Logfile of HijackThis v1.99.1
Scan saved at 1:17:03 AM, on 6/7/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
E:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\acs.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\PROGRA~1\COMMON~1\Stardock\SDMCP.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Motherboard Monitor 5\MBM5.EXE
C:\WINDOWS\Logi_MwX.Exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
C:\PROGRA~1\PESTPA~1\PPControl.exe
C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe
C:\Program Files\Lexmark 1200 Series\lxczbmon.exe
E:\Program Files\Steam\Steam.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\TRENDnet\TEW-441PC_443PI\TRENDnet.exe
E:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
E:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\PROGRA~1\MOZILLA.ORG\MOZILLA\MOZILLA.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Hello\Desktop\Super Secret Porn.... And HJT\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://forums.tomcoyote.org/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~2\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [MBM 5] "C:\Program Files\Motherboard Monitor 5\MBM5.EXE"
O4 - HKLM\..\Run: [InvisibleBrowsing] C:\Program Files\Invisible Browsing\InvisibleBrowsing.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] "C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [PPMemCheck] c:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [PestPatrol Control Center] c:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [CookiePatrol] c:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - HKLM\..\Run: [Lexmark 1200 Series] "C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKCU\..\Run: [Steam] "E:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe
O4 - HKCU\..\Run: [MCW Startup] "E:\Program Files\Monitor Calibration Wizard\MCW.exe" /s
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: LimeWire On Startup.lnk = E:\Program Files\LimeWire\LimeWire.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: 108Mbps Wireless LAN Adapte.lnk = C:\Program Files\TRENDnet\TEW-441PC_443PI\TRENDnet.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = E:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -
http://messenger.zon...kr.cab31267.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky...can_unicode.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) -
http://messenger.zon...nt.cab31267.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.5) -
http://housecall65.t...ivex/hcImpl.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) -
http://www.fileplane...DC_1_0_0_44.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://by104fd.bay10...es/MsnPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -
http://www.bitdefend...can8/oscan8.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.syma...n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zon...nt.cab31267.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) -
http://messenger.zon...ry/ZAxRcMgr.cab
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) -
http://support.f-sec...m/ols/fscax.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn...pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
http://messenger.zon...ro.cab32846.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) -
http://www.windowsec...scan/axscan.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) -
http://www.driverage...driveragent.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) -
http://download.mcaf...699/mcfscan.cab
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) -
http://www.gamespot.com/KDX/kdx.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: MCPClient - C:\PROGRA~1\COMMON~1\Stardock\mcpstub.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: RadClock - Unknown owner - C:\WINDOWS\system32\RadClock.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - E:\Program Files\Sygate\SPF\smc.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)
==================================================================================
Find AWF report by noahdfear ©2006
bak folders found
~~~~~~~~~~~
Directory of C:\PROGRA~1\AIM\BAK
08/05/2005 03:08 PM 67,160 aim.exe
1 File(s) 67,160 bytes
Directory of C:\PROGRA~1\MOTHER~1\BAK
06/12/2004 10:40 AM 594,944 MBM5.EXE
1 File(s) 594,944 bytes
Directory of C:\PROGRA~1\PEERGU~1\BAK
09/18/2005 06:40 PM 1,421,824 pg2.exe
1 File(s) 1,421,824 bytes
Directory of C:\PROGRA~1\PESTPA~1\BAK
01/10/2005 10:35 AM 73,728 CookiePatrol.exe
11/15/2004 12:49 PM 98,304 PPControl.exe
04/02/2004 04:11 PM 148,480 PPMemCheck.exe
3 File(s) 320,512 bytes
Directory of C:\PROGRA~1\QUICKT~1\BAK
12/27/2004 12:47 PM 98,304 qttask.exe
1 File(s) 98,304 bytes
Directory of C:\PROGRA~1\GRISOFT\AVG7\BAK
11/29/2006 05:04 PM 406,016 avgcc.exe
1 File(s) 406,016 bytes
Directory of C:\PROGRA~1\COMMON~1\REAL\UPDATE~1\BAK
10/04/2006 03:17 PM 185,784 realsched.exe
1 File(s) 185,784 bytes
Directory of C:\PROGRA~1\JAVA\JRE15~1.0_0\BIN\BAK
07/26/2006 03:03 AM 49,263 jusched.exe
1 File(s) 49,263 bytes
Directory of E:\PROGRA~1\MONITO~1\BAK
12/28/2005 02:06 AM 768 Daniels.mcw
12/20/2002 06:06 PM 321,024 MCW.exe
12/13/2006 05:09 PM 768 STARTUP
3 File(s) 322,560 bytes
Directory of E:\PROGRA~1\STEAM\BAK
10/08/2006 05:28 PM 1,249,280 Steam.exe
1 File(s) 1,249,280 bytes
Directory of E:\PROGRA~1\STARDOCK\WINCUS~1\BOOTSKIN\BAK
04/26/2004 05:21 PM 270,336 BootSkin.exe
1 File(s) 270,336 bytes
Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~
67160 Aug 5 2005 "C:\Program Files\AIM\aim.exe"
67160 Aug 5 2005 "C:\Program Files\AIM\bak\aim.exe"
594944 Jun 12 2004 "C:\Program Files\Motherboard Monitor 5\MBM5.EXE"
594944 Jun 12 2004 "C:\Program Files\Motherboard Monitor 5\bak\MBM5.EXE"
1421824 Sep 18 2005 "C:\Program Files\PeerGuardian2\bak\pg2.exe"
73728 Jan 10 2005 "C:\Program Files\PestPatrol\CookiePatrol.exe1165978882"
73728 Jan 10 2005 "C:\Program Files\PestPatrol\bak\CookiePatrol.exe"
98304 Nov 15 2004 "C:\Program Files\PestPatrol\PPControl.exe1165978882"
98304 Nov 15 2004 "C:\Program Files\PestPatrol\bak\PPControl.exe"
148480 Apr 19 2003 "C:\Program Files\PestPatrol\PPMemCheck.exe1165978882"
148480 Apr 2 2004 "C:\Program Files\PestPatrol\bak\PPMemCheck.exe"
98304 Dec 27 2004 "C:\Program Files\QuickTime\qttask.exe"
98304 Dec 27 2004 "C:\Program Files\QuickTime\bak\qttask.exe"
416256 May 1 2007 "C:\Program Files\Grisoft\AVG7\avgcc.exe"
406016 Nov 29 2006 "C:\Program Files\Grisoft\AVG7\bak\avgcc.exe"
185784 Oct 4 2006 "C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe"
83608 Mar 14 2007 "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
49263 Jul 26 2006 "C:\Program Files\Java\jre1.5.0_08\bin\bak\jusched.exe"
768 Dec 28 2005 "E:\Program Files\Monitor Calibration Wizard\Daniels.mcw"
768 Dec 28 2005 "E:\Program Files\Monitor Calibration Wizard\bak\Daniels.mcw"
321024 Dec 20 2002 "E:\Program Files\Monitor Calibration Wizard\MCW.exe"
321024 Dec 20 2002 "E:\Program Files\Monitor Calibration Wizard\bak\MCW.exe"
39936 Aug 5 2005 "C:\Program Files\AIM\startup.ocm"
362577 Jan 28 2005 "C:\Program Files\Spybot - Search & Destroy\Updates\startup.zip"
362599 Sep 29 2006 "C:\Program Files\Spybot - Search & Destroy1\Updates\startup.zip"
16812 Nov 19 2003 "C:\WINDOWS\Resources\Themes\Destiny\Sounds\StartUp.wav"
16812 Nov 19 2003 "C:\WINDOWS\Resources\Themes\SilverMAX\Sounds\StartUp.wav"
16812 Nov 19 2003 "C:\WINDOWS\Resources\Themes\Visions\Sounds\StartUp.wav"
768 Mar 20 2007 "E:\Program Files\Monitor Calibration Wizard\STARTUP"
1885 May 14 2004 "E:\Games\UT2004\System\Startup.int"
768 Dec 13 2006 "E:\Program Files\Monitor Calibration Wizard\bak\STARTUP"
4331 Nov 19 2001 "E:\Games\Put Games Here\UT1\System\Startup.int"
129078 Oct 7 1999 "E:\Program Files\Winlogos\themes\Techno\Startup.bmp"
1259000 Jun 2 2007 "E:\Program Files\Steam\Steam.exe"
1249280 Oct 8 2006 "E:\Program Files\Steam\bak\Steam.exe"
270336 Apr 26 2004 "E:\Program Files\Stardock\WinCustomize\BootSkin\BootSkin.exe"
270336 Apr 26 2004 "E:\Program Files\Stardock\WinCustomize\BootSkin\bak\BootSkin.exe"
end of report
==================================================================================
C:\Documents and Settings\All Users\Application Data\Avg7\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4af38191d2ab3248fc8eb14f36f9f1c9_5665b25f-fb83-4b68-ac04-9f5e355ecd5d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SpySheriff.zip/Uninstall.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SpySheriff.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\Hello\.housecall\Quarantine\20050127170952.zip.bac_a02612/Documents and Settings/Hello/Local Settings/Temp/bb.exe/stream/data0001 Infected: not-a-virus:AdWare.Win32.BargainBuddy.l skipped
C:\Documents and Settings\Hello\.housecall\Quarantine\20050127170952.zip.bac_a02612/Documents and Settings/Hello/Local Settings/Temp/bb.exe/stream/data0002 Infected: not-a-virus:AdWare.Win32.BargainBuddy.q skipped
C:\Documents and Settings\Hello\.housecall\Quarantine\20050127170952.zip.bac_a02612/Documents and Settings/Hello/Local Settings/Temp/bb.exe/stream/data0003 Infected: not-a-virus:AdWare.Win32.BargainBuddy.q skipped
C:\Documents and Settings\Hello\.housecall\Quarantine\20050127170952.zip.bac_a02612/Documents and Settings/Hello/Local Settings/Temp/bb.exe/stream/data0005 Infected: Trojan-Clicker.Win32.VB.ex skipped
C:\Documents and Settings\Hello\.housecall\Quarantine\20050127170952.zip.bac_a02612/Documents and Settings/Hello/Local Settings/Temp/bb.exe/stream/data0006/stream/data0001 Infected: not-a-virus:AdWare.Win32.BargainBuddy.n skipped
C:\Documents and Settings\Hello\.housecall\Quarantine\20050127170952.zip.bac_a02612/Documents and Settings/Hello/Local Settings/Temp/bb.exe/stream/data0006/stream Infected: not-a-virus:AdWare.Win32.BargainBuddy.n skipped
C:\Documents and Settings\Hello\.housecall\Quarantine\20050127170952.zip.bac_a02612/Documents and Settings/Hello/Local Settings/Temp/bb.exe/stream/data0006 Infected: not-a-virus:AdWare.Win32.BargainBuddy.n skipped
C:\Documents and Settings\Hello\.housecall\Quarantine\20050127170952.zip.bac_a02612/Documents and Settings/Hello/Local Settings/Temp/bb.exe/stream/data0007/stream/data0002 Infected: not-a-virus:AdWare.Win32.BargainBuddy.y skipped
C:\Documents and Settings\Hello\.housecall\Quarantine\20050127170952.zip.bac_a02612/Documents and Settings/Hello/Local Settings/Temp/bb.exe/stream/data0007/stream/data0005 Infected: not-a-virus:AdWare.Win32.BargainBuddy.n skipped
C:\Documents and Settings\Hello\.housecall\Quarantine\20050127170952.zip.bac_a02612/Documents and Settings/Hello/Local Settings/Temp/bb.exe/stream/data0007/stream/data0006 Infected: not-a-virus:AdWare.Win32.BargainBuddy.n skipped
C:\Documents and Settings\Hello\.housecall\Quarantine\20050127170952.zip.bac_a02612/Documents and Settings/Hello/Local Settings/Temp/bb.exe/stream/data0007/stream/data0007 Infected: not-a-virus:AdWare.Win32.BargainBuddy.n skipped
C:\Documents and Settings\Hello\.housecall\Quarantine\20050127170952.zip.bac_a02612/Documents and Settings/Hello/Local Settings/Temp/bb.exe/stream/data0007/stream/data0008 Infected: not-a-virus:AdWare.Win32.BargainBuddy.l skipped
C:\Documents and Settings\Hello\.housecall\Quarantine\20050127170952.zip.bac_a02612/Documents and Settings/Hello/Local Settings/Temp/bb.exe/stream/data0007/stream Infected: not-a-virus:AdWare.Win32.BargainBuddy.l skipped
C:\Documents and Settings\Hello\.housecall\Quarantine\20050127170952.zip.bac_a02612/Documents and Settings/Hello/Local Settings/Temp/bb.exe/stream/data0007 Infected: not-a-virus:AdWare.Win32.BargainBuddy.l skipped
C:\Documents and Settings\Hello\.housecall\Quarantine\20050127170952.zip.bac_a02612/Documents and Settings/Hello/Local Settings/Temp/bb.exe/stream Infected: not-a-virus:AdWare.Win32.BargainBuddy.l skipped
C:\Documents and Settings\Hello\.housecall\Quarantine\20050127170952.zip.bac_a02612/Documents and Settings/Hello/Local Settings/Temp/bb.exe Infected: not-a-virus:AdWare.Win32.BargainBuddy.l skipped
C:\Documents and Settings\Hello\.housecall\Quarantine\20050127170952.zip.bac_a02612 ZIP: infected - 16 skipped
C:\Documents and Settings\Hello\.housecall\Quarantine\20050127170952.zip.bac_a02612 CryptFF.b: infected - 16 skipped
C:\Documents and Settings\Hello\.housecall6.6\Quarantine\20050127170952.zip.bac_a02612/Documents and Settings/Hello/Local Settings/Temp/bb.exe/stream/data0001 Infected: not-a-virus:AdWare.Win32.BargainBuddy.l skipped
C:\Documents and Settings\Hello\.housecall6.6\Quarantine\20050127170952.zip.bac_a02612/Documents and Settings/Hello/Local Settings/Temp/bb.exe/stream/data0002 Infected: not-a-virus:AdWare.Win32.BargainBuddy.q skipped
C:\Documents and Settings\Hello\.housecall6.6\Quarantine\20050127170952.zip.bac_a02612/Documents and Settings/Hello/Local Settings/Temp/bb.exe/stream/data0003 Infected: not-a-virus:AdWare.Win32.BargainBuddy.q skipped
C:\Documents and Settings\Hello\.housecall6.6\Quarantine\20050127170952.zip.bac_a02612/Documents and Settings/Hello/Local Settings/Temp/bb.exe/stream/data0005 Infected: Trojan-Clicker.Win32.VB.ex skipped
C:\Documents and Settings\Hello\.housecall6.6\Quarantine\20050127170952.zip.bac_a02612/Documents and Settings/Hello/Local Settings/Temp/bb.exe/stream/data0006/stream/data0001 Infected: not-a-virus:AdWare.Win32.BargainBuddy.n skipped
C:\Documents and Settings\Hello\.housecall6.6\Quarantine\20050127170952.zip.bac_a02612/Documents and Settings/Hello/Local Settings/Temp/bb.exe/stream/data0006/stream Infected: not-a-virus:AdWare.Win32.BargainBuddy.n skipped
C:\Documents and Settings\Hello\.housecall6.6\Quarantine\20050127170952.zip.bac_a02612/Documents and Settings/Hello/Local Settings/Temp/bb.exe/stream/data0006 Infected: not-a-virus:AdWare.Win32.BargainBuddy.n skipped
C:\Documents and Settings\Hello\.housecall6.6\Quarantine\20050127170952.zip.bac_a02612/Documents and Settings/Hello/Local Settings/Temp/bb.exe/stream/data0007/stream/data0002 Infected: not-a-virus:AdWare.Win32.BargainBuddy.y skipped
C:\Documents and Settings\Hello\.housecall6.6\Quarantine\20050127170952.zip.bac_a02612/Documents and Settings/Hello/Local Settings/Temp/bb.exe/stream/data0007/stream/data0005 Infected: not-a-virus:AdWare.Win32.BargainBuddy.n skipped
C:\Documents and Settings\Hello\.housecall6.6\Quarantine\20050127170952.zip.bac_a02612/Documents and Settings/Hello/Local Settings/Temp/bb.exe/stream/data0007/stream/data0006 Infected: not-a-virus:AdWare.Win32.BargainBuddy.n skipped
C:\Documents and Settings\Hello\.housecall6.6\Quarantine\20050127170952.zip.bac_a02612/Documents and Settings/Hello/Local Settings/Temp/bb.exe/stream/data0007/stream/data0007 Infected: not-a-virus:AdWare.Win32.BargainBuddy.n skipped
C:\Documents and Settings\Hello\.housecall6.6\Quarantine\20050127170952.zip.bac_a02612/Documents and Settings/Hello/Local Settings/Temp/bb.exe/stream/data0007/stream/data0008 Infected: not-a-virus:AdWare.Win32.BargainBuddy.l skipped
C:\Documents and Settings\Hello\.housecall6.6\Quarantine\20050127170952.zip.bac_a02612/Documents and Settings/Hello/Local Settings/Temp/bb.exe/stream/data0007/stream Infected: not-a-virus:AdWare.Win32.BargainBuddy.l skipped
C:\Documents and Settings\Hello\.housecall6.6\Quarantine\20050127170952.zip.bac_a02612/Documents and Settings/Hello/Local Settings/Temp/bb.exe/stream/data0007 Infected: not-a-virus:AdWare.Win32.BargainBuddy.l skipped
C:\Documents and Settings\Hello\.housecall6.6\Quarantine\20050127170952.zip.bac_a02612/Documents and Settings/Hello/Local Settings/Temp/bb.exe/stream Infected: not-a-virus:AdWare.Win32.BargainBuddy.l skipped
C:\Documents and Settings\Hello\.housecall6.6\Quarantine\20050127170952.zip.bac_a02612/Documents and Settings/Hello/Local Settings/Temp/bb.exe Infected: not-a-virus:AdWare.Win32.BargainBuddy.l skipped
C:\Documents and Settings\Hello\.housecall6.6\Quarantine\20050127170952.zip.bac_a02612 ZIP: infected - 16 skipped
C:\Documents and Settings\Hello\.housecall6.6\Quarantine\20050127170952.zip.bac_a02612 CryptFF.b: infected - 16 skipped
C:\Documents and Settings\Hello\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Hello\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Hello\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Hello\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Hello\Local Settings\History\History.IE5\MSHist012007060620070607\index.dat Object is locked skipped
C:\Documents and Settings\Hello\Local Settings\Temp\~DF2A54.tmp Object is locked skipped
C:\Documents and Settings\Hello\Local Settings\Temp\~DF4C68.tmp Object is locked skipped
C:\Documents and Settings\Hello\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Hello\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Hello\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\PestPatrol\Quarantine\20050202215309.zip/Program Files/AT-Games/WebRebates_Auto_InstallSilent.exe/data0003/data0001 Infected: not-a-virus:AdWare.Win32.WebRebates.g skipped
C:\Program Files\PestPatrol\Quarantine\20050202215309.zip/Program Files/AT-Games/WebRebates_Auto_InstallSilent.exe/data0003 Infected: not-a-virus:AdWare.Win32.WebRebates.g skipped
C:\Program Files\PestPatrol\Quarantine\20050202215309.zip/Program Files/AT-Games/WebRebates_Auto_InstallSilent.exe/data0003 Infected: not-a-virus:AdWare.Win32.WebRebates.b skipped
C:\Program Files\PestPatrol\Quarantine\20050202215309.zip/Program Files/AT-Games/WebRebates_Auto_InstallSilent.exe/data0004 Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Program Files\PestPatrol\Quarantine\20050202215309.zip/Program Files/AT-Games/WebRebates_Auto_InstallSilent.exe/data0005 Infected: not-a-virus:AdWare.Win32.WebRebates.b skipped
C:\Program Files\PestPatrol\Quarantine\20050202215309.zip/Program Files/AT-Games/WebRebates_Auto_InstallSilent.exe Infected: not-a-virus:AdWare.Win32.WebRebates.b skipped
C:\Program Files\PestPatrol\Quarantine\20050202215309.zip ZIP: infected - 6 skipped
C:\Program Files\PestPatrol\Quarantine\20060508221511.zip/Documents and Settings/Hello/Desktop/Super Secret Porn.... And HJT/backups/backup-20060129-152747-601.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\PestPatrol\Quarantine\20060508221511.zip ZIP: infected - 1 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{299937F3-0AFF-4179-94BC-F2DA8F7C36FE}\RP463\A0105757.exe Object is locked skipped
C:\System Volume Information\_restore{299937F3-0AFF-4179-94BC-F2DA8F7C36FE}\RP477\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
E:\Program Files\Sygate\SPF\debug.log Object is locked skipped
E:\Program Files\Sygate\SPF\rawlog.log Object is locked skipped
E:\Program Files\Sygate\SPF\seclog.log Object is locked skipped
E:\Program Files\Sygate\SPF\syslog.log Object is locked skipped
E:\Program Files\Sygate\SPF\tralog.log Object is locked skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
E:\System Volume Information\_restore{299937F3-0AFF-4179-94BC-F2DA8F7C36FE}\RP477\change.log Object is locked skipped
Scan process completed.
================================================================================
System is running like usual... lol.
Edited by karamazov, 07 June 2007 - 12:17 AM.
Sometimes to maintain your authority in the face of criticism, you have to make stuff up.