HERE IS THE VIRUSTOTAL REPORT:
File kernel_.exe received on 01.04.2008 17:57:40 (CET)
Current status: finished
Result: 11/32 (34.38%)
Compact Print results
Antivirus Version Last Update Result
AhnLab-V3 - - -
AntiVir - - TR/Dldr.Adload.PN
Authentium - - -
Avast - - -
AVG - - -
BitDefender - - -
CAT-QuickHeal - - TrojanDownloader.Adload.pn
ClamAV - - -
DrWeb - - Trojan.Stars.183
eSafe - - -
eTrust-Vet - - -
Ewido - - -
FileAdvisor - - -
Fortinet - - W32/Adload.PN!tr.dldr
F-Prot - - -
F-Secure - - Trojan-Downloader.Win32.Adload.pn
Ikarus - - Trojan-Downloader.Win32.Adload.pn
Kaspersky - - Trojan-Downloader.Win32.Adload.pn
McAfee - - -
Microsoft - - -
NOD32v2 - - -
Norman - - W32/Adload.HAM
Panda - - -
Prevx1 - - Heuristic: Suspicious File With Bad Child Associations
Rising - - -
Sophos - - -
Sunbelt - - Adware.Starsdoor
Symantec - - -
TheHacker - - -
VBA32 - - -
VirusBuster - - -
Webwasher-Gateway - - Trojan.Dldr.Adload.PN
Additional information
MD5: 14c8e7949a7055b7ce23c1e69c9ca5a3
HERE IS THE KASPERSKY REPORT:
Friday, January 04, 2008 11:38:30 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 4/01/2008
Kaspersky Anti-Virus database records: 502630
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
C:\
D:\
E:\
G:\
Scan Statistics
Total number of scanned objects 63105
Number of viruses found 21
Number of infected objects 277
Number of suspicious objects 0
Duration of the scan process 02:35:39
Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\Bryce Helsel\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Bryce Helsel\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Bryce Helsel\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Bryce Helsel\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Bryce Helsel\Local Settings\History\History.IE5\MSHist012008010420080105\index.dat Object is locked skipped
C:\Documents and Settings\Bryce Helsel\Local Settings\Temp\~DFBCCB.tmp Object is locked skipped
C:\Documents and Settings\Bryce Helsel\Local Settings\Temp\~DFBCD9.tmp Object is locked skipped
C:\Documents and Settings\Bryce Helsel\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Bryce Helsel\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Bryce Helsel\ntuser.dat Object is locked skipped
C:\Documents and Settings\Bryce Helsel\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped
C:\Program Files\kernel\kernel .exe Infected: Trojan-Downloader.Win32.Adload.pn skipped
C:\Program Files\QuickTime\qttask .exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Program Files\QuickTime\qttask.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\Program Files\Apoint2K\Apoint.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\Program Files\Java\jre1.6.0_03\bin\jusched.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\Program Files\kernel\kernel.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\Program Files\Microsoft Office\Office12\GrooveMonitor.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\Program Files\MsMovies\p.zip.vir/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h skipped
C:\QooBox\Quarantine\C\Program Files\MsMovies\p.zip.vir ZIP: infected - 1 skipped
C:\QooBox\Quarantine\C\Program Files\QuickTime\qttask .exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\Program Files\QuickTime\qttask .exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\Program Files\Skype\Phone\Skype.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\Program Files\Toshiba\TOSCDSPD\toscdspd.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\Program Files\Toshiba\Touch and Launch\PadExe.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\Program Files\X3watchpro\x3watchpro.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\temp\ytesm1220.exe.vir/data0002 Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\QooBox\Quarantine\C\temp\ytesm1220.exe.vir/data0003 Infected: Trojan-Downloader.Win32.Small.hkt skipped
C:\QooBox\Quarantine\C\temp\ytesm1220.exe.vir/data0004 Infected: Trojan.Win32.Pakes.bvs skipped
C:\QooBox\Quarantine\C\temp\ytesm1220.exe.vir/data0005/data0002 Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\QooBox\Quarantine\C\temp\ytesm1220.exe.vir/data0005 Infected: not-a-virus:AdWare.Win32.TTC.a skipped
C:\QooBox\Quarantine\C\temp\ytesm1220.exe.vir NSIS: infected - 5 skipped
C:\QooBox\Quarantine\C\TOSHIBA\IVP\ISM\pinger.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\00THotkey.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\ctfmon.exe.tmp.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\dla\tfswctrl.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\hkcmd.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\igfxtray.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\xxyaw.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\catchme2008-01-04_134808.21.zip/xxyaw.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.dih skipped
C:\QooBox\Quarantine\catchme2008-01-04_134808.21.zip ZIP: infected - 1 skipped
C:\SDFix\backups\backups.zip/backups/b122.exe Infected: Trojan-Downloader.Win32.Agent.haq skipped
C:\SDFix\backups\backups.zip/backups/core.sys Infected: Rootkit.Win32.Agent.sg skipped
C:\SDFix\backups\backups.zip/backups/Crack.exe Infected: Trojan.Win32.Agent.cmn skipped
C:\SDFix\backups\backups.zip/backups/kernInstall.exe Infected: Trojan-Downloader.Win32.Agent.haq skipped
C:\SDFix\backups\backups.zip/backups/tem16A.tmp.exe/data0002 Infected: not-a-virus:AdWare.Win32.Agent.jb skipped
C:\SDFix\backups\backups.zip/backups/tem16A.tmp.exe Infected: not-a-virus:AdWare.Win32.Agent.jb skipped
C:\SDFix\backups\backups.zip/backups/winlogon.exe Infected: not-a-virus:PSWTool.Win32.PassView.p skipped
C:\SDFix\backups\backups.zip ZIP: infected - 7 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059301.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059309.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059314.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059315.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059316.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059317.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059318.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059319.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059320.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059321.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059322.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059323.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059324.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059325.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059326.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059327.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059328.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059329.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059331.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059347.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059348.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059351.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059352.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059353.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059354.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059355.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059356.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059357.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059358.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059359.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059360.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059361.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059362.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059363.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059364.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059365.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059366.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059367.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059370.exe Infected: Trojan.Win32.Agent.cmn skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059371.exe Infected: Trojan.Win32.Agent.cmn skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059402.exe Infected: not-a-virus:AdWare.Win32.Agent.zk skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059480.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059489.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059491.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059502.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059504.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059505.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059506.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059507.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059509.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059511.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059512.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059513.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059514.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059515.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059516.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059518.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059519.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059520.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059521.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059527.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059535.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059542.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059543.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059546.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059547.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059549.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059550.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059551.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059552.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059553.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059554.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059559.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059560.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059561.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059563.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059566.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059567.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059568.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059577.exe Infected: Trojan.Win32.Agent.cmn skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059626.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059816.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059818.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059826.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059828.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059829.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059830.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059831.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059832.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059833.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059835.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059836.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059838.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059839.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059840.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059844.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059845.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059847.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059849.exe Infected: Trojan.Win32.Agent.cmn skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059855.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059874.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059882.exe Infected: Trojan-Downloader.Win32.Agent.gwh skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059883.exe Infected: Trojan.Win32.Zapchast.ca skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059884.exe Infected: Trojan.Win32.Zapchast.ca skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059885.exe Infected: Trojan.Win32.Zapchast.ca skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059886.exe Infected: Trojan.Win32.Zapchast.ca skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059887.exe Infected: Trojan.Win32.Zapchast.ca skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059888.exe Infected: Trojan.Win32.Zapchast.ca skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059889.exe Infected: Trojan.Win32.Zapchast.ca skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059891.exe Infected: Trojan.Win32.Zapchast.ca skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059892.exe Infected: Trojan.Win32.Zapchast.ca skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059893.exe Infected: Trojan.Win32.Zapchast.ca skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059895.exe Infected: Trojan.Win32.Zapchast.ca skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059896.exe Infected: Trojan.Win32.Zapchast.ca skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059897.exe Infected: not-a-virus:AdWare.Win32.NewDotNet.e skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059898.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059899.exe Infected: Trojan-Downloader.Win32.VB.caw skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059902.dll Infected: Trojan-Downloader.Win32.Small.hlf skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059903.dll Infected: Trojan-Downloader.Win32.Small.hlf skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059904.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.dih skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059905.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.din skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059907.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059944.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059947.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059956.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059957.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059958.exe Infected: Trojan-Downloader.Win32.Adload.pn skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059960.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059961.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059962.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059963.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059964.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059965.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059966.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059967.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059968.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059969.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059971.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059973.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0059997.rbf Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060050.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060086.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060088.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060101.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060104.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060105.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060106.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060107.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060108.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060109.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060111.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060112.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060113.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060115.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060117.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060120.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060121.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060122.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060123.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060124.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060129.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060470.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060474.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060475.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060485.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060493.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060497.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060503.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060510.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060516.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060521.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060528.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060533.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060537.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060541.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060542.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060544.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060545.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060546.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060547.exe Infected: Trojan-Downloader.Win32.Agent.haq skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060549.exe Infected: not-a-virus:PSWTool.Win32.PassView.p skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060550.exe Infected: Trojan-Downloader.Win32.Agent.haq skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060551.exe Infected: Trojan.Win32.Agent.cmn skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060553.sys Infected: Rootkit.Win32.Agent.sg skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060561.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060563.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060564.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060565.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060566.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060567.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060568.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060569.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060570.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060571.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060572.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060573.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060574.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060575.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060576.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060577.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060578.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060579.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060580.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060581.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060585.exe Infected: Trojan-Downloader.Win32.Agent.haq skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060587.sys Infected: Rootkit.Win32.Agent.sg skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060588.exe Infected: Trojan.Win32.Agent.cmn skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060589.exe Infected: Trojan-Downloader.Win32.Agent.haq skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060593.exe/data0002 Infected: not-a-virus:AdWare.Win32.Agent.jb skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060593.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060596.exe Infected: not-a-virus:PSWTool.Win32.PassView.p skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060631.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060638.exe Infected: Trojan-Downloader.Win32.Adload.pn skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP788\A0060641.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP788\A0060642.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060644.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060645.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060646.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060647.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060648.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060649.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060650.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060651.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060652.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060653.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060654.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060655.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060657.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060658.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060659.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060660.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060663.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060664.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060671.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.dih skipped
C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP790\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Fonts\svchost .exe Infected: Trojan.Win32.Agent.cmn skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SFA02EC7C.tmp Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\ODiag.evt Object is locked skipped
C:\WINDOWS\system32\config\OSession.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_61c.dat Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
G:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP790\change.log Object is locked skipped
Scan process completed.
HERE IS THE COMBOFIX REPORT:
ComboFix 08-01-04.1 - Bryce Helsel 2008-01-04 18:01:47.2 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Bryce Helsel\Desktop\CFScript.txt
* Created a new restore point
FILE
C:\temp\ytesm1220.exe
C:\WINDOWS\system32\cqeyjjvd.ini
C:\WINDOWS\system32\xxblljkj.ini
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\temp\cEeer12
C:\temp\cEeer12\skAt.log
C:\temp\ytesm1220.exe
C:\WINDOWS\system32\aj2
C:\WINDOWS\system32\ardCo18
C:\WINDOWS\system32\cqeyjjvd.ini
C:\WINDOWS\system32\Logs
C:\WINDOWS\system32\mr9
C:\WINDOWS\system32\pp1
C:\WINDOWS\system32\xxblljkj.ini
.
((((((((((((((((((((((((( Files Created from 2007-12-04 to 2008-01-04 )))))))))))))))))))))))))))))))
.
2008-01-04 13:31 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-04 12:27 . 2008-01-04 12:28 d——– C:\WINDOWS\ERUNT
2008-01-04 02:36 . 2008-01-04 02:36 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-01-04 02:36 . 2008-01-04 02:36 1,409 –a—— C:\WINDOWS\QTFont.for
2008-01-03 17:17 . 2008-01-03 17:17 d——– C:\Program Files\Trend Micro
2008-01-03 15:09 . 2008-01-03 15:09 d——– C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-01-03 15:08 . 2008-01-03 17:15 d——– C:\Program Files\SUPERAntiSpyware
2008-01-03 14:57 . 2008-01-03 17:13 d——– C:\Program Files\RogueRemover FREE
2008-01-03 13:38 . 2008-01-03 13:38 d——– C:\Documents and Settings\Bryce Helsel\Application Data\PrevxCSI
2008-01-03 13:38 . 2008-01-03 13:38 d——– C:\Documents and Settings\All Users\Application Data\Prevx
2008-01-03 13:32 . 2007-12-04 09:53 23,152 –a—— C:\WINDOWS\system32\drivers\aswRdr.sys
2008-01-03 13:31 . 2007-12-04 08:04 837,496 –a—— C:\WINDOWS\system32\aswBoot.exe
2008-01-03 13:31 . 2004-01-09 04:13 380,928 –a—— C:\WINDOWS\system32\actskin4.ocx
2008-01-03 13:31 . 2007-12-04 07:54 95,608 –a—— C:\WINDOWS\system32\AVASTSS.scr
2008-01-03 13:31 . 2007-12-04 09:55 94,544 –a—— C:\WINDOWS\system32\drivers\aswmon2.sys
2008-01-03 13:31 . 2007-12-04 09:56 93,264 –a—— C:\WINDOWS\system32\drivers\aswmon.sys
2008-01-03 13:31 . 2007-12-04 09:51 42,912 –a—— C:\WINDOWS\system32\drivers\aswTdi.sys
2008-01-03 13:31 . 2007-12-04 09:49 26,624 –a—— C:\WINDOWS\system32\drivers\aavmker4.sys
2008-01-03 11:45 . 2008-01-04 13:43 d——– C:\Program Files\kernel
2008-01-02 12:01 . 2008-01-03 17:35 15,360 –a—— C:\WINDOWS\system32\ctfmon .exe
2008-01-02 01:49 . 2008-01-02 01:49 d——– C:\Program Files\Lavasoft
2008-01-02 01:49 . 2008-01-02 01:49 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-02 01:45 . 2008-01-03 17:15 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-01-02 01:20 . 2008-01-04 13:21 155,648 –a—— C:\WINDOWS\system32\igfxtray .exe
2008-01-02 01:20 . 2008-01-04 13:21 118,784 –a—— C:\WINDOWS\system32\hkcmd .exe
2008-01-02 01:19 . 2008-01-04 13:21 258,048 –a—— C:\WINDOWS\system32\
00THotkey .exe
2007-12-31 20:53 . 2007-12-31 20:53 d——– C:\Documents and Settings\Bryce Helsel\Incomplete
2007-12-31 20:51 . 2007-12-31 20:51 147,456 –a—— C:\WINDOWS\system32\vbzip10.dll
2007-12-31 20:46 . 2008-01-03 11:41 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-31 19:51 . 2007-12-31 19:51 d——– C:\WINDOWS\Cache
2007-12-31 17:05 . 2004-11-15 15:37 264,440 –a—— C:\WINDOWS\system32\drivers\stac97.sys
2007-12-30 18:34 . 2007-12-31 15:39 d——– C:\Program Files\Tunebite
2007-12-30 18:32 . 2007-12-30 18:32 d——– C:\Program Files\BitZipper
2007-12-30 18:32 . 2007-12-30 18:32 d——– C:\Documents and Settings\Bryce Helsel\Application Data\BitZipper
2007-12-30 17:09 . 2007-12-30 17:09 d——– C:\Documents and Settings\Bryce Helsel\Application Data\RTPlayer
2007-12-30 16:59 . 2007-12-31 15:37 d——– C:\Documents and Settings\Bryce Helsel\Application Data\tunebite
2007-12-26 22:33 . 2007-12-26 22:33 d——– C:\Program Files\NCH Software
2007-12-26 22:33 . 2007-12-26 22:33 d——– C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
2007-12-26 22:29 . 2007-12-26 22:46 d——– C:\Program Files\NCH Swift Sound
2007-12-26 22:29 . 2007-12-26 22:39 d——– C:\Documents and Settings\Bryce Helsel\Application Data\NCH Swift Sound
2007-12-26 21:33 . 2007-12-26 21:33 d——– C:\Program Files\Western Digital Technologies
2007-12-26 21:12 . 2007-12-26 21:12 d——– C:\Program Files\Common Files\ArcSoft
2007-12-26 21:12 . 2007-12-26 21:15 d——– C:\Documents and Settings\Bryce Helsel\Application Data\ArcSoft
2007-12-26 21:12 . 2004-08-04 07:52 413,696 -ra—— C:\WINDOWS\system32\msvc6473.rra
2007-12-26 21:12 . 2005-02-23 14:58 11,776 –a—— C:\WINDOWS\system32\drivers\afc.sys
2007-12-26 21:11 . 2007-12-26 21:11 d——– C:\WINDOWS\system32\PhotoImpression Slideshow
2007-12-26 21:11 . 2007-12-26 21:11 d——– C:\Program Files\ArcSoft
2007-12-26 21:11 . 2005-04-27 16:36 245,408 –a—— C:\WINDOWS\system32\unicows.dll
2007-12-26 21:11 . 1995-08-01 04:44 212,480 –a—— C:\WINDOWS\PCDLIB32.DLL
2007-12-26 21:11 . 2006-10-20 16:11 126,976 –a—— C:\WINDOWS\system32\PhotoImpression Slideshow.scr
2007-12-17 15:53 . 2008-01-04 13:43 d——– C:\Program Files\QuickTime
2007-12-11 17:34 . 2007-12-11 17:34 1,044,480 –a—— C:\WINDOWS\system32\libdivx.dll
2007-12-11 17:34 . 2007-12-11 17:34 200,704 –a—— C:\WINDOWS\system32\ssldivx.dll
2007-12-11 16:56 . 2007-12-11 16:56 d——– C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
2007-12-11 10:57 . 2007-12-11 10:57 65,536 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx
2007-12-11 10:57 . 2007-12-11 10:57 49,152 –a—— C:\WINDOWS\system32\QuickTime.qts
2007-12-08 19:14 . 2007-12-08 19:14 d——– C:\Program Files\iPod
2007-12-08 19:13 . 2007-12-08 19:14 d——– C:\Program Files\iTunes
2007-12-08 19:03 . 2007-12-08 19:03 d——– C:\Program Files\Common Files\Apple
2007-12-08 17:44 . 2007-12-08 17:44 d——– C:\Program Files\Windows Live Toolbar
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-04 18:43 ——— d—–w C:\Program Files\X3watchpro
2008-01-04 18:43 ——— d—–w C:\Program Files\Apoint2K
2008-01-04 18:27 ——— d—–w C:\Documents and Settings\Bryce Helsel\Application Data\Skype
2008-01-04 17:19 ——— d—–w C:\Program Files\Java
2008-01-04 08:16 ——— d–h–w C:\Documents and Settings\Bryce Helsel\Application Data\x3watchpro
2008-01-03 16:47 ——— d—–w C:\Documents and Settings\Bryce Helsel\Application Data\LimeWire
2008-01-01 21:00 ——— d—–w C:\Documents and Settings\Bryce Helsel\Application Data\Ruckus Network
2007-12-31 22:09 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-31 22:09 ——— d—–w C:\Program Files\SigmaTel
2007-12-31 21:49 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-12-31 06:58 ——— d—–w C:\Documents and Settings\Bryce Helsel\Application Data\uTorrent
2007-12-19 23:25 ——— d—–w C:\Program Files\DivX
2007-11-29 21:24 ——— d—–w C:\Documents and Settings\All Users\Application Data\Nero
2007-11-29 13:40 ——— d—–w C:\Program Files\MSXML 4.0
2007-11-28 01:29 ——— d—–w C:\Documents and Settings\Bryce Helsel\Application Data\Nero
2007-11-15 20:24 ——— d—–w C:\Program Files\MagicDisc
2007-11-15 05:46 ——— d—–w C:\Documents and Settings\Bryce Helsel\Application Data\MSN6
2007-11-15 05:03 ——— d—–w C:\Program Files\Creative
2007-11-15 04:42 ——— d—–w C:\Documents and Settings\All Users\Application Data\WinZip
2007-11-14 07:07 ——— d—–w C:\Program Files\Microsoft Works
2007-11-14 07:06 ——— d—–w C:\Program Files\MSBuild
2007-11-14 07:03 ——— d—–w C:\Program Files\Microsoft.NET
2007-11-14 06:53 ——— d—–w C:\Program Files\Microsoft Visual Studio 8
2007-11-14 06:07 ——— d—–w C:\Program Files\MagicISO
2007-11-14 06:04 223,128 —-a-w C:\WINDOWS\system32\drivers\vaxscsi.sys
2007-11-14 06:00 ——— d—–w C:\Program Files\Google
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2004-06-09 06:01 1,822,848 —-a-w C:\Documents and Settings\DLA Writing.temp\INSNTMSI.EXE
2004-06-09 06:01 1,709,160 —-a-w C:\Documents and Settings\DLA Writing.temp\INS9XMSI.EXE
2004-01-23 07:00 462,848 —-a-w C:\Documents and Settings\DLA Writing.temp\Setup.exe
2006-01-02 17:49 321 –sha-w C:\WINDOWS\system32\ospcont.dat
.
—-a-w 79,224 2008-01-04 18:22:44 C:\Program Files\Alwil Software\Avast4\ashDisp .exe
—-a-w 192,512 2008-01-04 18:21:37 C:\Program Files\Apoint2K\Apoint .exe
—-a-w 68,856 2008-01-04 18:23:10 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
—-a-w 132,496 2008-01-04 18:22:50 C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe
—-a-w 61,440 2008-01-04 18:23:13 C:\Program Files\kernel\kernel .exe
—-a-w 33,648 2008-01-04 18:22:39 C:\Program Files\Microsoft Office\Office12\GrooveMonitor .exe
—-a-w 286,720 2008-01-03 16:40:26 C:\Program Files\QuickTime\qttask .exe
—-a-w 662,016 2008-01-04 18:07:20 C:\Program Files\QuickTime\qttask .exe
—-a-w 86,073 2008-01-04 18:21:54 C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon .exe
—-a-w 22,880,040 2008-01-04 18:24:57 C:\Program Files\Skype\Phone\Skype .exe
—-a-w 1,318,912 2008-01-03 22:15:05 C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE .EXE
—-a-w 65,536 2008-01-04 18:22:48 C:\Program Files\Toshiba\TOSCDSPD\toscdspd .exe
—-a-w 1,089,589 2008-01-04 18:22:09 C:\Program Files\Toshiba\Touch and Launch\PadExe .exe
—-a-w 409,600 2008-01-04 18:22:18 C:\Program Files\X3watchpro\x3watchpro .exe
—-a-w 151,552 2008-01-04 18:22:10 C:\TOSHIBA\IVP\ISM\pinger .exe
—-a-w 839,703 2008-01-03 16:40:36 C:\WINDOWS\Fonts\svchost .exe
—-a-w 258,048 2008-01-04 18:21:38 C:\WINDOWS\system32\00THotkey .exe
—-a-w 15,360 2008-01-03 22:35:29 C:\WINDOWS\system32\ctfmon .exe
—-a-w 118,784 2008-01-04 18:21:46 C:\WINDOWS\system32\hkcmd .exe
—-a-w 155,648 2008-01-04 18:21:38 C:\WINDOWS\system32\igfxtray .exe
—-a-w 122,939 2008-01-04 18:21:34 C:\WINDOWS\system32\dla\tfswctrl .exe
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [ ]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56 15360]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2008-01-04 13:23 313472]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [ ]
"kernel"="C:\Program Files\kernel\kernel.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"00THotkey"="C:\WINDOWS\system32\
00THotkey.exe" [ ]
"000StTHK"="000StTHK.exe" [2001-06-23 20:28 24576 C:\WINDOWS\system32\
000StTHK.exe]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [ ]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [ ]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [ ]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [ ]
"SigmaTel StacMon"="C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe" [ ]
"AGRSMMSG"="AGRSMMSG.exe" [2004-02-20 15:00 88363 C:\WINDOWS\agrsmmsg.exe]
"PadTouch"="C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe" [ ]
"PINGER"="C:\TOSHIBA\IVP\ISM\pinger.exe" [ ]
"TPSMain"="TPSMain.exe" [2004-06-01 20:43 278528 C:\WINDOWS\system32\TPSMain.exe]
"x3watchpro"="C:\Program Files\X3watchpro\x3watchpro.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [ ]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 08:00 79224]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [ ]
C:\Documents and Settings\Bryce Helsel\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50]
Webshots.lnk - C:\Program Files\Webshots\Launcher.exe [2006-07-19 22:13:20]
S3 Camdrv30;Philips ToUcam XS;C:\WINDOWS\system32\Drivers\camdrv30.sys [2001-01-25 02:40]
S3 tbhsd;Tunebite High-Speed Dubbing;C:\WINDOWS\system32\drivers\tbhsd.sys []
.
Contents of the 'Scheduled Tasks' folder
"2007-12-29 23:35:13 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-04 22:49:03 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-01-04 17:07:41 C:\WINDOWS\Tasks\User_Feed_Synchronization-{EC38B375-0340-4869-8D44-280E8199B66E}.job"
- C:\WINDOWS\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-04 18:05:54
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-04 18:07:13
ComboFix-quarantined-files.txt 2008-01-04 23:07:05
ComboFix2.txt 2008-01-04 18:51:09
.
2007-12-12 04:26:47 — E O F —
HERE IS THE HIJACKTHIS REPORT:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:39:29 PM, on 1/4/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\System32\svchost.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\TPSMain.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Trend Micro\HijackThis\iseeu.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://g.msn.com/1me10enus/2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://g.msn.com/1me10enus/2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://g.msn.com/1me10enus/2
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: (no name) - {736b5468-bdad-41be-92d0-22ae2ddf7bcb} - (no file)
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\system32\00THotkey.exe
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SigmaTel StacMon] C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [PINGER] C:\TOSHIBA\IVP\ISM\pinger.exe /run
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [x3watchpro] C:\Program Files\X3watchpro\x3watchpro.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [kernel] C:\Program Files\kernel\kernel.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O8 - Extra context menu item: &Windows; Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {2B1AA38D-2D12-11D5-AAD0-00C04FA03D78} (LocalExec Control) -
https://my.uga.edu/nps/portal/gadgets/com.n…t/LocalExec.CAB
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo…toUploader3.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/…b?1132753115798
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdat…b?1132847722513
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
–
End of file - 9278 bytes