okay man i did the steps required here are the log files :
KARPESKY:
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Friday, December 21, 2007 12:33:57 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 20/12/2007
Kaspersky Anti-Virus database records: 490757
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 96357
Number of viruses found: 50
Number of infected objects: 194
Number of suspicious objects: 0
Duration of the scan process: 01:11:22
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\tony\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\tony\Desktop\mediacodec-v4.290.exe/stream/data0006 Infected: Trojan-Downloader.Win32.Zlob.ob skipped
C:\Documents and Settings\tony\Desktop\mediacodec-v4.290.exe/stream/data0007 Infected: Trojan-Downloader.Win32.Zlob.nf skipped
C:\Documents and Settings\tony\Desktop\mediacodec-v4.290.exe/stream Infected: Trojan-Downloader.Win32.Zlob.nf skipped
C:\Documents and Settings\tony\Desktop\mediacodec-v4.290.exe NSIS: infected - 3 skipped
C:\Documents and Settings\tony\Desktop\mediacodec-v4.290.exe UPX: infected - 3 skipped
C:\Documents and Settings\tony\Desktop\mediacodec-v4.290.exe PE_Patch.UPX: infected - 3 skipped
C:\Documents and Settings\tony\Desktop\Virus infection\SmitfraudFix.zip/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\tony\Desktop\Virus infection\SmitfraudFix.zip ZIP: infected - 1 skipped
C:\Documents and Settings\tony\Local Settings\Application Data\ApplicationHistory\hpqgalry.exe.cf8dd223.ini.inuse Object is locked skipped
C:\Documents and Settings\tony\Local Settings\Application Data\HP\Digital Imaging\db\administrativeInfo.dbf Object is locked skipped
C:\Documents and Settings\tony\Local Settings\Application Data\HP\Digital Imaging\db\albumImagesTable.cdx Object is locked skipped
C:\Documents and Settings\tony\Local Settings\Application Data\HP\Digital Imaging\db\albumImagesTable.dbf Object is locked skipped
C:\Documents and Settings\tony\Local Settings\Application Data\HP\Digital Imaging\db\albumTable.cdx Object is locked skipped
C:\Documents and Settings\tony\Local Settings\Application Data\HP\Digital Imaging\db\albumTable.dbf Object is locked skipped
C:\Documents and Settings\tony\Local Settings\Application Data\HP\Digital Imaging\db\CB_Server_Errors.txt Object is locked skipped
C:\Documents and Settings\tony\Local Settings\Application Data\HP\Digital Imaging\db\EXIFTable.cdx Object is locked skipped
C:\Documents and Settings\tony\Local Settings\Application Data\HP\Digital Imaging\db\EXIFTable.dbf Object is locked skipped
C:\Documents and Settings\tony\Local Settings\Application Data\HP\Digital Imaging\db\imageTable.cdx Object is locked skipped
C:\Documents and Settings\tony\Local Settings\Application Data\HP\Digital Imaging\db\imageTable.dbf Object is locked skipped
C:\Documents and Settings\tony\Local Settings\Application Data\HP\Digital Imaging\db\imageTable.fpt Object is locked skipped
C:\Documents and Settings\tony\Local Settings\Application Data\HP\Digital Imaging\db\keywordImagesTable.cdx Object is locked skipped
C:\Documents and Settings\tony\Local Settings\Application Data\HP\Digital Imaging\db\keywordImagesTable.dbf Object is locked skipped
C:\Documents and Settings\tony\Local Settings\Application Data\HP\Digital Imaging\db\keywordTable.cdx Object is locked skipped
C:\Documents and Settings\tony\Local Settings\Application Data\HP\Digital Imaging\db\keywordTable.dbf Object is locked skipped
C:\Documents and Settings\tony\Local Settings\Application Data\HP\Digital Imaging\db\managedFolderTable.dbf Object is locked skipped
C:\Documents and Settings\tony\Local Settings\Application Data\HP\Digital Imaging\db\pathnameTable.cdx Object is locked skipped
C:\Documents and Settings\tony\Local Settings\Application Data\HP\Digital Imaging\db\pathnameTable.dbf Object is locked skipped
C:\Documents and Settings\tony\Local Settings\Application Data\HP\Digital Imaging\db\ROFImagesTable.cdx Object is locked skipped
C:\Documents and Settings\tony\Local Settings\Application Data\HP\Digital Imaging\db\ROFImagesTable.dbf Object is locked skipped
C:\Documents and Settings\tony\Local Settings\Application Data\HP\Digital Imaging\db\ROFTable.cdx Object is locked skipped
C:\Documents and Settings\tony\Local Settings\Application Data\HP\Digital Imaging\db\ROFTable.dbf Object is locked skipped
C:\Documents and Settings\tony\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\tony\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\tony\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\tony\Local Settings\Temp\hpodvd09.log Object is locked skipped
C:\Documents and Settings\tony\Local Settings\Temp\Perflib_Perfdata_bb0.dat Object is locked skipped
C:\Documents and Settings\tony\Local Settings\Temp\~DF8225.tmp Object is locked skipped
C:\Documents and Settings\tony\Local Settings\Temp\~DFAEA7.tmp Object is locked skipped
C:\Documents and Settings\tony\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\tony\My Documents\My Completed Downloads\SmitfraudFix.zip/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\tony\My Documents\My Completed Downloads\SmitfraudFix.zip ZIP: infected - 1 skipped
C:\Documents and Settings\tony\My Documents\My Completed Downloads\VideoAccessCodecInstall.exe/stream/data0004 Infected: Trojan-Downloader.Win32.Zlob.fcm skipped
C:\Documents and Settings\tony\My Documents\My Completed Downloads\VideoAccessCodecInstall.exe/stream Infected: Trojan-Downloader.Win32.Zlob.fcm skipped
C:\Documents and Settings\tony\My Documents\My Completed Downloads\VideoAccessCodecInstall.exe NSIS: infected - 2 skipped
C:\Documents and Settings\tony\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\tony\ntuser.dat.LOG Object is locked skipped
C:\New Folder\Kazaa\kazaaFDL.exe/data0003 Infected: Trojan-Downloader.Win32.Dreamad skipped
C:\New Folder\Kazaa\kazaaFDL.exe Inno: infected - 1 skipped
C:\New Folder\Kazaa\Kazaamate.exe/data0020 Infected: not-a-virus:Server-Proxy.Win32.MarketScore.j skipped
C:\New Folder\Kazaa\Kazaamate.exe Inno: infected - 1 skipped
C:\New Folder\Kazaa\kpe12.exe/data0005 Infected: not-a-virus:AdWare.Win32.SaveNow.bx skipped
C:\New Folder\Kazaa\kpe12.exe NSIS: infected - 1 skipped
C:\New Folder\Kazaa\qksetup.exe/WISE0014.BIN/data0009 Infected: not-a-virus:AdWare.Win32.CommonName.b skipped
C:\New Folder\Kazaa\qksetup.exe/WISE0014.BIN/data0010 Infected: not-a-virus:AdWare.Win32.CommonName.d skipped
C:\New Folder\Kazaa\qksetup.exe/WISE0014.BIN Infected: not-a-virus:AdWare.Win32.CommonName.d skipped
C:\New Folder\Kazaa\qksetup.exe/WISE0017.BIN Infected: not-a-virus:AdWare.Win32.EZula.p skipped
C:\New Folder\Kazaa\qksetup.exe WiseSFX: infected - 4 skipped
C:\New Folder\Kazaa\speedup-2.7.3.exe/data0003/stream/data0007/data0002 Infected: not-a-virus:AdWare.Win32.NoName.b skipped
C:\New Folder\Kazaa\speedup-2.7.3.exe/data0003/stream/data0007/data0003 Infected: Trojan-Downloader.Win32.Lookme.g skipped
C:\New Folder\Kazaa\speedup-2.7.3.exe/data0003/stream/data0007/data0004 Infected: not-a-virus:AdWare.Win32.404Search.a skipped
C:\New Folder\Kazaa\speedup-2.7.3.exe/data0003/stream/data0007 Infected: not-a-virus:AdWare.Win32.404Search.a skipped
C:\New Folder\Kazaa\speedup-2.7.3.exe/data0003/stream Infected: not-a-virus:AdWare.Win32.404Search.a skipped
C:\New Folder\Kazaa\speedup-2.7.3.exe/data0003 Infected: not-a-virus:AdWare.Win32.404Search.a skipped
C:\New Folder\Kazaa\speedup-2.7.3.exe NSIS: infected - 6 skipped
C:\Program Files\DAEMON Tools\SetupDTSB.exe Infected: not-a-virus:AdTool.Win32.WhenU.a skipped
C:\Program Files\DAP\History\tony\_lasthist.dat Object is locked skipped
C:\Program Files\DAP\Log\DAP_REPORT.LOG Object is locked skipped
C:\Program Files\HP\hpcoretech\hpcmerr.log Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL\Data\master.mdf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL\Data\mastlog.ldf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL\Data\model.mdf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL\Data\modellog.ldf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL\Data\tempdb.mdf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL\Data\templog.ldf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL\LOG\ERRORLOG Object is locked skipped
C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped
C:\Program Files\MyWay\myBar\1.bin\MY2NS.EXE Infected: not-a-virus:AdWare.Win32.MyWay.b skipped
C:\Program Files\MyWay\myBar\1.bin\NPMYWAY.DLL Infected: not-a-virus:AdWare.Win32.MyWay.f skipped
C:\Program Files\Norton AntiVirus\Quarantine\0D17196E/WISE0007.BIN Infected: Trojan-Downloader.Win32.TSUpdate.p skipped
C:\Program Files\Norton AntiVirus\Quarantine\0D17196E WiseSFX: infected - 1 skipped
C:\Program Files\Norton AntiVirus\Quarantine\0D17196E CryptFF: infected - 1 skipped
C:\Program Files\Norton AntiVirus\Quarantine\0F8A36A3 Infected: not-a-virus:AdWare.Win32.Altnet.j skipped
C:\Program Files\Norton AntiVirus\Quarantine\107C7C39/WISE0007.BIN Infected: Trojan-Downloader.Win32.TSUpdate.p skipped
C:\Program Files\Norton AntiVirus\Quarantine\107C7C39 WiseSFX: infected - 1 skipped
C:\Program Files\Norton AntiVirus\Quarantine\107C7C39 CryptFF: infected - 1 skipped
C:\Program Files\Norton AntiVirus\Quarantine\107F2635 Infected: not-a-virus:AdWare.Win32.180Solutions skipped
C:\Program Files\Norton AntiVirus\Quarantine\10825032 Infected: not-a-virus:AdWare.Win32.Xupiter.m skipped
C:\Program Files\Norton AntiVirus\Quarantine\13010326 Infected: Trojan-Downloader.Win32.IstBar.gen skipped
C:\Program Files\Norton AntiVirus\Quarantine\18A7556D Infected: not-a-virus:AdWare.Win32.YourSiteBar.c skipped
C:\Program Files\Norton AntiVirus\Quarantine\34510A93/WISE0010.BIN Infected: Trojan-Downloader.Win32.TSUpdate.k skipped
C:\Program Files\Norton AntiVirus\Quarantine\34510A93/WISE0011.BIN Infected: Trojan-Downloader.Win32.TSUpdate.p skipped
C:\Program Files\Norton AntiVirus\Quarantine\34510A93/WISE0012.BIN Infected: Trojan-Downloader.Win32.TSUpdate.l skipped
C:\Program Files\Norton AntiVirus\Quarantine\34510A93/WISE0013.BIN Infected: not-a-virus:AdWare.Win32.Xupiter.m skipped
C:\Program Files\Norton AntiVirus\Quarantine\34510A93 WiseSFX: infected - 4 skipped
C:\Program Files\Norton AntiVirus\Quarantine\34510A93 CryptFF: infected - 4 skipped
C:\Program Files\Norton AntiVirus\Quarantine\357351B8.tmp Infected: Trojan.Win32.Favadd.m skipped
C:\Program Files\Norton AntiVirus\Quarantine\372D70BB Infected: not-a-virus:AdWare.Win32.Altnet.d skipped
C:\Program Files\Norton AntiVirus\Quarantine\41885A4D Infected: not-a-virus:AdWare.Win32.Altnet.a skipped
C:\Program Files\Norton AntiVirus\Quarantine\46066015 Infected: not-a-virus:AdWare.Win32.Altnet.d skipped
C:\Program Files\Norton AntiVirus\Quarantine\488E7D63 Infected: not-a-virus:AdWare.Win32.Altnet.a skipped
C:\Program Files\Norton AntiVirus\Quarantine\55133B7B Infected: Trojan-Downloader.Win32.IstBar.gm skipped
C:\Program Files\Norton AntiVirus\Quarantine\55166578 Infected: not-a-virus:AdWare.Win32.Altnet.d skipped
C:\Program Files\Norton AntiVirus\Quarantine\59A26613 Infected: not-a-virus:AdWare.Win32.180Solutions skipped
C:\Program Files\Norton AntiVirus\Quarantine\5A9654C1 Infected: not-a-virus:AdWare.Win32.Altnet.a skipped
C:\Program Files\Norton AntiVirus\Quarantine\5CD80560 Infected: not-a-virus:AdWare.Win32.Altnet.a skipped
C:\Program Files\Norton AntiVirus\Quarantine\61830BBE Infected: Trojan-Downloader.Win32.IstBar.gn skipped
C:\Program Files\Norton AntiVirus\Quarantine\639721D4 Infected: not-a-virus:AdWare.Win32.YourSiteBar.b skipped
C:\Program Files\Norton AntiVirus\Quarantine\6A794148 Infected: not-a-virus:AdWare.Win32.Altnet.j skipped
C:\Program Files\Norton AntiVirus\Quarantine\6C0B4C78 Infected: not-a-virus:AdWare.Win32.BrilliantDigital.3039 skipped
C:\Program Files\Norton AntiVirus\Quarantine\6CB71E18 Infected: not-a-virus:AdWare.Win32.BrilliantDigital.3039 skipped
C:\Program Files\Norton AntiVirus\Quarantine\76BF1D7C Infected: not-a-virus:AdWare.Win32.Altnet.a skipped
C:\Program Files\Norton AntiVirus\Quarantine\76C24779 Infected: not-a-virus:AdWare.Win32.Altnet.a skipped
C:\Program Files\Norton AntiVirus\Quarantine\76C57175 Infected: not-a-virus:AdWare.Win32.Altnet.d skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\01161E65.exe Infected: not-a-virus:AdWare.Win32.Lop.ag skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\01194862 Infected: not-a-virus:AdWare.Win32.Altnet.d skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\01194862.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\011C725E.exe Infected: Trojan-Downloader.Win32.Swizzor.fg skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\01410730.tmp Infected: Trojan-Downloader.Win32.Zlob.nf skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\02F860A4/data0003 Infected: Trojan-Downloader.Win32.Keenval.e skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\02F860A4 NSIS: infected - 1 skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\02F860A4 CryptFF: infected - 1 skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\02FA0E15.exe Infected: Packed.Win32.PolyCrypt.d skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\02FB0AA0.exe Infected: Packed.Win32.PolyCrypt.d skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\02FE349C.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\031C6645.exe Infected: Trojan-Downloader.Win32.IstBar.ij skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\03330C2C.exe Infected: Trojan-Downloader.Win32.IstBar.gen skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\04AF6AA0.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\0530584F.tmp Infected: Trojan-Downloader.Win32.Zlob.nf skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\05A40175.tmp Infected: Trojan-Downloader.Win32.Zlob.nf skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\07F72F7D.exe Infected: not-a-virus:AdWare.Win32.Lop.ag skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\07FA5979.exe Infected: not-a-virus:AdWare.Win32.Lop.ag skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\08C67AAD.tmp Infected: Trojan-Downloader.Win32.Zlob.nf skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\0A80684C.exe Infected: Packed.Win32.PolyCrypt.d skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\0B3D63DB.exe Infected: Trojan-Downloader.Win32.Swizzor.fg skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\0D72593B.dll Infected: not-a-virus:AdWare.Win32.Altnet.d skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\0F4640AB.tmp Infected: Trojan-Downloader.Win32.Zlob.nf skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\0FDF21D3.dll Infected: not-a-virus:AdWare.Win32.Altnet.d skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\1040269F.exe Infected: Trojan-Downloader.Win32.Swizzor.fg skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\108217EB.tmp Infected: Trojan-Downloader.Win32.Zlob.nf skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\113B320D.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\11BB7947.exe Infected: Packed.Win32.PolyCrypt.d skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\11BE2344.exe Infected: Packed.Win32.PolyCrypt.d skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\13522669.exe Infected: not-a-virus:AdWare.Win32.Lop.ag skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\142E2A9D.tmp Infected: Trojan-Downloader.Win32.Zlob.nf skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\189F7752.tmp Infected: Trojan-Downloader.Win32.Zlob.nf skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\18CD7A42.tmp Infected: Trojan-Downloader.Win32.Zlob.nf skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\1C0D0F65.tmp Infected: Trojan-Downloader.Win32.Zlob.nf skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\1C3658A5.exe Infected: Packed.Win32.PolyCrypt.d skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\24623432.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\247C7F3E.EXE Infected: Email-Worm.Win32.Rays skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\27B20985.exe Infected: Trojan-Downloader.Win32.Swizzor.fg skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\27C714A4.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\2A465549.exe Infected: Packed.Win32.PolyCrypt.d skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\2B451D6C.exe Infected: Packed.Win32.PolyCrypt.d skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\2BC17AEB.js Infected: Trojan-Downloader.JS.IstBar.ad skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\2E9959AE.exe Infected: Packed.Win32.PolyCrypt.d skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\2F214954.exe Infected: Packed.Win32.PolyCrypt.d skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\2F247351.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\2F281D4D.exe Infected: Packed.Win32.PolyCrypt.d skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\32CB77A3.exe Infected: Packed.Win32.PolyCrypt.d skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\335750A2.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\378F7118.exe/stream Infected: not-a-virus:AdWare.Win32.404Search.h skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\378F7118.exe NSIS: infected - 1 skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\378F7118.exe CryptFF: infected - 1 skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\39834689.dll Infected: not-a-virus:AdWare.Win32.Altnet.d skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\39864164.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\40732DDF.exe Infected: Packed.Win32.PolyCrypt.d skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\418D16BC.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\419140B9.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\41946AB5.exe Infected: Packed.Win32.PolyCrypt.d skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\419714B1.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\419A3EAE.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\419E68AA.exe Infected: Packed.Win32.PolyCrypt.d skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\41A112A7.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\41A43CA3.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\41A8669F.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\41AB109C.exe Infected: Packed.Win32.PolyCrypt.d skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\41AE3A98.bk! Infected: not-a-virus:AdWare.Win32.Lop.bb skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\41AE3A98.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\41B16495.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\431F2D17.dll Infected: not-a-virus:AdWare.Win32.Altnet.d skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\457405DC.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\4855068B.tmp Infected: Trojan-Downloader.Win32.Zlob.nf skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\4A7848A0.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\4BDB5C0F.tmp Infected: Trojan-Downloader.Win32.Zlob.nf skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\4F46043D.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\4FA94816.dll Infected: not-a-virus:AdWare.Win32.404Search.h skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\4FA94816.exe/stream Infected: not-a-virus:AdWare.Win32.404Search.h skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\4FA94816.exe NSIS: infected - 1 skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\4FA94816.exe CryptFF: infected - 1 skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\4FA94816.tmp Infected: not-a-virus:AdWare.Win32.180Solutions skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\4FAD7212.dll Infected: not-a-virus:AdWare.Win32.WinAD.ag skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\4FAD7212.exe Infected: not-a-virus:AdWare.Win32.WinAD.af skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\4FB01C0F.dll Infected: not-a-virus:AdWare.Win32.WinAD.ah skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\4FB01C0F.exe Infected: Trojan-Downloader.Win32.TSUpdate.p skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\53902CC3.exe Infected: Packed.Win32.PolyCrypt.d skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\53C91B28.dll Infected: not-a-virus:AdWare.Win32.Altnet.d skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\5608049E.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\564F6911.tmp Infected: Trojan-Downloader.Win32.Zlob.nf skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\58EB11F3.exe Infected: Packed.Win32.PolyCrypt.d skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\591B0468.exe Infected: not-a-virus:AdWare.Win32.Lop.ag skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\5C086C9A.tmp Infected: Trojan-Downloader.Win32.Zlob.nf skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\5D296C7F.exe Infected: not-a-virus:AdWare.Win32.Altnet.a skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\5D2C167B.exe Infected: not-a-virus:AdWare.Win32.Altnet.a skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\5D2F4078.dll Infected: not-a-virus:AdWare.Win32.BrilliantDigital.1007 skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\5D326A74.dll Infected: not-a-virus:AdWare.Win32.Altnet.d skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\61FE36A4.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\628C755C.tmp Infected: Trojan-Downloader.Win32.Zlob.nf skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\64A40DEC.exe Infected: Packed.Win32.PolyCrypt.d skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\68F022B6.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\71BB6F2D.tmp Infected: Trojan-Downloader.Win32.Zlob.nf skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\746237AD.exe Infected: Packed.Win32.PolyCrypt.d skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\77137A7E.tmp Infected: Trojan-Downloader.Win32.Zlob.nf skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\793C08D5.dll Infected: not-a-virus:AdWare.Win32.Altnet.d skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\7A1F0616.exe Infected: Packed.Win32.PolyCrypt.d skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\7B1D2F84.tmp Infected: Trojan-Downloader.Win32.Zlob.nf skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\7BDA3C1A.exe Infected: Packed.Win32.PolyCrypt.d skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\7C39561A.tmp Infected: Trojan-Downloader.Win32.Zlob.nf skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\7F177F55.tmp Infected: Trojan-Downloader.Win32.Zlob.nf skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\7F677A2F.exe Infected: Packed.Win32.PolyCrypt.d skipped
C:\qoobox\Quarantine\C\Program Files\XP Antivirus\xpa.exe.vir Infected: not-a-virus:FraudTool.Win32.XPAntivirus.d skipped
C:\qoobox\Quarantine\C\WINDOWS\jetctrl.dll.vir Infected: not-a-virus:AdWare.Win32.Vapsup.qu skipped
C:\qoobox\Quarantine\C\WINDOWS\kopmet.dll.vir Infected: not-a-virus:AdWare.Win32.Vapsup.qv skipped
C:\qoobox\Quarantine\C\WINDOWS\nretcip.exe.vir Infected: not-a-virus:AdWare.Win32.Vapsup.rz skipped
C:\Setup\MDX_Install_2.1.exe/file01 Infected: not-a-virus:AdWare.Win32.VB.c skipped
C:\Setup\MDX_Install_2.1.exe Inno: infected - 1 skipped
C:\Setup\mirc616.exe/data0001.bin Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped
C:\Setup\mirc616.exe mIRC: infected - 1 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{FC5C9A43-6B56-4E6E-8D29-639CAA44C75E}\RP598\A0404417.exe/file02 Infected: not-a-virus:AdWare.Win32.VB.c skipped
C:\System Volume Information\_restore{FC5C9A43-6B56-4E6E-8D29-639CAA44C75E}\RP598\A0404417.exe Inno: infected - 1 skipped
C:\System Volume Information\_restore{FC5C9A43-6B56-4E6E-8D29-639CAA44C75E}\RP598\A0404418.exe/file02 Infected: not-a-virus:AdWare.Win32.VB.c skipped
C:\System Volume Information\_restore{FC5C9A43-6B56-4E6E-8D29-639CAA44C75E}\RP598\A0404418.exe Inno: infected - 1 skipped
C:\System Volume Information\_restore{FC5C9A43-6B56-4E6E-8D29-639CAA44C75E}\RP602\A0407690.exe Infected: not-a-virus:FraudTool.Win32.XPAntivirus.d skipped
C:\System Volume Information\_restore{FC5C9A43-6B56-4E6E-8D29-639CAA44C75E}\RP602\A0407691.dll Infected: not-a-virus:AdWare.Win32.Vapsup.qu skipped
C:\System Volume Information\_restore{FC5C9A43-6B56-4E6E-8D29-639CAA44C75E}\RP602\A0407692.dll Infected: not-a-virus:AdWare.Win32.Vapsup.qv skipped
C:\System Volume Information\_restore{FC5C9A43-6B56-4E6E-8D29-639CAA44C75E}\RP602\A0407693.exe Infected: not-a-virus:AdWare.Win32.Vapsup.rz skipped
C:\System Volume Information\_restore{FC5C9A43-6B56-4E6E-8D29-639CAA44C75E}\RP602\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\dtscsi.sys Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\drivers\sptd9613.sys Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\ld9347.tmp Infected: Trojan-Downloader.Win32.Zlob.nf skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_57c.dat Object is locked skipped
C:\WINDOWS\Temp\spnserv.dat Object is locked skipped
C:\WINDOWS\Temp\spserv.dat Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
COMBOFIX: :
ComboFix 07-12-20.1 - tony 2007-12-21 0:36:03.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.178 [GMT 2:00]
Running from: C:\Documents and Settings\tony\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\tony\Desktop\CFScript.txt
* Created a new restore point
FILE
C:\WINDOWS\jetctrl.dll
C:\WINDOWS\kopmet.dll
C:\WINDOWS\nretcip.exe
C:\WINDOWS\vipextmst.dll
.
((((((((((((((((((((((((( Files Created from 2007-11-20 to 2007-12-20 )))))))))))))))))))))))))))))))
.
2007-12-20 15:04 . 2007-12-20 15:04 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-12-20 15:04 . 2007-12-20 15:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-12-18 14:05 . 2007-12-18 14:05 <DIR> d-------- C:\Documents and Settings\tony\Application Data\Grisoft
2007-12-18 14:05 . 2007-12-18 14:05 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-18 14:05 . 2007-05-30 14:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-12-04 22:26 . 2007-12-04 22:26 7,680 --ahs---- C:\WINDOWS\Thumbs.db
2007-11-24 23:01 . 2007-12-20 23:15 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2007-11-24 22:49 . 2007-11-24 22:49 479,298 --a------ C:\WINDOWS\system32\wbocx.ocx
2007-11-24 22:49 . 2007-11-24 22:49 172,032 --a------ C:\WINDOWS\system32\AniGIF.ocx
2007-11-24 22:49 . 2007-11-24 22:49 50,688 --a------ C:\WINDOWS\system32\wbhelp2.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-20 22:29 --------- d-----w C:\Documents and Settings\tony\Application Data\Metacafe
2007-12-20 22:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\Metacafe
2007-12-20 21:15 --------- d-----w C:\Program Files\Microsoft AntiSpyware
2007-11-24 21:04 --------- d-----w C:\Program Files\DAP
2007-11-13 10:25 20,480 ------w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-07 21:52 --------- d-----w C:\Program Files\SCC-TDS
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 13:03 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-10-27 15:40 227,328 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-25 23:37 --------- d-----w C:\Program Files\MSXML 4.0
2007-10-25 23:35 --------- d-----w C:\Program Files\Metacafe
2007-10-25 16:28 --------- d-----w C:\Program Files\MSN Messenger
2007-10-25 15:55 --------- d-----w C:\Program Files\MessengerPlus! 3
2007-10-25 15:38 --------- d-----w C:\Program Files\MessengerDiscovery
2007-10-25 15:35 --------- d-----w C:\Program Files\Ares
2007-10-25 15:32 --------- d-----w C:\Program Files\Nokia
2007-10-25 15:26 --------- d-----w C:\Program Files\EA SPORTS
2007-10-23 18:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\NVIDIA
2007-10-23 14:51 --------- d-----w C:\Documents and Settings\tony\Application Data\InstallShield
.
((((((((((((((((((((((((((((( snapshot@2007-12-20_14.04.28.23 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-05-24 10:27:16 213,048 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 13:47:20 94,208 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 13:49:54 950,272 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
+ 2007-12-20 17:42:37 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_57c.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 11:54]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2003-05-30 02:28]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2003-05-30 19:42]
"FastTVSync"="C:\Program Files\Common Files\InterVideo\FastTVSync\FastTVSync.exe" [2003-06-05 03:58]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-03 18:56 C:\WINDOWS\system32\rundll32.exe]
"nwiz"="nwiz.exe" [2006-10-22 11:22 C:\WINDOWS\system32\nwiz.exe]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2004-02-12 23:38]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-13 01:18]
"RCServer"="C:\Program Files\Remote Control\RCServer.exe" [2003-02-05 19:51]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-10-23 14:30]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2005-11-09 00:00]
"gcasServ"="C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" [2005-11-15 12:12]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-02-19 21:42]
"NvMediaCenter"="RUNDLL32.exe" [2004-08-03 18:56 C:\WINDOWS\system32\rundll32.exe]
"DownloadAccelerator"="C:\Program Files\DAP\DAP.exe" [2007-11-24 23:00]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Norton SystemWorks"="C:\Program Files\Norton SystemWorks\cfgwiz.exe" []
C:\Documents and Settings\tony\Start Menu\Programs\Startup\
Metacafe.lnk - C:\Program Files\Metacafe\MetacafeAgent.exe [2007-09-04 17:04:34]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-05-29 08:31:38]
HP Image Zone Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2004-05-29 09:06:36]
ImageFox.lnk - C:\WINDOWS\Installer\{92E64C51-5096-442F-9A44-61CB2941391D}\NewShortcut1.exe [2005-02-12 16:37:13]
InterVideo Scheduler server.lnk - C:\Program Files\InterVideo\WinDVD4PR\SchSvr.exe [2005-02-13 01:40:01]
InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe [2005-02-13 01:40:07]
Media Key.lnk - C:\Program Files\Media Key\MagicKey.exe [2005-02-12 16:57:23]
Metacafe.lnk - C:\Program Files\Metacafe\MetacafeAgent.exe [2007-09-04 17:04:34]
Service Manager.lnk - C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2000-08-06 01:03:20]
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\
0]
Source= file:///C:\WINDOWS\privacy_danger\index.htm
FriendlyName= Privacy Protection
R1 kbfilter;Keyboard Filter Driver;C:\WINDOWS\system32\drivers\kbfilter.sys [2002-07-11 12:00]
R1 UsbFltr;WayTechUSBFilterDriver;C:\WINDOWS\system32\drivers\UsbFltr.sys [2003-12-29 18:27]
R2 RCSERVER;Remote Control Server;"C:\Program Files\Remote Control\RCServer.exe" -service []
S3 FTLUND;Lundinova Filter Driver;C:\WINDOWS\system32\drivers\ftlund.sys [2004-01-19 17:27]
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-21 00:38:54
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-21 0:39:54
C:\ComboFix2.txt ... 2007-12-20 15:01
C:\ComboFix3.txt ... 2007-12-20 14:05
.
2007-12-20 11:56:33 --- E O F ---
HJT:
Logfile of HijackThis v1.99.1
Scan saved at 12:43:30 AM, on 12/21/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Remote Control\RCServer.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Rainbow Technologies\SPN Combo Installer\1.0.2\Server\WinNT\spnsrvnt.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\Common Files\InterVideo\FastTVSync\FastTVSync.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\DAP\DAP.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\ACD Systems\ImageFox\ImageFox.exe
C:\Program Files\InterVideo\WinDVD4PR\SchSvr.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\Media Key\MagicKey.exe
C:\Program Files\Media Key\OSD.EXE
C:\Program Files\Metacafe\MetacafeAgent.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://softwarerefer...=...6Ojg5&lid=2
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.hotmail.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 90.2.2.1:8080
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.1601.0\en-us\msntb.dll
O3 - Toolbar: (no name) - {86227D9C-0EFE-4f8a-AA55-30386A3F5686} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [FastTVSync] "C:\Program Files\Common Files\InterVideo\FastTVSync\FastTVSync.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [RCServer] "C:\Program Files\Remote Control\RCServer.exe" -servicehelper
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [DownloadAccelerator] "C:\Program Files\DAP\DAP.EXE" /STARTUP
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Metacafe.lnk = C:\Program Files\Metacafe\MetacafeAgent.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: ImageFox.lnk = ?
O4 - Global Startup: InterVideo Scheduler server.lnk = C:\Program Files\InterVideo\WinDVD4PR\SchSvr.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Media Key.lnk = C:\Program Files\Media Key\MagicKey.exe
O4 - Global Startup: Metacafe.lnk = C:\Program Files\Metacafe\MetacafeAgent.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Run DAP - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\PROGRA~1\DAP\DAP.EXE
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky...can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....k/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://totti007.spac...ad/MsnPUpld.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Remote Control Server (RCSERVER) - Unknown owner - C:\Program Files\Remote Control\RCServer.exe" -service (file missing)
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: SuperProServer - Unknown owner - C:\Program Files\Rainbow Technologies\SPN Combo Installer\1.0.2\Server\WinNT\spnsrvnt.exe
i know am disturbing but i really need ur help