.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003366.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003367.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003368.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003369.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003370.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003371.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003372.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003373.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003374.exe Infected: Trojan-Downloader.Win32.Small.dkt skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003375.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003376.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003377.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003378.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003379.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003381.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003382.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003383.exe Infected: Trojan-Dropper.Win32.Agent.ayl skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003384.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003385.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003386.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003387.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003388.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003389.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003390.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003391.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003392.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003393.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003394.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003395.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003396.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003397.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003398.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003399.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003400.exe Infected: Trojan-Downloader.Win32.Small.dkt skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003401.exe Infected: Trojan-Downloader.Win32.Small.dkt skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003402.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003403.exe Infected: Trojan-Dropper.Win32.Agent.ayl skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003404.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003405.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003406.exe Infected: Trojan.Win32.DNSChanger.hj skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003407.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003408.dll Infected: Trojan-Spy.Win32.BZub.go skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003409.exe Infected: Trojan-Downloader.Win32.Zlob.aow skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003410.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003411.exe Infected: not-virus:Hoax.Win32.Renos.fi skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003412.exe Infected: Trojan-Downloader.Win32.Small.dkt skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003413.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003414.exe Infected: Trojan-Clicker.Win32.Agent.hz skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003415.exe Infected: Trojan-Clicker.Win32.Agent.hz skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003416.dll Infected: Rootkit.Win32.Agent.cg skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003417.pif Infected: Backdoor.Win32.MSNMaker.w skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003418.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003419.dll Infected: Trojan.Win32.Obfuscated.ev skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003420.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003421.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003422.dll Infected: Rootkit.Win32.Agent.cg skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003423.dll Infected: Rootkit.Win32.Agent.cg skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003424.dll Infected: Rootkit.Win32.Agent.cg skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003425.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003426.dll Infected: Rootkit.Win32.Agent.cg skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003427.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003428.exe Infected: Trojan-Clicker.Win32.Agent.hz skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003429.exe Infected: Trojan-Clicker.Win32.Agent.hz skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003430.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003431.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003432.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003433.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003434.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003435.dll Infected: Trojan-Downloader.Win32.Small.cyn skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003436.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003437.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003438.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003439.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003440.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003441.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003442.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003443.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003444.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003445.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003446.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003447.dll Infected: Rootkit.Win32.Agent.cg skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003448.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003449.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003450.exe Infected: Backdoor.Win32.MSNMaker.w skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003451.dll Infected: Trojan.Win32.BHO.g skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003452.dll Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003453.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003454.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped

C:\System Volume Information\_restore{6568D756-9B83-425E-B237-6F9A1F21AEB7}\RP13\A0003455.dll Infected: Trojan.Win32.BHO.g skipped



Logfile of HijackThis v1.99.1
Scan saved at 6:27:02 PM, on 22/06/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADP.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\MSN Messenger\msrg.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\sistray.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer from OptusNet
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [EPSON Stylus CX4700 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADP.EXE /P26 "EPSON Stylus CX4700 Series" /O6 "USB001" /M "Stylus CX4700"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msrg.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.optusnet.com.au/
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by140fd.bay140.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1160365884022
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
Thanks for the returned reports, don't be worried about what HJT reports as missing it has a slight bug in that respect. The only entries you can be sure about are the 02 entries. I will be looking through the post later.I will ask when I want to see a HJT log from the other accounts this admin account we will refer to as "A" and so the following accounts we will call "B" "C" etc saves being confused,well it does for me! Can you check you have sent the complete kaspersky scan as it looks as though its been cut short it may need several posts. A good tip if you select the log then place a line at the bottom ie ======================== if you don't see the line your post has been cut short.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI