This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved]Vundo On My Windows Xp Machine

25 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Trevuren,

Here is the ComboFix log and HJT Log:

Regards, Khilafat


ComboFix 07-08-11 - "Salil" 2007-08-17 23:50:05.6 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.223 [GMT -4:00]
Command switches used :: C:\Documents and Settings\Salil\Desktop\CFScript.txt


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\Salil\APPLIC~1\hidn
C:\DOCUME~1\Salil\APPLIC~1\m
C:\DOCUME~1\Salil\APPLIC~1\m\list.oct
C:\DOCUME~1\Salil\APPLIC~1\m\shared\1503 a.d
C:\DOCUME~1\Salil\APPLIC~1\m\shared\after dark screensaver - star trek tng mac
C:\DOCUME~1\Salil\APPLIC~1\m\shared\codename panzers
C:\DOCUME~1\Salil\APPLIC~1\m\shared\command & conquer 3
C:\DOCUME~1\Salil\APPLIC~1\m\shared\esms executive outlook 3.4.18 crack.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\esoft audio converter v2.3.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\esoft interactives tower mogul v1.2.0 crack by tsrh.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\esoft interactives tower mogul v1.2.0.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\espanadir clasific pro v1.5.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\espion 2004 v4.0 multilanguage.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\espion 2004 v4.0 unique by fff serial number.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\espion 2004 v4.0 unique serial by fff.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\espion 2004 v4.0 unique.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\espion 2004 v4.0.1 by fff serial number.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\espion 2004 v4.0.1 multilanguage.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\espion 2004 v4.0.1 serial by fff.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\espion.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\espos 2.2 crack.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\espos v1.9 keygen - ucf.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\esquotes v1.0 by distinct.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\esrd stresscheck v5.0.76.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\esrd stresscheck v5.0.82.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\esri arcview v3.3 serial number.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\esri arcview v3.3.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\esri shapefile plug-in for gis.net 1.1.3 crack.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\essen cyber outlet 2.6 crack.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\essential nettools 2.2 build 55 by core.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\essential nettools 4 build 180 crack.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\essential nettools v2.02.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\essential nettools v3.0 build 75.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\essential nettools v3.0 build 87 by evaluator.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\essential nettools v3.0 build 87 by tsrh.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\essential nettools v3.2 build 130 multilanguage.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\essential tools for visual basic v6.0.97 keygen by core.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\essential tools for visual basic v6.0.98 serial number.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\essential tools for visual basic v6.0.98.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\essentialpim 1.71 crack.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\estimate master v2.16.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\estimate master v3.03 by scf.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\estimate master v3.03.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\estimating - invoicing - payroll 2.1.0.5b crack.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\estimator v1.65.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\estop! standard edition v3.30 by revenge serial number.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\estop! standard edition v3.30 keygen by dt.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\estop! standard edition v3.30.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\estos procall v2.05 by eclipse.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\estos procall v2.05.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\estos procall v2.06.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\estsoft alzip v5.2 keygen by eclipse.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\esybill 1.0 crack.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etabs nl v8.4.6 update crack by lnd.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etabs nl v8.4.7 update.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etd security scanner v3.0 professional serial by mad max.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eternal lines etlin http proxy v1.0.0.26 crack by underpl.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etextwizard 1.98 build 550 crack.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etherboss msn messenger conversation monitor & sniffer 1.1 crack.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etherdetect packet sniffer 1.2 crack.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etherdetect packet sniffer v1.1 patch by lash.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\ethereal - network protocol analyzer 0.10.14 crack.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etherlords demo 2 crack.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etherlords ii patch 1.03 crack.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etherpeek 4.2.1.1.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etherpeek v3.0 serial number.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etherpeek v3.0.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etherpeek v3.5.1 serial number.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etherpeek v4.0 serial number.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etherpeek v4.0.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etherpeek v4.1 demo.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etherpeek v4.2.0.2.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etherpeek v4.2.1.1.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etherpeek wildpackets nx serial number.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etherpeek wildpackets nx.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etherscan analyzer 1.2 build 1237 crack.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eti camcorder 2 (nokia 66xx) 2.01 crack.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etienne mp3 manager v1.01 keygen by core.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etiketten-designer 99 v1.00.7.05b serial by dbc.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etiketten-designer 99 v1.00.7.05b.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etimusoft 3d live pool v2.3, v2.32, v2.34, v2.35 crack by fff.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etimusoft 3d live pool v2.3, v2.32, v2.34, v2.35.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etiumsoft 3d live pool v2.35.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etka 2002 vw, audi.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etka seat 06001.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etka v6.2 skoda.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etoken universal license generator by hkz.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etoken universal license generator.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etresoft decoder v3.1 keygen by again.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etresoft decoder v3.1.1 keygen by again.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etresoft decoder v3.1.1.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etresoft decoder v3.1.3 keygen by eclipse.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etresoft decoder v3.1.4 keygen by eclipse.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etresoft decoder v3.1.4.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etresoft decoder v3.1.5.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etresoft decoder v3.1.7 serial number.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etresoft decoder v3.1.7.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etresoft.decoder.v3.0.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etrust antivirus v7.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etrust ez antivirus 2005 v7.0.1.4 final serial number.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etrust ez antivirus 2005 v7.0.1.4 final.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etrust ez antivirus 2005 v7.0.1.4 keygen by ror.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etrust ez antivirus 2005 v7.0.1.4 serial number.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etrust ez antivirus 2005 v7.0.1.4.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etrust ez antivirus 2005 v7.0.3.1 keygen by again.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etrust ez antivirus 2005 v7.0.3.1 serial number.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etrust ez antivirus 2005 v7.0.3.1.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etrust ez firewal 2005 v4.5 serial number.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etrust intrusion detection elite edition v1.5 serial number.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etrust pestpatrol v5.0 anti-spyware serial number.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etrust pestpatrol v5.0 anti-spyware.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etrust pestpatrol v5.0 anti spyware serial by yag.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etrust pestpatrol v5.0 anti spyware.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\ets carbu v1.20 serial by dbc.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etude sight reader 1.2.202 crack.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etymonix mpeg-2 video codec v1.0 keygen by core.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\etymonix mpeg-2 video codec v1.0x serial number.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\euchre buddy for pogo 1.6 crack.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\euclide v1.3 crack.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\euclide v2.1 serial by tnt.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eudora internet suite 2.1 crack.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eudora v4.0 x-mailer and x-sender er patch.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eudora v5.2 italian.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eudora v6.1 serial number.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eufa euro 2004 keygen by razor.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eufa euro 2004.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eugenius v1.7.25 serial number.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\euklid dynageo 2.5d crack.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\euklid dynageo v2.2d serial number.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\euklid dynageo v2.3 serial number.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\euklides v2.2 by enfusia serial number.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\euler quaternion pro 1.0 crack.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eureka v1.0 keygen by core.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurekalog v4.2.3 enterprise serial by ror.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\euritel v2.1.0 serial number.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\euritel v2.1.0.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\euro 2004 - german serial number.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\euro converter v2.2.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\euro cup manager 2004 1.0 crack.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\euro millions manager 1.0w crack.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\euro office box 2000 v4.0.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\euro plus nicelabel pro v3.6.4 serial number.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\euro.calc 1.4 for palmos.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\euro2000.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\euroglot 3.0 prof..zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\euroglot computer telekommunikation.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\euroglot supplements.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\euroglot technik by amok.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\euroglot technik.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\euroglot v3.0 prof upd.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\euroglot woerterbuch computertechnik serial number.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\euroglot woerterbuch computertechnik.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\euroglot woerterbuch medizin.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\euroglot woerterbuch technik.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\euroglot woerterbuch umgangssprache serial number.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurokey conversion v2003.2.10 by dbc.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurokey conversion v2003.2.10.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\europa universalis ii 1.02 to 1.03 patch crack.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\europa universalis se no dk v1.09.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\europlus + reward millenium.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurosystems eurovector 2 crack by signmaker.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurothink adresses 2002.1.10.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurothink adresses v2003.1.21 by dbc.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurothink adresses v2003.1.21.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurothink agenda v1.50.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurothink agenda v2003.1.21 by dbc.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurothink archives perso v2.00 crack by fff.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurothink bibliotheque v1.21 crack by fff.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurothink bibliotheque v1.21.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurothink cdtheque v1.50 crack by fff.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurothink cdtheque v1.50.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurothink cheque v1.13 crack by fff.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurothink cheque v1.13.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurothink compte v1.11 crack by fff.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurothink compte v1.11.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurothink consommation v1.11 crack by fff.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurothink consommation v1.11.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurothink eurokey conv2003 v2.10 crack by fff.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurothink eurokey conv2003 v2.10.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurothink inventaire perso v2.01 crack by fff.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurothink inventaire perso v2.01.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurothink smart organizer pro v1.5x crack by fff.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurothink supermarche v1.10 crack by fff.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eurothink supermarche v1.10.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eusms 4.1 crack.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eusoftware wizardbrush v5.5.3 keygen by nitrous.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eutron planet-share interfax v3.2.x english and italian.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\evanescence font crack.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\evasion3d meshpaint v1.0 for lightwave3d.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\evasion3d x-dof v2.0 for 3dsmax 7 keygen by paradox.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\evasion3d x-dof v2.0 for 3dsmax 7.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eve 2.0.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eve online - the second genesis 1.2.1 crack.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eve v2.0 for window serial number.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eve v2.2 keygen by tno.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\event calendar v8.0 serial number.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\event calendar v8.0.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\event manager v2.23 serial number.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\event manager v2.23.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\event manager v2.5 serial number.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\event manager v2.5.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eventcorder suite 2.0.41 crack.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eventcorder suite v2.0.34.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eventcorder suite v2.0.41 serial number.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eventcorder suite v2.0.42 keygen by nitrous.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eventcorder suite v2.0.42.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\eventid net eventreader v1.6.1 patch by ssg.zip
C:\DOCUME~1\Salil\APPLIC~1\m\shared\half-life
C:\DOCUME~1\Salil\APPLIC~1\m\shared\medal of honor
C:\DOCUME~1\Salil\APPLIC~1\m\shared\need for speed 5
C:\DOCUME~1\Salil\APPLIC~1\m\srvlist.oct


((((((((((((((((((((((((( Files Created from 2007-07-18 to 2007-08-18 )))))))))))))))))))))))))))))))


2007-08-16 20:04 d——– C:\RegistryBackup_16Aug
2007-08-12 09:16 135,168 –a—— C:\WINDOWS\SYSTEM32\igfxres.dll
2007-08-11 07:34 11,264 –a—— C:\WINDOWS\SYSTEM32\SpOrder.dll
2007-08-11 07:34 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\MailFrontier
2007-08-10 21:22 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-09 23:04 d——– C:\SAV32CLI
2007-08-05 19:40 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
2007-08-05 19:39 89,088 –a—— C:\WINDOWS\SYSTEM32\atl71.dll
2007-08-04 17:11 d——– C:\Temp
2007-07-31 20:17 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kodak


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2008-08-09 00:01 ——— d——– C:\Program Files\McAfee.com
2008-08-08 22:03 ——— d——– C:\Program Files\Trend Micro
2007-08-10 22:19 ——— d——– C:\Program Files\MSN Gaming Zone
2007-08-10 08:17 ——— d——– C:\Program Files\Dell Support
2007-08-09 23:44 ——— d——– C:\Program Files\Common Files\xing shared
2007-08-09 23:43 ——— d——– C:\Program Files\Common Files\Borland Shared
2007-08-05 19:45 ——— d——– C:\Program Files\Google
2007-07-07 18:24 ——— d——– C:\Program Files\Microsoft Money 2006
2007-06-26 11:13 851968 ——— C:\WINDOWS\system32\dllcache\vgx.dll
2007-06-26 10:09 658944 ——— C:\WINDOWS\system32\dllcache\wininet.dll
2007-06-26 02:08 1104896 –a—— C:\WINDOWS\system32\msxml3.dll
2007-06-26 02:08 1104896 ——— C:\WINDOWS\system32\dllcache\msxml3.dll
2007-06-19 09:31 282112 –a—— C:\WINDOWS\system32\gdi32.dll
2007-06-19 09:31 282112 ——— C:\WINDOWS\system32\dllcache\gdi32.dll
2007-06-14 14:09 96256 –a—— C:\WINDOWS\system32\dllcache\inseng.dll
2007-06-14 14:09 615424 ——— C:\WINDOWS\system32\dllcache\urlmon.dll
2007-06-14 14:09 55808 –a—— C:\WINDOWS\system32\dllcache\extmgr.dll
2007-06-14 14:09 532480 ——— C:\WINDOWS\system32\dllcache\mstime.dll
2007-06-14 14:09 474112 ——— C:\WINDOWS\system32\dllcache\shlwapi.dll
2007-06-14 14:09 449024 ——— C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-06-14 14:09 39424 ——— C:\WINDOWS\system32\dllcache\pngfilt.dll
2007-06-14 14:09 357888 ——— C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-06-14 14:09 3058688 ——— C:\WINDOWS\system32\dllcache\mshtml.dll
2007-06-14 14:09 251392 ——— C:\WINDOWS\system32\dllcache\iepeers.dll
2007-06-14 14:09 205312 ——— C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-06-14 14:09 16384 –a—— C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-06-14 14:09 151040 ——— C:\WINDOWS\system32\dllcache\cdfview.dll
2007-06-14 14:09 1494528 ——— C:\WINDOWS\system32\dllcache\shdocvw.dll
2007-06-14 14:09 146432 ——— C:\WINDOWS\system32\dllcache\msrating.dll
2007-06-14 14:09 1054208 ——— C:\WINDOWS\system32\dllcache\danim.dll
2007-06-14 14:09 1023488 ——— C:\WINDOWS\system32\dllcache\browseui.dll
2007-06-14 10:07 18432 ——— C:\WINDOWS\system32\dllcache\iedw.exe
2007-06-13 06:23 1033216 –a—— C:\WINDOWS\explorer.exe
2007-06-13 06:23 1033216 ——— C:\WINDOWS\system32\dllcache\explorer.exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" []
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-05-24 21:23]
"{30-0A-AF-F4-ZN}"="C:\windows\system32\ppdsregr.exe" []
"OfficeScanNT Monitor"="C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" [2006-02-07 17:16]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 09:35]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 09:32]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 09:36]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56]
"Sonic RecordNow!"="" []
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-03-27 15:22]

C:\Documents and Settings\Salil\Start Menu\Programs\Startup\
DESKTOP.INI [2002-09-03 10:00:00]
Webshots.lnk - C:\Program Files\Webshots\Launcher.exe [2005-04-23 13:23:05]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
DESKTOP.INI [2002-09-03 10:00:00]
Snapfish Picture Mover.lnk - C:\Program Files\Snapfish Picture Mover\SnapfishPictureMover.exe [2006-12-19 17:08:38]

R1 cdrbsvsd;cdrbsvsd;C:\WINDOWS\system32\drivers\cdrbsvsd.sys
R2 ntrtscan;OfficeScanNT RealTime Scan;"C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe"
R2 TM_CFW;Common Firewall Driver;\??\C:\Program Files\Trend Micro\OfficeScan Client\tm_cfw.sys
R2 tmlisten;OfficeScanNT Listener;"C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe"
R2 TmPreFilter;Trend Micro PreFilter;\??\C:\Program Files\Trend Micro\OfficeScan Client\TmPreFlt.sys
R3 IPSECSHM;Nortel IPSECSHM Adapter;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys
R3 PD0620VID;Creative WebCam Instant;C:\WINDOWS\system32\DRIVERS\P0620Vid.sys
S2 IPSECEXT;Nortel Extranet Access Protocol;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys


Contents of the 'Scheduled Tasks' folder
2007-08-18 03:51:00 C:\WINDOWS\Tasks\McAfee.com Update Check (KODKANI-Gauri).job - C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
2007-08-18 03:53:00 C:\WINDOWS\Tasks\McAfee.com Update Check (KODKANI-Salil).job - C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
2005-07-01 02:28:00 C:\WINDOWS\Tasks\Run Salil's Calculator.job - C:\WINDOWS\SYSTEM32\CALC.EXE

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-17 23:53:15
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-17 23:54:09
C:\ComboFix-quarantined-files.txt … 2007-08-17 23:53
C:\ComboFix2.txt … 2007-08-16 20:19
C:\ComboFix3.txt … 2007-08-15 21:22

— E O F —



===============

HJT LOG

===============


Logfile of HijackThis v1.99.1
Scan saved at 11:55:37 PM, on 8/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
C:\WINDOWS\TEMP\HA8AD5.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Snapfish Picture Mover\SnapfishPictureMover.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Trend Micro\OfficeScan Client\Pop3Trap.exe
C:\Program Files\Trend Micro\OfficeScan Client\pccntupd.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Hijackthis\Killer.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/mywaybiz
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [{30-0A-AF-F4-ZN}] C:\windows\system32\ppdsregr.exe SKY009
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Snapfish Picture Mover.lnk = C:\Program Files\Snapfish Picture Mover\SnapfishPictureMover.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {3DC2E31C-371A-4BD3-9A27-CDF57CE604CF} (MSN Money Charting) - http://moneycentral.msn.com/cabs/pmupd806.exe
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = cinci.rr.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = cinci.rr.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = cinci.rr.com
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
There is a file in your log of which I am unsure. For that reason, I need you to submit it to Jotti's for analysis.

1. Click HERE to get to Jotti's site.

2. At the top of the Jotti window, use the Browse button to locate the following file on your system:

C:\windows\system32\ppdsregr.exe

3. Once you have located the file, click SUBMIT and the content of the file will be uploaded by the site and analysed.

4. Please provide me with the results of the analysis.

Regards,

Trevuren
Hi Trevuren, I could not find the file you mentioned in that folder. So I tried to show hidden files for the system32 folder. There was an error while the system tried to do this and now I cannot see system32 folder at all under C:\windows. I hope I have not messed things up. Regards, Khilafat
PLEASE do not try things on your own. It just creates a lot of work for no good reason. Thanks I will try to find out about your problem. Trevuren
Try the following:

Go Start>>Run and type cmd and hit OK. A black window will appear on your desktop

Now at the command prompt type the following and hit Enter after each command:

cd..
cd\C:\Windows
attrib -a -h -r -s c:\windows\system32


Now EXIT the black window and look to see if your C:\Windows\System32 folder is now visible.
Hi Trevuren, With the steps you mentioned I can now the system32 folder! Thanks. However, I cannot see the ppdsregr.exe file in that folder. Regards, Khilafat
The file is probably missing due to a prior deletion

Please RUN HijackThis
  • Click the SCAN button to produce a log.

  • Place a check mark beside each one of the following items:

    O4 - HKLM\..\Run: [{30-0A-AF-F4-ZN}] C:\windows\system32\ppdsregr.exe SKY009

  • Now with all the items selected, and all windows closed except for HJT, delete them by clicking the FIX checked button. Close the HijackThis window.


Please use the Internet Explorer browser, and do an online scan with Kaspersky Online Scanner
Click Yes, when prompted to install its ActiveX component.
(Note.. for Internet Explorer 7 users: If at any time you have trouble with the "Accept" button of the license, click on the "Zoom" tool located at the bottom right of the IE window and set the zoom to 75 %. Once the license has been accepted, reset to 100%.)
The program launches and downloads the latest definition files.
  • Once the files are downloaded click on Next
  • Click on Scan Settings and configure as follows:
    • Scan using the following Anti-Virus database:
      • Extended
    • Scan Options:Scan Archives
      Scan Mail Bases
  • Click OK and, under select a target to scan, select My Computer
When the scan is done, in the Scan is completed window (below), any infection is displayed.
There is no option to clean/disinfect, however, we need to analyze the information on the report.
[external image: Posted Image]
[external image: Posted Image]
To obtain the report:
Click on: Save Report As (above - red blinking arrow)
Next, in the Save as prompt, Save in area, select: Desktop
In the File name area, use KScan, or something similar
In Save as type, click the drop arrow and select: Text file [*.txt]
Then, click: Save
Please post the Kaspersky Online Scanner Report in your reply, along with a fresh HijackThis log
Hi Trevuren,
Here are the logs:
Regards, Khilafat.

Virus Scan report:

——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Saturday, October 13, 2007 12:39:40 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.0
Kaspersky Anti-Virus database last update: 19/08/2007
Kaspersky Anti-Virus database records: 385030
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 67616
Number of viruses found: 75
Number of infected objects: 624
Number of suspicious objects: 14
Duration of the scan process: 00:50:31

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ad71417d35bb0342c2c8d7fca62da80b_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\PurityScan.zip/offun.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\PurityScan.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SpySheriff8.zip/Uninstall.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SpySheriff8.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde3.zip/retadpu572.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde3.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde4.zip/retadpu27.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde4.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde5.zip/retadpu1000106.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde5.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle.zip/Yazzle1281OinUninstaller.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle1.zip/Yazzle1162OinUninstaller.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle1.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\Gauri\Local Settings\Temp\6464.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\Documents and Settings\Gauri\Local Settings\Temp\a.exe Infected: Backdoor.Win32.Dumador.fp skipped
C:\Documents and Settings\Gauri\Local Settings\Temp\monsys.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\Documents and Settings\Gauri\Local Settings\Temp\poweragent.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\Documents and Settings\Gauri\Local Settings\Temp\server32.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\Documents and Settings\Gauri\Local Settings\Temp\svwin.exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\Documents and Settings\Gauri\Local Settings\Temporary Internet Files\Content.IE5UE768ZD\idien[1] Infected: Trojan.Win32.Agent.aoy skipped
C:\Documents and Settings\Gauri\Local Settings\Temporary Internet Files\Content.IE5\3HDZPOUM\adfcook[1] Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\Documents and Settings\Gauri\Local Settings\Temporary Internet Files\Content.IE5\3HDZPOUM\hlpsrv[1].exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\Documents and Settings\Gauri\Local Settings\Temporary Internet Files\Content.IE5\KBA5NGZM\hlpsrv[1].exe Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\Documents and Settings\Gauri\Local Settings\Temporary Internet Files\Content.IE5\KBA5NGZM\kcehc_eicooc20070702[1] Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\Documents and Settings\LocalService\Cookies\INDEX.DAT Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Salil\Application Data\Snapfish\Client\Data\DataCenter.ldb Object is locked skipped
C:\Documents and Settings\Salil\Application Data\Snapfish\Client\Data\DataCenter.madb Object is locked skipped
C:\Documents and Settings\Salil\Application Data\Snapfish\Client\Log\agent.log Object is locked skipped
C:\Documents and Settings\Salil\Cookies\INDEX.DAT Object is locked skipped
C:\Documents and Settings\Salil\Desktop\[4]-Submit_2007-08-15_204338.09.zip/dkhvjrtf.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\Documents and Settings\Salil\Desktop\[4]-Submit_2007-08-15_204338.09.zip/drvhak.dll Infected: Trojan.Win32.Agent.qt skipped
C:\Documents and Settings\Salil\Desktop\[4]-Submit_2007-08-15_204338.09.zip/rasterx.dll Infected: Trojan-Spy.Win32.Banker.cji skipped
C:\Documents and Settings\Salil\Desktop\[4]-Submit_2007-08-15_204338.09.zip/fertbuk.dll Infected: Trojan-Spy.Win32.Banker.cji skipped
C:\Documents and Settings\Salil\Desktop\[4]-Submit_2007-08-15_204338.09.zip ZIP: infected - 4 skipped
C:\Documents and Settings\Salil\Local Settings\Application Data\Microsoft\Terminal Server Client\Cache\bcache22.bmc Object is locked skipped
C:\Documents and Settings\Salil\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Salil\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Salil\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\Salil\Local Settings\Temp\JET7AFC.tmp Object is locked skipped
C:\Documents and Settings\Salil\Local Settings\Temp\JET7BA8.tmp Object is locked skipped
C:\Documents and Settings\Salil\Local Settings\Temp\logger.log Object is locked skipped
C:\Documents and Settings\Salil\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Salil\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Salil\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Microsoft\bak\svhost32.exe Infected: Trojan-PSW.Win32.Nilage.apx skipped
C:\Program Files\Radmin\AdmDll.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
C:\Program Files\Radmin\raddrv.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
C:\Program Files\Radmin\radmin.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.21 skipped
C:\Program Files\Radmin\r_server.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.21 skipped
C:\Program Files\Snapfish Picture Mover\Sample\DataCenter.ldb Object is locked skipped
C:\Program Files\Snapfish Picture Mover\Sample\DataCenter.madb Object is locked skipped
C:\Program Files\Trend Micro\OfficeScan Client\ConnLog\Conn_20070818.log Object is locked skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\1.exe Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\10.exe Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\1036000.exe Infected: Email-Worm.Win32.Bagle.bu skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\10_604.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\10_628.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\10_628.VI1 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\10_628.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\10_630.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\10_630.VI1 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\10_630.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\10_634.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\10_638.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\10_63c.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\10_64c.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\10_64c.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\10_650.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\10_650.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\10_654.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\10_658.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\112900265.exe Infected: Email-Worm.Win32.Bagle.bx skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\1146734.exe Infected: Email-Worm.Win32.Bagle.bu skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\1171781.exe Infected: Email-Worm.Win32.Bagle.cv skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\1197625.exe Infected: Email-Worm.Win32.Bagle.cv skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\1198843.exe Infected: Email-Worm.Win32.Bagle.ex skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\13995390.exe Infected: Email-Worm.Win32.Bagle.ej skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\14014703.exe Infected: Email-Worm.Win32.Bagle.ej skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\1473125.exe Infected: Email-Worm.Win32.Bagle.cb skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\169359.exe Infected: Email-Worm.Win32.Bagle.ex skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\174733984.exe Infected: Email-Worm.Win32.Bagle.cv skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\174761500.exe Infected: Email-Worm.Win32.Bagle.cv skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\1753343.exe Infected: Email-Worm.Win32.Bagle.bx skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\1_630.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\1_630.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\1_634.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\1_634.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\1_638.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\1_638.VI1 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\1_638.VI2 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\1_638.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\1_63c.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\1_63c.VI1 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\1_63c.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\1_64c.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\1_654.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\1_654.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\1_658.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\1_658.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\2.exe Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\203234.exe Infected: Email-Worm.Win32.Bagle.ex skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\2043421.exe Infected: Email-Worm.Win32.Bagle.ep skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\20786250.exe Infected: Email-Worm.Win32.Bagle.bx skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\219918078.exe Infected: Email-Worm.Win32.Bagle.cv skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\219936515.exe Infected: Email-Worm.Win32.Bagle.cv skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\22005906.exe Infected: Email-Worm.Win32.Bagle.ex skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\22053468.exe Infected: Email-Worm.Win32.Bagle.ex skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\22124828.exe Infected: Email-Worm.Win32.Bagle.ex skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\22146734.exe Infected: Email-Worm.Win32.Bagle.ex skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\22174875.exe Infected: Email-Worm.Win32.Bagle.ex skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\22242500.exe Infected: Email-Worm.Win32.Bagle.ex skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\22362687.exe Infected: Email-Worm.Win32.Bagle.ep skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\22391343.exe Infected: Email-Worm.Win32.Bagle.ep skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\22403781.exe Infected: Email-Worm.Win32.Bagle.ep skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\22805609.exe Infected: Email-Worm.Win32.Bagle.bu skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\22921484.exe Infected: Email-Worm.Win32.Bagle.bu skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\23086000.exe Infected: Email-Worm.Win32.Bagle.bu skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\23145796.exe Infected: Email-Worm.Win32.Bagle.bu skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\23187656.exe Infected: Email-Worm.Win32.Bagle.bu skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\23391031.exe Infected: Email-Worm.Win32.Bagle.bp skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\23699765.exe Infected: Email-Worm.Win32.Bagle.bu skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\23705062.exe Infected: Email-Worm.Win32.Bagle.bu skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\24083968.exe Infected: Email-Worm.Win32.Bagle.bu skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\24100390.exe Infected: Trojan-Downloader.Win32.Small.aso skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\242709203.exe Infected: Email-Worm.Win32.Bagle.cv skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\242735468.exe Infected: Email-Worm.Win32.Bagle.cv skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\24310531.exe Infected: Email-Worm.Win32.Bagle.bu skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\24688906.exe Infected: Email-Worm.Win32.Bagle.ca skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\25039500.exe Infected: Email-Worm.Win32.Bagle.ex skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\265919031.exe Infected: Email-Worm.Win32.Bagle.cv skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\265948000.exe Infected: Email-Worm.Win32.Bagle.cv skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\29242843.exe Infected: Email-Worm.Win32.Bagle.dq skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\29275046.exe Infected: Email-Worm.Win32.Bagle.dq skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\2_604.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\2_628.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\2_630.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\2_634.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\2_634.VI1 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\2_634.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\2_638.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\2_638.VI1 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\2_638.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\2_64c.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\2_650.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\2_650.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\2_654.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\2_658.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\2_658.VI1 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\2_658.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\3.exe Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\341343.exe Infected: Email-Worm.Win32.Bagle.bu skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\34349703.exe Infected: Email-Worm.Win32.Bagle.bu skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\34356250.exe Infected: Email-Worm.Win32.Bagle.bu skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\348281.exe Infected: Email-Worm.Win32.Bagle.bu skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\35036593.exe Infected: Email-Worm.Win32.Bagle.bu skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\35047234.exe Infected: Email-Worm.Win32.Bagle.bu skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\363078.exe Infected: Email-Worm.Win32.Bagle.ep skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\392515.exe Infected: Email-Worm.Win32.Bagle.ep skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\3_604.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\3_628.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\3_628.VI1 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\3_628.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\3_630.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\3_634.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\3_638.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\3_63c.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\3_63c.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\3_650.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\3_650.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\3_654.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\3_654.VI1 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\3_654.VI2 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\3_654.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\3_658.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\4.exe Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\40156.exe Infected: Email-Worm.Win32.Bagle.ex skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\43533750.exe Infected: Email-Worm.Win32.Bagle.bx skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\43687.exe Infected: Email-Worm.Win32.Bagle.ex skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\43966703.exe Infected: Email-Worm.Win32.Bagle.ex skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\44003875.exe Infected: Email-Worm.Win32.Bagle.ex skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\44195531.exe Infected: Email-Worm.Win32.Bagle.ex skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\44375.exe Infected: Email-Worm.Win32.Bagle.ex skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\44381578.exe Infected: Email-Worm.Win32.Bagle.ep skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\44382687.exe Infected: Email-Worm.Win32.Bagle.ep skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\45662625.exe Infected: Email-Worm.Win32.Bagle.bu skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\45713968.exe Infected: Email-Worm.Win32.Bagle.ep skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\45763625.exe Infected: Email-Worm.Win32.Bagle.bu skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\45979937.exe Infected: Email-Worm.Win32.Bagle.bu skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\45988468.exe Infected: Email-Worm.Win32.Bagle.bu skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\46007562.exe Infected: Email-Worm.Win32.Bagle.bu skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\46225046.exe Infected: Email-Worm.Win32.Bagle.bu skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\46280312.exe Infected: Email-Worm.Win32.Bagle.bu skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\462843.exe Infected: Email-Worm.Win32.Bagle.ex skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\46700750.exe Infected: Email-Worm.Win32.Bagle.bp skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\46968.exe Infected: Email-Worm.Win32.Bagle.ex skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\47132125.exe Infected: Email-Worm.Win32.Bagle.cg skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\47400953.exe Infected: Email-Worm.Win32.Bagle.bu skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\47627031.exe Infected: Email-Worm.Win32.Bagle.bu skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\48076468.exe Infected: Trojan-Downloader.Win32.Small.aso skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\48106343.exe Infected: Email-Worm.Win32.Bagle.cz skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\48133906.exe Infected: Email-Worm.Win32.Bagle.cz skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\49453.exe Infected: Email-Worm.Win32.Bagle.ex skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\4_604.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\4_604.VI1 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\4_604.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\4_628.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\4_630.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\4_634.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\4_634.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\4_638.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\4_638.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\4_63c.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\4_64c.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\4_650.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\4_650.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\4_658.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\4_658.VI1 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\4_658.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\5.scr Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\505890.exe Infected: Email-Worm.Win32.Bagle.bu skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\52221500.exe Infected: Email-Worm.Win32.Bagle.du skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\52253875.exe Infected: Email-Worm.Win32.Bagle.du skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\532109.exe Infected: Email-Worm.Win32.Bagle.bs skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\532578.exe Infected: Email-Worm.Win32.Bagle.ep skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\53437.exe Infected: Email-Worm.Win32.Bagle.ex skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\55078.exe Infected: Email-Worm.Win32.Bagle.ex skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\5_604.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\5_604.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\5_628.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\5_630.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\5_634.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\5_64c.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\5_64c.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\5_650.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\5_650.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\5_654.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\5_654.VI1 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\5_654.VI2 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\5_654.VI3 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\5_654.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\5_658.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\5_658.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\6.exe Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\61765.exe Infected: Email-Worm.Win32.Bagle.ex skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\6228796.exe Infected: Email-Worm.Win32.Bagle.cz skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\6252265.exe Infected: Email-Worm.Win32.Bagle.cz skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\63125.exe Infected: Email-Worm.Win32.Bagle.ex skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\659812.exe Infected: Trojan-Downloader.Win32.Small.aso skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\66528390.exe Infected: Email-Worm.Win32.Bagle.bx skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\6_604.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\6_604.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\6_628.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\6_628.VI1 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\6_628.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\6_630.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\6_634.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\6_638.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\6_63c.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\6_64c.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\6_64c.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\6_650.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\6_650.VI1 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\6_650.VI2 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\6_650.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\6_658.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\7.exe Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\721921.exe Infected: Email-Worm.Win32.Bagle.bu skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\73906.exe Infected: Email-Worm.Win32.Bagle.ex skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\7_604.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\7_604.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\7_628.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\7_628.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\7_630.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\7_638.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\7_638.VI1 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\7_638.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\7_64c.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\7_654.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\7_654.VI1 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\7_654.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\7_658.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\7_658.VI1 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\7_658.VI2 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\7_658.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\8.exe Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\88140.exe Infected: Email-Worm.Win32.Bagle.ex skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\89672390.exe Infected: Email-Worm.Win32.Bagle.bx skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\8_628.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\8_630.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\8_634.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\8_634.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\8_638.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\8_638.VI1 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\8_638.VI2 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\8_638.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\8_64c.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\8_64c.VI1 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\8_64c.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\8_650.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\8_650.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\8_654.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\8_658.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\8_658.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\9.exe Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\948531.exe Infected: Email-Worm.Win32.Bagle.bu skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\9_604.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\9_604.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\9_628.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\9_628.VI1 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\9_628.VI2 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\9_628.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\9_630.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\9_634.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\9_638.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\9_638.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\9_63c.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\9_63c.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\9_650.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\9_654.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\9_654.VI1 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\9_654.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\ACDSee 9.exe Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\ACDSee 9_604.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\ACDSee 9_604.VI1 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\ACDSee 9_604.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\ACDSee 9_628.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\ACDSee 9_630.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\ACDSee 9_630.VI1 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\ACDSee 9_630.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\ACDSee 9_634.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\ACDSee 9_634.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\ACDSee 9_638.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\ACDSee 9_638.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\ACDSee 9_64c.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\ACDSee 9_650.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\ACDSee 9_654.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\ACDSee 9_658.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\ACDSee 9_658.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Adobe Photoshop 9 full.exe Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Adobe Photoshop 9 full_604.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Adobe Photoshop 9 full_604.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Adobe Photoshop 9 full_628.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Adobe Photoshop 9 full_628.VI1 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Adobe Photoshop 9 full_628.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Adobe Photoshop 9 full_634.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Adobe Photoshop 9 full_634.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Adobe Photoshop 9 full_638.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Adobe Photoshop 9 full_638.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Adobe Photoshop 9 full_63c.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Adobe Photoshop 9 full_650.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Adobe Photoshop 9 full_650.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Adobe Photoshop 9 full_654.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Adobe Photoshop 9 full_654.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Adobe Photoshop 9 full_658.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Adobe Photoshop 9 full_658.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Ahead Nero 7.exe Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Ahead Nero 7_604.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Ahead Nero 7_604.VI1 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Ahead Nero 7_604.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Ahead Nero 7_628.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Ahead Nero 7_630.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Ahead Nero 7_634.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Ahead Nero 7_638.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Ahead Nero 7_63c.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Ahead Nero 7_63c.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Ahead Nero 7_64c.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Ahead Nero 7_650.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Ahead Nero 7_650.VI1 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Ahead Nero 7_650.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Ahead Nero 7_654.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Ahead Nero 7_654.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Ahead Nero 7_658.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\anti_troj.exe Infected: Email-Worm.Win32.Bagle.fn skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\awtss.dll Infected: Trojan-Downloader.Win32.Agent.yf skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\dvpd.dll Infected: Backdoor.Win32.Dumador.eo skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\firewall_anti.exe Infected: Email-Worm.Win32.Bagle.cv skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\firewall_anti.exe.dll Infected: Email-Worm.Win32.Bagle.cv skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\hidn1.exe Infected: Email-Worm.Win32.Bagle.gl skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Matrix 3 Revolution English Subtitles.exe Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Matrix 3 Revolution English Subtitles_604.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Matrix 3 Revolution English Subtitles_604.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Matrix 3 Revolution English Subtitles_630.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Matrix 3 Revolution English Subtitles_634.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Matrix 3 Revolution English Subtitles_638.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Matrix 3 Revolution English Subtitles_638.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Matrix 3 Revolution English Subtitles_63c.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Matrix 3 Revolution English Subtitles_64c.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Matrix 3 Revolution English Subtitles_64c.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Matrix 3 Revolution English Subtitles_650.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Matrix 3 Revolution English Subtitles_650.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Matrix 3 Revolution English Subtitles_654.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Matrix 3 Revolution English Subtitles_658.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Matrix 3 Revolution English Subtitles_658.VI1 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Matrix 3 Revolution English Subtitles_658.VI2 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Matrix 3 Revolution English Subtitles_658.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\mue.exe Infected: Trojan-Downloader.Win32.Bagle.y skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\muk.exe Infected: Trojan-Downloader.Win32.Bagle.aa skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Opera 8 New!.exe Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Opera 8 New!_604.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Opera 8 New!_630.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Opera 8 New!_630.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Opera 8 New!_634.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Opera 8 New!_634.VI1 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Opera 8 New!_634.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Opera 8 New!_63c.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Opera 8 New!_64c.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Opera 8 New!_650.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Opera 8 New!_650.VI1 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Opera 8 New!_650.VI2 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Opera 8 New!_650.VI3 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Opera 8 New!_650.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Opera 8 New!_654.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Opera 8 New!_658.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Opera 8 New!_658.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\rsysinit.exe Infected: Trojan.Win32.ExitWin.z skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\sa_exe.exe Infected: Email-Worm.Win32.Bagle.bp skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\sa_exe.exe.dll Infected: SpamTool.Win32.Maniac.b skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\svc.exe Infected: Email-Worm.Win32.Bagle.ca skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\sysformat.exe Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\sysformat.exeopen Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\sysformat.exeopenopen/ykfswwz.exe Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\sysformat.exeopenopen ZIP: infected - 1 skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\sysformat.exeopenopen CryptFF.b: infected - 1 skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\vedxga1me4t1.exe Infected: Trojan-Downloader.Win32.Small.cxx skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\vx1dt1.game Infected: Trojan-Downloader.Win32.Small.cxx skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\vx1dt1_908.VIR Infected: Trojan-Downloader.Win32.Small.cxx skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\WinAmp 5 Pro Keygen Crack Update.exe Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\WinAmp 5 Pro Keygen Crack Update_604.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\WinAmp 5 Pro Keygen Crack Update_628.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\WinAmp 5 Pro Keygen Crack Update_630.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\WinAmp 5 Pro Keygen Crack Update_630.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\WinAmp 5 Pro Keygen Crack Update_634.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\WinAmp 5 Pro Keygen Crack Update_638.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\WinAmp 5 Pro Keygen Crack Update_638.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\WinAmp 5 Pro Keygen Crack Update_63c.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\WinAmp 5 Pro Keygen Crack Update_63c.VI1 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\WinAmp 5 Pro Keygen Crack Update_63c.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\WinAmp 5 Pro Keygen Crack Update_64c.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\WinAmp 5 Pro Keygen Crack Update_64c.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\WinAmp 5 Pro Keygen Crack Update_654.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\WinAmp 5 Pro Keygen Crack Update_654.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\WinAmp 5 Pro Keygen Crack Update_658.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\WinAmp 5 Pro Keygen Crack Update_658.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\WinAmp 6 New!.exe Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\WinAmp 6 New!_628.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\WinAmp 6 New!_628.VI1 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\WinAmp 6 New!_628.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\WinAmp 6 New!_630.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\WinAmp 6 New!_634.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\WinAmp 6 New!_634.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\WinAmp 6 New!_63c.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\WinAmp 6 New!_64c.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\WinAmp 6 New!_64c.VI1 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\WinAmp 6 New!_64c.VI2 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\WinAmp 6 New!_64c.VI3 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\WinAmp 6 New!_64c.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\WinAmp 6 New!_650.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\WinAmp 6 New!_650.VI1 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\WinAmp 6 New!_650.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\WinAmp 6 New!_654.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\wind2ll2.exe Infected: Email-Worm.Win32.Bagle.ex skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\windll.exe Infected: Email-Worm.Win32.Bagle.bu skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\windll2.exe Infected: Email-Worm.Win32.Bagle.ej skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Windown Longhorn Beta Leak.exe Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Windown Longhorn Beta Leak_604.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Windown Longhorn Beta Leak_630.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Windown Longhorn Beta Leak_630.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Windown Longhorn Beta Leak_634.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Windown Longhorn Beta Leak_638.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Windown Longhorn Beta Leak_638.VI1 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Windown Longhorn Beta Leak_638.VI2 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Windown Longhorn Beta Leak_638.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Windown Longhorn Beta Leak_63c.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Windown Longhorn Beta Leak_63c.VI1 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Windown Longhorn Beta Leak_63c.VI2 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Windown Longhorn Beta Leak_63c.VI3 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Windown Longhorn Beta Leak_63c.VI4 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Windown Longhorn Beta Leak_63c.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Windown Longhorn Beta Leak_64c.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\Windown Longhorn Beta Leak_658.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\winlog.dll Infected: Email-Worm.Win32.Bagle.fn skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\winlog.exe Infected: Email-Worm.Win32.Bagle.fn skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\winshost.exe Infected: Email-Worm.Win32.Bagle.bj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\wintems.exe Infected: Email-Worm.Win32.Bagle.fn skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\wiwshost.exe Infected: Email-Worm.Win32.Bagle.bj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\XXX hardcore images.exe Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\XXX hardcore images_604.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\XXX hardcore images_604.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\XXX hardcore images_628.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\XXX hardcore images_630.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\XXX hardcore images_630.VI1 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\XXX hardcore images_630.VI2 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\XXX hardcore images_630.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\XXX hardcore images_634.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\XXX hardcore images_634.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\XXX hardcore images_638.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\XXX hardcore images_638.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\XXX hardcore images_63c.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\XXX hardcore images_64c.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\XXX hardcore images_64c.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\XXX hardcore images_654.VI0 Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\XXX hardcore images_654.VIR Infected: Email-Worm.Win32.Bagle.fj skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\~10.exe Infected: Email-Worm.Win32.Bagle.pac skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\~12.exe Infected: Email-Worm.Win32.Bagle.pac skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\~14.exe Infected: Email-Worm.Win32.Bagle.pac skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\~14_650.VIR Infected: Email-Worm.Win32.Bagle.pac skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\~16.exe Infected: Email-Worm.Win32.Bagle.pac skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\~18.exe Infected: Email-Worm.Win32.Bagle.pac skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\~19.exe Infected: Email-Worm.Win32.Bagle.pac skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\~1B.exe Infected: Email-Worm.Win32.Bagle.pac skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\~1D.exe Infected: Email-Worm.Win32.Bagle.pac skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\~1F.exe Infected: Email-Worm.Win32.Bagle.pac skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\~21.exe Infected: Email-Worm.Win32.Bagle.pac skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\~23.exe Infected: Email-Worm.Win32.Bagle.pac skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\~25.exe Infected: Email-Worm.Win32.Bagle.pac skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\~27.exe Infected: Email-Worm.Win32.Bagle.pac skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\~29.exe Infected: Email-Worm.Win32.Bagle.pac skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\~2B.exe Infected: Email-Worm.Win32.Bagle.pac skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\~2D.exe Infected: Email-Worm.Win32.Bagle.pac skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\~2F.exe Infected: Email-Worm.Win32.Bagle.pac skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\~31.exe Infected: Email-Worm.Win32.Bagle.pac skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\~33.exe Infected: Email-Worm.Win32.Bagle.pac skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\~35.exe Infected: Email-Worm.Win32.Bagle.pac skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\~37.exe Infected: Email-Worm.Win32.Bagle.pac skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\~37_630.VIR Infected: Email-Worm.Win32.Bagle.pac skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\~39.exe Infected: Email-Worm.Win32.Bagle.pac skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\~3B.exe Infected: Email-Worm.Win32.Bagle.pac skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\~3C.exe Infected: Email-Worm.Win32.Bagle.pac skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\~40.exe Infected: Email-Worm.Win32.Bagle.pac skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\~48.exe Infected: Email-Worm.Win32.Bagle.pac skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\~4C.exe Infected: Email-Worm.Win32.Bagle.pac skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\~68.exe Infected: Email-Worm.Win32.Bagle.pac skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\~9.exe Infected: Email-Worm.Win32.Bagle.pac skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\~A.exe Infected: Email-Worm.Win32.Bagle.fn skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\~B.exe Infected: Email-Worm.Win32.Bagle.fn skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\~C.exe Infected: Email-Worm.Win32.Bagle.pac skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\~C_658.VIR Infected: Email-Worm.Win32.Bagle.fn skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\~D.exe Infected: Email-Worm.Win32.Bagle.pac skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\~F.exe Infected: Email-Worm.Win32.Bagle.pac skipped
C:\Program Files\WinBudget\bin\carp**.1169509029.old/EXE-file Infected: not-a-virus:AdWare.Win32.BHO.by skipped
C:\Program Files\WinBudget\bin\carp**.1169509029.old Embedded EXE: infected - 1 skipped
C:\Program Files\WinBudget\bin\matrix.dll.1187052632.old Infected: not-a-virus:AdWare.Win32.BHO.by skipped
C:\QooBox\Quarantine\C\Documents and Settings\All Users\Documents\Settings\bot.dll.vir Infected: Email-Worm.Win32.Zhelatin.gh skipped
C:\QooBox\Quarantine\C\DOCUME~1\Salil\APPLIC~1\hidires\bak\hidr.exe.vir Infected: Trojan-PSW.Win32.LdPinch.bhb skipped
C:\QooBox\Quarantine\C\DOCUME~1\Salil\APPLIC~1\hidires\m_hook.sys.vir Infected: Email-Worm.Win32.Bagle.gy skipped
C:\QooBox\Quarantine\C\Program Files\Microsoft\svhost32.exe.vir Infected: Trojan-Downloader.Win32.Agent.awf skipped
C:\QooBox\Quarantine\C\Program Files\MSN\hoke2.dll.vir Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\QooBox\Quarantine\C\Program Files\MSN\hoke4444.dll.vir Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\QooBox\Quarantine\C\Program Files\MSN\hoke83122.dll.vir Infected: not-a-virus:AdWare.Win32.TTC.b skipped
C:\QooBox\Quarantine\C\Program Files\MSN Gaming Zone\lavuqa.dll.vir Infected: Trojan.Win32.BHO.ab skipped
C:\QooBox\Quarantine\C\Program Files\Outerinfo\OiUninstaller.exe.vir/data0002 Infected: not-a-virus:AdWare.Win32.PurityScan.fk skipped
C:\QooBox\Quarantine\C\Program Files\Outerinfo\OiUninstaller.exe.vir NSIS: infected - 1 skipped
C:\QooBox\Quarantine\C\Program Files\TTC.dll.vir Infected: not-a-virus:AdWare.Win32.TTC.c skipped
C:\QooBox\Quarantine\C\Temp\bass.exe.vir/data0002/data0002 Infected: not-a-virus:AdWare.Win32.TTC.b skipped
C:\QooBox\Quarantine\C\Temp\bass.exe.vir/data0002 Infected: not-a-virus:AdWare.Win32.TTC.b skipped
C:\QooBox\Quarantine\C\Temp\bass.exe.vir/data0006 Infected: Trojan-Downloader.Win32.Small.eqn skipped
C:\QooBox\Quarantine\C\Temp\bass.exe.vir/data0007 Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\QooBox\Quarantine\C\Temp\bass.exe.vir/data0008 Infected: Trojan-Dropper.Win32.Agent.mu skipped
C:\QooBox\Quarantine\C\Temp\bass.exe.vir NSIS: infected - 5 skipped
C:\QooBox\Quarantine\C\temp.zip.vir Infected: Email-Worm.Win32.Bagle.gen skipped
C:\QooBox\Quarantine\C\U.exe.vir Infected: Trojan.Win32.Agent.ato skipped
C:\QooBox\Quarantine\C\WINDOWS\24233484.exe.vir Infected: Email-Worm.Win32.Bagle.ce skipped
C:\QooBox\Quarantine\C\WINDOWS\45510703.exe.vir Infected: Email-Worm.Win32.Bagle.bq skipped
C:\QooBox\Quarantine\C\WINDOWS\b122.exe.vir Infected: not-a-virus:AdWare.Win32.Rond.c skipped
C:\QooBox\Quarantine\C\WINDOWS\DOWNLO~1\UWA7P_0001_N91M0809NetInstaller.exe.vir Infected: not-a-virus:Downloader.Win32.WinFixer.o skipped
C:\QooBox\Quarantine\C\WINDOWS\mgrs.exe.vir Infected: Trojan-Downloader.Win32.Alphabet.p skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\amlxuluw.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\aukmkpqy.exe.vir Infected: Trojan-Dropper.Win32.Agent.bmk skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\byxvvtr.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\configs\kmhp83122.exe.vir/data0002 Infected: not-a-virus:AdWare.Win32.TTC.b skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\configs\kmhp83122.exe.vir NSIS: infected - 1 skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\dms.dll.vir Infected: Trojan-PSW.Win32.Nilage.apx skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\dnsersnd.dll.vir Infected: Trojan-Clicker.Win32.Small.cf skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\driver\w717.exe.vir Infected: Trojan-Downloader.Win32.Small.eqn skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\drvfim.dll.vir Infected: Trojan.Win32.Agent.qt skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\f02WtR\f02WtR1065.exe.vir Infected: Trojan-Downloader.Win32.VB.awj skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\f06WtR\f06WtR1083.exe.vir Infected: Trojan-Downloader.Win32.VB.awj skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\F3\n553.exe.vir Infected: Trojan-Dropper.Win32.Agent.mu skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\gebcywv.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\hlpsrv.exe.vir Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\install.exe.vir Infected: Trojan-Dropper.Win32.Agent.bfr skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\is67718.exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.ks skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\jbhook.dll.vir Infected: Trojan-PSW.Win32.Small.br skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\nwslhekh.exe.vir Infected: Trojan-Dropper.Win32.Agent.bmk skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\Outerinfo-1440.exe.vir/data0004/data0002 Infected: not-a-virus:AdWare.Win32.PurityScan.fk skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\Outerinfo-1440.exe.vir/data0004 Infected: not-a-virus:AdWare.Win32.PurityScan.fk skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\Outerinfo-1440.exe.vir NSIS: infected - 2 skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\skna455101.exe.vir/data0002 Infected: not-a-virus:AdWare.Win32.TTC.c skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\skna455101.exe.vir NSIS: infected - 1 skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\uqpllopt.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\user10.exe.vir Infected: Trojan-Downloader.Win32.Small.dxm skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\waverevenue.exe.vir Infected: Trojan-Downloader.Win32.Small.eqn skipped
C:\QooBox\Quarantine\C\WINDOWS\TISKY009.exe.vir Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped
C:\QooBox\Quarantine\C\WINDOWS\tk58.exe.vir Infected: Trojan.Win32.BHO.ab skipped
C:\QooBox\Quarantine\C\WINDOWS\TTC-4444.exe.vir/data0002 Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\QooBox\Quarantine\C\WINDOWS\TTC-4444.exe.vir NSIS: infected - 1 skipped
C:\QooBox\Quarantine\C\WINDOWS\yekwh0578.exe.vir Infected: Trojan-Downloader.Win32.Small.dxm skipped
C:\QooBox\Quarantine\catchme2007-08-11_ 70426.26.zip/core.sys Infected: Rootkit.Win32.Agent.eq skipped
C:\QooBox\Quarantine\catchme2007-08-11_ 70426.26.zip/opnopon.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\QooBox\Quarantine\catchme2007-08-11_ 70426.26.zip ZIP: infected - 2 skipped
C:\SALIL\VPN\radmin21.exe/AdmDll.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
C:\SALIL\VPN\radmin21.exe/raddrv.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
C:\SALIL\VPN\radmin21.exe/radmin.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.21 skipped
C:\SALIL\VPN\radmin21.exe/r_server.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.21 skipped
C:\SALIL\VPN\radmin21.exe Gentee: infected - 4 skipped
C:\SALIL\VPN\radmin[1].exe.txt/radmin21.exe/AdmDll.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
C:\SALIL\VPN\radmin[1].exe.txt/radmin21.exe/raddrv.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
C:\SALIL\VPN\radmin[1].exe.txt/radmin21.exe/radmin.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.21 skipped
C:\SALIL\VPN\radmin[1].exe.txt/radmin21.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.21 skipped
C:\SALIL\VPN\radmin[1].exe.txt ZIP: infected - 4 skipped
C:\SALIL\VPN\radmin[1].exe.txt PE_Patch: infected - 4 skipped
C:\SALIL\VPN\radmin[1].exe.zip/radmin21.exe/AdmDll.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
C:\SALIL\VPN\radmin[1].exe.zip/radmin21.exe/raddrv.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
C:\SALIL\VPN\radmin[1].exe.zip/radmin21.exe/radmin.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.21 skipped
C:\SALIL\VPN\radmin[1].exe.zip/radmin21.exe/r_server.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.21 skipped
C:\SALIL\VPN\radmin[1].exe.zip/radmin21.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.21 skipped
C:\SALIL\VPN\radmin[1].exe.zip ZIP: infected - 5 skipped
C:\sti.log Object is locked skipped
C:\VundoFix Backups\gebbcda.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\VundoFix Backups\hgghiih.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\VundoFix Backups\icbmrsyu.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.hb skipped
C:\VundoFix Backups\jkkihff.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\VundoFix Backups\rqroppm.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\VundoFix Backups\rqrpnlm.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\VundoFix Backups\ssttq.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.la skipped
C:\VundoFix Backups\wvuuvuu.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\WINDOWS\$NtUninstallKB917953$\tcpip.sys Infected: Trojan.Win32.Patched.ad skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\SYSTEM32\admdll.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
C:\WINDOWS\SYSTEM32\argysyko.dll Infected: Trojan-Spy.Win32.Agent.kg skipped
C:\WINDOWS\SYSTEM32\bak\dxdlg32.exe Infected: Trojan.Win32.VB.avs skipped
C:\WINDOWS\SYSTEM32\bak\system43.exe Infected: Trojan-Downloader.Win32.Small.ehw skipped
C:\WINDOWS\SYSTEM32\bak\winldra.exe Infected: Backdoor.Win32.Dumador.fp skipped
C:\WINDOWS\SYSTEM32\byftlqsv.dll Infected: Trojan-Spy.Win32.Agent.kg skipped
C:\WINDOWS\SYSTEM32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\SYSTEM32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\AppEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SAM Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SecEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SysEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\ehnstmtk.dll Infected: Trojan-Spy.Win32.Agent.kg skipped
C:\WINDOWS\SYSTEM32\fbsbajrx.dll Infected: Trojan-Spy.Win32.Agent.kg skipped
C:\WINDOWS\SYSTEM32\fjiumiwc.dll Infected: Trojan-Spy.Win32.Agent.kg skipped
C:\WINDOWS\SYSTEM32\fyjjskts.dll Infected: Trojan-Spy.Win32.Agent.kg skipped
C:\WINDOWS\SYSTEM32\gjwovsvc.dll Infected: Trojan-Spy.Win32.Agent.kg skipped
C:\WINDOWS\SYSTEM32\gkqphsxt.dll Infected: Trojan-Spy.Win32.Agent.kg skipped
C:\WINDOWS\SYSTEM32\H323LOG.TXT Object is locked skipped
C:\WINDOWS\SYSTEM32\hxdtxqtd.dll Infected: Trojan-Spy.Win32.Agent.kg skipped
C:\WINDOWS\SYSTEM32\hyycdesc.dll Infected: Trojan-Spy.Win32.Agent.kg skipped
C:\WINDOWS\SYSTEM32\jb.exe Infected: Trojan-PSW.Win32.Nilage.apx skipped
C:\WINDOWS\SYSTEM32\jogviplf.dll Infected: Trojan-Spy.Win32.Agent.kg skipped
C:\WINDOWS\SYSTEM32\knapecdb.dll Infected: Trojan-Spy.Win32.Agent.kg skipped
C:\WINDOWS\SYSTEM32\qkkciodf.dll Infected: Trojan-Spy.Win32.Agent.kg skipped
C:\WINDOWS\SYSTEM32\qmewfvde.dll Infected: Trojan-Spy.Win32.Agent.kg skipped
C:\WINDOWS\SYSTEM32\qnyqwunv.dll Infected: Trojan-Spy.Win32.Agent.kg skipped
C:\WINDOWS\SYSTEM32\svc23.exe Infected: Email-Worm.Win32.Bagle.cj skipped
C:\WINDOWS\SYSTEM32\ujtiddib.dll Infected: Trojan-Spy.Win32.Agent.kg skipped
C:\WINDOWS\SYSTEM32\uljhuwaq.dll Infected: Trojan-Spy.Win32.Agent.kg skipped
C:\WINDOWS\SYSTEM32\vlifxqbd.dll Infected: Trojan-Spy.Win32.Agent.kg skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\winb2.exe Infected: Email-Worm.Win32.Bagle.gj skipped
C:\WINDOWS\SYSTEM32\wivmmrjr.dll Infected: Trojan-Spy.Win32.Agent.kg skipped
C:\WINDOWS\SYSTEM32\wwww.exe Infected: Trojan-Downloader.Win32.Delf.ain skipped
C:\WINDOWS\SYSTEM32\ycvjluxf.dll Infected: Trojan-Spy.Win32.Agent.kg skipped
C:\WINDOWS\SYSTEM32\yssjveon.dll Infected: Trojan-Spy.Win32.Agent.kg skipped
C:\WINDOWS\WIADEBUG.LOG Object is locked skipped
C:\WINDOWS\WIASERVC.LOG Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.



=====================

HJT REPORT

=====================


Logfile of HijackThis v1.99.1
Scan saved at 1:53:33 AM, on 10/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Snapfish Picture Mover\SnapfishPictureMover.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
C:\Program Files\Trend Micro\OfficeScan Client\Pop3Trap.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\TEMP\LG5A87.EXE
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\Killer.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/mywaybiz
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Snapfish Picture Mover.lnk = C:\Program Files\Snapfish Picture Mover\SnapfishPictureMover.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {3DC2E31C-371A-4BD3-9A27-CDF57CE604CF} (MSN Money Charting) - http://moneycentral.msn.com/cabs/pmupd806.exe
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = cinci.rr.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = cinci.rr.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = cinci.rr.com
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
I need you to do the following:

1. DELETE the content of the following folder, not the folder itself:

C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\ <==That is like a quarantine.

do the same with the following folder (Remember, only its content):

C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\


2. 1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\Documents and Settings\Gauri\Local Settings\Temp\6464.exe
C:\Documents and Settings\Gauri\Local Settings\Temp\a.exe
C:\Documents and Settings\Gauri\Local Settings\Temp\monsys.exe
C:\Documents and Settings\Gauri\Local Settings\Temp\poweragent.exe
C:\Documents and Settings\Gauri\Local Settings\Temp\server32.exe
C:\Documents and Settings\Gauri\Local Settings\Temp\svwin.exe
C:\Documents and Settings\Gauri\Local Settings\Temporary Internet Files\Content.IE5UE768ZD\idien[1]
C:\Documents and Settings\Gauri\Local Settings\Temporary Internet Files\Content.IE5\3HDZPOUM\adfcook[1]
C:\Documents and Settings\Gauri\Local Settings\Temporary Internet Files\Content.IE5\3HDZPOUM\hlpsrv[1].exe
C:\Documents and Settings\Gauri\Local Settings\Temporary Internet Files\Content.IE5\KBA5NGZM\hlpsrv[1].exe
C:\Documents and Settings\Gauri\Local Settings\Temporary Internet Files\Content.IE5\KBA5NGZM\kcehc_eicooc20070702[1]
C:\Documents and Settings\Salil\Desktop\[4]-Submit_2007-08-15_204338.09.zip
C:\Program Files\Microsoft\bak\svhost32.exe
C:\Program Files\Radmin\AdmDll.dll
C:\Program Files\Radmin\raddrv.dll
C:\Program Files\Radmin\radmin.exe
C:\Program Files\Radmin\r_server.exe
C:\Program Files\WinBudget\bin\carp**.1169509029.old
C:\Program Files\WinBudget\bin\matrix.dll.1187052632.old
C:\SALIL\VPN\radmin21.exe
C:\SALIL\VPN\radmin[1].exe.txt
C:\SALIL\VPN\radmin[1].exe.zip
C:\WINDOWS\$NtUninstallKB917953$\tcpip.sys
C:\WINDOWS\SYSTEM32\admdll.dll
C:\WINDOWS\SYSTEM32\argysyko.dll
C:\WINDOWS\SYSTEM32\bak\dxdlg32.exe
C:\WINDOWS\SYSTEM32\bak\system43.exe
C:\WINDOWS\SYSTEM32\bak\winldra.exe
C:\WINDOWS\SYSTEM32\byftlqsv.dll
C:\WINDOWS\SYSTEM32\ehnstmtk.dll
C:\WINDOWS\SYSTEM32\fbsbajrx.dll
C:\WINDOWS\SYSTEM32\fjiumiwc.dll
C:\WINDOWS\SYSTEM32\fyjjskts.dll
C:\WINDOWS\SYSTEM32\gjwovsvc.dll
C:\WINDOWS\SYSTEM32\gkqphsxt.dll
C:\WINDOWS\SYSTEM32\hxdtxqtd.dll
C:\WINDOWS\SYSTEM32\hyycdesc.dll
C:\WINDOWS\SYSTEM32\jb.exe
C:\WINDOWS\SYSTEM32\jogviplf.dll
C:\WINDOWS\SYSTEM32\knapecdb.dll
C:\WINDOWS\SYSTEM32\qkkciodf.dll
C:\WINDOWS\SYSTEM32\qmewfvde.dll
C:\WINDOWS\SYSTEM32\qnyqwunv.dll
C:\WINDOWS\SYSTEM32\svc23.exe
C:\WINDOWS\SYSTEM32\ujtiddib.dll
C:\WINDOWS\SYSTEM32\uljhuwaq.dll
C:\WINDOWS\SYSTEM32\vlifxqbd.dll
C:\WINDOWS\SYSTEM32\winb2.exe
C:\WINDOWS\SYSTEM32\wivmmrjr.dll
C:\WINDOWS\SYSTEM32\wwww.exe
C:\WINDOWS\SYSTEM32\ycvjluxf.dll
C:\WINDOWS\SYSTEM32\yssjveon.dll


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.
Hi Trevuren,

(I can now post to the forum. )

I have posted the two logs that you had requested.

Thank-you for your cotinued support and patience in dealing with my problem. I really appreciate it.

Regards,
Khilafat.

=====

ComboFix 07-08-11 - "Salil" 2007-10-13 17:38:18.7 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.230 [GMT -4:00]
Command switches used :: C:\Documents and Settings\Salil\Desktop\CFScript.txt

FILE::
C:\Documents and Settings\Gauri\Local Settings\Temp\6464.exe
C:\Documents and Settings\Gauri\Local Settings\Temp\a.exe
C:\Documents and Settings\Gauri\Local Settings\Temp\monsys.exe
C:\Documents and Settings\Gauri\Local Settings\Temp\poweragent.exe
C:\Documents and Settings\Gauri\Local Settings\Temp\server32.exe
C:\Documents and Settings\Gauri\Local Settings\Temp\svwin.exe
C:\Documents and Settings\Gauri\Local Settings\Temporary Internet Files\Content.IE5UE768ZD\idien[1]
C:\Documents and Settings\Gauri\Local Settings\Temporary Internet Files\Content.IE5\3HDZPOUM\adfcook[1]
C:\Documents and Settings\Gauri\Local Settings\Temporary Internet Files\Content.IE5\3HDZPOUM\hlpsrv[1].exe
C:\Documents and Settings\Gauri\Local Settings\Temporary Internet Files\Content.IE5\KBA5NGZM\hlpsrv[1].exe
C:\Documents and Settings\Gauri\Local Settings\Temporary Internet Files\Content.IE5\KBA5NGZM\kcehc_eicooc20070702[1]
C:\Documents and Settings\Salil\Desktop\[4]-Submit_2007-08-15_204338.09.zip
C:\Program Files\Microsoft\bak\svhost32.exe
C:\Program Files\Radmin\AdmDll.dll
C:\Program Files\Radmin\raddrv.dll
C:\Program Files\Radmin\radmin.exe
C:\Program Files\Radmin\r_server.exe
C:\Program Files\WinBudget\bin\matrix.dll.1187052632.old
C:\SALIL\VPN\radmin21.exe
C:\SALIL\VPN\radmin[1].exe.txt
C:\SALIL\VPN\radmin[1].exe.zip
C:\WINDOWS\$NtUninstallKB917953$\tcpip.sys
C:\WINDOWS\SYSTEM32\admdll.dll
C:\WINDOWS\SYSTEM32\argysyko.dll
C:\WINDOWS\SYSTEM32\bak\dxdlg32.exe
C:\WINDOWS\SYSTEM32\bak\system43.exe
C:\WINDOWS\SYSTEM32\bak\winldra.exe
C:\WINDOWS\SYSTEM32\byftlqsv.dll
C:\WINDOWS\SYSTEM32\ehnstmtk.dll
C:\WINDOWS\SYSTEM32\fbsbajrx.dll
C:\WINDOWS\SYSTEM32\fjiumiwc.dll
C:\WINDOWS\SYSTEM32\fyjjskts.dll
C:\WINDOWS\SYSTEM32\gjwovsvc.dll
C:\WINDOWS\SYSTEM32\gkqphsxt.dll
C:\WINDOWS\SYSTEM32\hxdtxqtd.dll
C:\WINDOWS\SYSTEM32\hyycdesc.dll
C:\WINDOWS\SYSTEM32\jb.exe
C:\WINDOWS\SYSTEM32\jogviplf.dll
C:\WINDOWS\SYSTEM32\knapecdb.dll
C:\WINDOWS\SYSTEM32\qkkciodf.dll
C:\WINDOWS\SYSTEM32\qmewfvde.dll
C:\WINDOWS\SYSTEM32\qnyqwunv.dll
C:\WINDOWS\SYSTEM32\svc23.exe
C:\WINDOWS\SYSTEM32\ujtiddib.dll
C:\WINDOWS\SYSTEM32\uljhuwaq.dll
C:\WINDOWS\SYSTEM32\vlifxqbd.dll
C:\WINDOWS\SYSTEM32\winb2.exe
C:\WINDOWS\SYSTEM32\wivmmrjr.dll
C:\WINDOWS\SYSTEM32\wwww.exe
C:\WINDOWS\SYSTEM32\ycvjluxf.dll
C:\WINDOWS\SYSTEM32\yssjveon.dll


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Documents and Settings\Gauri\Local Settings\Temp\6464.exe
C:\Documents and Settings\Gauri\Local Settings\Temp\a.exe
C:\Documents and Settings\Gauri\Local Settings\Temp\monsys.exe
C:\Documents and Settings\Gauri\Local Settings\Temp\poweragent.exe
C:\Documents and Settings\Gauri\Local Settings\Temp\server32.exe
C:\Documents and Settings\Gauri\Local Settings\Temp\svwin.exe
C:\Documents and Settings\Gauri\Local Settings\Temporary Internet Files\Content.IE5\3HDZPOUM\adfcook[1]
C:\Documents and Settings\Gauri\Local Settings\Temporary Internet Files\Content.IE5\3HDZPOUM\hlpsrv[1].exe
C:\Documents and Settings\Gauri\Local Settings\Temporary Internet Files\Content.IE5\KBA5NGZM\hlpsrv[1].exe
C:\Documents and Settings\Gauri\Local Settings\Temporary Internet Files\Content.IE5\KBA5NGZM\kcehc_eicooc20070702[1]
C:\Documents and Settings\Salil\Desktop\[4]-Submit_2007-08-15_204338.09.zip
C:\Program Files\Microsoft\bak\svhost32.exe
C:\Program Files\Radmin\AdmDll.dll
C:\Program Files\Radmin\r_server.exe
C:\Program Files\Radmin\raddrv.dll
C:\Program Files\Radmin\radmin.exe
C:\Program Files\WinBudget\bin\matrix.dll.1187052632.old
C:\SALIL\VPN\radmin[1].exe.txt
C:\SALIL\VPN\radmin[1].exe.zip
C:\SALIL\VPN\radmin21.exe
C:\WINDOWS\$NtUninstallKB917953$\tcpip.sys
C:\WINDOWS\SYSTEM32\admdll.dll
C:\WINDOWS\SYSTEM32\argysyko.dll
C:\WINDOWS\SYSTEM32\bak\dxdlg32.exe
C:\WINDOWS\SYSTEM32\bak\system43.exe
C:\WINDOWS\SYSTEM32\bak\winldra.exe
C:\WINDOWS\SYSTEM32\byftlqsv.dll
C:\WINDOWS\SYSTEM32\ehnstmtk.dll
C:\WINDOWS\SYSTEM32\fbsbajrx.dll
C:\WINDOWS\SYSTEM32\fjiumiwc.dll
C:\WINDOWS\SYSTEM32\fyjjskts.dll
C:\WINDOWS\SYSTEM32\gjwovsvc.dll
C:\WINDOWS\SYSTEM32\gkqphsxt.dll
C:\WINDOWS\SYSTEM32\hxdtxqtd.dll
C:\WINDOWS\SYSTEM32\hyycdesc.dll
C:\WINDOWS\SYSTEM32\jb.exe
C:\WINDOWS\SYSTEM32\jogviplf.dll
C:\WINDOWS\SYSTEM32\knapecdb.dll
C:\WINDOWS\SYSTEM32\qkkciodf.dll
C:\WINDOWS\SYSTEM32\qmewfvde.dll
C:\WINDOWS\SYSTEM32\qnyqwunv.dll
C:\WINDOWS\SYSTEM32\svc23.exe
C:\WINDOWS\SYSTEM32\ujtiddib.dll
C:\WINDOWS\SYSTEM32\uljhuwaq.dll
C:\WINDOWS\SYSTEM32\vlifxqbd.dll
C:\WINDOWS\SYSTEM32\winb2.exe
C:\WINDOWS\SYSTEM32\wivmmrjr.dll
C:\WINDOWS\SYSTEM32\wwww.exe
C:\WINDOWS\SYSTEM32\ycvjluxf.dll
C:\WINDOWS\SYSTEM32\yssjveon.dll


((((((((((((((((((((((((( Files Created from 2007-09-13 to 2007-10-13 )))))))))))))))))))))))))))))))


2007-10-12 23:19 d——– C:\WINDOWS\SYSTEM32\Kaspersky Lab
2007-10-12 23:19 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2008-08-09 00:01 ——— d——– C:\Program Files\McAfee.com
2008-08-08 22:03 ——— d——– C:\Program Files\Trend Micro
2007-10-13 17:41 ——— d——– C:\Program Files\Radmin


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" []
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-05-24 21:23]
"OfficeScanNT Monitor"="C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" [2006-02-07 17:16]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 09:35]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 09:32]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 09:36]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56]
"Sonic RecordNow!"="" []
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-03-27 15:22]

C:\Documents and Settings\Salil\Start Menu\Programs\Startup\
DESKTOP.INI [2002-09-03 10:00:00]
Webshots.lnk - C:\Program Files\Webshots\Launcher.exe [2005-04-23 13:23:05]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
DESKTOP.INI [2002-09-03 10:00:00]
Snapfish Picture Mover.lnk - C:\Program Files\Snapfish Picture Mover\SnapfishPictureMover.exe [2006-12-19 17:08:38]

R1 cdrbsvsd;cdrbsvsd;C:\WINDOWS\system32\drivers\cdrbsvsd.sys
R2 ntrtscan;OfficeScanNT RealTime Scan;"C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe"
R2 TM_CFW;Common Firewall Driver;\??\C:\Program Files\Trend Micro\OfficeScan Client\tm_cfw.sys
R2 tmlisten;OfficeScanNT Listener;"C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe"
R2 TmPreFilter;Trend Micro PreFilter;\??\C:\Program Files\Trend Micro\OfficeScan Client\TmPreFlt.sys
R3 IPSECSHM;Nortel IPSECSHM Adapter;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys
R3 PD0620VID;Creative WebCam Instant;C:\WINDOWS\system32\DRIVERS\P0620Vid.sys
S2 IPSECEXT;Nortel Extranet Access Protocol;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys


Contents of the 'Scheduled Tasks' folder
2007-10-13 22:46:00 C:\WINDOWS\Tasks\McAfee.com Update Check (KODKANI-Gauri).job - C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
2007-10-13 22:43:00 C:\WINDOWS\Tasks\McAfee.com Update Check (KODKANI-Salil).job - C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
2005-07-01 02:28:00 C:\WINDOWS\Tasks\Run Salil's Calculator.job - C:\WINDOWS\SYSTEM32\CALC.EXE

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-13 18:46:33
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-10-13 18:48:19 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-10-13 18:47
C:\ComboFix2.txt … 2007-08-17 23:54
C:\ComboFix3.txt … 2007-08-16 20:19

— E O F —


=============
HJT LOG
============

Logfile of HijackThis v1.99.1
Scan saved at 6:48:56 PM, on 10/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
C:\WINDOWS\TEMP\ZVB2DF.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\cmd.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Trend Micro\OfficeScan Client\Pop3Trap.exe
C:\Program Files\Snapfish Picture Mover\SnapfishPictureMover.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\cmd.exe
C:\ComboFix\vfind.cfexe
C:\Program Files\Hijackthis\Killer.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/mywaybiz
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Snapfish Picture Mover.lnk = C:\Program Files\Snapfish Picture Mover\SnapfishPictureMover.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {3DC2E31C-371A-4BD3-9A27-CDF57CE604CF} (MSN Money Charting) - http://moneycentral.msn.com/cabs/pmupd806.exe
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = cinci.rr.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = cinci.rr.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = cinci.rr.com
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
Now that your logs are clean, let us make sure your entire system is bug free:

Please use the Internet Explorer browser, and do an online scan with Kaspersky Online Scanner
Click Yes, when prompted to install its ActiveX component.
(Note.. for Internet Explorer 7 users: If at any time you have trouble with the "Accept" button of the license, click on the "Zoom" tool located at the bottom right of the IE window and set the zoom to 75 %. Once the license has been accepted, reset to 100%.)
The program launches and downloads the latest definition files.
  • Once the files are downloaded click on Next
  • Click on Scan Settings and configure as follows:
    • Scan using the following Anti-Virus database:
      • Extended
    • Scan Options:Scan Archives
      Scan Mail Bases
  • Click OK and, under select a target to scan, select My Computer
When the scan is done, in the Scan is completed window (below), any infection is displayed.
There is no option to clean/disinfect, however, we need to analyze the information on the report.
[external image: Posted Image]
[external image: Posted Image]
To obtain the report:
Click on: Save Report As (above - red blinking arrow)
Next, in the Save as prompt, Save in area, select: Desktop
In the File name area, use KScan, or something similar
In Save as type, click the drop arrow and select: Text file [*.txt]
Then, click: Save
Please post the Kaspersky Online Scanner Report in your reply, along with a fresh HijackThis log
Hi Trevuren

Here are the logs that you had requested.

Regards, Khilafat

================
KASPERSKY ONLINE SCANNER REPORT
Sunday, October 14, 2007 8:11:01 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.0
Kaspersky Anti-Virus database last update: 20/08/2007
Kaspersky Anti-Virus database records: 386201
——————————————————————————-
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 67411
Number of viruses found: 48
Number of infected objects: 138
Number of suspicious objects: 0
Duration of the scan process: 00:51:14
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ad71417d35bb0342c2c8d7fca62da80b_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\Gauri\Local Settings\Temporary Internet Files\Content.IE5UE768ZD\idien[1] Infected: Trojan.Win32.Agent.aoy skipped
C:\Documents and Settings\LocalService\Cookies\INDEX.DAT Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Salil\Application Data\Snapfish\Client\Data\DataCenter.ldb Object is locked skipped
C:\Documents and Settings\Salil\Application Data\Snapfish\Client\Data\DataCenter.madb Object is locked skipped
C:\Documents and Settings\Salil\Application Data\Snapfish\Client\Log\agent.log Object is locked skipped
C:\Documents and Settings\Salil\Cookies\INDEX.DAT Object is locked skipped
C:\Documents and Settings\Salil\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Salil\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Salil\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\Salil\Local Settings\History\History.IE5\MSHist012007101420071015\index.dat Object is locked skipped
C:\Documents and Settings\Salil\Local Settings\Temp\JET74A3.tmp Object is locked skipped
C:\Documents and Settings\Salil\Local Settings\Temp\JET756E.tmp Object is locked skipped
C:\Documents and Settings\Salil\Local Settings\Temp\logger.log Object is locked skipped
C:\Documents and Settings\Salil\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Salil\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Salil\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Snapfish Picture Mover\Sample\DataCenter.ldb Object is locked skipped
C:\Program Files\Snapfish Picture Mover\Sample\DataCenter.madb Object is locked skipped
C:\Program Files\Trend Micro\OfficeScan Client\ConnLog\Conn_20071014.log Object is locked skipped
C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\awtss.dll Infected: Trojan-Downloader.Win32.Agent.yf skipped
C:\Program Files\WinBudget\bin\carp**.1169509029.old/EXE-file Infected: not-a-virus:AdWare.Win32.BHO.by skipped
C:\Program Files\WinBudget\bin\carp**.1169509029.old Embedded EXE: infected - 1 skipped
C:\QooBox\Quarantine\C\Documents and Settings\All Users\Documents\Settings\bot.dll.vir Infected: Email-Worm.Win32.Zhelatin.gh skipped
C:\QooBox\Quarantine\C\Documents and Settings\Gauri\Local Settings\Temp\6464.exe.vir Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Gauri\Local Settings\Temp\a.exe.vir Infected: Backdoor.Win32.Dumador.fp skipped
C:\QooBox\Quarantine\C\Documents and Settings\Gauri\Local Settings\Temp\monsys.exe.vir Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Gauri\Local Settings\Temp\poweragent.exe.vir Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Gauri\Local Settings\Temp\server32.exe.vir Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Gauri\Local Settings\Temp\svwin.exe.vir Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Gauri\Local Settings\Temporary Internet Files\Content.IE5\3HDZPOUM\adfcook[1].vir Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\QooBox\Quarantine\C\Documents and Settings\Gauri\Local Settings\Temporary Internet Files\Content.IE5\3HDZPOUM\hlpsrv[1].exe.vir Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Gauri\Local Settings\Temporary Internet Files\Content.IE5\KBA5NGZM\hlpsrv[1].exe.vir Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\QooBox\Quarantine\C\Documents and Settings\Gauri\Local Settings\Temporary Internet Files\Content.IE5\KBA5NGZM\kcehc_eicooc20070702[1].vir Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\QooBox\Quarantine\C\Documents and Settings\Salil\Desktop\[4]-Submit_2007-08-15_204338.09.zip.vir/dkhvjrtf.exe Infected: Trojan.Win32.Agent.aoy skipped
C:\QooBox\Quarantine\C\Documents and Settings\Salil\Desktop\[4]-Submit_2007-08-15_204338.09.zip.vir/drvhak.dll Infected: Trojan.Win32.Agent.qt skipped
C:\QooBox\Quarantine\C\Documents and Settings\Salil\Desktop\[4]-Submit_2007-08-15_204338.09.zip.vir/rasterx.dll Infected: Trojan-Spy.Win32.Banker.cji skipped
C:\QooBox\Quarantine\C\Documents and Settings\Salil\Desktop\[4]-Submit_2007-08-15_204338.09.zip.vir/fertbuk.dll Infected: Trojan-Spy.Win32.Banker.cji skipped
C:\QooBox\Quarantine\C\Documents and Settings\Salil\Desktop\[4]-Submit_2007-08-15_204338.09.zip.vir ZIP: infected - 4 skipped
C:\QooBox\Quarantine\C\DOCUME~1\Salil\APPLIC~1\hidires\bak\hidr.exe.vir Infected: Trojan-PSW.Win32.LdPinch.bhb skipped
C:\QooBox\Quarantine\C\DOCUME~1\Salil\APPLIC~1\hidires\m_hook.sys.vir Infected: Email-Worm.Win32.Bagle.gy skipped
C:\QooBox\Quarantine\C\Program Files\Microsoft\bak\svhost32.exe.vir Infected: Trojan-PSW.Win32.Nilage.apx skipped
C:\QooBox\Quarantine\C\Program Files\Microsoft\svhost32.exe.vir Infected: Trojan-Downloader.Win32.Agent.awf skipped
C:\QooBox\Quarantine\C\Program Files\MSN\hoke2.dll.vir Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\QooBox\Quarantine\C\Program Files\MSN\hoke4444.dll.vir Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\QooBox\Quarantine\C\Program Files\MSN\hoke83122.dll.vir Infected: not-a-virus:AdWare.Win32.TTC.b skipped
C:\QooBox\Quarantine\C\Program Files\MSN Gaming Zone\lavuqa.dll.vir Infected: Trojan.Win32.BHO.ab skipped
C:\QooBox\Quarantine\C\Program Files\Outerinfo\OiUninstaller.exe.vir/data0002 Infected: not-a-virus:AdWare.Win32.PurityScan.fk skipped
C:\QooBox\Quarantine\C\Program Files\Outerinfo\OiUninstaller.exe.vir NSIS: infected - 1 skipped
C:\QooBox\Quarantine\C\Program Files\Radmin\AdmDll.dll.vir Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
C:\QooBox\Quarantine\C\Program Files\Radmin\raddrv.dll.vir Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
C:\QooBox\Quarantine\C\Program Files\Radmin\radmin.exe.vir Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.21 skipped
C:\QooBox\Quarantine\C\Program Files\Radmin\r_server.exe.vir Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.21 skipped
C:\QooBox\Quarantine\C\Program Files\TTC.dll.vir Infected: not-a-virus:AdWare.Win32.TTC.c skipped
C:\QooBox\Quarantine\C\Program Files\WinBudget\bin\matrix.dll.1187052632.old.vir Infected: not-a-virus:AdWare.Win32.BHO.by skipped
C:\QooBox\Quarantine\C\SALIL\VPN\radmin21.exe.vir/AdmDll.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
C:\QooBox\Quarantine\C\SALIL\VPN\radmin21.exe.vir/raddrv.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
C:\QooBox\Quarantine\C\SALIL\VPN\radmin21.exe.vir/radmin.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.21 skipped
C:\QooBox\Quarantine\C\SALIL\VPN\radmin21.exe.vir/r_server.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.21 skipped
C:\QooBox\Quarantine\C\SALIL\VPN\radmin21.exe.vir Gentee: infected - 4 skipped
C:\QooBox\Quarantine\C\SALIL\VPN\radmin[1].exe.txt.vir/radmin21.exe/AdmDll.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
C:\QooBox\Quarantine\C\SALIL\VPN\radmin[1].exe.txt.vir/radmin21.exe/raddrv.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
C:\QooBox\Quarantine\C\SALIL\VPN\radmin[1].exe.txt.vir/radmin21.exe/radmin.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.21 skipped
C:\QooBox\Quarantine\C\SALIL\VPN\radmin[1].exe.txt.vir/radmin21.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.21 skipped
C:\QooBox\Quarantine\C\SALIL\VPN\radmin[1].exe.txt.vir ZIP: infected - 4 skipped
C:\QooBox\Quarantine\C\SALIL\VPN\radmin[1].exe.txt.vir PE_Patch: infected - 4 skipped
C:\QooBox\Quarantine\C\SALIL\VPN\radmin[1].exe.zip.vir/radmin21.exe/AdmDll.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
C:\QooBox\Quarantine\C\SALIL\VPN\radmin[1].exe.zip.vir/radmin21.exe/raddrv.dll Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
C:\QooBox\Quarantine\C\SALIL\VPN\radmin[1].exe.zip.vir/radmin21.exe/radmin.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.21 skipped
C:\QooBox\Quarantine\C\SALIL\VPN\radmin[1].exe.zip.vir/radmin21.exe/r_server.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.21 skipped
C:\QooBox\Quarantine\C\SALIL\VPN\radmin[1].exe.zip.vir/radmin21.exe Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.21 skipped
C:\QooBox\Quarantine\C\SALIL\VPN\radmin[1].exe.zip.vir ZIP: infected - 5 skipped
C:\QooBox\Quarantine\C\Temp\bass.exe.vir/data0002/data0002 Infected: not-a-virus:AdWare.Win32.TTC.b skipped
C:\QooBox\Quarantine\C\Temp\bass.exe.vir/data0002 Infected: not-a-virus:AdWare.Win32.TTC.b skipped
C:\QooBox\Quarantine\C\Temp\bass.exe.vir/data0006 Infected: Virus.Win32.Virut.i skipped
C:\QooBox\Quarantine\C\Temp\bass.exe.vir/data0007 Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\QooBox\Quarantine\C\Temp\bass.exe.vir/data0008 Infected: Trojan-Dropper.Win32.Agent.mu skipped
C:\QooBox\Quarantine\C\Temp\bass.exe.vir NSIS: infected - 5 skipped
C:\QooBox\Quarantine\C\temp.zip.vir Infected: Email-Worm.Win32.Bagle.gen skipped
C:\QooBox\Quarantine\C\U.exe.vir Infected: Trojan.Win32.Agent.ato skipped
C:\QooBox\Quarantine\C\WINDOWS\$NtUninstallKB917953$\tcpip.sys.vir Infected: Trojan.Win32.Patched.ad skipped
C:\QooBox\Quarantine\C\WINDOWS\24233484.exe.vir Infected: Email-Worm.Win32.Bagle.ce skipped
C:\QooBox\Quarantine\C\WINDOWS\45510703.exe.vir Infected: Email-Worm.Win32.Bagle.bq skipped
C:\QooBox\Quarantine\C\WINDOWS\b122.exe.vir Infected: not-a-virus:AdWare.Win32.Rond.c skipped
C:\QooBox\Quarantine\C\WINDOWS\DOWNLO~1\UWA7P_0001_N91M0809NetInstaller.exe.vir Infected: not-a-virus:Downloader.Win32.WinFixer.o skipped
C:\QooBox\Quarantine\C\WINDOWS\mgrs.exe.vir Infected: Trojan-Downloader.Win32.Alphabet.p skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\admdll.dll.vir Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\amlxuluw.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\argysyko.dll.vir Infected: Trojan-Spy.Win32.Agent.kg skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\aukmkpqy.exe.vir Infected: Trojan-Dropper.Win32.Agent.bmk skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\bak\dxdlg32.exe.vir Infected: Trojan.Win32.VB.avs skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\bak\system43.exe.vir Infected: Trojan-Downloader.Win32.Small.ehw skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\bak\winldra.exe.vir Infected: Backdoor.Win32.Dumador.fp skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\byftlqsv.dll.vir Infected: Trojan-Spy.Win32.Agent.kg skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\byxvvtr.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\configs\kmhp83122.exe.vir/data0002 Infected: not-a-virus:AdWare.Win32.TTC.b skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\configs\kmhp83122.exe.vir NSIS: infected - 1 skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\dms.dll.vir Infected: Trojan-PSW.Win32.Nilage.apx skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\dnsersnd.dll.vir Infected: Trojan-Clicker.Win32.Small.cf skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\driver\w717.exe.vir Infected: Virus.Win32.Virut.i skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\drvfim.dll.vir Infected: Trojan.Win32.Agent.qt skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\ehnstmtk.dll.vir Infected: Trojan-Spy.Win32.Agent.kg skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\f02WtR\f02WtR1065.exe.vir Infected: Trojan-Downloader.Win32.VB.awj skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\f06WtR\f06WtR1083.exe.vir Infected: Trojan-Downloader.Win32.VB.awj skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\F3\n553.exe.vir Infected: Trojan-Dropper.Win32.Agent.mu skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\fbsbajrx.dll.vir Infected: Trojan-Spy.Win32.Agent.kg skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\fjiumiwc.dll.vir Infected: Trojan-Spy.Win32.Agent.kg skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\fyjjskts.dll.vir Infected: Trojan-Spy.Win32.Agent.kg skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\gebcywv.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\gjwovsvc.dll.vir Infected: Trojan-Spy.Win32.Agent.kg skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\gkqphsxt.dll.vir Infected: Trojan-Spy.Win32.Agent.kg skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\hlpsrv.exe.vir Infected: Trojan-Clicker.Win32.Small.mv skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\hxdtxqtd.dll.vir Infected: Trojan-Spy.Win32.Agent.kg skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\hyycdesc.dll.vir Infected: Trojan-Spy.Win32.Agent.kg skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\install.exe.vir Infected: Trojan-Dropper.Win32.Agent.bfr skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\is67718.exe.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.ks skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\jb.exe.vir Infected: Trojan-PSW.Win32.Nilage.apx skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\jbhook.dll.vir Infected: Trojan-PSW.Win32.Small.br skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\jogviplf.dll.vir Infected: Trojan-Spy.Win32.Agent.kg skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\knapecdb.dll.vir Infected: Trojan-Spy.Win32.Agent.kg skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\nwslhekh.exe.vir Infected: Trojan-Dropper.Win32.Agent.bmk skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\Outerinfo-1440.exe.vir/data0004/data0002 Infected: not-a-virus:AdWare.Win32.PurityScan.fk skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\Outerinfo-1440.exe.vir/data0004 Infected: not-a-virus:AdWare.Win32.PurityScan.fk skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\Outerinfo-1440.exe.vir NSIS: infected - 2 skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\qkkciodf.dll.vir Infected: Trojan-Spy.Win32.Agent.kg skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\qmewfvde.dll.vir Infected: Trojan-Spy.Win32.Agent.kg skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\qnyqwunv.dll.vir Infected: Trojan-Spy.Win32.Agent.kg skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\skna455101.exe.vir/data0002 Infected: not-a-virus:AdWare.Win32.TTC.c skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\skna455101.exe.vir NSIS: infected - 1 skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\svc23.exe.vir Infected: Email-Worm.Win32.Bagle.cj skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\ujtiddib.dll.vir Infected: Trojan-Spy.Win32.Agent.kg skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\uljhuwaq.dll.vir Infected: Trojan-Spy.Win32.Agent.kg skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\uqpllopt.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\user10.exe.vir Infected: Trojan-Downloader.Win32.Small.dxm skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\vlifxqbd.dll.vir Infected: Trojan-Spy.Win32.Agent.kg skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\waverevenue.exe.vir Infected: Virus.Win32.Virut.i skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\winb2.exe.vir Infected: Email-Worm.Win32.Bagle.gj skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\wivmmrjr.dll.vir Infected: Trojan-Spy.Win32.Agent.kg skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\wwww.exe.vir Infected: Trojan-Downloader.Win32.Delf.ain skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\ycvjluxf.dll.vir Infected: Trojan-Spy.Win32.Agent.kg skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\yssjveon.dll.vir Infected: Trojan-Spy.Win32.Agent.kg skipped
C:\QooBox\Quarantine\C\WINDOWS\TISKY009.exe.vir Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped
C:\QooBox\Quarantine\C\WINDOWS\tk58.exe.vir Infected: Trojan.Win32.BHO.ab skipped
C:\QooBox\Quarantine\C\WINDOWS\TTC-4444.exe.vir/data0002 Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\QooBox\Quarantine\C\WINDOWS\TTC-4444.exe.vir NSIS: infected - 1 skipped
C:\QooBox\Quarantine\C\WINDOWS\yekwh0578.exe.vir Infected: Trojan-Downloader.Win32.Small.dxm skipped
C:\QooBox\Quarantine\catchme2007-08-11_ 70426.26.zip/core.sys Infected: Rootkit.Win32.Agent.eq skipped
C:\QooBox\Quarantine\catchme2007-08-11_ 70426.26.zip/opnopon.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\QooBox\Quarantine\catchme2007-08-11_ 70426.26.zip ZIP: infected - 2 skipped
C:\sti.log Object is locked skipped
C:\VundoFix Backups\gebbcda.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\VundoFix Backups\hgghiih.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\VundoFix Backups\icbmrsyu.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.hb skipped
C:\VundoFix Backups\jkkihff.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\VundoFix Backups\rqroppm.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\VundoFix Backups\rqrpnlm.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\VundoFix Backups\ssttq.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.la skipped
C:\VundoFix Backups\wvuuvuu.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\AppEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SAM Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SecEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SysEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\H323LOG.TXT Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\WIADEBUG.LOG Object is locked skipped
C:\WINDOWS\WIASERVC.LOG Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.




——————————-
Logfile of HijackThis v1.99.1
Scan saved at 8:12:02 PM, on 10/14/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Snapfish Picture Mover\SnapfishPictureMover.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trend Micro\OfficeScan Client\Pop3Trap.exe
C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\TEMP\XUDED5.EXE
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Hijackthis\Killer.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/mywaybiz
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Snapfish Picture Mover.lnk = C:\Program Files\Snapfish Picture Mover\SnapfishPictureMover.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {3DC2E31C-371A-4BD3-9A27-CDF57CE604CF} (MSN Money Charting) - http://moneycentral.msn.com/cabs/pmupd806.exe
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = cinci.rr.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = cinci.rr.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = cinci.rr.com
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
Download OTMoveIt by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt.exe to run it.
  • Copy the content of the quotebox below to the clipboard by highlighting ALL of
    the file paths and pressing CTRL + C (or, after highlighting, right-click and choose
    copy):

    C:\Documents and Settings\Gauri\Local Settings\Temporary Internet Files\Content.IE5UE768ZD\idien[1]
    C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\awtss.dll
    C:\Program Files\WinBudget
    C:\VundoFix Backups


  • Return to OTMoveIt, right click on the "Paste List of Files/Folders to be
    moved"
    window and choose Paste.
  • Click the red Moveit! button.
  • Close OTMoveIt
If a file or folder cannot be moved immediately you may be asked to reboot
the machine to finish the move process. If you are asked to reboot the machine
choose Yes.

Please "Copy" the results from the "Results" window (to the right) and then "Paste"
them into your next reply on the forum. Reboot into Normal Mode if you have to reboot.
Hi Trevuren, (sorry for delay in reply. For some reason I am unable to login using IE. I now used FireFox) Here are the results from OnMoveIt File/Folder C:\Documents and Settings\Gauri\Local Settings\Temporary Internet Files\Content.IE5UE768ZD\idien[1] not found. LoadLibrary failed for C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\awtss.dll C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\awtss.dll NOT unregistered. C:\Program Files\Trend Micro\OfficeScan Client\SUSPECT\awtss.dll moved successfully. C:\Program Files\WinBudget\bin moved successfully. C:\Program Files\WinBudget moved successfully. C:\VundoFix Backups moved successfully. Regards, Khilafat Created on 10/15/2007 23:42:53

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI