Kaspersky:
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Wednesday, January 02, 2008 6:59:25 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 1/01/2008
Kaspersky Anti-Virus database records: 501232
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
G:\
H:\
I:\
Scan Statistics:
Total number of scanned objects: 101282
Number of viruses found: 10
Number of infected objects: 105
Number of suspicious objects: 0
Duration of the scan process: 01:22:02
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-12082006-172723.log Object is locked skipped
C:\Documents and Settings\Karen\Local Settings\Temporary Internet Files\AntiPhishing\6729BBF9-D54C-48CB-A4D7-AD400339D808.dat Object is locked skipped
C:\Documents and Settings\Karen\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Trent\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Trent\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Trent\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Trent\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{D3FCC922-A3B3-4530-BC57-3D3492A47E1A} Object is locked skipped
C:\Documents and Settings\Trent\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Trent\Local Settings\Temporary Internet Files\Content.IE5\GHDFYAUD\crossdomain[2].xml Object is locked skipped
C:\Documents and Settings\Trent\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Trent\Local Settings\Temporary Internet Files\Content.IE5\JSWVASB9\songspot160_310[1].swf Object is locked skipped
C:\Documents and Settings\Trent\Local Settings\Temporary Internet Files\Content.IE5\PA6O65DW\BurstingInteractionsPipe[1].htm Object is locked skipped
C:\Documents and Settings\Trent\ntuser.dat Object is locked skipped
C:\Documents and Settings\Trent\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\integ\avast.int Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\report\Resident protection.txt Object is locked skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\aonjubrn.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\bklqaxby.exe.vir Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\bytovxdl.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\cwtnwxay.exe.vir Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\dfcdcghn.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\drslxpip.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\eqrehcfu.exe.vir Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\ftuxcdon.exe.vir Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\hdsmaygg.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\iqfqyfou.exe.vir Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\irnxfftl.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\ispansum.dll.vir Infected: Trojan.Win32.Pakes.bwd skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\iypcnnrx.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\jqglukae.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\kariejls.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\muegqyfk.exe.vir Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\nuvmfcbu.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\oorujrox.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\oqtoetcf.exe.vir Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\ovudypfb.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\psoafycu.exe.vir Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\qhnnkgqb.exe.vir Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\qwkccyen.exe.vir Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\rbtcmyjv.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\rebyhnsg.dll.vir Infected: Backdoor.Win32.Agent.dlj skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\rucwqisl.exe.vir Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\scpwidrq.exe.vir Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\scwlngob.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\ujqarjfu.exe.vir Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\utoveqbu.exe.vir Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\vqpsyrvq.exe.vir Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\wvqekdob.exe.vir Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\yioiregb.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\SDFix\backups\backups.zip/backups/Crack.exe Infected: Trojan.Win32.Agent.cmn skipped
C:\SDFix\backups\backups.zip ZIP: infected - 1 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP576\A0234477.exe Infected: Trojan-Downloader.Win32.Small.guf skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP577\A0234499.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP577\A0234501.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP577\A0234521.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ak skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP577\A0234523.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP577\A0234524.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP577\A0234525.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.azt skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP577\A0234529.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.azt skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP582\A0234661.exe Infected: not-a-virus:PSWTool.Win32.PassView.p skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP585\A0235908.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.azt skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP585\A0235932.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP586\A0235959.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP588\A0235993.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.azt skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP589\A0236020.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP594\A0237108.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP596\A0237176.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP598\A0237201.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.azt skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP599\A0237238.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP600\A0237263.exe Infected: Trojan.Win32.Agent.cmn skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP602\A0237322.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.azt skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP602\A0237323.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.azt skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP602\A0237324.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.azt skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP602\A0237325.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.azt skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP602\A0237326.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.azt skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP602\A0237327.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.azt skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP602\A0237328.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.azt skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP602\A0237329.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.azt skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP602\A0237330.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.azt skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP602\A0237331.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.azt skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP602\A0237332.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.azt skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP604\A0237538.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.azt skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP606\A0237606.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP608\A0237632.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP610\A0238682.exe Infected: Trojan.Win32.Agent.cmn skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP610\A0238690.exe Infected: Trojan.Win32.Agent.cmn skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP610\A0238733.dll Infected: Backdoor.Win32.Agent.dlj skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP611\A0238762.dll Infected: Backdoor.Win32.Agent.dlj skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP614\A0238790.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP614\A0238791.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP614\A0238792.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP614\A0238793.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP614\A0238794.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP614\A0238795.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP614\A0238796.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP614\A0238797.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP614\A0238798.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP614\A0238799.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP614\A0238800.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP614\A0238801.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP614\A0238802.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP614\A0238803.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP614\A0238804.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP614\A0238805.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP614\A0238806.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP614\A0238808.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP614\A0238809.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP614\A0238810.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP614\A0238811.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP614\A0238812.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP614\A0238813.dll Infected: Trojan.Win32.Pakes.bwd skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP614\A0238814.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP614\A0238815.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP614\A0238816.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP614\A0238819.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP614\A0238820.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP614\A0238822.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP614\A0238823.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP614\A0238824.dll Infected: Backdoor.Win32.Agent.dlj skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP614\A0238825.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP614\A0238826.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\System Volume Information\_restore{BB3D050C-545B-4A12-BEC2-3427D97105BC}\RP621\change.log Object is locked skipped
C:\WINDOWS\CSC\00000001 Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb Object is locked skipped
C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log Object is locked skipped
C:\WINDOWS\SoftwareDistribution\DataStore\Logs\tmp.edb Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_5dc.dat Object is locked skipped
C:\WINDOWS\Temp\_avast4_\Webshlock.txt Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
ComboFix:
ComboFix 07-12-21.4 - Trent 2007-12-28 8:23:32.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.868 [GMT 10:00]
Running from: C:\Documents and Settings\Trent\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Trent\Desktop\CFScript.txt
* Created a new restore point
FILE
C:\WINDOWS\system32\bfugaktu.ini
C:\WINDOWS\system32\caaxcjvp.ini
C:\WINDOWS\system32\fvddupcs.ini
C:\WINDOWS\system32\fvsuakbg.ini
C:\WINDOWS\system32\gjjganwe.ini
C:\WINDOWS\system32\hynsobvs.ini
C:\WINDOWS\system32\maqnteon.ini
C:\WINDOWS\system32\pxurieqy.ini
C:\WINDOWS\system32\ullyomsh.ini
C:\WINDOWS\system32\ulrasaih.ini
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\bfugaktu.ini
C:\WINDOWS\system32\caaxcjvp.ini
C:\WINDOWS\system32\fvddupcs.ini
C:\WINDOWS\system32\fvsuakbg.ini
C:\WINDOWS\system32\gjjganwe.ini
C:\WINDOWS\system32\hynsobvs.ini
C:\WINDOWS\system32\maqnteon.ini
C:\WINDOWS\system32\pxurieqy.ini
C:\WINDOWS\system32\ullyomsh.ini
C:\WINDOWS\system32\ulrasaih.ini
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_SVKP
-------\SVKP
((((((((((((((((((((((((( Files Created from 2007-11-27 to 2007-12-27 )))))))))))))))))))))))))))))))
.
2007-12-24 11:11 . 2007-12-24 11:14 <DIR> d-------- C:\Program Files\CCleaner
2007-12-24 10:44 . 2007-12-24 10:45 <DIR> d-------- C:\WINDOWS\ERUNT
2007-12-21 14:25 . 2007-12-21 14:25 <DIR> d-------- C:\Program Files\Trend Micro
2007-12-19 17:47 . 2007-12-19 17:47 1,158 --a------ C:\WINDOWS\mozver.dat
2007-12-18 13:05 . 2007-12-19 17:45 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-18 12:46 . 2007-12-18 12:46 0 --a------ C:\WINDOWS\nsreg.dat
2007-12-08 17:57 . 2007-12-21 12:47 <DIR> d-------- C:\Program Files\XoftSpySE
2007-12-08 17:53 . 2007-12-08 17:53 <DIR> d-------- C:\Program Files\RegistryFix
2007-12-07 08:43 . 2007-12-07 08:43 <DIR> d-------- C:\Program Files\FDRLab
2007-12-07 08:43 . 2007-12-07 08:43 <DIR> d-------- C:\Documents and Settings\Trent\Application Data\VideoEgg
2007-12-05 12:03 . 2007-12-05 12:03 147,456 --a------ C:\WINDOWS\system32\vbzip10.dll
2007-12-03 11:22 . 2007-12-19 17:40 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-03 11:22 . 2007-12-03 11:22 0 --a------ C:\WINDOWS\AoADVDRipper.INI
2007-12-03 11:21 . 2005-12-30 20:10 761,856 --a------ C:\WINDOWS\system32\xvidcore.dll
2007-12-03 11:21 . 2005-12-30 20:18 180,224 --a------ C:\WINDOWS\system32\xvidvfw.dll
2007-12-03 11:21 . 2002-07-17 09:20 45,056 --a------ C:\WINDOWS\system32\Wnaspi32.dll
2007-12-03 11:21 . 2002-07-17 08:53 16,877 --a------ C:\WINDOWS\system32\drivers\Aspi32.sys
2007-12-03 11:21 . 2002-07-17 16:22 4,455 --a------ C:\WINDOWS\system\Winaspi.dll
2007-12-03 11:21 . 2002-07-17 16:22 3,535 --a------ C:\WINDOWS\system\Wowpost.exe
2007-11-28 20:42 . 2007-11-28 20:42 <DIR> d-------- C:\WINDOWS\Typing Tournament V1.1.1 Home
2007-11-28 20:42 . 2007-12-07 14:06 <DIR> d-------- C:\Program Files\Typing Tournament V1.1.1 Home
2007-11-27 19:50 . 2007-11-27 19:50 <DIR> d-------- C:\WINDOWS\Numbers Up! VP V1.2.5
2007-11-27 19:50 . 2007-11-27 19:52 <DIR> d-------- C:\Program Files\Numbers Up! VP V1.2.5
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-21 02:47 --------- d-----w C:\Program Files\ydt
2007-12-18 02:20 --------- d-----w C:\Documents and Settings\Trent\Application Data\FrostWire
2007-12-17 05:40 --------- d-----w C:\Program Files\LimeWire
2007-12-04 14:56 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-04 14:55 94,544 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-04 14:53 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-04 14:51 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-04 14:49 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-11-18 02:26 102,400 ----a-w C:\WINDOWS\Segmento_AlphaUninstall.exe
2007-11-18 02:01 77,824 ----a-w C:\WINDOWS\iRODUninstall.exe
2007-11-18 01:58 77,824 ----a-w C:\WINDOWS\SkycarUninstall.exe
2007-11-17 07:58 --------- d-----w C:\Program Files\Picasa2
2007-11-17 07:11 --------- d-----w C:\Program Files\Windows Media Connect 2
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-09 12:22 --------- d-----w C:\Documents and Settings\Karen\Application Data\alot
2007-11-06 10:09 --------- d-----w C:\Documents and Settings\JESS\Application Data\alot
2007-11-03 10:18 --------- d-----w C:\Program Files\FrameShow
2007-11-03 04:28 --------- d-----w C:\Documents and Settings\Trent\Application Data\PhotoFrameShow
2006-12-01 10:10 6,144 ----a-w C:\Documents and Settings\Karen\Application Data\internaldb8186.dat
.
((((((((((((((((((((((((((((( snapshot@2007-12-27_16.31.59.65 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-12-27 06:29:41 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_600.dat
+ 2007-12-27 23:18:03 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_600.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2005-10-24 15:53]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2003-01-13 14:07]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2003-01-13 13:53]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2003-08-06 01:04]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 23:00]
"PCSuiteTrayApplication"="C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.exe" [2005-12-13 08:49]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 18:20]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 02:41]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe" [2005-04-13 03:48]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 18:58]
"Segmento"="C:\Program Files\ydt\Segmento_Alpha\Segmento_Alpha.exe" []
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2005-04-25 13:45]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-10-24 07:18]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Personal Coach.lnk - C:\Program Files\Broderbund\Mavis Beacon Teaches Typing 15\minimavis.exe [2007-07-17 15:45:58]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableCAD"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"= C:\Program Files\Qualcomm\Eudora\EuShlExt.dll [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2006-10-30 09:36 256576 --a------ C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 11:50 155648 --a------ C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
2007-10-24 07:18 443968 --a------ C:\Program Files\Picasa2\PicasaMediaDetector.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe -atboottime
S3 usbanyka;Anyka USB Web Camera;C:\WINDOWS\system32\DRIVERS\UsbAnyka.sys [2007-02-02 14:02]
.
Contents of the 'Scheduled Tasks' folder
"2007-11-30 22:31:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-12-27 22:26:00 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
"2007-12-27 22:18:43 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2005-06-16 09:39:57 C:\WINDOWS\Tasks\RegistryMedicAuotScan.job"
- C:\Program Files\Iomatic\Registry Medic\RegMedical.exe
"2005-08-18 08:51:52 C:\WINDOWS\Tasks\XoftSpy.job"
- C:\Program Files\XoftSpy\XoftSpy.exe
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-28 09:18:57
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-28 9:20:27 - machine was rebooted
C:\ComboFix2.txt ... 2007-12-27 16:32
.
2007-12-18 03:17:07 --- E O F ---
HJT:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:11:50 PM, on 2/01/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: TrendProtect - {E3578B37-6346-4EC1-A82B-38273A100DCF} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O3 - Toolbar: TrendProtect - {F83BE649-1CC3-48EE-B2E2-0826CEF3822A} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -onlytray
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Segmento] C:\Program Files\ydt\Segmento_Alpha\Segmento_Alpha.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: Personal Coach.lnk = ?
O8 - Extra context menu item: &Search -
http://edits.mywebse...arch.jhtml?p=ZS
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky...can_unicode.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) -
http://www.musicnote...ad/mnviewer.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) -
http://messenger.zon...nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....k/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://by122fd.bay12...es/MsnPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) -
http://messenger.zon...1/GAME_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://v5.windowsupd...b?1109297745000
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) -
http://javadl-esd.su...ows-i586-jc.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zon...nt.cab31267.cab
O16 - DPF: {AF2E62B6-F9E1-4D4F-A10A-9DC8E6DCBCC0} (VideoEgg ActiveX Loader) -
http://update.videoe...ggPublisher.exe
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
http://messenger.zon...ro.cab53083.cab
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = qld.bigpond.net.au
O17 - HKLM\System\CS1\Services\VxD\MSTCP: SearchList = qld.bigpond.net.au
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = qld.bigpond.net.au
O17 - HKLM\System\CS2\Services\VxD\MSTCP: SearchList = qld.bigpond.net.au
O17 - HKLM\System\CCS\Services\VxD\MSTCP: SearchList = qld.bigpond.net.au
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = qld.bigpond.net.au
O18 - Protocol: trendprotect - {BC3A5F6F-12A0-4B14-A184-32939F413823} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
--
End of file - 8327 bytes