This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Help! Cannot Open Microsoft Word Files!

37 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

i have already reformatted my computera a few times but norton antivirus keeps on telling me there's a virus on my computer called bloodhound. Norton Antivirus has also been giving me problems. windows that are blank pop up very often last time but after i reformated my computer once more, it only pops up when i open microsoft word documents. my documents are about 700KB in size. The black window tells me that my file is too big for my computer. however, i could open microsoft powerpoint. please help me!!! i have already tried all means for the past few weeks. =) thank you very much!



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:23:52 PM, on 9/9/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\gearsec.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\System32\CTFMON.EXE
C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [load] C:\WINDOWS\uninstall\rundl132.exe
O4 - HKLM\..\Run: [upxdnd] C:\WINDOWS\upxdnd.exe
O4 - HKLM\..\Run: [cmdbcs] C:\WINDOWS\cmdbcs.exe
O4 - HKLM\..\Run: [DbgHlp32] C:\WINDOWS\DbgHlp32.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKLM\..\Policies\Explorer\Run: [MSDEG32] LYLoader.exe
O4 - HKLM\..\Policies\Explorer\Run: [MSDWG32] LYLoadbr.exe
O4 - HKLM\..\Policies\Explorer\Run: [MSDCG32 ] LYLeador.exe
O4 - HKLM\..\Policies\Explorer\Run: [MSDOG32] LYLoador.exe
O4 - HKLM\..\Policies\Explorer\Run: [MSDSG32] LYLoadar.exe
O4 - HKLM\..\Policies\Explorer\Run: [MSDMG32] LYLoadmr.exe
O4 - HKLM\..\Policies\Explorer\Run: [MSDHG32] LYLoadhr.exe
O4 - HKLM\..\Policies\Explorer\Run: [MSDQG32] LYLoadqr.exe
O4 - HKCU\..\Policies\Explorer\Run: [w] %SystemRoot%\WinRaR.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O20 - AppInit_DLLs: wlhpri.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SAVScan - Unknown owner - c:\Program Files\Norton AntiVirus\SAVScan.exe

–
End of file - 7325 bytes
_________________________________
Welcome to the Forums.

The fixes we will use are specific to your problems and should only be used for this issue on this machine.

Please only use this topic to reply to. Do not start another thread.
If any other issues arise let me know.
The process is not instant. Please continue to review my answers until I tell you your machine is clear. Absence of symptoms does not mean that everything is clear. So lets do this to the end!
  • All hijackthis logs I ask for should be done in normal mode ( not safe mode)
  • These logs should be done last after you have followed my instructions in the previous post.


___________________________________
Please disable SpybotSD TeaTimer, as it may hinder the removal of the infection. You can enable it after you're clean.
To disable SpybotSD TeaTimer:
Open Spybot and click on Mode and check Advanced Mode
Check yes to next window.
Click on Tools in bottom left hand corner.
Click on System Startup icon.
Uncheck Teatimer box.
Click Allow Change box.




Please if you decide to seek help at another forum let us know. There is a shortage of helpers and tying 2 of us up is a waste of time.
If you have any questions about any advice given here please STOP and ask!


______________________________
HJT
Run hijackthis and choose scan only and place a check by the following lines if present.
Close all other windows and browsers except HJT before clicking on Fix Checked


O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - HKLM\..\Run: [load] C:\WINDOWS\uninstall\rundl132.exe
O4 - HKLM\..\Run: [upxdnd] C:\WINDOWS\upxdnd.exe
O4 - HKLM\..\Run: [cmdbcs] C:\WINDOWS\cmdbcs.exe
O4 - HKLM\..\Run: [DbgHlp32] C:\WINDOWS\DbgHlp32.exe
O4 - HKLM\..\Policies\Explorer\Run: [MSDEG32] LYLoader.exe
O4 - HKLM\..\Policies\Explorer\Run: [MSDWG32] LYLoadbr.exe
O4 - HKLM\..\Policies\Explorer\Run: [MSDCG32 ] LYLeador.exe
O4 - HKLM\..\Policies\Explorer\Run: [MSDOG32] LYLoador.exe
O4 - HKLM\..\Policies\Explorer\Run: [MSDSG32] LYLoadar.exe
O4 - HKLM\..\Policies\Explorer\Run: [MSDMG32] LYLoadmr.exe
O4 - HKLM\..\Policies\Explorer\Run: [MSDHG32] LYLoadhr.exe
O4 - HKLM\..\Policies\Explorer\Run: [MSDQG32] LYLoadqr.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm







_____________________________
Submit a file to Jotti
Please go here : http://virusscan.jotti.org/
On top of the page there is a field to add the filepath, copy and paste these filepaths: 1 at a time.


c:\windows\system32\wlhpri.dll

c:\windows\WinRaR.exe


Please do them both. I know what winrar is I just don't like it's location.


Then hit Submit
The scan will take a while before the result comes up so please be patient.
Then copy the result and post it here in this thread.

If Jotti's service load is too high, you can use the following scanner instead:
http://www.virustotal.com/xhtml/index_en.html

_______________________________________


1. Download Combo fix from one of these locations.
http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply . (c:\comboFix.txt)

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

________________________________________

In your next reply I would like to see:
  • A new HJT log
  • The report from Combo fix
  • The report from Jottis/virus total
HI! =) i'm so sorry this reply took so long. Thanks for helping me! really appreciate it! =) and yes, i definitely still need your help.
I've tried my best to follow the instructions you gave me but i encountered some problems along the way.

Firstly, when disabling spybot teatimer, i couldnt locate the box u wanted me to check. Instead, i disabled Spybot by clicking on tools, den clicking Resident and checking the box that disables teatimer. i hope i dint make things complicated for you. If so, please do tell me.

When running Hijack This, i couldnt locate the last two files you wanted me to check, namely:

O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm


So here's my new HijackThis Log:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:43:16 PM, on 9/17/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\gearsec.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jucheck.exe
C:\WINDOWS\System32\hkcmd.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [AAWTray] C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Policies\Explorer\Run: [w] %SystemRoot%\WinRaR.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O20 - AppInit_DLLs: wlhpri.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe

–
End of file - 6349 bytes



And As for ComboFix, Here's the log:



ComboFix 07-09-17.2 - "Owner" 2007-09-17 23:32:04.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.44 [GMT 8:00]
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\_desktop.ini
C:\privilege.dat
C:\WINDOWS\richdll.dll
C:\WINDOWS\system32\cmdbcs.dll
C:\WINDOWS\system32\drivers\npf.sys
C:\WINDOWS\system32\lyloader.exe
C:\WINDOWS\system32\lymangr.dll
C:\WINDOWS\system32\msdeg32.dll
C:\WINDOWS\system32\Packet.dll
C:\WINDOWS\system32\SHQMANGR.DLL
C:\WINDOWS\system32\upxdnd.dll
C:\WINDOWS\system32\WanPacket.dll
C:\WINDOWS\system32\wpcap.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


——-\LEGACY_NPF
——-\NPF


((((((((((((((((((((((((( Files Created from 2007-08-17 to 2007-09-17 )))))))))))))))))))))))))))))))
.

2007-09-17 23:31 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-09-12 22:37 16,608 –a—— C:\WINDOWS\system32\LYLOADMR.EXE
2007-09-09 22:34 76,560 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2007-09-09 20:54 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinZip
2007-09-09 20:01 d——– C:\Program Files\Common Files\Panda Software
2007-09-09 19:24 d——– C:\DOCUME~1\Owner\.housecall6.6
2007-09-09 18:18 d——– C:\WINDOWS\DED53B0BB67C4244AE6AD6FD3C28D1EF.TMP
2007-09-09 15:33 d——– C:\Program Files\Lavasoft
2007-09-09 15:33 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-09-09 15:31 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-09-09 14:57 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-09-09 14:51 d——– C:\Program Files\Trend Micro
2007-09-09 13:54 d—s—- C:\DOCUME~1\Owner\UserData
2007-09-09 13:46 24,576 ——— C:\WINDOWS\system32\ftmgpd.dll
2007-09-08 23:17 27,648 –a—— C:\WINDOWS\system32\SHQ.DLL
2007-09-08 23:17 20 –a—— C:\WINDOWS\system32\mhsha1.dat
2007-09-08 22:39 182,880 –a–c— C:\WINDOWS\system32\dllcache\iuengine.dll
2007-09-08 22:39 182,880 –a—— C:\WINDOWS\system32\iuengine.dll
2007-09-08 22:19 17,920 –a—— C:\WINDOWS\system32\mdimon.dll
2007-09-08 22:16 d——– C:\Program Files\Microsoft ActiveSync
2007-09-08 22:16 d——– C:\Program Files\Common Files\L&H
2007-09-08 22:14 d——– C:\WINDOWS\SHELLNEW
2007-09-08 22:13 d——– C:\Program Files\Microsoft.NET
2007-09-08 22:11 dr-h—– C:\MSOCache
2007-09-08 22:08 51,056 -ra—— C:\WINDOWS\system32\drivers\hpzid412.sys
2007-09-08 22:08 21,760 –a–c— C:\WINDOWS\system32\dllcache\usbstor.sys
2007-09-08 22:08 16,496 -ra—— C:\WINDOWS\system32\drivers\HPZipr12.sys
2007-09-08 22:07 28,160 –a–c— C:\WINDOWS\system32\dllcache\usbccgp.sys
2007-09-08 22:07 28,160 –a—— C:\WINDOWS\system32\drivers\usbccgp.sys
2007-09-08 22:07 24,960 –a–c— C:\WINDOWS\system32\dllcache\usbprint.sys
2007-09-08 22:07 24,960 –a—— C:\WINDOWS\system32\drivers\usbprint.sys
2007-09-08 22:07 21,488 -ra—— C:\WINDOWS\system32\drivers\HPZius12.sys
2007-09-08 22:07 14,208 –a–c— C:\WINDOWS\system32\dllcache\usbscan.sys
2007-09-08 22:07 14,208 –a—— C:\WINDOWS\system32\drivers\usbscan.sys
2007-09-08 22:03 626,960 -ra—— C:\WINDOWS\system32\hpvaut32.dll
2007-09-08 22:03 487,424 -ra—— C:\WINDOWS\system32\hpvcp70.dll
2007-09-08 22:03 44,544 -ra—— C:\WINDOWS\system32\MSXML4a.dll
2007-09-08 22:03 344,064 -ra—— C:\WINDOWS\system32\hpvcr70.dll
2007-09-08 22:02 d——– C:\Program Files\Common Files\Hewlett-Packard
2007-09-08 21:59 43,488 –a—— C:\WINDOWS\system32\drivers\AFS2K.SYS
2007-09-08 21:59 d——– C:\Program Files\Common Files\HP
2007-09-08 21:55 34,383 ——— C:\WINDOWS\hpomdl03.dat
2007-09-08 21:55 28,886 –a—— C:\WINDOWS\hpoins03.dat
2007-09-08 21:55 d——– C:\Program Files\HP
2007-09-08 21:49 23,552 –a—— C:\WINDOWS\system32\oubttg.dll
2007-09-08 21:48 24,064 –a—— C:\WINDOWS\system32\gbekry.dll
2007-09-08 21:48 19,968 –a—— C:\WINDOWS\system32\mohekj.dll
2007-09-08 09:49 58 –a—— C:\WINDOWS\system32\wlgini.dll
2007-09-08 09:49 23,552 –a—— C:\WINDOWS\system32\DbgHlp32.dll
2007-09-08 09:48 59 –a—— C:\WINDOWS\system32\kawdacs.dll
2007-09-08 09:48 58 –a—— C:\WINDOWS\system32\kaqhacs.dll
2007-09-08 09:48 58 –a—— C:\WINDOWS\system32\kapjacs.dll
2007-09-08 09:48 56 –a—— C:\WINDOWS\system32\rsjzafg.dll
2007-09-08 09:48 55 –a—— C:\WINDOWS\system32\kvdxacf.dll
2007-09-08 09:48 51 –a—— C:\WINDOWS\system32\zxiini.dll
2007-09-08 09:48 50 –a—— C:\WINDOWS\system32\raqjani.dll
2007-09-08 09:48 32,768 ——— C:\WINDOWS\dbhelp.dll
2007-09-08 09:47 52 –a—— C:\WINDOWS\system32\mygini.dll
2007-09-03 08:39 249 –a—— C:\WINDOWS\system\hpsysdrv.dat
2007-09-03 08:38 d——– C:\WINDOWS\I386
2007-09-03 08:33 dr——- C:\DOCUME~1\ALLUSE~1\Documents
2007-09-02 17:59 155,648 –a—— C:\WINDOWS\system32\igfxres.dll
2007-09-02 17:57 204,800 –a—— C:\WINDOWS\system32\IVIresizeW7.dll
2007-09-02 17:57 200,704 –a—— C:\WINDOWS\system32\IVIresizeA6.dll
2007-09-02 17:57 20,480 –a—— C:\WINDOWS\system32\IVIresize.dll
2007-09-02 17:57 192,512 –a—— C:\WINDOWS\system32\IVIresizeP6.dll
2007-09-02 17:57 192,512 –a—— C:\WINDOWS\system32\IVIresizeM6.dll
2007-09-02 17:57 188,416 –a—— C:\WINDOWS\system32\IVIresizePX.dll
2007-09-02 17:57 10,368 ——— C:\WINDOWS\system32\drivers\pfc.sys
2007-09-02 17:57 d——– C:\WINDOWS\uninstall
2007-09-02 17:57 d——– C:\WINDOWS\system32\config\SYSTEM~1\WINDOWS
2007-09-02 17:57 d——– C:\WINDOWS\system32\config\SYSTEM~1\APPLIC~1\Symantec
2007-09-02 17:57 d——– C:\WINDOWS\system32\config\SYSTEM~1\APPLIC~1\SampleView
2007-09-02 17:57 d——– C:\WINDOWS\system32\config\SYSTEM~1\APPLIC~1\Real
2007-09-02 17:57 d——– C:\863d765bceb76777372b95ff1d0a40
2007-09-02 17:57 d——– C:\54f4ff25124b3b9e53a7416b03
2007-09-02 17:56 57,856 –a—— C:\WINDOWS\system32\drivers\drmk.sys
2007-09-02 17:56 134,272 –a—— C:\WINDOWS\system32\drivers\portcls.sys
2007-09-02 17:56 d——– C:\Program Files\InterVideo
2007-09-02 17:54 51,072 –a—— C:\WINDOWS\system32\drivers\i8042prt.sys
2007-09-02 17:54 23,424 –a—— C:\WINDOWS\system32\drivers\kbdclass.sys
2007-09-02 17:54 d——– C:\DOCUME~1\DEFAUL~1\WINDOWS

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-09 21:34 ——— d——– C:\Program Files\QuickTime
2007-09-09 21:34 ——— d——– C:\Program Files\Presario PC Help
2007-09-09 21:34 ——— d——– C:\Program Files\PC-Doctor for Windows
2007-09-09 21:33 ——— d——– C:\Program Files\Norton AntiVirus
2007-09-09 21:33 ——— d——– C:\Program Files\Microsoft Works
2007-09-09 21:32 ——— d——– C:\Program Files\iTunes
2007-09-09 21:28 ——— d——– C:\Program Files\Easy Internet signup
2007-09-09 20:02 ——— d——– C:\Program Files\Common Files\InstallShield
2007-09-02 17:59 3674 -rahs—- C:\WINDOWS\system32\drivers\HP_P9902CV-AB4 SR1120CF SE610_YC_Pres_QTHT424_E43SEhwRET1_4_IGamila Giovani Neon series_SMICRO-STAR INTERNATIONAL CO., LTD_V030_B3.10_T040415_WXH1_L409_M248_J80_7Intel_8Pentium 4_92.8_111063044_N10EC8139_P_Z_K_A808624C5.MRK
2007-09-02 17:56 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-08-07 13:58 8320 –a—— C:\WINDOWS\system32\drivers\AWRTRD.sys
2007-08-07 13:56 9344 –a—— C:\WINDOWS\system32\drivers\NSDriver.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.

*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2003-08-17 06:57]
"MSPY2002"="C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe" [2003-08-17 00:24]
"PHIME2002ASync"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe" [2003-08-17 00:25]
"PHIME2002A"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe" [2003-08-17 00:25]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2004-04-01 20:57]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 23:04]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2004-02-11 00:51]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-12 02:02]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-04-01 22:04]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2004-01-17 02:16]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2003-11-03 23:50]
"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2003-08-15 07:59]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2003-09-13 02:13]
"AlcxMonitor"="ALCXMNTR.EXE" [2003-04-04 03:35 C:\WINDOWS\ALCXMNTR.EXE]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd.exe" [2003-06-25 11:24]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-06-26 18:50]
"AAWTray"="C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe" [2007-08-08 15:53]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\System32\ctfmon.exe" [2003-08-16 09:54]

C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
Compaq Connections.lnk - C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe [2004-04-01 22:26:37]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2003-07-07 01:20:40]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoInstrumentation"=1 (0x1)
"NoStartMenuSubFolders"=1 (0x1)
"NoFavoritesMenu"=1 (0x1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{8562452F-FA36-BA4F-892A-FF5FBBAC5318}"= C:\WINDOWS\System32\myhpri.dll [2004-08-04 09:47 20521]
"{2C87A354-ABC3-DEDE-FF33-3213FD7447C2}"= C:\WINDOWS\System32\kvdxbma.dll [2004-08-04 09:48 17494]
"{28907901-1416-3389-9981-372178569982}"= C:\WINDOWS\System32\kawdbzy.dll [2004-08-04 09:48 17502]
"{9A65498A-7653-9801-1647-987114AB7F49}"= C:\WINDOWS\System32\zxipri.dll [2004-08-04 09:48 20520]
"{14783410-4F90-34A0-7820-3230ACD05F41}"= C:\WINDOWS\System32\raqjapi.dll [2004-08-04 09:48 20556]
"{12FAACDE-34DA-CCD4-AB4D-DA34485A3421}"= C:\WINDOWS\System32\rsjzapm.dll [2004-08-04 09:48 19544]
"{1A321487-4977-D98A-C8D5-6488257545A1}"= C:\WINDOWS\System32\kapjazy.dll [2004-08-04 09:48 18012]
"{37D81718-1314-5200-2597-587901018073}"= C:\WINDOWS\System32\kaqhczy.dll [2004-08-04 09:48 16988]
"{5182C1EB-375C-573D-1F5E-234552345215}"= C:\WINDOWS\System32\wlhpri.dll [2004-08-04 09:49 20527]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=raqjapi.dll


*Newly Created Service* - ALG
*Newly Created Service* - IPNAT
.
Contents of the 'Scheduled Tasks' folder
"2007-09-08 14:13:19 C:\WINDOWS\Tasks\HP DArC Task #Hewlett-Packard#hp psc 1300 series#1189260524.job"
- C:\Program Files\HP\hpcoretech\comp\hpdarc.exe
"2007-09-15 02:31:28 C:\WINDOWS\Tasks\HP DArC Task #Hewlett-Packard#hp psc 1300 series#1189262568.job"
- C:\Program Files\HP\hpcoretech\comp\hpdarc.exe
"2007-09-09 06:03:02 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job"
- c:\PROGRA~1\NORTON~1\Navw32.exe
"2007-09-09 06:03:02 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
"2007-09-15 02:27:55 C:\WINDOWS\Tasks\WebReg 20070915102754.job"
.
**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-17 23:36:34
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-09-17 23:38:28 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-09-17 23:38
.
— E O F —



i used virustotal to scan my computer and here are the results:

For c:\windows\system32\wlhpri.dll



File wlhpri.dll_ received on 09.17.2007 17:45:36 (CET)

Result: 26/32 (81.25%)

Antivirus Version Last Update Result
AhnLab-V3 2007.9.14.0 2007.09.14 -
AntiVir 7.6.0.10 2007.09.17 TR/Spy.Delf.aao.4
Authentium 4.93.8 2007.09.16 W32/Trojan.BYIC
Avast 4.7.1043.0 2007.09.16 Win32:Delf-FVM
AVG 7.5.0.485 2007.09.17 PSW.Generic5.JGE
BitDefender 7.2 2007.09.17 BehavesLike:Trojan.WUDisable
CAT-QuickHeal 9.00 2007.09.17 TrojanSpy.Delf.aao
ClamAV 0.91.2 2007.09.17 Trojan.Spy-12343
DrWeb 4.33 2007.09.17 Trojan.PWS.Gamania.3932
eSafe 7.0.15.0 2007.09.17 Win32.Delf.aao
eTrust-Vet 31.1.5141 2007.09.17 Win32/Storark.AO
Ewido 4.0 2007.09.17 Logger.Delf.aao
FileAdvisor 1 2007.09.17 -
Fortinet 3.11.0.0 2007.09.17 Gampass.A
F-Prot 4.3.2.48 2007.09.16 W32/Trojan.BYIC
F-Secure 6.70.13030.0 2007.09.17 Trojan-Spy.Win32.Delf.aao
Ikarus T3.1.1.12 2007.09.17 Trojan-Spy.Win32.Delf.uv
Kaspersky 4.0.2.24 2007.09.17 Trojan-Spy.Win32.Delf.aao
McAfee 5120 2007.09.14 -
Microsoft 1.2803 2007.09.17 Trojan:Win32/Delf.AT!dll
NOD32v2 2534 2007.09.17 -
Norman 5.80.02 2007.09.17 W32/Malware.AJMA
Panda 9.0.0.4 2007.09.17 Trj/Lineage.FCW
Prevx1 V2 2007.09.17 -
Rising 19.41.02.00 2007.09.17 Trojan.PSW.Win32.OnlineGames.yat
Sophos 4.21.0 2007.09.17 Mal/Delagen-A
Sunbelt 2.2.907.0 2007.09.15 Trojan.WUDisable
Symantec 10 2007.09.17 Infostealer.Gampass
TheHacker 6.2.5.061 2007.09.17 Trojan/Spy.Delf.aao
VBA32 3.12.2.4 2007.09.17 Trojan-Spy.Win32.Delf.aao
VirusBuster 4.3.26:9 2007.09.17 -
Webwasher-Gateway 6.0.1 2007.09.17 Trojan.Spy.Delf.aao.4


Additional information
File size: 20527 bytes
MD5: 449ffc4fef1e9ad73c14624fa8131e66
SHA1: 41268c23d6006211ef5e72e1e2965148cc37b044



For c:\windows\WinRaR.exe

it said, "0 bytes size received / Se ha recibido un archivo vacio"




i hope the information i've provided is helpful… Please help me!!! :)
Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\system32\oubttg.dll
C:\WINDOWS\system32\gbekry.dll
C:\WINDOWS\system32\mohekj.dll
C:\WINDOWS\system32\wlgini.dll
C:\WINDOWS\system32\DbgHlp32.dll
C:\WINDOWS\system32\kawdacs.dll
C:\WINDOWS\system32\kaqhacs.dll
C:\WINDOWS\system32\kapjacs.dll
C:\WINDOWS\system32\rsjzafg.dll
C:\WINDOWS\system32\zxiini.dll
C:\WINDOWS\system32\raqjani.dll
C:\WINDOWS\system32\mygini.dll
C:\windows\WinRaR.exe
C:\WINDOWS\System32\myhpri.dll
C:\WINDOWS\System32\kvdxbma.dll
C:\WINDOWS\System32\kawdbzy.dll
C:\WINDOWS\System32\zxipri.dll
C:\WINDOWS\System32\raqjapi.dll
C:\WINDOWS\System32\rsjzapm.dll
C:\WINDOWS\System32\kapjazy.dll
C:\WINDOWS\System32\kaqhczy.dll
C:\WINDOWS\System32\wlhpri.dll

Registry::
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"W"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{8562452F-FA36-BA4F-892A-FF5FBBAC5318}"=-
"{2C87A354-ABC3-DEDE-FF33-3213FD7447C2}"=-
"{28907901-1416-3389-9981-372178569982}"=-
"{9A65498A-7653-9801-1647-987114AB7F49}"=-
"{14783410-4F90-34A0-7820-3230ACD05F41}"=-
"{12FAACDE-34DA-CCD4-AB4D-DA34485A3421}"=-
"{1A321487-4977-D98A-C8D5-6488257545A1}"=-
"{37D81718-1314-5200-2597-587901018073}"=-
"{5182C1EB-375C-573D-1F5E-234552345215}"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=""



Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:ComboFix.txt which I will need in your next reply.


__________________________________________



______________________________

Download and install CCleaner from here


If you use either the Firefox or Mozilla browsers, the box to uncheck for Cookies is on the Applications tab, under Firefox/Mozilla.
  • Set Cookie Retention.
    Click on the Options block on the left, then choose Cookies.
    Under the Cookies to delete pane, highlight any cookies you would like to retain permanently (those companies or sites with which you regularly visit or do business), and click the right arrow > to move them to the Cookies to keep pane.
  • Reset Temp File Removal for Regular Use.
    Click on the Options block on the left. Select the Advanced button.
    Check "Only delete files in Windows Temp folders older than 48 hours".


    Now run the program and click on Run Cleaner
    ( Do not use the Issues block to clean anything with this program. It is for experts only and it is risky).

_________________________________
Please do an online scan with Kaspersky Online Scanner
Click on Kaspersky Online Scanner
You will be promted to install an ActiveX component from Kaspersky, Click Yes.
The program will launch and then start to download the latest definition files.
Once the scanner is installed and the definitions downloaded, click Next.
Now click on Scan Settings
In the scan settings make sure that the following are selected:
Scan using the following Anti-Virus database:

Extended (If available otherwise Standard)
Scan Options:
Scan Archives
Scan Mail Bases
Click OK

Now under select a target to scan select My Computer


Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.



The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.

Now click on the Save as Text button:

Save the file to your desktop.

Copy and paste that information in your next post.


______________________________

In your original post you said you have reformatted a few times just to get reinfected again.

Do you have some programs backed up somewhere that you install that were recieved by another individual or download ?



_____________________________
In your next reply I would like to see:
  • A new HJT log
  • The report from Combo fix
  • The report from Kasperskys
this is my new hijackthis logfile

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:18:56 AM, on 9/19/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\gearsec.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Java\j2re1.4.2_03\bin\jucheck.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [AAWTray] C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe

–
End of file - 6397 bytes




ComboFix Report




ComboFix 07-09-17.2 - "Owner" 2007-09-18 21:30:47.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.27 [GMT 8:00]
* Created a new restore point

FILE::
C:\WINDOWS\system32\oubttg.dll
C:\WINDOWS\system32\gbekry.dll
C:\WINDOWS\system32\mohekj.dll
C:\WINDOWS\system32\wlgini.dll
C:\WINDOWS\system32\DbgHlp32.dll
C:\WINDOWS\system32\kawdacs.dll
C:\WINDOWS\system32\kaqhacs.dll
C:\WINDOWS\system32\kapjacs.dll
C:\WINDOWS\system32\rsjzafg.dll
C:\WINDOWS\system32\zxiini.dll
C:\WINDOWS\system32\raqjani.dll
C:\WINDOWS\system32\mygini.dll
C:\windows\WinRaR.exe
C:\WINDOWS\System32\myhpri.dll
C:\WINDOWS\System32\kvdxbma.dll
C:\WINDOWS\System32\kawdbzy.dll
C:\WINDOWS\System32\zxipri.dll
C:\WINDOWS\System32\raqjapi.dll
C:\WINDOWS\System32\rsjzapm.dll
C:\WINDOWS\System32\kapjazy.dll
C:\WINDOWS\System32\kaqhczy.dll
C:\WINDOWS\System32\wlhpri.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\DbgHlp32.dll
C:\WINDOWS\system32\gbekry.dll
C:\WINDOWS\system32\kapjacs.dll
C:\WINDOWS\System32\kapjazy.dll
C:\WINDOWS\system32\kaqhacs.dll
C:\WINDOWS\System32\kaqhczy.dll
C:\WINDOWS\system32\kawdacs.dll
C:\WINDOWS\System32\kawdbzy.dll
C:\WINDOWS\System32\kvdxbma.dll
C:\WINDOWS\system32\mohekj.dll
C:\WINDOWS\system32\mygini.dll
C:\WINDOWS\System32\myhpri.dll
C:\WINDOWS\system32\oubttg.dll
C:\WINDOWS\system32\raqjani.dll
C:\WINDOWS\System32\raqjapi.dll
C:\WINDOWS\system32\rsjzafg.dll
C:\WINDOWS\System32\rsjzapm.dll
C:\WINDOWS\system32\wlgini.dll
C:\WINDOWS\System32\wlhpri.dll
C:\WINDOWS\system32\zxiini.dll
C:\WINDOWS\System32\zxipri.dll

.
((((((((((((((((((((((((( Files Created from 2007-08-18 to 2007-09-18 )))))))))))))))))))))))))))))))
.

2007-09-17 23:31 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-09-12 22:37 16,608 –a—— C:\WINDOWS\system32\LYLOADMR.EXE
2007-09-09 22:34 76,560 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2007-09-09 20:54 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinZip
2007-09-09 20:01 d——– C:\Program Files\Common Files\Panda Software
2007-09-09 19:24 d——– C:\DOCUME~1\Owner\.housecall6.6
2007-09-09 18:18 d——– C:\WINDOWS\DED53B0BB67C4244AE6AD6FD3C28D1EF.TMP
2007-09-09 15:33 d——– C:\Program Files\Lavasoft
2007-09-09 15:33 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-09-09 15:31 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-09-09 14:57 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-09-09 14:51 d——– C:\Program Files\Trend Micro
2007-09-09 13:54 d—s—- C:\DOCUME~1\Owner\UserData
2007-09-09 13:46 24,576 ——— C:\WINDOWS\system32\ftmgpd.dll
2007-09-08 23:17 27,648 –a—— C:\WINDOWS\system32\SHQ.DLL
2007-09-08 23:17 20 –a—— C:\WINDOWS\system32\mhsha1.dat
2007-09-08 22:39 182,880 –a–c— C:\WINDOWS\system32\dllcache\iuengine.dll
2007-09-08 22:39 182,880 –a—— C:\WINDOWS\system32\iuengine.dll
2007-09-08 22:19 17,920 –a—— C:\WINDOWS\system32\mdimon.dll
2007-09-08 22:16 d——– C:\Program Files\Microsoft ActiveSync
2007-09-08 22:16 d——– C:\Program Files\Common Files\L&H
2007-09-08 22:14 d——– C:\WINDOWS\SHELLNEW
2007-09-08 22:13 d——– C:\Program Files\Microsoft.NET
2007-09-08 22:11 dr-h—– C:\MSOCache
2007-09-08 22:08 51,056 -ra—— C:\WINDOWS\system32\drivers\hpzid412.sys
2007-09-08 22:08 21,760 –a–c— C:\WINDOWS\system32\dllcache\usbstor.sys
2007-09-08 22:08 16,496 -ra—— C:\WINDOWS\system32\drivers\HPZipr12.sys
2007-09-08 22:07 28,160 –a–c— C:\WINDOWS\system32\dllcache\usbccgp.sys
2007-09-08 22:07 28,160 –a—— C:\WINDOWS\system32\drivers\usbccgp.sys
2007-09-08 22:07 24,960 –a–c— C:\WINDOWS\system32\dllcache\usbprint.sys
2007-09-08 22:07 24,960 –a—— C:\WINDOWS\system32\drivers\usbprint.sys
2007-09-08 22:07 21,488 -ra—— C:\WINDOWS\system32\drivers\HPZius12.sys
2007-09-08 22:07 14,208 –a–c— C:\WINDOWS\system32\dllcache\usbscan.sys
2007-09-08 22:07 14,208 –a—— C:\WINDOWS\system32\drivers\usbscan.sys
2007-09-08 22:03 626,960 -ra—— C:\WINDOWS\system32\hpvaut32.dll
2007-09-08 22:03 487,424 -ra—— C:\WINDOWS\system32\hpvcp70.dll
2007-09-08 22:03 44,544 -ra—— C:\WINDOWS\system32\MSXML4a.dll
2007-09-08 22:03 344,064 -ra—— C:\WINDOWS\system32\hpvcr70.dll
2007-09-08 22:02 d——– C:\Program Files\Common Files\Hewlett-Packard
2007-09-08 21:59 43,488 –a—— C:\WINDOWS\system32\drivers\AFS2K.SYS
2007-09-08 21:59 d——– C:\Program Files\Common Files\HP
2007-09-08 21:55 34,383 ——— C:\WINDOWS\hpomdl03.dat
2007-09-08 21:55 28,886 –a—— C:\WINDOWS\hpoins03.dat
2007-09-08 21:55 d——– C:\Program Files\HP
2007-09-08 09:48 55 –a—— C:\WINDOWS\system32\kvdxacf.dll
2007-09-08 09:48 32,768 ——— C:\WINDOWS\dbhelp.dll
2007-09-03 08:39 249 –a—— C:\WINDOWS\system\hpsysdrv.dat
2007-09-03 08:38 d——– C:\WINDOWS\I386
2007-09-03 08:33 dr——- C:\DOCUME~1\ALLUSE~1\Documents
2007-09-02 17:59 155,648 –a—— C:\WINDOWS\system32\igfxres.dll
2007-09-02 17:57 204,800 –a—— C:\WINDOWS\system32\IVIresizeW7.dll
2007-09-02 17:57 200,704 –a—— C:\WINDOWS\system32\IVIresizeA6.dll
2007-09-02 17:57 20,480 –a—— C:\WINDOWS\system32\IVIresize.dll
2007-09-02 17:57 192,512 –a—— C:\WINDOWS\system32\IVIresizeP6.dll
2007-09-02 17:57 192,512 –a—— C:\WINDOWS\system32\IVIresizeM6.dll
2007-09-02 17:57 188,416 –a—— C:\WINDOWS\system32\IVIresizePX.dll
2007-09-02 17:57 10,368 ——— C:\WINDOWS\system32\drivers\pfc.sys
2007-09-02 17:57 d——– C:\WINDOWS\uninstall
2007-09-02 17:57 d——– C:\WINDOWS\system32\config\SYSTEM~1\WINDOWS
2007-09-02 17:57 d——– C:\WINDOWS\system32\config\SYSTEM~1\APPLIC~1\Symantec
2007-09-02 17:57 d——– C:\WINDOWS\system32\config\SYSTEM~1\APPLIC~1\SampleView
2007-09-02 17:57 d——– C:\WINDOWS\system32\config\SYSTEM~1\APPLIC~1\Real
2007-09-02 17:57 d——– C:\863d765bceb76777372b95ff1d0a40
2007-09-02 17:57 d——– C:\54f4ff25124b3b9e53a7416b03
2007-09-02 17:56 57,856 –a—— C:\WINDOWS\system32\drivers\drmk.sys
2007-09-02 17:56 134,272 –a—— C:\WINDOWS\system32\drivers\portcls.sys
2007-09-02 17:56 d——– C:\Program Files\InterVideo
2007-09-02 17:54 51,072 –a—— C:\WINDOWS\system32\drivers\i8042prt.sys
2007-09-02 17:54 23,424 –a—— C:\WINDOWS\system32\drivers\kbdclass.sys
2007-09-02 17:54 d——– C:\DOCUME~1\DEFAUL~1\WINDOWS

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-09 21:34 ——— d——– C:\Program Files\QuickTime
2007-09-09 21:34 ——— d——– C:\Program Files\Presario PC Help
2007-09-09 21:34 ——— d——– C:\Program Files\PC-Doctor for Windows
2007-09-09 21:33 ——— d——– C:\Program Files\Norton AntiVirus
2007-09-09 21:33 ——— d——– C:\Program Files\Microsoft Works
2007-09-09 21:32 ——— d——– C:\Program Files\iTunes
2007-09-09 21:28 ——— d——– C:\Program Files\Easy Internet signup
2007-09-09 20:02 ——— d——– C:\Program Files\Common Files\InstallShield
2007-09-02 17:59 3674 -rahs—- C:\WINDOWS\system32\drivers\HP_P9902CV-AB4 SR1120CF SE610_YC_Pres_QTHT424_E43SEhwRET1_4_IGamila Giovani Neon series_SMICRO-STAR INTERNATIONAL CO., LTD_V030_B3.10_T040415_WXH1_L409_M248_J80_7Intel_8Pentium 4_92.8_111063044_N10EC8139_P_Z_K_A808624C5.MRK
2007-09-02 17:56 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-08-07 13:58 8320 –a—— C:\WINDOWS\system32\drivers\AWRTRD.sys
2007-08-07 13:56 9344 –a—— C:\WINDOWS\system32\drivers\NSDriver.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.

*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2003-08-17 06:57]
"MSPY2002"="C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe" [2003-08-17 00:24]
"PHIME2002ASync"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe" [2003-08-17 00:25]
"PHIME2002A"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe" [2003-08-17 00:25]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2004-04-01 20:57]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 23:04]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2004-02-11 00:51]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-12 02:02]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-04-01 22:04]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2004-01-17 02:16]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2003-11-03 23:50]
"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2003-08-15 07:59]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2003-09-13 02:13]
"AlcxMonitor"="ALCXMNTR.EXE" [2003-04-04 03:35 C:\WINDOWS\ALCXMNTR.EXE]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd.exe" [2003-06-25 11:24]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-06-26 18:50]
"AAWTray"="C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe" [2007-08-08 15:53]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\System32\ctfmon.exe" [2003-08-16 09:54]

C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
Compaq Connections.lnk - C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe [2004-04-01 22:26:37]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2003-07-07 01:20:40]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoInstrumentation"=1 (0x1)
"NoStartMenuSubFolders"=1 (0x1)
"NoFavoritesMenu"=1 (0x1)


.
Contents of the 'Scheduled Tasks' folder
"2007-09-08 14:13:19 C:\WINDOWS\Tasks\HP DArC Task #Hewlett-Packard#hp psc 1300 series#1189260524.job"
- C:\Program Files\HP\hpcoretech\comp\hpdarc.exe
"2007-09-15 02:31:28 C:\WINDOWS\Tasks\HP DArC Task #Hewlett-Packard#hp psc 1300 series#1189262568.job"
- C:\Program Files\HP\hpcoretech\comp\hpdarc.exe
"2007-09-09 06:03:02 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job"
- c:\PROGRA~1\NORTON~1\Navw32.exe
"2007-09-09 06:03:02 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
"2007-09-15 02:27:55 C:\WINDOWS\Tasks\WebReg 20070915102754.job"
.
**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-18 21:35:32
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-09-18 21:37:16 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-09-18 21:37
C:\ComboFix2.txt … 2007-09-17 23:38
.
— E O F —

Kasperskys report






——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Wednesday, September 19, 2007 1:16:52 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 1 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.1
Kaspersky Anti-Virus database last update: 18/09/2007
Kaspersky Anti-Virus database records: 420276
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 54874
Number of viruses found: 32
Number of infected objects: 612
Number of suspicious objects: 0
Duration of the scan process: 01:19:07

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\17[1].exe.bac_a02396 Infected: Trojan-PSW.Win32.OnLineGames.bwr skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\4[1].exe.bac_a02396 Infected: Trojan-PSW.Win32.OnLineGames.cfq skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\7[1].exe.bac_a02396 Infected: Trojan-PSW.Win32.OnLineGames.bgr skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\A0000044.exe.bac_a00940 Infected: Virus.Win32.AutoRun.ao skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\A0000426.exe.bac_a00940 Infected: Virus.Win32.AutoRun.ao skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\A0000442.exe.bac_a00940 Infected: Virus.Win32.AutoRun.ao skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\A0000524.exe.bac_a00940 Infected: Virus.Win32.AutoRun.ao skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\A0000531.exe.bac_a00940 Infected: Virus.Win32.AutoRun.ao skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\A0000544.exe.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\A0000545.exe.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\A0001059.pif.bac_a02396 Infected: Worm.Win32.QQPass.m skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\App00153.exe.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\App03902.exe.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\App04827.exe.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\App05436.exe.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\App06334.exe.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\App09961.exe.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\App11538.exe.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\App16827.exe.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\App18467.exe.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\App19169.exe.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\App19912.exe.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\App21726.exe.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\App30333.exe.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\App31322.exe.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\autochk.exe.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\autofmt.exe.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\cmdbcs.exe.bac_a02396 Infected: Trojan-PSW.Win32.OnLineGames.bgr skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\DbgHlp32.exe.bac_a02396 Infected: Trojan-PSW.Win32.OnLineGames.bwr skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\dbhelp.dll.bac_a02396 Infected: Trojan-PSW.Win32.Delf.aaw skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\DWWIN.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\EXPAND.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\HP_EndBuild_for_BBoot_ALL_WW_0000-02.exe.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\NETSETUP.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\NTSD.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\REGEDIT.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\SYSPARSE.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\TELNET.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\upxdnd.exe.bac_a02396 Infected: Trojan-PSW.Win32.OnLineGames.cfq skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\USBReader_ALL_WW_XP_0000-01.exe.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\USETUP.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB828741-x86-ARA.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB828741-x86-CHS.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB828741-x86-CHT.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB828741-x86-DAN.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB828741-x86-DEU.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB828741-x86-ENU.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB828741-x86-ESN.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB828741-x86-FIN.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB828741-x86-FRA.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB828741-x86-ITA.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB828741-x86-JPN.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB828741-x86-KOR.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB828741-x86-NLD.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB828741-x86-NOR.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB828741-x86-PTG.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB828741-x86-RUS.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB828741-x86-SVE.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB828741-x86-TRK.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB835732-x86-ARA.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB835732-x86-CHS.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB835732-x86-CHT.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB835732-x86-DAN.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB835732-x86-DEU.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB835732-x86-ENU.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB835732-x86-ESN.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB835732-x86-FIN.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB835732-x86-FRA.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB835732-x86-ITA.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB835732-x86-JPN.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB835732-x86-KOR.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB835732-x86-NLD.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB835732-x86-NOR.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB835732-x86-PTG.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB835732-x86-RUS.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB835732-x86-SVE.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB835732-x86-TRK.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WINNT.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WINNT32.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped
C:\Documents and Settings\Owner\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\History\History.IE5\MSHist012007091820070919\index.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Owner\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Owner\ntuser.dat.LOG Object is locked skipped
C:\hp\bin\KillWind.exe Infected: not-a-virus:RiskTool.Win32.PsKill.p skipped
C:\hpcmerr.log Object is locked skipped
C:\Program Files\Compaq Connections\1940576\Users\Default\Data\chandir.dat Object is locked skipped
C:\Program Files\Compaq Connections\1940576\Users\Default\Data\chandir.idx Object is locked skipped
C:\Program Files\Compaq Connections\1940576\Users\Default\Data\chn.dat Object is locked skipped
C:\Program Files\Compaq Connections\1940576\Users\Default\Data\chn.idx Object is locked skipped
C:\Program Files\Compaq Connections\1940576\Users\Default\Data\D0000000.FCS Object is locked skipped
C:\Program Files\Compaq Connections\1940576\Users\Default\Data\inuse.txt Object is locked skipped
C:\Program Files\Compaq Connections\1940576\Users\Default\Data\L0000001.FCS Object is locked skipped
C:\Program Files\Compaq Connections\1940576\Users\Default\Data\main.log Object is locked skipped
C:\Program Files\Compaq Connections\1940576\Users\Default\Data\prs.dat Object is locked skipped
C:\Program Files\Compaq Connections\1940576\Users\Default\Data\prs.idx Object is locked skipped
C:\Program Files\Compaq Connections\1940576\Users\Default\Data\prs_die.dat Object is locked skipped
C:\Program Files\Compaq Connections\1940576\Users\Default\Data\prs_die.idx Object is locked skipped
C:\Program Files\Compaq Connections\1940576\Users\Default\Data\prs_dnd.dat Object is locked skipped
C:\Program Files\Compaq Connections\1940576\Users\Default\Data\prs_dnd.idx Object is locked skipped
C:\Program Files\Compaq Connections\1940576\Users\Default\Data\prs_ext.dat Object is locked skipped
C:\Program Files\Compaq Connections\1940576\Users\Default\Data\prs_ext.idx Object is locked skipped
C:\Program Files\Compaq Connections\1940576\Users\Default\Data\prs_rcv.dat Object is locked skipped
C:\Program Files\Compaq Connections\1940576\Users\Default\Data\prs_rcv.idx Object is locked skipped
C:\Program Files\Compaq Connections\1940576\Users\Default\Data\storydb.dat Object is locked skipped
C:\Program Files\Compaq Connections\1940576\Users\Default\Data\storydb.idx Object is locked skipped
C:\Program Files\Norton AntiVirus\AVApp.log Object is locked skipped
C:\Program Files\Norton AntiVirus\AVError.log Object is locked skipped
C:\Program Files\Norton AntiVirus\AVVirus.log Object is locked skipped
C:\qoobox\Quarantine\C\Privilege.dat.vir Infected: Trojan-Dropper.Win32.Agent.bvh skipped
C:\qoobox\Quarantine\C\WINDOWS\RichDll.dll.vir Infected: Worm.Win32.Viking.lz skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\cmdbcs.dll.vir Infected: Trojan-PSW.Win32.OnLineGames.cdv skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\DbgHlp32.dll.vir Infected: Trojan-PSW.Win32.OnLineGames.bws skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\gbekry.dll.vir Infected: Trojan-PSW.Win32.OnLineGames.cdv skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\kapjazy.dll.vir Infected: Trojan-PSW.Win32.Agent.pl skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\kaqhczy.dll.vir Infected: Trojan-PSW.Win32.OnLineGames.bou skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\kawdbzy.dll.vir Infected: Trojan-Spy.Win32.Delf.ago skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\kvdxbma.dll.vir Infected: Trojan-Spy.Win32.Delf.agk skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\LYLOADER.EXE.vir Infected: Trojan-PSW.Win32.OnLineGames.bmt skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\LYMANGR.DLL.vir Infected: Trojan-PSW.Win32.OnLineGames.bmu skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\mohekj.dll.vir Infected: Trojan-PSW.Win32.OnLineGames.cdz skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\MSDEG32.DLL.vir Infected: Trojan-PSW.Win32.OnLineGames.bmv skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\myhpri.dll.vir Infected: Trojan-PSW.Win32.OnLineGames.bjk skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\oubttg.dll.vir Infected: Trojan-PSW.Win32.OnLineGames.bws skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\raqjapi.dll.vir Infected: Trojan-PSW.Win32.OnLineGames.blx skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\rsjzapm.dll.vir Infected: Trojan-PSW.Win32.OnLineGames.bmj skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\SHQMANGR.DLL.vir Infected: Trojan-PSW.Win32.OnLineGames.cyk skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\upxdnd.dll.vir Infected: Trojan-PSW.Win32.OnLineGames.cdz skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\wlhpri.dll.vir Infected: Trojan-Spy.Win32.Delf.aao skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\zxipri.dll.vir Infected: Trojan-Spy.Win32.Delf.aao skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000033.dll Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000070.exe Infected: not-a-virus:RiskTool.Win32.PsKill.p skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000334.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000336.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000352.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000354.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000360.dll Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000361.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000363.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000364.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000424.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000434.dll Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000460.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000461.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000467.EXE Infected: Trojan-PSW.Win32.OnLineGames.bmt skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000468.sys Infected: Trojan-Downloader.Win32.Small.czl skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000469.DLL Infected: Trojan-PSW.Win32.OnLineGames.bmu skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000471.DLL Infected: Trojan-PSW.Win32.OnLineGames.bmv skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000472.dll Infected: Trojan-PSW.Win32.Delf.aaw skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000473.dll Infected: Trojan-PSW.Win32.OnLineGames.cdz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000474.dll Infected: Trojan-PSW.Win32.OnLineGames.bws skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000475.dll Infected: Trojan-PSW.Win32.OnLineGames.cdv skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000477.dll Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000478.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000479.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000480.exe Infected: Trojan-PSW.Win32.Delf.aaw skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000481.exe Infected: Trojan-PSW.Win32.OnLineGames.box skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP1\snapshot\MFEX-1.DAT Infected: Trojan-PSW.Win32.OnLineGames.bmt skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP1\snapshot\MFEX-2.DAT Infected: Trojan-PSW.Win32.OnLineGames.bmu skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP10\A0002146.dll Infected: Trojan-PSW.Win32.OnLineGames.bws skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP10\A0002147.dll Infected: Trojan-PSW.Win32.OnLineGames.cdv skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP10\A0002148.dll Infected: Trojan-PSW.Win32.OnLineGames.cdz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP10\A0002150.dll Infected: Trojan-PSW.Win32.OnLineGames.bws skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP10\A0002158.dll Infected: Trojan-PSW.Win32.OnLineGames.bjk skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP10\A0002159.dll Infected: Trojan-Spy.Win32.Delf.agk skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP10\A0002160.dll Infected: Trojan-Spy.Win32.Delf.ago skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP10\A0002161.dll Infected: Trojan-Spy.Win32.Delf.aao skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP10\A0002162.dll Infected: Trojan-PSW.Win32.OnLineGames.blx skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP10\A0002163.dll Infected: Trojan-PSW.Win32.OnLineGames.bmj skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP10\A0002164.dll Infected: Trojan-PSW.Win32.Agent.pl skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP10\A0002165.dll Infected: Trojan-PSW.Win32.OnLineGames.bou skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP10\A0002166.dll Infected: Trojan-Spy.Win32.Delf.aao skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP10\change.log Object is locked skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP2\snapshot\MFEX-1.DAT Infected: Trojan-PSW.Win32.OnLineGames.bmt skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP2\snapshot\MFEX-2.DAT Infected: Trojan-PSW.Win32.OnLineGames.bmu skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP3\snapshot\MFEX-1.DAT Infected: Trojan-PSW.Win32.OnLineGames.bmt skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP3\snapshot\MFEX-2.DAT Infected: Trojan-PSW.Win32.OnLineGames.bmu skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP4\snapshot\MFEX-1.DAT Infected: Trojan-PSW.Win32.OnLineGames.bmt skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP4\snapshot\MFEX-2.DAT Infected: Trojan-PSW.Win32.OnLineGames.bmu skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP5\snapshot\MFEX-1.DAT Infected: Trojan-PSW.Win32.OnLineGames.bmt skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP5\snapshot\MFEX-2.DAT Infected: Trojan-PSW.Win32.OnLineGames.bmu skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP6\A0000548.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP6\A0000549.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP6\A0000550.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP6\snapshot\MFEX-1.DAT Infected: Trojan-PSW.Win32.OnLineGames.bmt skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP6\snapshot\MFEX-2.DAT Infected: Trojan-Dropper.Win32.Agent.bvh skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000623.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000624.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000625.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000626.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000627.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000628.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000629.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000630.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000631.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000632.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000633.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000634.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000635.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000636.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000637.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000638.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000639.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000640.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000641.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000642.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000643.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000644.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000645.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000646.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000647.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000648.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000649.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000650.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000651.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000652.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000653.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000654.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000655.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000656.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000657.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000658.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000659.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000660.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000661.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000662.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000663.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000664.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000665.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000666.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000667.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000668.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000669.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000670.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000671.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000672.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000673.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000674.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000675.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000676.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000677.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000678.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000679.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000680.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000681.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000682.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000683.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000684.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000685.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000686.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000687.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000688.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000689.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000690.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000691.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000692.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000693.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000694.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000695.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000696.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000697.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000698.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000699.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000700.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000701.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000702.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000703.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000704.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000705.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000706.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000707.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000708.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000709.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000710.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000711.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000712.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000713.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000714.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000715.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000716.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000717.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000718.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000719.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000720.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000721.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000722.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000723.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000724.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000725.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000726.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000727.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000728.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000729.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000730.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000731.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000732.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000733.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000734.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000735.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000736.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000737.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000738.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000739.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000740.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000741.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000742.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000743.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000744.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000745.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000746.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000747.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000748.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000749.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000750.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000751.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000752.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000753.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000754.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000755.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000756.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000757.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000758.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000759.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000760.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000761.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000762.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000763.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000764.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000765.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000766.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000767.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000768.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000769.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000770.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000771.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000772.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000773.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000774.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000775.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000776.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000777.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000778.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000779.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000780.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000781.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000782.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000783.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000784.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000785.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000786.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000787.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000788.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000789.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000790.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000791.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000792.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000793.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000794.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000795.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000796.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000797.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000798.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000799.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000800.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000801.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000802.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000803.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000804.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000805.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000806.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000807.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000808.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000809.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000810.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000811.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000812.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000813.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000814.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000815.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000816.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000817.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000818.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000819.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000820.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000821.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000822.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000823.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000824.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000825.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000826.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000827.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000828.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000829.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000830.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000831.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000832.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000833.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000834.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000835.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000836.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000837.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000838.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000839.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000840.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000841.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000842.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000843.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000844.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000845.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000846.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000847.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000848.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000849.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000850.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000851.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000852.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000853.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000854.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000855.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000856.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000857.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000858.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000859.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000860.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000861.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000862.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000863.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000864.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000865.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000866.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000867.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000868.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000869.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000870.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000871.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000872.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000873.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000874.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000875.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000876.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000877.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000878.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000879.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000880.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000881.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000882.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000883.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000884.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000885.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000886.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000887.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000888.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000889.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000890.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000891.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000892.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000893.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000894.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000895.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000896.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000897.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000898.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000899.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000900.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000901.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000902.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000903.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000904.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000905.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000906.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000907.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000908.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000909.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000910.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000911.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000912.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000913.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000914.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000915.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000916.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000917.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000918.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000919.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000920.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000921.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000922.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000923.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000924.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000925.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000926.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000927.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000928.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000929.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000930.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000931.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000932.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000933.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000934.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000935.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000936.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000937.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000938.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000939.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000940.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000941.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000942.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000943.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000944.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000945.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000946.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000947.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000948.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000949.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000950.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000951.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000952.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000953.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000954.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000955.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000956.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000957.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000958.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000959.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000960.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000961.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000962.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000963.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000964.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000965.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000966.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000967.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000968.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000969.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000970.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000971.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000972.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000973.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000974.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000975.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000976.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000977.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000978.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000979.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000980.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000981.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000982.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000983.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000984.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000985.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000986.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000987.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000988.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000989.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000990.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000991.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000992.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000993.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000994.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000995.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000996.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000997.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000998.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000999.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001000.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001001.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001002.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001003.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001004.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001005.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001006.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001007.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001008.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001009.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001010.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001011.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001012.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001013.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001014.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001015.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001016.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001017.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001018.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001019.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001020.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001021.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001022.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001023.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001024.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001025.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001026.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001027.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001028.exe Infected: Trojan-PSW.Win32.OnLineGames.box skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001029.exe Infected: Trojan-PSW.Win32.Delf.aaw skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001030.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001031.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001032.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001033.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001034.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001035.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001036.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001037.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001038.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001039.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001040.EXE Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001041.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001042.sys Infected: Trojan-Downloader.Win32.Small.czl skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001043.exe Infected: Trojan-PSW.Win32.Agent.pl skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001044.exe Infected: Trojan-PSW.Win32.OnLineGames.bou skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001045.exe Infected: Trojan-Spy.Win32.Delf.ago skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001046.exe Infected: Trojan-Spy.Win32.Delf.agk skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001047.exe Infected: Trojan-PSW.Win32.OnLineGames.blb skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001048.exe Infected: Backdoor.Win32.Agent.alh skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001049.exe Infected: Trojan-PSW.Win32.OnLineGames.blx skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001050.exe Infected: Trojan-PSW.Win32.OnLineGames.bmj skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001051.exe Infected: Trojan-Downloader.Win32.Small.czl skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001052.exe Infected: Trojan-Spy.Win32.Delf.abi skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001053.exe Infected: Trojan-Spy.Win32.Delf.ach skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001054.exe Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001055.dll Infected: Trojan-PSW.Win32.OnLineGames.box skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001056.exe Infected: Trojan-PSW.Win32.Delf.aaw skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001057.exe Infected: Trojan-PSW.Win32.OnLineGames.box skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001060.exe Infected: Trojan-PSW.Win32.OnLineGames.bgr skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001061.exe Infected: Trojan-PSW.Win32.OnLineGames.bwr skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001062.exe Infected: Trojan-PSW.Win32.OnLineGames.cfq skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\snapshot\MFEX-1.DAT Infected: Trojan-PSW.Win32.OnLineGames.bmt skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\snapshot\MFEX-2.DAT Infected: Trojan-Dropper.Win32.Agent.bvh skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP8\snapshot\MFEX-1.DAT Infected: Trojan-PSW.Win32.OnLineGames.bmt skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP8\snapshot\MFEX-2.DAT Infected: Trojan-Dropper.Win32.Agent.bvh skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP9\A0002083.DLL Infected: Trojan-PSW.Win32.OnLineGames.cyk skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP9\A0002088.dll Infected: Trojan-PSW.Win32.OnLineGames.cdv skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP9\A0002089.dll Infected: Worm.Win32.Viking.lz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP9\A0002090.EXE Infected: Trojan-PSW.Win32.OnLineGames.bmt skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP9\A0002091.DLL Infected: Trojan-PSW.Win32.OnLineGames.bmu skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP9\A0002092.DLL Infected: Trojan-PSW.Win32.OnLineGames.bmv skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP9\A0002093.dll Infected: Trojan-PSW.Win32.OnLineGames.cdz skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP9\snapshot\MFEX-1.DAT Infected: Trojan-PSW.Win32.OnLineGames.bmt skipped
C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP9\snapshot\MFEX-2.DAT Infected: Trojan-Dropper.Win32.Agent.bvh skipped
C:\WINDOWS\dbhelp.dll Infected: Trojan-PSW.Win32.Delf.aaw skipped
C:\WINDOWS\Debug\oakley.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\LYLOADMR.EXE Infected: Trojan-Dropper.Win32.Agent.bvh skipped
C:\WINDOWS\system32\SHQ.DLL Infected: Trojan.Win32.Agent.bmq skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
D:\myplayer.com Infected: Trojan-Spy.Win32.Agent.pn skipped
D:\vqrycmb.exe Object is locked skipped
D:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP10\change.log Object is locked skipped
D:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP10\A0002280.exe Infected: Virus.Win32.AutoRun.ao skipped

Scan process completed.



"Do you have some programs backed up somewhere that you install that were recieved by another individual or download ?"

sorry but i'm not really sure what your question meant. did u mean programs that i received from others and installed? if that's the case, i dint receive any downloads from any individual and as for the rest of the programs such as msn web messenger and winzip, i obtain them through online means and am not really sure whether they're backed up somewhere but i doubt so. but if you're talking about programs that are backed up (in hard copy) that i install, there's only microsoft.
Open notepad and copy/paste the text in the quotebox below into it:

File::
D:\vqrycmb.exe
D:\myplayer.com
C:\WINDOWS\system32\SHQ.DLL
C:\WINDOWS\system32\LYLOADMR.EXE
C:\WINDOWS\dbhelp.dll



Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:ComboFix.txt which I will need in your next reply.

________________________________________



You need to update SunJava for security reasons.
Updating Java:
Download the latest version of
Java Runtime Environment (JRE) 6u2
  • Scroll down to where it says "Java Runtime Environment (JRE) 6u2… allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name. It should have the [external image: Posted Image] icon next to it.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u2-windows-i586-p.exe to install the newest version.



_____________________________
In your next reply I would like to see:
  • A new HJT log
  • The report from combofix
  • Let me know how things seem to be running.

    OH! I was asking about a saved program as you mentioned you reformatted a few times just to become reinfected again. Was just curious is all.
combofix log:

ComboFix 07-09-17.2 - "Owner" 2007-09-20 19:22:37.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.42 [GMT 8:00]
* Created a new restore point

FILE::
D:\vqrycmb.exe
D:\myplayer.com
C:\WINDOWS\system32\SHQ.DLL
C:\WINDOWS\system32\LYLOADMR.EXE
C:\WINDOWS\dbhelp.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\dbhelp.dll
C:\WINDOWS\system32\LYLOADMR.EXE
C:\WINDOWS\system32\SHQ.DLL
D:\myplayer.com

.
((((((((((((((((((((((((( Files Created from 2007-08-20 to 2007-09-20 )))))))))))))))))))))))))))))))
.

2007-09-18 21:44 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-09-18 21:44 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
2007-09-18 21:39 d——– C:\Program Files\CCleaner
2007-09-17 23:31 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-09-09 22:34 76,560 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2007-09-09 20:54 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinZip
2007-09-09 20:01 d——– C:\Program Files\Common Files\Panda Software
2007-09-09 19:24 d——– C:\DOCUME~1\Owner\.housecall6.6
2007-09-09 18:18 d——– C:\WINDOWS\DED53B0BB67C4244AE6AD6FD3C28D1EF.TMP
2007-09-09 15:33 d——– C:\Program Files\Lavasoft
2007-09-09 15:33 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-09-09 15:31 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-09-09 14:57 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-09-09 14:51 d——– C:\Program Files\Trend Micro
2007-09-09 13:54 d—s—- C:\DOCUME~1\Owner\UserData
2007-09-09 13:46 24,576 ——— C:\WINDOWS\system32\ftmgpd.dll
2007-09-08 23:17 20 –a—— C:\WINDOWS\system32\mhsha1.dat
2007-09-08 22:39 182,880 –a–c— C:\WINDOWS\system32\dllcache\iuengine.dll
2007-09-08 22:39 182,880 –a—— C:\WINDOWS\system32\iuengine.dll
2007-09-08 22:19 17,920 –a—— C:\WINDOWS\system32\mdimon.dll
2007-09-08 22:16 d——– C:\Program Files\Microsoft ActiveSync
2007-09-08 22:16 d——– C:\Program Files\Common Files\L&H
2007-09-08 22:14 d——– C:\WINDOWS\SHELLNEW
2007-09-08 22:13 d——– C:\Program Files\Microsoft.NET
2007-09-08 22:11 dr-h—– C:\MSOCache
2007-09-08 22:08 51,056 -ra—— C:\WINDOWS\system32\drivers\hpzid412.sys
2007-09-08 22:08 21,760 –a–c— C:\WINDOWS\system32\dllcache\usbstor.sys
2007-09-08 22:08 16,496 -ra—— C:\WINDOWS\system32\drivers\HPZipr12.sys
2007-09-08 22:07 28,160 –a–c— C:\WINDOWS\system32\dllcache\usbccgp.sys
2007-09-08 22:07 28,160 –a—— C:\WINDOWS\system32\drivers\usbccgp.sys
2007-09-08 22:07 24,960 –a–c— C:\WINDOWS\system32\dllcache\usbprint.sys
2007-09-08 22:07 24,960 –a—— C:\WINDOWS\system32\drivers\usbprint.sys
2007-09-08 22:07 21,488 -ra—— C:\WINDOWS\system32\drivers\HPZius12.sys
2007-09-08 22:07 14,208 –a–c— C:\WINDOWS\system32\dllcache\usbscan.sys
2007-09-08 22:07 14,208 –a—— C:\WINDOWS\system32\drivers\usbscan.sys
2007-09-08 22:03 626,960 -ra—— C:\WINDOWS\system32\hpvaut32.dll
2007-09-08 22:03 487,424 -ra—— C:\WINDOWS\system32\hpvcp70.dll
2007-09-08 22:03 44,544 -ra—— C:\WINDOWS\system32\MSXML4a.dll
2007-09-08 22:03 344,064 -ra—— C:\WINDOWS\system32\hpvcr70.dll
2007-09-08 22:02 d——– C:\Program Files\Common Files\Hewlett-Packard
2007-09-08 21:59 43,488 –a—— C:\WINDOWS\system32\drivers\AFS2K.SYS
2007-09-08 21:59 d——– C:\Program Files\Common Files\HP
2007-09-08 21:55 34,383 ——— C:\WINDOWS\hpomdl03.dat
2007-09-08 21:55 28,886 –a—— C:\WINDOWS\hpoins03.dat
2007-09-08 21:55 d——– C:\Program Files\HP
2007-09-08 09:48 55 –a—— C:\WINDOWS\system32\kvdxacf.dll
2007-09-03 08:39 249 –a—— C:\WINDOWS\system\hpsysdrv.dat
2007-09-03 08:38 d——– C:\WINDOWS\I386
2007-09-03 08:33 dr——- C:\DOCUME~1\ALLUSE~1\Documents
2007-09-02 17:59 155,648 –a—— C:\WINDOWS\system32\igfxres.dll
2007-09-02 17:57 204,800 –a—— C:\WINDOWS\system32\IVIresizeW7.dll
2007-09-02 17:57 200,704 –a—— C:\WINDOWS\system32\IVIresizeA6.dll
2007-09-02 17:57 20,480 –a—— C:\WINDOWS\system32\IVIresize.dll
2007-09-02 17:57 192,512 –a—— C:\WINDOWS\system32\IVIresizeP6.dll
2007-09-02 17:57 192,512 –a—— C:\WINDOWS\system32\IVIresizeM6.dll
2007-09-02 17:57 188,416 –a—— C:\WINDOWS\system32\IVIresizePX.dll
2007-09-02 17:57 10,368 ——— C:\WINDOWS\system32\drivers\pfc.sys
2007-09-02 17:57 d——– C:\WINDOWS\uninstall
2007-09-02 17:57 d——– C:\WINDOWS\system32\config\SYSTEM~1\WINDOWS
2007-09-02 17:57 d——– C:\WINDOWS\system32\config\SYSTEM~1\APPLIC~1\Symantec
2007-09-02 17:57 d——– C:\WINDOWS\system32\config\SYSTEM~1\APPLIC~1\SampleView
2007-09-02 17:57 d——– C:\WINDOWS\system32\config\SYSTEM~1\APPLIC~1\Real
2007-09-02 17:57 d——– C:\863d765bceb76777372b95ff1d0a40
2007-09-02 17:57 d——– C:\54f4ff25124b3b9e53a7416b03
2007-09-02 17:56 57,856 –a—— C:\WINDOWS\system32\drivers\drmk.sys
2007-09-02 17:56 134,272 –a—— C:\WINDOWS\system32\drivers\portcls.sys
2007-09-02 17:56 d——– C:\Program Files\InterVideo
2007-09-02 17:54 51,072 –a—— C:\WINDOWS\system32\drivers\i8042prt.sys
2007-09-02 17:54 23,424 –a—— C:\WINDOWS\system32\drivers\kbdclass.sys
2007-09-02 17:54 d——– C:\DOCUME~1\DEFAUL~1\WINDOWS

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-09 21:34 ——— d——– C:\Program Files\QuickTime
2007-09-09 21:34 ——— d——– C:\Program Files\Presario PC Help
2007-09-09 21:34 ——— d——– C:\Program Files\PC-Doctor for Windows
2007-09-09 21:33 ——— d——– C:\Program Files\Norton AntiVirus
2007-09-09 21:33 ——— d——– C:\Program Files\Microsoft Works
2007-09-09 21:32 ——— d——– C:\Program Files\iTunes
2007-09-09 21:28 ——— d——– C:\Program Files\Easy Internet signup
2007-09-09 20:02 ——— d——– C:\Program Files\Common Files\InstallShield
2007-09-02 17:59 3674 -rahs—- C:\WINDOWS\system32\drivers\HP_P9902CV-AB4 SR1120CF SE610_YC_Pres_QTHT424_E43SEhwRET1_4_IGamila Giovani Neon series_SMICRO-STAR INTERNATIONAL CO., LTD_V030_B3.10_T040415_WXH1_L409_M248_J80_7Intel_8Pentium 4_92.8_111063044_N10EC8139_P_Z_K_A808624C5.MRK
2007-09-02 17:56 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-08-07 13:58 8320 –a—— C:\WINDOWS\system32\drivers\AWRTRD.sys
2007-08-07 13:56 9344 –a—— C:\WINDOWS\system32\drivers\NSDriver.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.

*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2003-08-17 06:57]
"MSPY2002"="C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe" [2003-08-17 00:24]
"PHIME2002ASync"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe" [2003-08-17 00:25]
"PHIME2002A"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe" [2003-08-17 00:25]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2004-04-01 20:57]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 23:04]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2004-02-11 00:51]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-12 02:02]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-04-01 22:04]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2004-01-17 02:16]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2003-11-03 23:50]
"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2003-08-15 07:59]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2003-09-13 02:13]
"AlcxMonitor"="ALCXMNTR.EXE" [2003-04-04 03:35 C:\WINDOWS\ALCXMNTR.EXE]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd.exe" [2003-06-25 11:24]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-06-26 18:50]
"AAWTray"="C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe" [2007-08-08 15:53]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\System32\ctfmon.exe" [2003-08-16 09:54]

C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
Compaq Connections.lnk - C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe [2004-04-01 22:26:37]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2003-07-07 01:20:40]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoInstrumentation"=1 (0x1)
"NoStartMenuSubFolders"=1 (0x1)
"NoFavoritesMenu"=1 (0x1)


.
Contents of the 'Scheduled Tasks' folder
"2007-09-08 14:13:19 C:\WINDOWS\Tasks\HP DArC Task #Hewlett-Packard#hp psc 1300 series#1189260524.job"
- C:\Program Files\HP\hpcoretech\comp\hpdarc.exe
"2007-09-15 02:31:28 C:\WINDOWS\Tasks\HP DArC Task #Hewlett-Packard#hp psc 1300 series#1189262568.job"
- C:\Program Files\HP\hpcoretech\comp\hpdarc.exe
"2007-09-09 06:03:02 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job"
- c:\PROGRA~1\NORTON~1\Navw32.exe
"2007-09-09 06:03:02 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
"2007-09-15 02:27:55 C:\WINDOWS\Tasks\WebReg 20070915102754.job"
.
**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-20 19:25:51
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-09-20 19:28:06 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-09-20 19:27
C:\ComboFix2.txt … 2007-09-18 21:37
C:\ComboFix3.txt … 2007-09-17 23:38
.
— E O F —
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:29:43 PM, on 9/20/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\gearsec.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [AAWTray] C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe

–
End of file - 6630 bytes


my computer seems to be running fine but i still cant open word files.
so i reinstalled microsoft word and i could open microsoft word files now but that black window still pops up. it disappears real quickly so i cant really tell de words. is there any way to get rid of the black window? i'm not sure if it's my computer's problem or microsoft's problem.

btw, my mp3 also seems to be infected with a virus which i suspect, came from my computer. a blank folder always pops up now and then in my mp3. what would u recommend i scan my mp3 with to get rid of any possible problems?

thank you! :)
For now do not plug the MP3 player into the computer.
I will have to ask around a bit to get some more infor on checking an MP3 player.

I may have missed 2 or 3 files that should of went.
Let's do this first.
Then once your all clean we need to get service pack 2 installed.
It has a lot of common error fixes in with it.

DO NOT INSTALL SP 2 BEFORE WE'RE SURE YOUR CLEAN.!
This can have undesireable effects!


________________________________________

Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\system32\mhsha1.dat
C:\WINDOWS\system32\kvdxacf.dll



Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:ComboFix.txt which I will need in your next reply.



_____________________________
Submit a file to Jotti
Please go here : http://virusscan.jotti.org/
On top of the page there is a field to add the filepath, copy and paste these filepaths: 1 at a time.


C:\WINDOWS\system32\ftmgpd.dll


Then hit Submit
The scan will take a while before the result comes up so please be patient.
Then copy the result and post it here in this thread.

If Jotti's service load is too high, you can use the following scanner instead:
http://www.virustotal.com/xhtml/index_en.html

____________________________________


Download and Save Blacklight to your desktop:

You will have to hit the Accept button:

Then download
Blacklight Beta graphical user interface version
should be the first one.

  • Doubleclick on blbeta.exe.
  • Click on Scan.
  • Once the Scan is Finished, click on Next.
  • Click on Exit.
    A new document will be produced on the desktop.
    Open this document with Notepad.
  • Copy and Paste its contents your next reply.
_____________________________
In your next reply I would like to see:
  • A new HJT log
  • The report from Black Light
  • The report from Panda online scanner
  • The reports from comboFix. CFScript.txt
my combo fix log:


ComboFix 07-09-17.2 - "Owner" 2007-09-28 20:42:58.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.31 [GMT 8:00]
* Created a new restore point

FILE::
C:\WINDOWS\system32\mhsha1.dat
C:\WINDOWS\system32\kvdxacf.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\kvdxacf.dll
C:\WINDOWS\system32\mhsha1.dat

.
((((((((((((((((((((((((( Files Created from 2007-08-28 to 2007-09-28 )))))))))))))))))))))))))))))))
.

2007-09-27 23:28 d——– C:\DOCUME~1\Owner\APPLIC~1\Apple Computer
2007-09-23 17:49 d——– C:\DOCUME~1\Owner\Contacts
2007-09-23 17:48 d—-c— C:\WINDOWS\system32\DRVSTORE
2007-09-23 17:48 d——– C:\Program Files\MSN Messenger
2007-09-20 20:12 d——– C:\Program Files\Microsoft ActiveSync
2007-09-20 19:55 d——– C:\DOCUME~1\Owner\APPLIC~1\MSN6
2007-09-20 19:55 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\MSN6
2007-09-18 21:44 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-09-18 21:44 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
2007-09-18 21:39 d——– C:\Program Files\CCleaner
2007-09-17 23:31 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-09-09 22:34 76,560 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2007-09-09 20:54 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinZip
2007-09-09 20:01 d——– C:\Program Files\Common Files\Panda Software
2007-09-09 19:24 d——– C:\DOCUME~1\Owner\.housecall6.6
2007-09-09 18:18 d——– C:\WINDOWS\DED53B0BB67C4244AE6AD6FD3C28D1EF.TMP
2007-09-09 15:33 d——– C:\Program Files\Lavasoft
2007-09-09 15:33 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-09-09 15:31 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-09-09 14:57 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-09-09 14:51 d——– C:\Program Files\Trend Micro
2007-09-09 13:54 d—s—- C:\DOCUME~1\Owner\UserData
2007-09-09 13:46 24,576 ——— C:\WINDOWS\system32\ftmgpd.dll
2007-09-08 22:39 182,880 –a–c— C:\WINDOWS\system32\dllcache\iuengine.dll
2007-09-08 22:39 182,880 –a—— C:\WINDOWS\system32\iuengine.dll
2007-09-08 22:19 17,920 –a—— C:\WINDOWS\system32\mdimon.dll
2007-09-08 22:16 d——– C:\Program Files\Common Files\L&H
2007-09-08 22:14 d——– C:\WINDOWS\SHELLNEW
2007-09-08 22:13 d——– C:\Program Files\Microsoft.NET
2007-09-08 22:11 dr-h—– C:\MSOCache
2007-09-08 22:08 51,056 -ra—— C:\WINDOWS\system32\drivers\hpzid412.sys
2007-09-08 22:08 21,760 –a–c— C:\WINDOWS\system32\dllcache\usbstor.sys
2007-09-08 22:08 16,496 -ra—— C:\WINDOWS\system32\drivers\HPZipr12.sys
2007-09-08 22:07 28,160 –a–c— C:\WINDOWS\system32\dllcache\usbccgp.sys
2007-09-08 22:07 28,160 –a—— C:\WINDOWS\system32\drivers\usbccgp.sys
2007-09-08 22:07 24,960 –a–c— C:\WINDOWS\system32\dllcache\usbprint.sys
2007-09-08 22:07 24,960 –a—— C:\WINDOWS\system32\drivers\usbprint.sys
2007-09-08 22:07 21,488 -ra—— C:\WINDOWS\system32\drivers\HPZius12.sys
2007-09-08 22:07 14,208 –a–c— C:\WINDOWS\system32\dllcache\usbscan.sys
2007-09-08 22:07 14,208 –a—— C:\WINDOWS\system32\drivers\usbscan.sys
2007-09-08 22:03 626,960 -ra—— C:\WINDOWS\system32\hpvaut32.dll
2007-09-08 22:03 487,424 -ra—— C:\WINDOWS\system32\hpvcp70.dll
2007-09-08 22:03 44,544 -ra—— C:\WINDOWS\system32\MSXML4a.dll
2007-09-08 22:03 344,064 -ra—— C:\WINDOWS\system32\hpvcr70.dll
2007-09-08 22:02 d——– C:\Program Files\Common Files\Hewlett-Packard
2007-09-08 21:59 43,488 –a—— C:\WINDOWS\system32\drivers\AFS2K.SYS
2007-09-08 21:59 d——– C:\Program Files\Common Files\HP
2007-09-08 21:55 34,383 ——— C:\WINDOWS\hpomdl03.dat
2007-09-08 21:55 28,886 –a—— C:\WINDOWS\hpoins03.dat
2007-09-08 21:55 d——– C:\Program Files\HP
2007-09-03 08:39 249 –a—— C:\WINDOWS\system\hpsysdrv.dat
2007-09-03 08:38 d——– C:\WINDOWS\I386
2007-09-03 08:33 dr——- C:\DOCUME~1\ALLUSE~1\Documents
2007-09-02 17:59 155,648 –a—— C:\WINDOWS\system32\igfxres.dll
2007-09-02 17:57 204,800 –a—— C:\WINDOWS\system32\IVIresizeW7.dll
2007-09-02 17:57 200,704 –a—— C:\WINDOWS\system32\IVIresizeA6.dll
2007-09-02 17:57 20,480 –a—— C:\WINDOWS\system32\IVIresize.dll
2007-09-02 17:57 192,512 –a—— C:\WINDOWS\system32\IVIresizeP6.dll
2007-09-02 17:57 192,512 –a—— C:\WINDOWS\system32\IVIresizeM6.dll
2007-09-02 17:57 188,416 –a—— C:\WINDOWS\system32\IVIresizePX.dll
2007-09-02 17:57 10,368 ——— C:\WINDOWS\system32\drivers\pfc.sys
2007-09-02 17:57 d——– C:\WINDOWS\uninstall
2007-09-02 17:57 d——– C:\WINDOWS\system32\config\SYSTEM~1\WINDOWS
2007-09-02 17:57 d——– C:\WINDOWS\system32\config\SYSTEM~1\APPLIC~1\Symantec
2007-09-02 17:57 d——– C:\WINDOWS\system32\config\SYSTEM~1\APPLIC~1\SampleView
2007-09-02 17:57 d——– C:\WINDOWS\system32\config\SYSTEM~1\APPLIC~1\Real
2007-09-02 17:57 d——– C:\863d765bceb76777372b95ff1d0a40
2007-09-02 17:57 d——– C:\54f4ff25124b3b9e53a7416b03
2007-09-02 17:56 57,856 –a—— C:\WINDOWS\system32\drivers\drmk.sys
2007-09-02 17:56 134,272 –a—— C:\WINDOWS\system32\drivers\portcls.sys
2007-09-02 17:56 d——– C:\Program Files\InterVideo
2007-09-02 17:54 51,072 –a—— C:\WINDOWS\system32\drivers\i8042prt.sys
2007-09-02 17:54 23,424 –a—— C:\WINDOWS\system32\drivers\kbdclass.sys
2007-09-02 17:54 d——– C:\DOCUME~1\DEFAUL~1\WINDOWS

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-27 23:12 ——— d——– C:\DOCUME~1\Owner\APPLIC~1\Real
2007-09-20 20:11 ——— d——– C:\Program Files\Microsoft Works
2007-09-09 21:34 ——— d——– C:\Program Files\QuickTime
2007-09-09 21:34 ——— d——– C:\Program Files\Presario PC Help
2007-09-09 21:34 ——— d——– C:\Program Files\PC-Doctor for Windows
2007-09-09 21:33 ——— d——– C:\Program Files\Norton AntiVirus
2007-09-09 21:32 ——— d——– C:\Program Files\iTunes
2007-09-09 21:28 ——— d——– C:\Program Files\Easy Internet signup
2007-09-09 20:02 ——— d——– C:\Program Files\Common Files\InstallShield
2007-09-02 17:59 3674 -rahs—- C:\WINDOWS\system32\drivers\HP_P9902CV-AB4 SR1120CF SE610_YC_Pres_QTHT424_E43SEhwRET1_4_IGamila Giovani Neon series_SMICRO-STAR INTERNATIONAL CO., LTD_V030_B3.10_T040415_WXH1_L409_M248_J80_7Intel_8Pentium 4_92.8_111063044_N10EC8139_P_Z_K_A808624C5.MRK
2007-09-02 17:56 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-08-07 13:58 8320 –a—— C:\WINDOWS\system32\drivers\AWRTRD.sys
2007-08-07 13:56 9344 –a—— C:\WINDOWS\system32\drivers\NSDriver.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.

*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2003-08-17 06:57]
"MSPY2002"="C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe" [2003-08-17 00:24]
"PHIME2002ASync"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe" [2003-08-17 00:25]
"PHIME2002A"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe" [2003-08-17 00:25]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 23:04]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2004-02-11 00:51]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-12 02:02]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-04-01 22:04]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2004-01-17 02:16]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2003-11-03 23:50]
"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2003-08-15 07:59]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2003-09-13 02:13]
"AlcxMonitor"="ALCXMNTR.EXE" [2003-04-04 03:35 C:\WINDOWS\ALCXMNTR.EXE]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd.exe" [2003-06-25 11:24]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-06-26 18:50]
"AAWTray"="C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe" [2007-08-08 15:53]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\System32\ctfmon.exe" [2003-08-16 09:54]

C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
Compaq Connections.lnk - C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe [2004-04-01 22:26:37]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2003-07-07 01:20:40]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoInstrumentation"=1 (0x1)
"NoStartMenuSubFolders"=1 (0x1)
"NoFavoritesMenu"=1 (0x1)


.
Contents of the 'Scheduled Tasks' folder
"2007-09-08 14:13:19 C:\WINDOWS\Tasks\HP DArC Task #Hewlett-Packard#hp psc 1300 series#1189260524.job"
- C:\Program Files\HP\hpcoretech\comp\hpdarc.exe
"2007-09-15 02:31:28 C:\WINDOWS\Tasks\HP DArC Task #Hewlett-Packard#hp psc 1300 series#1189262568.job"
- C:\Program Files\HP\hpcoretech\comp\hpdarc.exe
"2007-09-09 06:03:02 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job"
- c:\PROGRA~1\NORTON~1\Navw32.exe
"2007-09-09 06:03:02 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
"2007-09-15 02:27:55 C:\WINDOWS\Tasks\WebReg 20070915102754.job"
.
**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-28 20:47:34
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-09-28 20:49:35 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-09-28 20:49
C:\ComboFix2.txt … 2007-09-20 19:28
C:\ComboFix3.txt … 2007-09-18 21:37
.
— E O F —
this is my jotti log File: ftmgpd.dll Status: INFECTED/MALWARE MD5: e61e018dc3262746b0ad2f88983dad9f Packers detected: - Bit9 reports: Not analyzed yet (more info) Scanner results Scan taken on 28 Sep 2007 12:52:08 (GMT) A-Squared Found nothing AntiVir Found TR/Drop.Small.MT.15 ArcaVir Found nothing Avast Found Win32:Nilage-JY AVG Antivirus Found Generic7.HVD BitDefender Found Generic.PWS.Games.4.CC2F213E ClamAV Found Trojan.Spy-12539 CPsecure Found nothing Dr.Web Found Trojan.PWS.Wsgame.1210 F-Prot Antivirus Found nothing F-Secure Anti-Virus Found nothing Fortinet Found nothing Kaspersky Anti-Virus Found nothing NOD32 Found probably a variant of Win32/Genetik (probable variant) Norman Virus Control Found nothing Panda Antivirus Found Trj/Agent.GME Rising Antivirus Found Trojan.PSW.Win32.OnlineGames.yka Sophos Antivirus Found Mal/Gampass-A VirusBuster Found Trojan.PWS.OnlineGames.Gen.40 VBA32 Found MalwareScope.Trojan-PSW.Game.12

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI