This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Problem similar to Intelligent Advisor, instead I get

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have already downloaded Hijack This and I have gone into the Add/Remove Programs and removed "PlayMP3z" and "Browsing Advisor" from the list of programs. I immediately rebooted and I also encountered the same popups. Other than the popups, there are no other immediate, noticeable problems on my part. I am going to copy and paste the log file, and I seek help to remove the malware. Thank you.




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:58:30 PM, on 1/3/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\System32\svchost.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\00THotkey.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\system32\00THotkey .exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Apoint2K\Apoint .exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
C:\WINDOWS\system32\dla\tfswctrl .exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\WINDOWS\system32\igfxtray .exe
C:\WINDOWS\system32\hkcmd .exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon .exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe .exe
C:\Program Files\X3watchpro\x3watchpro.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\X3watchpro\x3watchpro .exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor .exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd .exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\kernel\kernel.exe
C:\WINDOWS\system32\ctfmon .exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
C:\Program Files\kernel\kernel .exe
C:\PROGRA~1\Webshots\webshots.scr
C:\Program Files\Skype\Phone\Skype .exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/1me10enus/2
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/1me10enus/2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/1me10enus/2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/1me10enus/2
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast High-Speed Internet
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
F3 - REG:win.ini: load=C:\WINDOWS\system32\xxyaw.exe
O3 - Toolbar: (no name) - {736b5468-bdad-41be-92d0-22ae2ddf7bcb} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\system32\00THotkey.exe
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SigmaTel StacMon] C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [PINGER] C:\TOSHIBA\IVP\ISM\pinger.exe /run
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [x3watchpro] C:\Program Files\X3watchpro\x3watchpro.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [70f3b715] rundll32.exe "C:\WINDOWS\system32\dvjjyeqc.dll",b
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\RunServices: [Microsoft Windows System] qucaaaaa.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [kernel] C:\Program Files\kernel\kernel.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab
O16 - DPF: {2B1AA38D-2D12-11D5-AAD0-00C04FA03D78} (LocalExec Control) - https://my.uga.edu/nps/portal/gadgets/com.n…t/LocalExec.CAB
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo…toUploader3.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1132753115798
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1132847722513
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe

–
End of file - 10192 bytes
Hi! Welcome to the WTT forums.
My name is Scotty. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research.
Please be patient.

Rename HijackThis
There is a possibility an infection which is hiding part of the HijackThis log because it's called hijackthis.exe.
Using Windows Explore by right-clicking the Start button and left clicking Explore navigate to: C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

Right-click on HijackThis.exe & select Rename to iseeu.exe and post back a new Hijackthis log.



Please make a uninstall list using HijackThis
To access the Uninstall Manager you would do the following:

1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.
5. Click on the Save list… button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here in a reply.
Thanks Scotty for your continuing support.

Here is the new log, followed by the uninstall list:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:12:33 PM, on 1/3/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\System32\svchost.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\00THotkey.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\system32\00THotkey .exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Apoint2K\Apoint .exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
C:\WINDOWS\system32\dla\tfswctrl .exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\WINDOWS\system32\igfxtray .exe
C:\WINDOWS\system32\hkcmd .exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon .exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe .exe
C:\Program Files\X3watchpro\x3watchpro.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\X3watchpro\x3watchpro .exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor .exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd .exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\kernel\kernel.exe
C:\WINDOWS\system32\ctfmon .exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
C:\Program Files\kernel\kernel .exe
C:\PROGRA~1\Webshots\webshots.scr
C:\Program Files\Skype\Phone\Skype .exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\iseeu.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/1me10enus/2
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/1me10enus/2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/1me10enus/2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/1me10enus/2
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast High-Speed Internet
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
F3 - REG:win.ini: load=C:\WINDOWS\system32\xxyaw.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {6E23AB67-9ADE-4820-810F-0192507D9A60} - C:\WINDOWS\system32\xxyaw.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: (no name) - {BF5BE4E2-CC2E-4437-9BD7-757C85F1C947} - (no file)
O3 - Toolbar: (no name) - {736b5468-bdad-41be-92d0-22ae2ddf7bcb} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\system32\00THotkey.exe
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SigmaTel StacMon] C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [PINGER] C:\TOSHIBA\IVP\ISM\pinger.exe /run
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [x3watchpro] C:\Program Files\X3watchpro\x3watchpro.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [70f3b715] rundll32.exe "C:\WINDOWS\system32\dvjjyeqc.dll",b
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\RunServices: [Microsoft Windows System] qucaaaaa.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [kernel] C:\Program Files\kernel\kernel.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab
O16 - DPF: {2B1AA38D-2D12-11D5-AAD0-00C04FA03D78} (LocalExec Control) - https://my.uga.edu/nps/portal/gadgets/com.n…t/LocalExec.CAB
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo…toUploader3.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1132753115798
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1132847722513
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: nd_gfx9 - nd_gfx9.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe

–
End of file - 11370 bytes



NOW HERE IS THE UNINSTALL LIST

2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
Ad-Aware 2007
Adobe Flash Player ActiveX
Adobe Reader 7.0.8
Adobe SVG Viewer 3.0
AIM 6
ALPS Touch Pad Driver
Apple Mobile Device Support
Apple Software Update
ArcSoft PhotoImpression 6
Atheros Wireless LAN MiniPCI card Driver
avast! Antivirus
Bible Explorer 4 Download Edition
BitZipper 5.0.2
Bonjour Core for Windows
Canon MP160
CCleaner (remove only)
CD/DVD Drive Acoustic Silencer
CloneCD
Creative Removable Disk Manager
Creative System Information
Creative ZEN Vision M Series
DivX Web Player
Google Toolbar for Internet Explorer
HijackThis 2.0.2
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
Intel® Extreme Graphics 2 Driver
Intel® PRO Network Adapters and Drivers
InterActual Player
InterVideo WinDVD for Toshiba
iTunes
J2SE Runtime Environment 5.0 Update 11
Java™ 6 Update 2
Java™ 6 Update 3
Java™ SE Runtime Environment 6 Update 1
Macromedia Shockwave Player
Magic ISO Maker v5.4 (build 0251)
MagicDisc 2.5.79
Microsoft .NET Framework 2.0
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft User-Mode Driver Framework Feature Pack 1.0
MSN Music Assistant
MSXML 4.0 SP2 (KB936181)
Notebook Maximizer
QuickTime
Ruckus Player
Security Update for CAPICOM (KB931906)
Security Update for CAPICOM (KB931906)
Security Update for Microsoft .NET Framework 2.0 (KB928365)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893066)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901190)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937894)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB944653)
SigmaTel AC97 Audio Drivers
Skype™ 3.5
Sonic DLA
Sonic RecordNow!
Starcraft
Switch
TOSHIBA ConfigFree
TOSHIBA PC Diagnostic Tool
TOSHIBA Power Saver
Toshiba Registration
TOSHIBA Software Modem
TOSHIBA Software Upgrades
TOSHIBA Speech System Applications
TOSHIBA Speech System SR Engine(U.S.) Version1.0
TOSHIBA Speech System TTS Engine(U.S.) Version1.0
Toshiba Tbiosdrv Driver
TOSHIBA Utilities
Touch and Launch
Update for Outlook 2007 Junk Email Filter (kb943597)
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
VCRedistSetup
VideoLink Mail
Viewpoint Media Player
WD Diagnostics
Webshots Desktop
Windows Defender Signatures
Windows Genuine Advantage v1.3.0254.0
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Live Toolbar
Windows Live Toolbar
Windows Media Connect
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 10 Hotfix - KB895316
Windows Media Player 11
Windows Media Player 11
Windows XP Hotfix - KB867282
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB884018
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB885855
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Service Pack 2
X3watchpro 1.6.9
Hi

First off, go to Add/Remove Programs and remove all instances of Java except Java™ 6 Update 3.


Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back in your next reply.


If you already have Combofix, please delete that copy and download it again as it's being updated regularly.

Please download Combofix from Bleeping Computer.

If you can't download it from there, please try these 2 alternative sites:

Forospyware
Geeks to Go

  • Save it to your Desktop.
  • Disconnect from the Internet, than disable your anti-virus and any real-time anti-spyware monitors that are running.
  • Click Start>Run copy/paste or type "%userprofile%\desktop\combofix.exe" /killall into the Run box and click OK.
  • When finished, it shall produce a log for you. Post that log in your next reply with a new HijackThis log.
Note 1: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Note 2:Remember to re-enable your anti-virus and anti-spyware before reconnecting to the Internet.

Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task-Manager use the Processes tab (press ctrl alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.

In your next reply post:
Report.txt
ComboFix.txt
New HijackThis log taken after the above scan has run
Thanks again for your continuing support.

Here is the report.txt:


SDFix: Version 1.123

Run by [removed] on Fri 01/04/2008 at 12:29 PM

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:

Name:
core

Path:
system32\drivers\core.sys

core - Deleted



Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting…


Normal Mode:
Checking Files:

Trojan Files Found:

C:\Documents and Settings\Bryce Helsel\Local Settings\Temp\tem16A.tmp.exe - Deleted
C:\Documents and Settings\Bryce Helsel\Local Settings\Temp\tem16E.tmp.exe - Deleted
C:\Documents and Settings\Bryce Helsel\Local Settings\Temp\upd1C1.tmp.exe - Deleted
C:\Temp\1cb\syscheck.log - Deleted
C:\Program Files\Temporary\kernInstall.exe - Deleted
C:\DOCUME~1\BRYCEH~1\LOCALS~1\Temp\removalfile.bat - Deleted
C:\n.bat - Deleted
C:\winlogon.exe - Deleted
C:\x.dat - Deleted
C:\z.dat - Deleted
C:\WINDOWS\b122.exe - Deleted
C:\WINDOWS\Fonts\Crack.exe - Deleted
C:\WINDOWS\system32\drivers\core.cache.dsk - Deleted
C:\WINDOWS\system32\drivers\core.sys - Deleted
C:\WINDOWS\system32\pac.txt - Deleted
C:\WINDOWS\system32\plugin1.dat - Deleted
C:\WINDOWS\system32\SysPr.prx - Deleted
C:\WINDOWS\Fonts\*.zip - 1 File(s) 637,943 bytes - Deleted
C:\WINDOWS\Fonts\'\*.zip - 1 File(s) 637,944 bytes - Deleted

x.dat and z.dat data copied to \SDFix\Data.txt


Folder C:\Program Files\Temporary - Removed
Folder C:\Temp\1cb - Removed
Folder C:\Temp\tn3 - Removed
Folder C:\WINDOWS\Fonts\' - Removed
Folder C:\WINDOWS\system32\Z1 - Removed

Removing Temp Files…

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

catchme 0.3.1333.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-04 13:10:45
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden services & system hive …

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:dd9dc2aa
"s2"=dword:171f4b8d
"h0"=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:b9,83,e1,be,08,a3,26,8b,1e,ee,48,d4,b7,0a,68,7f,78,e6,b9,d2,dc,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:b9,83,e1,be,08,a3,26,8b,1e,ee,48,d4,b7,0a,68,7f,78,e6,b9,d2,dc,..

scanning hidden registry entries …

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update]
"OfflineDetectionPending"=dword:00000001

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services:
——————



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:æTorrent"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\NetMeeting\\conf.exe"="C:\\Program Files\\NetMeeting\\conf.exe:*:Enabled:Windowsr NetMeetingr"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Program Files\\Ruckus Player\\Ruckus.exe"="C:\\Program Files\\Ruckus Player\\Ruckus.exe:*:Enabled:Ruckus"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\WINDOWS\\system32\\dpvsetup.exe"="C:\\WINDOWS\\system32\\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype. Take a deep breath "
"C:\\Program Files\\Skype\\Phone\\Skype .exe"="C:\\Program Files\\Skype\\Phone\\Skype .exe:*:Enabled:Skype. Take a deep breath "

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

Remaining Files:
—————

File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes:

Sat 11 Aug 2007 48 ..SH. — "C:\WINDOWS\SFA02EC7C.tmp"
Wed 10 Oct 2007 625,152 A.SH. — "C:\Program Files\Internet Explorer\iexplore.exe"
Wed 13 Oct 2004 1,694,208 ..SH. — "C:\Program Files\Messenger\msmsgs.exe"
Wed 4 Aug 2004 60,416 A.SH. — "C:\Program Files\Outlook Express\msimn.exe"
Sun 27 Nov 2005 4,348 A.SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Mon 6 Feb 2006 703 A..H. — "C:\Program Files\InterActual\InterActual Player\iti8.tmp"
Sat 2 Dec 2006 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"
Sat 22 Sep 2007 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\cf7ced0e70c80a1e476f1abf49afecb1\BIT15.tmp"

Finished!



HERE IS THE COMBOFIX LOG:


ComboFix 08-01-04.1 - Bryce Helsel 2008-01-04 13:35:24.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.61 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\desktop\combofix.exe
Command switches used :: /killall
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\kernel\kernel.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\msmovies
C:\Program Files\msmovies\p.zip
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\Program Files\X3watchpro\x3watchpro.exe
C:\TOSHIBA\IVP\ISM\pinger.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\00THotkey.exe
C:\WINDOWS\system32\ctfmon.exe.tmp
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\wayxx.ini
C:\WINDOWS\system32\wayxx.ini2
C:\WINDOWS\system32\xxyaw.dll
C:\WINDOWS\system32\xxyaw.exe
G:\Autorun.inf

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_CORE


((((((((((((((((((((((((( Files Created from 2007-12-04 to 2008-01-04 )))))))))))))))))))))))))))))))
.

2008-01-04 13:31 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-04 12:27 . 2008-01-04 12:28 d——– C:\WINDOWS\ERUNT
2008-01-04 02:36 . 2008-01-04 02:36 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-01-04 02:36 . 2008-01-04 02:36 1,409 –a—— C:\WINDOWS\QTFont.for
2008-01-03 17:17 . 2008-01-03 17:17 d——– C:\Program Files\Trend Micro
2008-01-03 15:09 . 2008-01-03 15:09 d——– C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-01-03 15:08 . 2008-01-03 17:15 d——– C:\Program Files\SUPERAntiSpyware
2008-01-03 14:57 . 2008-01-03 17:13 d——– C:\Program Files\RogueRemover FREE
2008-01-03 13:38 . 2008-01-03 13:38 d——– C:\Documents and Settings\Bryce Helsel\Application Data\PrevxCSI
2008-01-03 13:38 . 2008-01-03 13:38 d——– C:\Documents and Settings\All Users\Application Data\Prevx
2008-01-03 13:32 . 2007-12-04 09:53 23,152 –a—— C:\WINDOWS\system32\drivers\aswRdr.sys
2008-01-03 13:31 . 2007-12-04 08:04 837,496 –a—— C:\WINDOWS\system32\aswBoot.exe
2008-01-03 13:31 . 2004-01-09 04:13 380,928 –a—— C:\WINDOWS\system32\actskin4.ocx
2008-01-03 13:31 . 2007-12-04 07:54 95,608 –a—— C:\WINDOWS\system32\AVASTSS.scr
2008-01-03 13:31 . 2007-12-04 09:55 94,544 –a—— C:\WINDOWS\system32\drivers\aswmon2.sys
2008-01-03 13:31 . 2007-12-04 09:56 93,264 –a—— C:\WINDOWS\system32\drivers\aswmon.sys
2008-01-03 13:31 . 2007-12-04 09:51 42,912 –a—— C:\WINDOWS\system32\drivers\aswTdi.sys
2008-01-03 13:31 . 2007-12-04 09:49 26,624 –a—— C:\WINDOWS\system32\drivers\aavmker4.sys
2008-01-03 11:45 . 2008-01-04 13:43 d——– C:\Program Files\kernel
2008-01-03 11:29 . 2008-01-03 15:06 1,031,752 –ahs—- C:\WINDOWS\system32\cqeyjjvd.ini
2008-01-02 12:01 . 2008-01-03 17:35 15,360 –a—— C:\WINDOWS\system32\ctfmon .exe
2008-01-02 01:49 . 2008-01-02 01:49 d——– C:\Program Files\Lavasoft
2008-01-02 01:49 . 2008-01-02 01:49 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-02 01:45 . 2008-01-03 17:15 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-01-02 01:20 . 2008-01-04 13:21 155,648 –a—— C:\WINDOWS\system32\igfxtray .exe
2008-01-02 01:20 . 2008-01-04 13:21 118,784 –a—— C:\WINDOWS\system32\hkcmd .exe
2008-01-02 01:19 . 2008-01-04 13:21 258,048 –a—— C:\WINDOWS\system32\00THotkey .exe
2008-01-01 15:31 . 2008-01-02 21:41 1,031,578 –ahs—- C:\WINDOWS\system32\xxblljkj.ini
2007-12-31 20:53 . 2007-12-31 20:53 d——– C:\Documents and Settings\Bryce Helsel\Incomplete
2007-12-31 20:51 . 2007-12-31 20:51 147,456 –a—— C:\WINDOWS\system32\vbzip10.dll
2007-12-31 20:48 . 2007-12-31 20:48 d——– C:\WINDOWS\system32\pp1
2007-12-31 20:48 . 2008-01-03 14:13 d——– C:\WINDOWS\system32\mr9
2007-12-31 20:48 . 2008-01-03 16:35 d——– C:\WINDOWS\system32\ardCo18
2007-12-31 20:48 . 2008-01-03 14:13 d——– C:\WINDOWS\system32\aj2
2007-12-31 20:48 . 2007-12-31 20:48 d——– C:\temp\cEeer12
2007-12-31 20:48 . 2007-12-31 20:48 333,942 –a—— C:\temp\ytesm1220.exe
2007-12-31 20:46 . 2008-01-03 11:41 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-31 19:51 . 2007-12-31 19:51 d——– C:\WINDOWS\Cache
2007-12-31 17:05 . 2004-11-15 15:37 264,440 –a—— C:\WINDOWS\system32\drivers\stac97.sys
2007-12-30 18:34 . 2007-12-31 15:39 d——– C:\Program Files\Tunebite
2007-12-30 18:32 . 2007-12-30 18:32 d——– C:\Program Files\BitZipper
2007-12-30 18:32 . 2007-12-30 18:32 d——– C:\Documents and Settings\Bryce Helsel\Application Data\BitZipper
2007-12-30 17:09 . 2007-12-30 17:09 d——– C:\Documents and Settings\Bryce Helsel\Application Data\RTPlayer
2007-12-30 16:59 . 2007-12-31 15:37 d——– C:\Documents and Settings\Bryce Helsel\Application Data\tunebite
2007-12-30 16:58 . 2007-12-30 16:58 d——– C:\WINDOWS\system32\Logs
2007-12-26 22:33 . 2007-12-26 22:33 d——– C:\Program Files\NCH Software
2007-12-26 22:33 . 2007-12-26 22:33 d——– C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
2007-12-26 22:29 . 2007-12-26 22:46 d——– C:\Program Files\NCH Swift Sound
2007-12-26 22:29 . 2007-12-26 22:39 d——– C:\Documents and Settings\Bryce Helsel\Application Data\NCH Swift Sound
2007-12-26 21:33 . 2007-12-26 21:33 d——– C:\Program Files\Western Digital Technologies
2007-12-26 21:12 . 2007-12-26 21:12 d——– C:\Program Files\Common Files\ArcSoft
2007-12-26 21:12 . 2007-12-26 21:15 d——– C:\Documents and Settings\Bryce Helsel\Application Data\ArcSoft
2007-12-26 21:12 . 2004-08-04 07:52 413,696 -ra—— C:\WINDOWS\system32\msvc6473.rra
2007-12-26 21:12 . 2005-02-23 14:58 11,776 –a—— C:\WINDOWS\system32\drivers\afc.sys
2007-12-26 21:11 . 2007-12-26 21:11 d——– C:\WINDOWS\system32\PhotoImpression Slideshow
2007-12-26 21:11 . 2007-12-26 21:11 d——– C:\Program Files\ArcSoft
2007-12-26 21:11 . 2005-04-27 16:36 245,408 –a—— C:\WINDOWS\system32\unicows.dll
2007-12-26 21:11 . 1995-08-01 04:44 212,480 –a—— C:\WINDOWS\PCDLIB32.DLL
2007-12-26 21:11 . 2006-10-20 16:11 126,976 –a—— C:\WINDOWS\system32\PhotoImpression Slideshow.scr
2007-12-17 15:53 . 2008-01-04 13:43 d——– C:\Program Files\QuickTime
2007-12-11 17:34 . 2007-12-11 17:34 1,044,480 –a—— C:\WINDOWS\system32\libdivx.dll
2007-12-11 17:34 . 2007-12-11 17:34 200,704 –a—— C:\WINDOWS\system32\ssldivx.dll
2007-12-11 16:56 . 2007-12-11 16:56 d——– C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
2007-12-11 10:57 . 2007-12-11 10:57 65,536 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx
2007-12-11 10:57 . 2007-12-11 10:57 49,152 –a—— C:\WINDOWS\system32\QuickTime.qts
2007-12-08 19:14 . 2007-12-08 19:14 d——– C:\Program Files\iPod
2007-12-08 19:13 . 2007-12-08 19:14 d——– C:\Program Files\iTunes
2007-12-08 19:03 . 2007-12-08 19:03 d——– C:\Program Files\Common Files\Apple
2007-12-08 17:44 . 2007-12-08 17:44 d——– C:\Program Files\Windows Live Toolbar

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-04 18:43 ——— d—–w C:\Program Files\X3watchpro
2008-01-04 18:43 ——— d—–w C:\Program Files\Apoint2K
2008-01-04 18:27 ——— d—–w C:\Documents and Settings\Bryce Helsel\Application Data\Skype
2008-01-04 17:19 ——— d—–w C:\Program Files\Java
2008-01-04 08:16 ——— d–h–w C:\Documents and Settings\Bryce Helsel\Application Data\x3watchpro
2008-01-03 16:47 ——— d—–w C:\Documents and Settings\Bryce Helsel\Application Data\LimeWire
2008-01-01 21:00 ——— d—–w C:\Documents and Settings\Bryce Helsel\Application Data\Ruckus Network
2007-12-31 22:09 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-31 22:09 ——— d—–w C:\Program Files\SigmaTel
2007-12-31 21:49 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-12-31 06:58 ——— d—–w C:\Documents and Settings\Bryce Helsel\Application Data\uTorrent
2007-12-19 23:25 ——— d—–w C:\Program Files\DivX
2007-11-29 21:24 ——— d—–w C:\Documents and Settings\All Users\Application Data\Nero
2007-11-29 13:40 ——— d—–w C:\Program Files\MSXML 4.0
2007-11-28 01:29 ——— d—–w C:\Documents and Settings\Bryce Helsel\Application Data\Nero
2007-11-15 20:24 ——— d—–w C:\Program Files\MagicDisc
2007-11-15 05:46 ——— d—–w C:\Documents and Settings\Bryce Helsel\Application Data\MSN6
2007-11-15 05:03 ——— d—–w C:\Program Files\Creative
2007-11-15 04:42 ——— d—–w C:\Documents and Settings\All Users\Application Data\WinZip
2007-11-14 07:07 ——— d—–w C:\Program Files\Microsoft Works
2007-11-14 07:06 ——— d—–w C:\Program Files\MSBuild
2007-11-14 07:03 ——— d—–w C:\Program Files\Microsoft.NET
2007-11-14 06:53 ——— d—–w C:\Program Files\Microsoft Visual Studio 8
2007-11-14 06:07 ——— d—–w C:\Program Files\MagicISO
2007-11-14 06:04 223,128 —-a-w C:\WINDOWS\system32\drivers\vaxscsi.sys
2007-11-14 06:00 ——— d—–w C:\Program Files\Google
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2004-06-09 06:01 1,822,848 —-a-w C:\Documents and Settings\DLA Writing.temp\INSNTMSI.EXE
2004-06-09 06:01 1,709,160 —-a-w C:\Documents and Settings\DLA Writing.temp\INS9XMSI.EXE
2004-01-23 07:00 462,848 —-a-w C:\Documents and Settings\DLA Writing.temp\Setup.exe
2006-01-02 17:49 321 –sha-w C:\WINDOWS\system32\ospcont.dat
.
—-a-w		   313,472 2008-01-04 18:23:04  C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager .exe
—-a-w			79,224 2008-01-04 18:22:44  C:\Program Files\Alwil Software\Avast4\ashDisp .exe
—-a-w		   192,512 2008-01-04 18:21:37  C:\Program Files\Apoint2K\Apoint .exe
—-a-w			68,856 2008-01-04 18:23:10  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
—-a-w		   132,496 2008-01-04 18:22:50  C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe
—-a-w			61,440 2008-01-04 18:23:13  C:\Program Files\kernel\kernel .exe
—-a-w			33,648 2008-01-04 18:22:39  C:\Program Files\Microsoft Office\Office12\GrooveMonitor .exe
—-a-w		   286,720 2008-01-03 16:40:26  C:\Program Files\QuickTime\qttask	.exe
—-a-w		   662,016 2008-01-04 18:07:20  C:\Program Files\QuickTime\qttask .exe
—-a-w			86,073 2008-01-04 18:21:54  C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon .exe
—-a-w		22,880,040 2008-01-04 18:24:57  C:\Program Files\Skype\Phone\Skype .exe
—-a-w		 1,318,912 2008-01-03 22:15:05  C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE .EXE
—-a-w			65,536 2008-01-04 18:22:48  C:\Program Files\Toshiba\TOSCDSPD\toscdspd .exe
—-a-w		 1,089,589 2008-01-04 18:22:09  C:\Program Files\Toshiba\Touch and Launch\PadExe .exe
—-a-w		   409,600 2008-01-04 18:22:18  C:\Program Files\X3watchpro\x3watchpro .exe
—-a-w		   151,552 2008-01-04 18:22:10  C:\TOSHIBA\IVP\ISM\pinger .exe
—-a-w		   839,703 2008-01-03 16:40:36  C:\WINDOWS\Fonts\svchost .exe
—-a-w		   258,048 2008-01-04 18:21:38  C:\WINDOWS\system32\00THotkey .exe
—-a-w			15,360 2008-01-03 22:35:29  C:\WINDOWS\system32\ctfmon .exe
—-a-w		   118,784 2008-01-04 18:21:46  C:\WINDOWS\system32\hkcmd .exe
—-a-w		   155,648 2008-01-04 18:21:38  C:\WINDOWS\system32\igfxtray .exe
—-a-w		   122,939 2008-01-04 18:21:34  C:\WINDOWS\system32\dla\tfswctrl .exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [ ]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56 15360]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [ ]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [ ]
"kernel"="C:\Program Files\kernel\kernel.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"00THotkey"="C:\WINDOWS\system32\00THotkey.exe" [ ]
"000StTHK"="000StTHK.exe" [2001-06-23 20:28 24576 C:\WINDOWS\system32\000StTHK.exe]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [ ]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [ ]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [ ]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [ ]
"SigmaTel StacMon"="C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe" [ ]
"AGRSMMSG"="AGRSMMSG.exe" [2004-02-20 15:00 88363 C:\WINDOWS\agrsmmsg.exe]
"PadTouch"="C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe" [ ]
"PINGER"="C:\TOSHIBA\IVP\ISM\pinger.exe" [ ]
"TPSMain"="TPSMain.exe" [2004-06-01 20:43 278528 C:\WINDOWS\system32\TPSMain.exe]
"x3watchpro"="C:\Program Files\X3watchpro\x3watchpro.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [ ]
"70f3b715"="C:\WINDOWS\system32\dvjjyeqc.dll" [ ]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 08:00 79224]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [ ]

C:\Documents and Settings\Bryce Helsel\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50]
Webshots.lnk - C:\Program Files\Webshots\Launcher.exe [2006-07-19 22:13:20]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\nd_gfx9]
nd_gfx9.dll

S3 Camdrv30;Philips ToUcam XS;C:\WINDOWS\system32\Drivers\camdrv30.sys [2001-01-25 02:40]
S3 tbhsd;Tunebite High-Speed Dubbing;C:\WINDOWS\system32\drivers\tbhsd.sys []

.
Contents of the 'Scheduled Tasks' folder
"2007-12-29 23:35:13 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-04 18:49:04 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-01-04 17:07:41 C:\WINDOWS\Tasks\User_Feed_Synchronization-{EC38B375-0340-4869-8D44-280E8199B66E}.job"
- C:\WINDOWS\system32\msfeedssync.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-04 13:48:27
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-04 13:51:08 - machine was rebooted [Bryce Helsel]
ComboFix-quarantined-files.txt 2008-01-04 18:51:04
.
2007-12-12 04:26:47 — E O F —


HERE IS THE NEWEST HIJACK THIS LOG:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:57:57 PM, on 1/4/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\System32\svchost.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\TPSMain.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\iseeu.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/1me10enus/2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/1me10enus/2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/1me10enus/2
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: (no name) - {736b5468-bdad-41be-92d0-22ae2ddf7bcb} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\system32\00THotkey.exe
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SigmaTel StacMon] C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [PINGER] C:\TOSHIBA\IVP\ISM\pinger.exe /run
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [x3watchpro] C:\Program Files\X3watchpro\x3watchpro.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [70f3b715] rundll32.exe "C:\WINDOWS\system32\dvjjyeqc.dll",b
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [kernel] C:\Program Files\kernel\kernel.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab
O16 - DPF: {2B1AA38D-2D12-11D5-AAD0-00C04FA03D78} (LocalExec Control) - https://my.uga.edu/nps/portal/gadgets/com.n…t/LocalExec.CAB
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo…toUploader3.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1132753115798
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1132847722513
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: nd_gfx9 - nd_gfx9.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe

–
End of file - 9390 bytes
Hi

First thing you need to do is navigate to this folder
C:\SDFix\Data.txt

Check and see which, if any, of your passwords are in there. This is extremely important if you use your computer for banking. If there are sensitive passwords I would suggest calling your bank and credit card company and take appropriate action.
There are not any sensitive passwords, Scotty. But I am still getting popups every once and a while, and I am assuming there is still more to be done to rid my computer of the malware. Thanks.
Hi

You have the latest variant of Vundo which means Startup programs are infected and every time you reboot you get re-infected. Try to keep the computer on while I write up a fix for you. It might take a little while.

Meantime

Download RenV.exe By sUBs to your Desktop.
  • Double click RenV.exe to run it.
  • When finished it will produce a log.
  • Post that log in your next reply please.
Ran on Fri 01/04/2008 - 15:24:14.74

—-a-w		   313,472 2008-01-04 18:23:04  C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager .exe
—-a-w			79,224 2008-01-04 18:22:44  C:\Program Files\Alwil Software\Avast4\ashDisp .exe
—-a-w		   192,512 2008-01-04 18:21:37  C:\Program Files\Apoint2K\Apoint .exe
—-a-w			68,856 2008-01-04 18:23:10  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
—-a-w		   132,496 2008-01-04 18:22:50  C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe
—-a-w			61,440 2008-01-04 18:23:13  C:\Program Files\kernel\kernel .exe
—-a-w			33,648 2008-01-04 18:22:39  C:\Program Files\Microsoft Office\Office12\GrooveMonitor .exe
—-a-w		   286,720 2008-01-03 16:40:26  C:\Program Files\QuickTime\qttask	.exe
—-a-w		   662,016 2008-01-04 18:07:20  C:\Program Files\QuickTime\qttask .exe
—-a-w			86,073 2008-01-04 18:21:54  C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon .exe
—-a-w		22,880,040 2008-01-04 18:24:57  C:\Program Files\Skype\Phone\Skype .exe
—-a-w		 1,318,912 2008-01-03 22:15:05  C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE .EXE
—-a-w			65,536 2008-01-04 18:22:48  C:\Program Files\Toshiba\TOSCDSPD\toscdspd .exe
—-a-w		 1,089,589 2008-01-04 18:22:09  C:\Program Files\Toshiba\Touch and Launch\PadExe .exe
—-a-w		   409,600 2008-01-04 18:22:18  C:\Program Files\X3watchpro\x3watchpro .exe
—-a-w		   151,552 2008-01-04 18:22:10  C:\TOSHIBA\IVP\ISM\pinger .exe
—-a-w		   839,703 2008-01-03 16:40:36  C:\WINDOWS\Fonts\svchost .exe
—-a-w		   258,048 2008-01-04 18:21:38  C:\WINDOWS\system32\00THotkey .exe
—-a-w			15,360 2008-01-03 22:35:29  C:\WINDOWS\system32\ctfmon .exe
—-a-w		   118,784 2008-01-04 18:21:46  C:\WINDOWS\system32\hkcmd .exe
—-a-w		   155,648 2008-01-04 18:21:38  C:\WINDOWS\system32\igfxtray .exe
—-a-w		   122,939 2008-01-04 18:21:34  C:\WINDOWS\system32\dla\tfswctrl .exe

 Entries:			   22  (22)
 Directories:			0  Files:			22
 Bytes:		 29,342,168  Blocks:	   57,315
Hi

To enable the viewing of Hidden files follow these steps:
  • Close all programs so that you are at your desktop.
  • Double-click on the My Computer icon (or click Start, then select My Computer)
  • Select the Tools menu and click Folder Options.
  • After the new window appears select the View tab.
  • Put a checkmark in the checkbox labeled Display the contents of system folders.
  • Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
  • Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
  • Remove the checkmark from the checkbox labeled Hide protected operating system files.
  • Press the Apply button and then the OK button and shutdown My Computer.
    Now your computer is configured to show all hidden files.

Go to http://www.virustotal.com/en/indexf.html
Copy the following line into the white textbox:
C:\Program Files\kernel\kernel.exe
Click Send.
Please post the results of this scan to this thread.

Remember to disconnect from the Internet and disable your anti-virus before carrying out the next instruction, and to reenable the anti-virus before reconnecting to the Internet


Open Notepad - it must be Notepad, not Wordpad.
Copy the text below in the code box by highlighting all the text with your mouse and pressing Ctrl+C

File::
C:\WINDOWS\system32\cqeyjjvd.ini
C:\WINDOWS\system32\xxblljkj.ini
C:\temp\ytesm1220.exe

RenV::
C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager .exe
C:\Program Files\Alwil Software\Avast4\ashDisp .exe
C:\Program Files\Apoint2K\Apoint .exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe
C:\Program Files\kernel\kernel .exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor .exe
C:\Program Files\QuickTime\qttask	.exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon .exe
C:\Program Files\Skype\Phone\Skype .exe
C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE .EXE
C:\Program Files\Toshiba\TOSCDSPD\toscdspd .exe
C:\Program Files\Toshiba\Touch and Launch\PadExe .exe
C:\Program Files\X3watchpro\x3watchpro .exe
C:\TOSHIBA\IVP\ISM\pinger .exe
C:\WINDOWS\system32\[u]0[/u]0THotkey .exe
C:\WINDOWS\system32\ctfmon .exe
C:\WINDOWS\system32\hkcmd .exe
C:\WINDOWS\system32\igfxtray .exe
C:\WINDOWS\system32\dla\tfswctrl .exe

Folder::
C:\WINDOWS\system32\pp1
C:\WINDOWS\system32\mr9
C:\WINDOWS\system32\ardCo18
C:\WINDOWS\system32\aj2
C:\temp\cEeer12
C:\WINDOWS\system32\Logs

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"70f3b715"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\nd_gfx9]

Go to the Notepad window and click Edit > Paste
Then click File > Save
Name the file "CFScript.txt" (including the quotes)
Save the file to your Desktop

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe

Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task-Manager use the Processes tab (press ctrl alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.

Please do an online scan with Kaspersky Online Scanner. You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings
  • In the scan settings make sure that the following are selected:
    • Scan using the following Anti-Virus database:

      + Extended(If available otherwise Standard)
    • Scan Options:

      + Scan Archives
      + Scan Mail Bases
  • Click OK
  • Now under select a target to scan select My Computer
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button
  • Save the file to your desktop.
  • Copy and paste that information in your next post.

With the exception of Internet Explorer, which is needed for the Kaspersky Scan, keep ALL programs closed until the scan is complete. This includes your anti-virus. Once you have installed the Scanner, and the updated definitions, you can disconnect from the Internet.Re-enable the anti-virus before reconnecting to the Internet.


In your next reply post:
Virustotal result
Kasperskey report
ComboFix.txt
New HJT log taken after the above scan has run
HERE IS THE VIRUSTOTAL REPORT:

File kernel_.exe received on 01.04.2008 17:57:40 (CET)
Current status: finished

Result: 11/32 (34.38%)
Compact Print results
Antivirus Version Last Update Result
AhnLab-V3 - - -
AntiVir - - TR/Dldr.Adload.PN
Authentium - - -
Avast - - -
AVG - - -
BitDefender - - -
CAT-QuickHeal - - TrojanDownloader.Adload.pn
ClamAV - - -
DrWeb - - Trojan.Stars.183
eSafe - - -
eTrust-Vet - - -
Ewido - - -
FileAdvisor - - -
Fortinet - - W32/Adload.PN!tr.dldr
F-Prot - - -
F-Secure - - Trojan-Downloader.Win32.Adload.pn
Ikarus - - Trojan-Downloader.Win32.Adload.pn
Kaspersky - - Trojan-Downloader.Win32.Adload.pn
McAfee - - -
Microsoft - - -
NOD32v2 - - -
Norman - - W32/Adload.HAM
Panda - - -
Prevx1 - - Heuristic: Suspicious File With Bad Child Associations
Rising - - -
Sophos - - -
Sunbelt - - Adware.Starsdoor
Symantec - - -
TheHacker - - -
VBA32 - - -
VirusBuster - - -
Webwasher-Gateway - - Trojan.Dldr.Adload.PN
Additional information
MD5: 14c8e7949a7055b7ce23c1e69c9ca5a3


HERE IS THE KASPERSKY REPORT:

Friday, January 04, 2008 11:38:30 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 4/01/2008
Kaspersky Anti-Virus database records: 502630


Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true

Scan Target My Computer
C:\
D:\
E:\
G:\

Scan Statistics
Total number of scanned objects 63105
Number of viruses found 21
Number of infected objects 277
Number of suspicious objects 0
Duration of the scan process 02:35:39

Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped

C:\Documents and Settings\Bryce Helsel\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\Bryce Helsel\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\Bryce Helsel\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\Bryce Helsel\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Bryce Helsel\Local Settings\History\History.IE5\MSHist012008010420080105\index.dat Object is locked skipped

C:\Documents and Settings\Bryce Helsel\Local Settings\Temp\~DFBCCB.tmp Object is locked skipped

C:\Documents and Settings\Bryce Helsel\Local Settings\Temp\~DFBCD9.tmp Object is locked skipped

C:\Documents and Settings\Bryce Helsel\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped

C:\Documents and Settings\Bryce Helsel\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Bryce Helsel\ntuser.dat Object is locked skipped

C:\Documents and Settings\Bryce Helsel\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped

C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped

C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped

C:\Program Files\kernel\kernel .exe Infected: Trojan-Downloader.Win32.Adload.pn skipped

C:\Program Files\QuickTime\qttask .exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\Program Files\QuickTime\qttask.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\QooBox\Quarantine\C\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\QooBox\Quarantine\C\Program Files\Apoint2K\Apoint.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\QooBox\Quarantine\C\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\QooBox\Quarantine\C\Program Files\Java\jre1.6.0_03\bin\jusched.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\QooBox\Quarantine\C\Program Files\kernel\kernel.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\QooBox\Quarantine\C\Program Files\Microsoft Office\Office12\GrooveMonitor.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\QooBox\Quarantine\C\Program Files\MsMovies\p.zip.vir/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h skipped

C:\QooBox\Quarantine\C\Program Files\MsMovies\p.zip.vir ZIP: infected - 1 skipped

C:\QooBox\Quarantine\C\Program Files\QuickTime\qttask .exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\QooBox\Quarantine\C\Program Files\QuickTime\qttask .exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\QooBox\Quarantine\C\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\QooBox\Quarantine\C\Program Files\Skype\Phone\Skype.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\QooBox\Quarantine\C\Program Files\Toshiba\TOSCDSPD\toscdspd.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\QooBox\Quarantine\C\Program Files\Toshiba\Touch and Launch\PadExe.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\QooBox\Quarantine\C\Program Files\X3watchpro\x3watchpro.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\QooBox\Quarantine\C\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\QooBox\Quarantine\C\temp\ytesm1220.exe.vir/data0002 Infected: Trojan-Downloader.Win32.Small.buy skipped

C:\QooBox\Quarantine\C\temp\ytesm1220.exe.vir/data0003 Infected: Trojan-Downloader.Win32.Small.hkt skipped

C:\QooBox\Quarantine\C\temp\ytesm1220.exe.vir/data0004 Infected: Trojan.Win32.Pakes.bvs skipped

C:\QooBox\Quarantine\C\temp\ytesm1220.exe.vir/data0005/data0002 Infected: not-a-virus:AdWare.Win32.TTC.a skipped

C:\QooBox\Quarantine\C\temp\ytesm1220.exe.vir/data0005 Infected: not-a-virus:AdWare.Win32.TTC.a skipped

C:\QooBox\Quarantine\C\temp\ytesm1220.exe.vir NSIS: infected - 5 skipped

C:\QooBox\Quarantine\C\TOSHIBA\IVP\ISM\pinger.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\00THotkey.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\ctfmon.exe.tmp.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\dla\tfswctrl.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\hkcmd.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\igfxtray.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\xxyaw.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\QooBox\Quarantine\catchme2008-01-04_134808.21.zip/xxyaw.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.dih skipped

C:\QooBox\Quarantine\catchme2008-01-04_134808.21.zip ZIP: infected - 1 skipped

C:\SDFix\backups\backups.zip/backups/b122.exe Infected: Trojan-Downloader.Win32.Agent.haq skipped

C:\SDFix\backups\backups.zip/backups/core.sys Infected: Rootkit.Win32.Agent.sg skipped

C:\SDFix\backups\backups.zip/backups/Crack.exe Infected: Trojan.Win32.Agent.cmn skipped

C:\SDFix\backups\backups.zip/backups/kernInstall.exe Infected: Trojan-Downloader.Win32.Agent.haq skipped

C:\SDFix\backups\backups.zip/backups/tem16A.tmp.exe/data0002 Infected: not-a-virus:AdWare.Win32.Agent.jb skipped

C:\SDFix\backups\backups.zip/backups/tem16A.tmp.exe Infected: not-a-virus:AdWare.Win32.Agent.jb skipped

C:\SDFix\backups\backups.zip/backups/winlogon.exe Infected: not-a-virus:PSWTool.Win32.PassView.p skipped

C:\SDFix\backups\backups.zip ZIP: infected - 7 skipped

C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059301.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059309.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059314.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059315.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059316.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059317.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059318.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059319.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059320.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059321.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059322.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059323.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059324.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059325.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059326.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059327.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059328.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059329.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059331.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059347.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059348.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059351.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059352.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059353.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059354.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059355.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059356.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059357.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059358.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059359.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059360.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059361.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059362.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059363.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059364.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059365.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059366.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059367.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059370.exe Infected: Trojan.Win32.Agent.cmn skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059371.exe Infected: Trojan.Win32.Agent.cmn skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059402.exe Infected: not-a-virus:AdWare.Win32.Agent.zk skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059480.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059489.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059491.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059502.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059504.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059505.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059506.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059507.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059509.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059511.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059512.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059513.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059514.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059515.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059516.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059518.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059519.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059520.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059521.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059527.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059535.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059542.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059543.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059546.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059547.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059549.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059550.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059551.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059552.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059553.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059554.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059559.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059560.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059561.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059563.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059566.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059567.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059568.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059577.exe Infected: Trojan.Win32.Agent.cmn skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059626.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059816.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059818.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059826.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059828.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059829.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059830.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059831.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059832.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059833.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059835.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059836.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059838.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059839.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059840.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059844.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059845.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059847.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059849.exe Infected: Trojan.Win32.Agent.cmn skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059855.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059874.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059882.exe Infected: Trojan-Downloader.Win32.Agent.gwh skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059883.exe Infected: Trojan.Win32.Zapchast.ca skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059884.exe Infected: Trojan.Win32.Zapchast.ca skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059885.exe Infected: Trojan.Win32.Zapchast.ca skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059886.exe Infected: Trojan.Win32.Zapchast.ca skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059887.exe Infected: Trojan.Win32.Zapchast.ca skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059888.exe Infected: Trojan.Win32.Zapchast.ca skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059889.exe Infected: Trojan.Win32.Zapchast.ca skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059891.exe Infected: Trojan.Win32.Zapchast.ca skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059892.exe Infected: Trojan.Win32.Zapchast.ca skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059893.exe Infected: Trojan.Win32.Zapchast.ca skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059895.exe Infected: Trojan.Win32.Zapchast.ca skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059896.exe Infected: Trojan.Win32.Zapchast.ca skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059897.exe Infected: not-a-virus:AdWare.Win32.NewDotNet.e skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059898.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059899.exe Infected: Trojan-Downloader.Win32.VB.caw skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059902.dll Infected: Trojan-Downloader.Win32.Small.hlf skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059903.dll Infected: Trojan-Downloader.Win32.Small.hlf skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059904.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.dih skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059905.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.din skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059907.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059944.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059947.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059956.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059957.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059958.exe Infected: Trojan-Downloader.Win32.Adload.pn skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059960.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059961.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059962.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059963.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059964.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059965.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059966.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059967.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059968.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059969.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059971.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059973.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0059997.rbf Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060050.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060086.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060088.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060101.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060104.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060105.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060106.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060107.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060108.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060109.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060111.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060112.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060113.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060115.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060117.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060120.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060121.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060122.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060123.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060124.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060129.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060470.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060474.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060475.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060485.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060493.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060497.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060503.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060510.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060516.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060521.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060528.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060533.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060537.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060541.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060542.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060544.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060545.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060546.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060547.exe Infected: Trojan-Downloader.Win32.Agent.haq skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060549.exe Infected: not-a-virus:PSWTool.Win32.PassView.p skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060550.exe Infected: Trojan-Downloader.Win32.Agent.haq skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060551.exe Infected: Trojan.Win32.Agent.cmn skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060553.sys Infected: Rootkit.Win32.Agent.sg skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060561.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060563.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060564.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060565.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060566.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060567.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060568.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060569.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060570.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060571.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060572.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060573.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060574.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060575.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060576.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060577.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060578.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060579.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060580.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060581.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060585.exe Infected: Trojan-Downloader.Win32.Agent.haq skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060587.sys Infected: Rootkit.Win32.Agent.sg skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060588.exe Infected: Trojan.Win32.Agent.cmn skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060589.exe Infected: Trojan-Downloader.Win32.Agent.haq skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060593.exe/data0002 Infected: not-a-virus:AdWare.Win32.Agent.jb skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060593.exe NSIS: infected - 1 skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060596.exe Infected: not-a-virus:PSWTool.Win32.PassView.p skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060631.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060638.exe Infected: Trojan-Downloader.Win32.Adload.pn skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP788\A0060641.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP788\A0060642.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060644.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060645.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060646.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060647.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060648.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060649.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060650.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060651.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060652.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060653.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060654.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060655.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060657.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060658.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060659.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060660.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060663.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060664.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060671.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.dih skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP790\change.log Object is locked skipped

C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

C:\WINDOWS\Fonts\svchost .exe Infected: Trojan.Win32.Agent.cmn skipped

C:\WINDOWS\SchedLgU.Txt Object is locked skipped

C:\WINDOWS\SFA02EC7C.tmp Object is locked skipped

C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped

C:\WINDOWS\Sti_Trace.log Object is locked skipped

C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped

C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped

C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped

C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\default Object is locked skipped

C:\WINDOWS\system32\config\default.LOG Object is locked skipped

C:\WINDOWS\system32\config\Internet.evt Object is locked skipped

C:\WINDOWS\system32\config\ODiag.evt Object is locked skipped

C:\WINDOWS\system32\config\OSession.evt Object is locked skipped

C:\WINDOWS\system32\config\SAM Object is locked skipped

C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped

C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\SECURITY Object is locked skipped

C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped

C:\WINDOWS\system32\config\software Object is locked skipped

C:\WINDOWS\system32\config\software.LOG Object is locked skipped

C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\system Object is locked skipped

C:\WINDOWS\system32\config\system.LOG Object is locked skipped

C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped

C:\WINDOWS\system32\h323log.txt Object is locked skipped

C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

C:\WINDOWS\Temp\Perflib_Perfdata_61c.dat Object is locked skipped

C:\WINDOWS\wiadebug.log Object is locked skipped

C:\WINDOWS\wiaservc.log Object is locked skipped

C:\WINDOWS\WindowsUpdate.log Object is locked skipped

G:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP790\change.log Object is locked skipped

Scan process completed.

HERE IS THE COMBOFIX REPORT:

ComboFix 08-01-04.1 - Bryce Helsel 2008-01-04 18:01:47.2 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Bryce Helsel\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\temp\ytesm1220.exe
C:\WINDOWS\system32\cqeyjjvd.ini
C:\WINDOWS\system32\xxblljkj.ini
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\temp\cEeer12
C:\temp\cEeer12\skAt.log
C:\temp\ytesm1220.exe
C:\WINDOWS\system32\aj2
C:\WINDOWS\system32\ardCo18
C:\WINDOWS\system32\cqeyjjvd.ini
C:\WINDOWS\system32\Logs
C:\WINDOWS\system32\mr9
C:\WINDOWS\system32\pp1
C:\WINDOWS\system32\xxblljkj.ini

.
((((((((((((((((((((((((( Files Created from 2007-12-04 to 2008-01-04 )))))))))))))))))))))))))))))))
.

2008-01-04 13:31 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-04 12:27 . 2008-01-04 12:28 d——– C:\WINDOWS\ERUNT
2008-01-04 02:36 . 2008-01-04 02:36 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-01-04 02:36 . 2008-01-04 02:36 1,409 –a—— C:\WINDOWS\QTFont.for
2008-01-03 17:17 . 2008-01-03 17:17 d——– C:\Program Files\Trend Micro
2008-01-03 15:09 . 2008-01-03 15:09 d——– C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-01-03 15:08 . 2008-01-03 17:15 d——– C:\Program Files\SUPERAntiSpyware
2008-01-03 14:57 . 2008-01-03 17:13 d——– C:\Program Files\RogueRemover FREE
2008-01-03 13:38 . 2008-01-03 13:38 d——– C:\Documents and Settings\Bryce Helsel\Application Data\PrevxCSI
2008-01-03 13:38 . 2008-01-03 13:38 d——– C:\Documents and Settings\All Users\Application Data\Prevx
2008-01-03 13:32 . 2007-12-04 09:53 23,152 –a—— C:\WINDOWS\system32\drivers\aswRdr.sys
2008-01-03 13:31 . 2007-12-04 08:04 837,496 –a—— C:\WINDOWS\system32\aswBoot.exe
2008-01-03 13:31 . 2004-01-09 04:13 380,928 –a—— C:\WINDOWS\system32\actskin4.ocx
2008-01-03 13:31 . 2007-12-04 07:54 95,608 –a—— C:\WINDOWS\system32\AVASTSS.scr
2008-01-03 13:31 . 2007-12-04 09:55 94,544 –a—— C:\WINDOWS\system32\drivers\aswmon2.sys
2008-01-03 13:31 . 2007-12-04 09:56 93,264 –a—— C:\WINDOWS\system32\drivers\aswmon.sys
2008-01-03 13:31 . 2007-12-04 09:51 42,912 –a—— C:\WINDOWS\system32\drivers\aswTdi.sys
2008-01-03 13:31 . 2007-12-04 09:49 26,624 –a—— C:\WINDOWS\system32\drivers\aavmker4.sys
2008-01-03 11:45 . 2008-01-04 13:43 d——– C:\Program Files\kernel
2008-01-02 12:01 . 2008-01-03 17:35 15,360 –a—— C:\WINDOWS\system32\ctfmon .exe
2008-01-02 01:49 . 2008-01-02 01:49 d——– C:\Program Files\Lavasoft
2008-01-02 01:49 . 2008-01-02 01:49 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-02 01:45 . 2008-01-03 17:15 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-01-02 01:20 . 2008-01-04 13:21 155,648 –a—— C:\WINDOWS\system32\igfxtray .exe
2008-01-02 01:20 . 2008-01-04 13:21 118,784 –a—— C:\WINDOWS\system32\hkcmd .exe
2008-01-02 01:19 . 2008-01-04 13:21 258,048 –a—— C:\WINDOWS\system32\00THotkey .exe
2007-12-31 20:53 . 2007-12-31 20:53 d——– C:\Documents and Settings\Bryce Helsel\Incomplete
2007-12-31 20:51 . 2007-12-31 20:51 147,456 –a—— C:\WINDOWS\system32\vbzip10.dll
2007-12-31 20:46 . 2008-01-03 11:41 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-31 19:51 . 2007-12-31 19:51 d——– C:\WINDOWS\Cache
2007-12-31 17:05 . 2004-11-15 15:37 264,440 –a—— C:\WINDOWS\system32\drivers\stac97.sys
2007-12-30 18:34 . 2007-12-31 15:39 d——– C:\Program Files\Tunebite
2007-12-30 18:32 . 2007-12-30 18:32 d——– C:\Program Files\BitZipper
2007-12-30 18:32 . 2007-12-30 18:32 d——– C:\Documents and Settings\Bryce Helsel\Application Data\BitZipper
2007-12-30 17:09 . 2007-12-30 17:09 d——– C:\Documents and Settings\Bryce Helsel\Application Data\RTPlayer
2007-12-30 16:59 . 2007-12-31 15:37 d——– C:\Documents and Settings\Bryce Helsel\Application Data\tunebite
2007-12-26 22:33 . 2007-12-26 22:33 d——– C:\Program Files\NCH Software
2007-12-26 22:33 . 2007-12-26 22:33 d——– C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
2007-12-26 22:29 . 2007-12-26 22:46 d——– C:\Program Files\NCH Swift Sound
2007-12-26 22:29 . 2007-12-26 22:39 d——– C:\Documents and Settings\Bryce Helsel\Application Data\NCH Swift Sound
2007-12-26 21:33 . 2007-12-26 21:33 d——– C:\Program Files\Western Digital Technologies
2007-12-26 21:12 . 2007-12-26 21:12 d——– C:\Program Files\Common Files\ArcSoft
2007-12-26 21:12 . 2007-12-26 21:15 d——– C:\Documents and Settings\Bryce Helsel\Application Data\ArcSoft
2007-12-26 21:12 . 2004-08-04 07:52 413,696 -ra—— C:\WINDOWS\system32\msvc6473.rra
2007-12-26 21:12 . 2005-02-23 14:58 11,776 –a—— C:\WINDOWS\system32\drivers\afc.sys
2007-12-26 21:11 . 2007-12-26 21:11 d——– C:\WINDOWS\system32\PhotoImpression Slideshow
2007-12-26 21:11 . 2007-12-26 21:11 d——– C:\Program Files\ArcSoft
2007-12-26 21:11 . 2005-04-27 16:36 245,408 –a—— C:\WINDOWS\system32\unicows.dll
2007-12-26 21:11 . 1995-08-01 04:44 212,480 –a—— C:\WINDOWS\PCDLIB32.DLL
2007-12-26 21:11 . 2006-10-20 16:11 126,976 –a—— C:\WINDOWS\system32\PhotoImpression Slideshow.scr
2007-12-17 15:53 . 2008-01-04 13:43 d——– C:\Program Files\QuickTime
2007-12-11 17:34 . 2007-12-11 17:34 1,044,480 –a—— C:\WINDOWS\system32\libdivx.dll
2007-12-11 17:34 . 2007-12-11 17:34 200,704 –a—— C:\WINDOWS\system32\ssldivx.dll
2007-12-11 16:56 . 2007-12-11 16:56 d——– C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
2007-12-11 10:57 . 2007-12-11 10:57 65,536 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx
2007-12-11 10:57 . 2007-12-11 10:57 49,152 –a—— C:\WINDOWS\system32\QuickTime.qts
2007-12-08 19:14 . 2007-12-08 19:14 d——– C:\Program Files\iPod
2007-12-08 19:13 . 2007-12-08 19:14 d——– C:\Program Files\iTunes
2007-12-08 19:03 . 2007-12-08 19:03 d——– C:\Program Files\Common Files\Apple
2007-12-08 17:44 . 2007-12-08 17:44 d——– C:\Program Files\Windows Live Toolbar

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-04 18:43 ——— d—–w C:\Program Files\X3watchpro
2008-01-04 18:43 ——— d—–w C:\Program Files\Apoint2K
2008-01-04 18:27 ——— d—–w C:\Documents and Settings\Bryce Helsel\Application Data\Skype
2008-01-04 17:19 ——— d—–w C:\Program Files\Java
2008-01-04 08:16 ——— d–h–w C:\Documents and Settings\Bryce Helsel\Application Data\x3watchpro
2008-01-03 16:47 ——— d—–w C:\Documents and Settings\Bryce Helsel\Application Data\LimeWire
2008-01-01 21:00 ——— d—–w C:\Documents and Settings\Bryce Helsel\Application Data\Ruckus Network
2007-12-31 22:09 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-31 22:09 ——— d—–w C:\Program Files\SigmaTel
2007-12-31 21:49 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-12-31 06:58 ——— d—–w C:\Documents and Settings\Bryce Helsel\Application Data\uTorrent
2007-12-19 23:25 ——— d—–w C:\Program Files\DivX
2007-11-29 21:24 ——— d—–w C:\Documents and Settings\All Users\Application Data\Nero
2007-11-29 13:40 ——— d—–w C:\Program Files\MSXML 4.0
2007-11-28 01:29 ——— d—–w C:\Documents and Settings\Bryce Helsel\Application Data\Nero
2007-11-15 20:24 ——— d—–w C:\Program Files\MagicDisc
2007-11-15 05:46 ——— d—–w C:\Documents and Settings\Bryce Helsel\Application Data\MSN6
2007-11-15 05:03 ——— d—–w C:\Program Files\Creative
2007-11-15 04:42 ——— d—–w C:\Documents and Settings\All Users\Application Data\WinZip
2007-11-14 07:07 ——— d—–w C:\Program Files\Microsoft Works
2007-11-14 07:06 ——— d—–w C:\Program Files\MSBuild
2007-11-14 07:03 ——— d—–w C:\Program Files\Microsoft.NET
2007-11-14 06:53 ——— d—–w C:\Program Files\Microsoft Visual Studio 8
2007-11-14 06:07 ——— d—–w C:\Program Files\MagicISO
2007-11-14 06:04 223,128 —-a-w C:\WINDOWS\system32\drivers\vaxscsi.sys
2007-11-14 06:00 ——— d—–w C:\Program Files\Google
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2004-06-09 06:01 1,822,848 —-a-w C:\Documents and Settings\DLA Writing.temp\INSNTMSI.EXE
2004-06-09 06:01 1,709,160 —-a-w C:\Documents and Settings\DLA Writing.temp\INS9XMSI.EXE
2004-01-23 07:00 462,848 —-a-w C:\Documents and Settings\DLA Writing.temp\Setup.exe
2006-01-02 17:49 321 –sha-w C:\WINDOWS\system32\ospcont.dat
.
—-a-w			79,224 2008-01-04 18:22:44  C:\Program Files\Alwil Software\Avast4\ashDisp .exe
—-a-w		   192,512 2008-01-04 18:21:37  C:\Program Files\Apoint2K\Apoint .exe
—-a-w			68,856 2008-01-04 18:23:10  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
—-a-w		   132,496 2008-01-04 18:22:50  C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe
—-a-w			61,440 2008-01-04 18:23:13  C:\Program Files\kernel\kernel .exe
—-a-w			33,648 2008-01-04 18:22:39  C:\Program Files\Microsoft Office\Office12\GrooveMonitor .exe
—-a-w		   286,720 2008-01-03 16:40:26  C:\Program Files\QuickTime\qttask	.exe
—-a-w		   662,016 2008-01-04 18:07:20  C:\Program Files\QuickTime\qttask .exe
—-a-w			86,073 2008-01-04 18:21:54  C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon .exe
—-a-w		22,880,040 2008-01-04 18:24:57  C:\Program Files\Skype\Phone\Skype .exe
—-a-w		 1,318,912 2008-01-03 22:15:05  C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE .EXE
—-a-w			65,536 2008-01-04 18:22:48  C:\Program Files\Toshiba\TOSCDSPD\toscdspd .exe
—-a-w		 1,089,589 2008-01-04 18:22:09  C:\Program Files\Toshiba\Touch and Launch\PadExe .exe
—-a-w		   409,600 2008-01-04 18:22:18  C:\Program Files\X3watchpro\x3watchpro .exe
—-a-w		   151,552 2008-01-04 18:22:10  C:\TOSHIBA\IVP\ISM\pinger .exe
—-a-w		   839,703 2008-01-03 16:40:36  C:\WINDOWS\Fonts\svchost .exe
—-a-w		   258,048 2008-01-04 18:21:38  C:\WINDOWS\system32\00THotkey .exe
—-a-w			15,360 2008-01-03 22:35:29  C:\WINDOWS\system32\ctfmon .exe
—-a-w		   118,784 2008-01-04 18:21:46  C:\WINDOWS\system32\hkcmd .exe
—-a-w		   155,648 2008-01-04 18:21:38  C:\WINDOWS\system32\igfxtray .exe
—-a-w		   122,939 2008-01-04 18:21:34  C:\WINDOWS\system32\dla\tfswctrl .exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [ ]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56 15360]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2008-01-04 13:23 313472]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [ ]
"kernel"="C:\Program Files\kernel\kernel.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"00THotkey"="C:\WINDOWS\system32\00THotkey.exe" [ ]
"000StTHK"="000StTHK.exe" [2001-06-23 20:28 24576 C:\WINDOWS\system32\000StTHK.exe]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [ ]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [ ]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [ ]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [ ]
"SigmaTel StacMon"="C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe" [ ]
"AGRSMMSG"="AGRSMMSG.exe" [2004-02-20 15:00 88363 C:\WINDOWS\agrsmmsg.exe]
"PadTouch"="C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe" [ ]
"PINGER"="C:\TOSHIBA\IVP\ISM\pinger.exe" [ ]
"TPSMain"="TPSMain.exe" [2004-06-01 20:43 278528 C:\WINDOWS\system32\TPSMain.exe]
"x3watchpro"="C:\Program Files\X3watchpro\x3watchpro.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [ ]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 08:00 79224]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [ ]

C:\Documents and Settings\Bryce Helsel\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50]
Webshots.lnk - C:\Program Files\Webshots\Launcher.exe [2006-07-19 22:13:20]

S3 Camdrv30;Philips ToUcam XS;C:\WINDOWS\system32\Drivers\camdrv30.sys [2001-01-25 02:40]
S3 tbhsd;Tunebite High-Speed Dubbing;C:\WINDOWS\system32\drivers\tbhsd.sys []

.
Contents of the 'Scheduled Tasks' folder
"2007-12-29 23:35:13 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-04 22:49:03 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-01-04 17:07:41 C:\WINDOWS\Tasks\User_Feed_Synchronization-{EC38B375-0340-4869-8D44-280E8199B66E}.job"
- C:\WINDOWS\system32\msfeedssync.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-04 18:05:54
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-04 18:07:13
ComboFix-quarantined-files.txt 2008-01-04 23:07:05
ComboFix2.txt 2008-01-04 18:51:09
.
2007-12-12 04:26:47 — E O F —


HERE IS THE HIJACKTHIS REPORT:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:39:29 PM, on 1/4/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\System32\svchost.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\TPSMain.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Trend Micro\HijackThis\iseeu.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/1me10enus/2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/1me10enus/2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/1me10enus/2
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: (no name) - {736b5468-bdad-41be-92d0-22ae2ddf7bcb} - (no file)
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\system32\00THotkey.exe
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SigmaTel StacMon] C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [PINGER] C:\TOSHIBA\IVP\ISM\pinger.exe /run
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [x3watchpro] C:\Program Files\X3watchpro\x3watchpro.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [kernel] C:\Program Files\kernel\kernel.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O8 - Extra context menu item: &Windows; Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {2B1AA38D-2D12-11D5-AAD0-00C04FA03D78} (LocalExec Control) - https://my.uga.edu/nps/portal/gadgets/com.n…t/LocalExec.CAB
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo…toUploader3.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1132753115798
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1132847722513
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe

–
End of file - 9278 bytes
Hi

  • Click Start > Run type Notepad click OK.
  • This will open an empty Notepad file.
  • Copy/Paste the contents of the box below into Notepad.
C:\Program Files\Alwil Software\Avast4\ashDisp .exe
C:\Program Files\Apoint2K\Apoint .exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe
C:\Program Files\kernel\kernel .exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor .exe
C:\Program Files\QuickTime\qttask	.exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon .exe
C:\Program Files\Skype\Phone\Skype .exe
C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE .EXE
C:\Program Files\Toshiba\TOSCDSPD\toscdspd .exe
C:\Program Files\Toshiba\Touch and Launch\PadExe .exe
C:\Program Files\X3watchpro\x3watchpro .exe
C:\TOSHIBA\IVP\ISM\pinger .exe
C:\WINDOWS\Fonts\svchost .exe
C:\WINDOWS\system32\[u]0[/u]0THotkey .exe
C:\WINDOWS\system32\ctfmon .exe
C:\WINDOWS\system32\hkcmd .exe
C:\WINDOWS\system32\igfxtray .exe
C:\WINDOWS\system32\dla\tfswctrl .exe
  • Save this as Log.txt to your Desktop.
[external image: Posted Image]
  • Refering to the picture above, drag Log.txt into RenV.exe
  • When finished, it shall produce a new log for you.
  • Post that log in your next reply please.


Remember to disconnect from the Internet and disable your anti-virus before carrying out the next instruction, and to reenable the anti-virus before reconnecting to the Internet


Open Notepad - it must be Notepad, not Wordpad.
Copy the text below in the code box by highlighting all the text with your mouse and pressing Ctrl+C

File::
C:\WINDOWS\system32\msvc6473.rra
 
Folder::
C:\Program Files\kernel

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"kernel"=-

Go to the Notepad window and click Edit > Paste
Then click File > Save
Name the file "CFScript.txt" (including the quotes)
Save the file to your Desktop

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe

Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task-Manager use the Processes tab (press ctrl alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.

In your next reply post:
RenV log
ComboFix.txt
New HJT log taken after the above scan has run
HERE IS THE RENV LOG:

Ran on Sat 01/05/2008 - 10:51:59.23

——w			79,224 2008-01-04 18:22:44  C:\Program Files\Alwil Software\Avast4\ashDisp .exe
—-a-w		   258,048 2008-01-04 18:21:38  C:\WINDOWS\system32\00THotkey .exe

 Entries:				2  (2)
 Directories:			0  Files:			 2
 Bytes:			337,272  Blocks:		  659

HERE IS THE COMBOFIX LOG:

ComboFix 08-01-04.1 - Bryce Helsel 2008-01-05 12:22:37.3 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Bryce Helsel\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\WINDOWS\system32\msvc6473.rra
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\kernel
C:\Program Files\kernel\kernel.exe
C:\WINDOWS\system32\msvc6473.rra

.
((((((((((((((((((((((((( Files Created from 2007-12-05 to 2008-01-05 )))))))))))))))))))))))))))))))
.

2008-01-05 10:51 . 2008-01-04 13:21 155,648 –a—— C:\WINDOWS\system32\igfxtray.exe
2008-01-05 10:51 . 2008-01-04 13:21 118,784 –a—— C:\WINDOWS\system32\hkcmd.exe
2008-01-04 18:10 . 2008-01-04 18:10 d——– C:\WINDOWS\system32\Kaspersky Lab
2008-01-04 18:10 . 2008-01-04 18:10 d——– C:\WINDOWS\LastGood
2008-01-04 18:10 . 2008-01-04 18:10 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-01-04 13:31 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-04 12:27 . 2008-01-04 12:28 d——– C:\WINDOWS\ERUNT
2008-01-04 02:36 . 2008-01-04 02:36 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-01-04 02:36 . 2008-01-04 02:36 1,409 –a—— C:\WINDOWS\QTFont.for
2008-01-03 17:17 . 2008-01-03 17:17 d——– C:\Program Files\Trend Micro
2008-01-03 15:09 . 2008-01-03 15:09 d——– C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-01-03 15:08 . 2008-01-05 10:46 d——– C:\Program Files\SUPERAntiSpyware
2008-01-03 14:57 . 2008-01-03 17:13 d——– C:\Program Files\RogueRemover FREE
2008-01-03 13:38 . 2008-01-03 13:38 d——– C:\Documents and Settings\Bryce Helsel\Application Data\PrevxCSI
2008-01-03 13:38 . 2008-01-03 13:38 d——– C:\Documents and Settings\All Users\Application Data\Prevx
2008-01-03 13:32 . 2007-12-04 09:53 23,152 –a—— C:\WINDOWS\system32\drivers\aswRdr.sys
2008-01-03 13:31 . 2007-12-04 08:04 837,496 –a—— C:\WINDOWS\system32\aswBoot.exe
2008-01-03 13:31 . 2004-01-09 04:13 380,928 –a—— C:\WINDOWS\system32\actskin4.ocx
2008-01-03 13:31 . 2007-12-04 07:54 95,608 –a—— C:\WINDOWS\system32\AVASTSS.scr
2008-01-03 13:31 . 2007-12-04 09:55 94,544 –a—— C:\WINDOWS\system32\drivers\aswmon2.sys
2008-01-03 13:31 . 2007-12-04 09:56 93,264 –a—— C:\WINDOWS\system32\drivers\aswmon.sys
2008-01-03 13:31 . 2007-12-04 09:51 42,912 –a—— C:\WINDOWS\system32\drivers\aswTdi.sys
2008-01-03 13:31 . 2007-12-04 09:49 26,624 –a—— C:\WINDOWS\system32\drivers\aavmker4.sys
2008-01-02 01:49 . 2008-01-02 01:49 d——– C:\Program Files\Lavasoft
2008-01-02 01:49 . 2008-01-02 01:49 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-02 01:45 . 2008-01-03 17:15 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-01-02 01:19 . 2008-01-04 13:21 258,048 –a—— C:\WINDOWS\system32\00THotkey .exe
2007-12-31 20:53 . 2007-12-31 20:53 d——– C:\Documents and Settings\Bryce Helsel\Incomplete
2007-12-31 20:51 . 2007-12-31 20:51 147,456 –a—— C:\WINDOWS\system32\vbzip10.dll
2007-12-31 20:46 . 2008-01-03 11:41 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-31 19:51 . 2007-12-31 19:51 d——– C:\WINDOWS\Cache
2007-12-31 17:05 . 2004-11-15 15:37 264,440 –a—— C:\WINDOWS\system32\drivers\stac97.sys
2007-12-30 18:34 . 2007-12-31 15:39 d——– C:\Program Files\Tunebite
2007-12-30 18:32 . 2007-12-30 18:32 d——– C:\Program Files\BitZipper
2007-12-30 18:32 . 2007-12-30 18:32 d——– C:\Documents and Settings\Bryce Helsel\Application Data\BitZipper
2007-12-30 17:09 . 2007-12-30 17:09 d——– C:\Documents and Settings\Bryce Helsel\Application Data\RTPlayer
2007-12-30 16:59 . 2007-12-31 15:37 d——– C:\Documents and Settings\Bryce Helsel\Application Data\tunebite
2007-12-26 22:33 . 2007-12-26 22:33 d——– C:\Program Files\NCH Software
2007-12-26 22:33 . 2007-12-26 22:33 d——– C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
2007-12-26 22:29 . 2007-12-26 22:46 d——– C:\Program Files\NCH Swift Sound
2007-12-26 22:29 . 2007-12-26 22:39 d——– C:\Documents and Settings\Bryce Helsel\Application Data\NCH Swift Sound
2007-12-26 21:33 . 2007-12-26 21:33 d——– C:\Program Files\Western Digital Technologies
2007-12-26 21:12 . 2007-12-26 21:12 d——– C:\Program Files\Common Files\ArcSoft
2007-12-26 21:12 . 2007-12-26 21:15 d——– C:\Documents and Settings\Bryce Helsel\Application Data\ArcSoft
2007-12-26 21:12 . 2005-02-23 14:58 11,776 –a—— C:\WINDOWS\system32\drivers\afc.sys
2007-12-26 21:11 . 2007-12-26 21:11 d——– C:\WINDOWS\system32\PhotoImpression Slideshow
2007-12-26 21:11 . 2007-12-26 21:11 d——– C:\Program Files\ArcSoft
2007-12-26 21:11 . 2005-04-27 16:36 245,408 –a—— C:\WINDOWS\system32\unicows.dll
2007-12-26 21:11 . 1995-08-01 04:44 212,480 –a—— C:\WINDOWS\PCDLIB32.DLL
2007-12-26 21:11 . 2006-10-20 16:11 126,976 –a—— C:\WINDOWS\system32\PhotoImpression Slideshow.scr
2007-12-17 15:53 . 2008-01-05 10:45 d——– C:\Program Files\QuickTime
2007-12-11 17:34 . 2007-12-11 17:34 1,044,480 –a—— C:\WINDOWS\system32\libdivx.dll
2007-12-11 17:34 . 2007-12-11 17:34 200,704 –a—— C:\WINDOWS\system32\ssldivx.dll
2007-12-11 16:56 . 2007-12-11 16:56 d——– C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
2007-12-11 10:57 . 2007-12-11 10:57 65,536 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx
2007-12-11 10:57 . 2007-12-11 10:57 49,152 –a—— C:\WINDOWS\system32\QuickTime.qts
2007-12-08 19:14 . 2007-12-08 19:14 d——– C:\Program Files\iPod
2007-12-08 19:13 . 2007-12-08 19:14 d——– C:\Program Files\iTunes
2007-12-08 19:03 . 2007-12-08 19:03 d——– C:\Program Files\Common Files\Apple
2007-12-08 17:44 . 2007-12-08 17:44 d——– C:\Program Files\Windows Live Toolbar

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-05 15:46 ——— d—–w C:\Program Files\X3watchpro
2008-01-05 15:45 ——— d—–w C:\Program Files\Apoint2K
2008-01-04 18:27 ——— d—–w C:\Documents and Settings\Bryce Helsel\Application Data\Skype
2008-01-04 17:19 ——— d—–w C:\Program Files\Java
2008-01-04 08:16 ——— d–h–w C:\Documents and Settings\Bryce Helsel\Application Data\x3watchpro
2008-01-03 16:47 ——— d—–w C:\Documents and Settings\Bryce Helsel\Application Data\LimeWire
2008-01-01 21:00 ——— d—–w C:\Documents and Settings\Bryce Helsel\Application Data\Ruckus Network
2007-12-31 22:09 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-31 22:09 ——— d—–w C:\Program Files\SigmaTel
2007-12-31 21:49 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-12-31 06:58 ——— d—–w C:\Documents and Settings\Bryce Helsel\Application Data\uTorrent
2007-12-19 23:25 ——— d—–w C:\Program Files\DivX
2007-11-29 21:24 ——— d—–w C:\Documents and Settings\All Users\Application Data\Nero
2007-11-29 13:40 ——— d—–w C:\Program Files\MSXML 4.0
2007-11-28 01:29 ——— d—–w C:\Documents and Settings\Bryce Helsel\Application Data\Nero
2007-11-15 20:24 ——— d—–w C:\Program Files\MagicDisc
2007-11-15 05:46 ——— d—–w C:\Documents and Settings\Bryce Helsel\Application Data\MSN6
2007-11-15 05:03 ——— d—–w C:\Program Files\Creative
2007-11-15 04:42 ——— d—–w C:\Documents and Settings\All Users\Application Data\WinZip
2007-11-14 07:07 ——— d—–w C:\Program Files\Microsoft Works
2007-11-14 07:06 ——— d—–w C:\Program Files\MSBuild
2007-11-14 07:03 ——— d—–w C:\Program Files\Microsoft.NET
2007-11-14 06:53 ——— d—–w C:\Program Files\Microsoft Visual Studio 8
2007-11-14 06:07 ——— d—–w C:\Program Files\MagicISO
2007-11-14 06:04 223,128 —-a-w C:\WINDOWS\system32\drivers\vaxscsi.sys
2007-11-14 06:00 ——— d—–w C:\Program Files\Google
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2004-06-09 06:01 1,822,848 —-a-w C:\Documents and Settings\DLA Writing.temp\INSNTMSI.EXE
2004-06-09 06:01 1,709,160 —-a-w C:\Documents and Settings\DLA Writing.temp\INS9XMSI.EXE
2004-01-23 07:00 462,848 —-a-w C:\Documents and Settings\DLA Writing.temp\Setup.exe
2006-01-02 17:49 321 –sha-w C:\WINDOWS\system32\ospcont.dat
.
——w			79,224 2008-01-04 18:22:44  C:\Program Files\Alwil Software\Avast4\ashDisp .exe
—-a-w		   258,048 2008-01-04 18:21:38  C:\WINDOWS\system32\00THotkey .exe


((((((((((((((((((((((((((((( snapshot@2008-01-04_13.50.49.52 )))))))))))))))))))))))))))))))))))))))))
.
- 2004-08-04 07:56:48 15,360 —-a-w C:\WINDOWS\system32\ctfmon.exe
+ 2008-01-03 22:35:29 15,360 —-a-w C:\WINDOWS\system32\ctfmon.exe
+ 2008-01-04 18:21:34 122,939 —-a-w C:\WINDOWS\system32\dla\tfswctrl.exe
- 2004-08-04 07:56:48 15,360 -c–a-w C:\WINDOWS\system32\dllcache\ctfmon.exe
+ 2008-01-03 22:35:29 15,360 -c–a-w C:\WINDOWS\system32\dllcache\ctfmon.exe
+ 2005-05-24 17:27:16 213,048 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 20:47:20 94,208 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 20:49:54 950,272 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2008-01-04 13:22 65536]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-01-04 13:24 22880040]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-01-03 17:35 15360]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2008-01-04 13:23 313472]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-01-04 13:23 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"00THotkey"="C:\WINDOWS\system32\00THotkey.exe" [ ]
"000StTHK"="000StTHK.exe" [2001-06-23 20:28 24576 C:\WINDOWS\system32\000StTHK.exe]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2008-01-04 13:21 192512]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2008-01-04 13:21 122939]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2008-01-04 13:21 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2008-01-04 13:21 118784]
"SigmaTel StacMon"="C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe" [2008-01-04 13:21 86073]
"AGRSMMSG"="AGRSMMSG.exe" [2004-02-20 15:00 88363 C:\WINDOWS\agrsmmsg.exe]
"PadTouch"="C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe" [2008-01-04 13:22 1089589]
"PINGER"="C:\TOSHIBA\IVP\ISM\pinger.exe" [2008-01-04 13:22 151552]
"TPSMain"="TPSMain.exe" [2004-06-01 20:43 278528 C:\WINDOWS\system32\TPSMain.exe]
"x3watchpro"="C:\Program Files\X3watchpro\x3watchpro.exe" [2008-01-04 13:22 409600]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-01-04 13:22 33648]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 08:00 79224]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2008-01-04 13:22 132496]

C:\Documents and Settings\Bryce Helsel\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50]
Webshots.lnk - C:\Program Files\Webshots\Launcher.exe [2006-07-19 22:13:20]


.
Contents of the 'Scheduled Tasks' folder
"2007-12-29 23:35:13 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-05 16:49:07 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-01-05 14:14:30 C:\WINDOWS\Tasks\User_Feed_Synchronization-{EC38B375-0340-4869-8D44-280E8199B66E}.job"
- C:\WINDOWS\system32\msfeedssync.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-05 12:26:51
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-05 12:28:24
ComboFix-quarantined-files.txt 2008-01-05 17:28:08
ComboFix2.txt 2008-01-04 23:07:14
ComboFix3.txt 2008-01-04 18:51:09
.
2007-12-12 04:26:47 — E O F —


HERE IS THE HIJACK THIS LOG:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:34:20 PM, on 1/5/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\System32\svchost.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\TPSMain.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\iseeu.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/1me10enus/2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/1me10enus/2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/1me10enus/2
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: (no name) - {736b5468-bdad-41be-92d0-22ae2ddf7bcb} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\system32\00THotkey.exe
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SigmaTel StacMon] C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [PINGER] C:\TOSHIBA\IVP\ISM\pinger.exe /run
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [x3watchpro] C:\Program Files\X3watchpro\x3watchpro.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {2B1AA38D-2D12-11D5-AAD0-00C04FA03D78} (LocalExec Control) - https://my.uga.edu/nps/portal/gadgets/com.n…t/LocalExec.CAB
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo…toUploader3.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1132753115798
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1132847722513
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe

–
End of file - 9216 bytes
Hi

Almost there.

Remember to disconnect from the Internet and disable your anti-virus before carrying out the next instruction, and to reenable the anti-virus before reconnecting to the Internet


Open Notepad - it must be Notepad, not Wordpad.
Copy the text below in the code box by highlighting all the text with your mouse and pressing Ctrl+C

RenV::
——w			79,224 2008-01-04 18:22:44  C:\Program Files\Alwil Software\Avast4\ashDisp .exe
—-a-w		   258,048 2008-01-04 18:21:38  C:\WINDOWS\system32\[u]0[/u]0THotkey .exe

Go to the Notepad window and click Edit > Paste
Then click File > Save
Name the file "CFScript.txt" (including the quotes)
Save the file to your Desktop

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe

Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task-Manager use the Processes tab (press ctrl alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.

Step 2:

You will need to run the Kaspersky Online Scanner again, something Ive never had to instruct someone to do before, so it may have an entry in All Programs or it may not. If it does start it up and make sure it is up to date. And remember to scan all areas and save a report.

If not, uninstall it through Add/Remove Programs and follow my previous instructions on how to use it.

In your next reply post:
Kaspersky report
ComboFix.txt
New HJT log taken after the above scan has run
HERE IS THE KASPERKY LOG:

Saturday, January 05, 2008 5:28:16 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 5/01/2008
Kaspersky Anti-Virus database records: 503016


Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true

Scan Target My Computer
C:\
D:\
E:\
G:\

Scan Statistics
Total number of scanned objects 63659
Number of viruses found 21
Number of infected objects 278
Number of suspicious objects 0
Duration of the scan process 02:53:36

Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped

C:\Documents and Settings\Bryce Helsel\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\Bryce Helsel\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\Bryce Helsel\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\Bryce Helsel\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Bryce Helsel\Local Settings\Temp\~DF298.tmp Object is locked skipped

C:\Documents and Settings\Bryce Helsel\Local Settings\Temp\~DF2C4D.tmp Object is locked skipped

C:\Documents and Settings\Bryce Helsel\Local Settings\Temp\~DF2C5B.tmp Object is locked skipped

C:\Documents and Settings\Bryce Helsel\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped

C:\Documents and Settings\Bryce Helsel\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Bryce Helsel\ntuser.dat Object is locked skipped

C:\Documents and Settings\Bryce Helsel\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped

C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped

C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped

C:\QooBox\Quarantine\C\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\QooBox\Quarantine\C\Program Files\Apoint2K\Apoint.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\QooBox\Quarantine\C\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\QooBox\Quarantine\C\Program Files\Java\jre1.6.0_03\bin\jusched.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\QooBox\Quarantine\C\Program Files\kernel\kernel.exe.vir Infected: Trojan-Downloader.Win32.Adload.pn skipped

C:\QooBox\Quarantine\C\Program Files\Microsoft Office\Office12\GrooveMonitor.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\QooBox\Quarantine\C\Program Files\MsMovies\p.zip.vir/Video.exe Infected: Trojan-Dropper.Win32.WinAD.h skipped

C:\QooBox\Quarantine\C\Program Files\MsMovies\p.zip.vir ZIP: infected - 1 skipped

C:\QooBox\Quarantine\C\Program Files\QuickTime\qttask .exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\QooBox\Quarantine\C\Program Files\QuickTime\qttask .exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\QooBox\Quarantine\C\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\QooBox\Quarantine\C\Program Files\Skype\Phone\Skype.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\QooBox\Quarantine\C\Program Files\Toshiba\TOSCDSPD\toscdspd.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\QooBox\Quarantine\C\Program Files\Toshiba\Touch and Launch\PadExe.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\QooBox\Quarantine\C\Program Files\X3watchpro\x3watchpro.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\QooBox\Quarantine\C\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\QooBox\Quarantine\C\temp\ytesm1220.exe.vir/data0002 Infected: Trojan-Downloader.Win32.Small.buy skipped

C:\QooBox\Quarantine\C\temp\ytesm1220.exe.vir/data0003 Infected: Trojan-Downloader.Win32.Small.hkt skipped

C:\QooBox\Quarantine\C\temp\ytesm1220.exe.vir/data0004 Infected: Trojan.Win32.Pakes.bvs skipped

C:\QooBox\Quarantine\C\temp\ytesm1220.exe.vir/data0005/data0002 Infected: not-a-virus:AdWare.Win32.TTC.a skipped

C:\QooBox\Quarantine\C\temp\ytesm1220.exe.vir/data0005 Infected: not-a-virus:AdWare.Win32.TTC.a skipped

C:\QooBox\Quarantine\C\temp\ytesm1220.exe.vir NSIS: infected - 5 skipped

C:\QooBox\Quarantine\C\TOSHIBA\IVP\ISM\pinger.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\00THotkey.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\ctfmon.exe.tmp.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\dla\tfswctrl.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\hkcmd.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\igfxtray.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\xxyaw.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\QooBox\Quarantine\catchme2008-01-04_134808.21.zip/xxyaw.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.dih skipped

C:\QooBox\Quarantine\catchme2008-01-04_134808.21.zip ZIP: infected - 1 skipped

C:\SDFix\backups\backups.zip/backups/b122.exe Infected: Trojan-Downloader.Win32.Agent.haq skipped

C:\SDFix\backups\backups.zip/backups/core.sys Infected: Rootkit.Win32.Agent.sg skipped

C:\SDFix\backups\backups.zip/backups/Crack.exe Infected: Trojan.Win32.Agent.cmn skipped

C:\SDFix\backups\backups.zip/backups/kernInstall.exe Infected: Trojan-Downloader.Win32.Agent.haq skipped

C:\SDFix\backups\backups.zip/backups/tem16A.tmp.exe/data0002 Infected: not-a-virus:AdWare.Win32.Agent.jb skipped

C:\SDFix\backups\backups.zip/backups/tem16A.tmp.exe Infected: not-a-virus:AdWare.Win32.Agent.jb skipped

C:\SDFix\backups\backups.zip/backups/winlogon.exe Infected: not-a-virus:PSWTool.Win32.PassView.p skipped

C:\SDFix\backups\backups.zip ZIP: infected - 7 skipped

C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059301.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059309.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059314.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059315.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059316.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059317.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059318.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059319.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059320.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059321.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059322.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059323.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059324.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059325.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059326.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059327.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059328.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059329.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP779\A0059331.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059347.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059348.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059351.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059352.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059353.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059354.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059355.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059356.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059357.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059358.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059359.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059360.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059361.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059362.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059363.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059364.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059365.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059366.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059367.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059370.exe Infected: Trojan.Win32.Agent.cmn skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP780\A0059371.exe Infected: Trojan.Win32.Agent.cmn skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059402.exe Infected: not-a-virus:AdWare.Win32.Agent.zk skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059480.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059489.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059491.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059502.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059504.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059505.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059506.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059507.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059509.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059511.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059512.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059513.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059514.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059515.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059516.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059518.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059519.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059520.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059521.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059527.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059535.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059542.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059543.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059546.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059547.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059549.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059550.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059551.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059552.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059553.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059554.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059559.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059560.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059561.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059563.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059566.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059567.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059568.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP781\A0059577.exe Infected: Trojan.Win32.Agent.cmn skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059626.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059816.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059818.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059826.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059828.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059829.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059830.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059831.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059832.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059833.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059835.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059836.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059838.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059839.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059840.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059844.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059845.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059847.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059849.exe Infected: Trojan.Win32.Agent.cmn skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059855.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP782\A0059874.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059882.exe Infected: Trojan-Downloader.Win32.Agent.gwh skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059883.exe Infected: Trojan.Win32.Zapchast.ca skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059884.exe Infected: Trojan.Win32.Zapchast.ca skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059885.exe Infected: Trojan.Win32.Zapchast.ca skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059886.exe Infected: Trojan.Win32.Zapchast.ca skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059887.exe Infected: Trojan.Win32.Zapchast.ca skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059888.exe Infected: Trojan.Win32.Zapchast.ca skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059889.exe Infected: Trojan.Win32.Zapchast.ca skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059891.exe Infected: Trojan.Win32.Zapchast.ca skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059892.exe Infected: Trojan.Win32.Zapchast.ca skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059893.exe Infected: Trojan.Win32.Zapchast.ca skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059895.exe Infected: Trojan.Win32.Zapchast.ca skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059896.exe Infected: Trojan.Win32.Zapchast.ca skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059897.exe Infected: not-a-virus:AdWare.Win32.NewDotNet.e skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059898.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059899.exe Infected: Trojan-Downloader.Win32.VB.caw skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059902.dll Infected: Trojan-Downloader.Win32.Small.hlf skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059903.dll Infected: Trojan-Downloader.Win32.Small.hlf skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059904.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.dih skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059905.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.din skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059907.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059944.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059947.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059956.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059957.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059958.exe Infected: Trojan-Downloader.Win32.Adload.pn skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059960.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059961.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059962.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059963.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059964.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059965.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059966.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059967.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059968.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059969.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059971.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP783\A0059973.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0059997.rbf Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060050.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060086.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060088.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060101.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060104.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060105.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060106.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060107.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060108.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060109.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060111.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060112.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060113.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060115.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060117.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060120.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060121.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060122.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060123.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060124.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP784\A0060129.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060470.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060474.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060475.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060485.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060493.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060497.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060503.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060510.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060516.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060521.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060528.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060533.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060537.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060541.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060542.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060544.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060545.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060546.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060547.exe Infected: Trojan-Downloader.Win32.Agent.haq skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060549.exe Infected: not-a-virus:PSWTool.Win32.PassView.p skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060550.exe Infected: Trojan-Downloader.Win32.Agent.haq skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060551.exe Infected: Trojan.Win32.Agent.cmn skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060553.sys Infected: Rootkit.Win32.Agent.sg skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060561.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060563.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060564.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060565.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060566.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060567.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060568.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060569.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060570.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060571.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060572.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060573.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060574.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060575.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060576.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060577.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060578.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060579.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060580.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060581.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060585.exe Infected: Trojan-Downloader.Win32.Agent.haq skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060587.sys Infected: Rootkit.Win32.Agent.sg skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060588.exe Infected: Trojan.Win32.Agent.cmn skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060589.exe Infected: Trojan-Downloader.Win32.Agent.haq skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060593.exe/data0002 Infected: not-a-virus:AdWare.Win32.Agent.jb skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060593.exe NSIS: infected - 1 skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060596.exe Infected: not-a-virus:PSWTool.Win32.PassView.p skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060631.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP787\A0060638.exe Infected: Trojan-Downloader.Win32.Adload.pn skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP788\A0060641.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP788\A0060642.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060644.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060645.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060646.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060647.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060648.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060649.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060650.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060651.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060652.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060653.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060654.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060655.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060657.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060658.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060659.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060660.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060663.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060664.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP789\A0060671.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.dih skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP790\A0060756.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP790\A0060760.exe Infected: Trojan-Downloader.Win32.Adload.pn skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP790\A0060762.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP790\A0060771.exe Infected: Trojan.Win32.Agent.cmn skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP791\A0060785.exe Infected: Trojan-Downloader.Win32.Adload.pn skipped

C:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP792\change.log Object is locked skipped

C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

C:\WINDOWS\SchedLgU.Txt Object is locked skipped

C:\WINDOWS\SFA02EC7C.tmp Object is locked skipped

C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped

C:\WINDOWS\Sti_Trace.log Object is locked skipped

C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped

C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped

C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped

C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\default Object is locked skipped

C:\WINDOWS\system32\config\default.LOG Object is locked skipped

C:\WINDOWS\system32\config\Internet.evt Object is locked skipped

C:\WINDOWS\system32\config\ODiag.evt Object is locked skipped

C:\WINDOWS\system32\config\OSession.evt Object is locked skipped

C:\WINDOWS\system32\config\SAM Object is locked skipped

C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped

C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\SECURITY Object is locked skipped

C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped

C:\WINDOWS\system32\config\software Object is locked skipped

C:\WINDOWS\system32\config\software.LOG Object is locked skipped

C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\system Object is locked skipped

C:\WINDOWS\system32\config\system.LOG Object is locked skipped

C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped

C:\WINDOWS\system32\h323log.txt Object is locked skipped

C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

C:\WINDOWS\Temp\Perflib_Perfdata_61c.dat Object is locked skipped

C:\WINDOWS\wiadebug.log Object is locked skipped

C:\WINDOWS\wiaservc.log Object is locked skipped

C:\WINDOWS\WindowsUpdate.log Object is locked skipped

G:\System Volume Information\_restore{D4242EAB-D9B1-4440-A1AD-74C1FF54E125}\RP792\change.log Object is locked skipped

Scan process completed.


HERE IS THE COMBOFIX LOG:

ComboFix 08-01-04.1 - Bryce Helsel 2008-01-05 13:56:06.4 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Bryce Helsel\Desktop\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2007-12-05 to 2008-01-05 )))))))))))))))))))))))))))))))
.

2008-01-05 10:51 . 2008-01-04 13:21 155,648 –a—— C:\WINDOWS\system32\igfxtray.exe
2008-01-05 10:51 . 2008-01-04 13:21 118,784 –a—— C:\WINDOWS\system32\hkcmd.exe
2008-01-04 18:10 . 2008-01-04 18:10 d——– C:\WINDOWS\system32\Kaspersky Lab
2008-01-04 18:10 . 2008-01-04 18:10 d——– C:\WINDOWS\LastGood
2008-01-04 18:10 . 2008-01-04 18:10 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-01-04 13:31 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-04 12:27 . 2008-01-04 12:28 d——– C:\WINDOWS\ERUNT
2008-01-04 02:36 . 2008-01-04 02:36 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-01-04 02:36 . 2008-01-04 02:36 1,409 –a—— C:\WINDOWS\QTFont.for
2008-01-03 17:17 . 2008-01-03 17:17 d——– C:\Program Files\Trend Micro
2008-01-03 15:09 . 2008-01-03 15:09 d——– C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-01-03 15:08 . 2008-01-05 10:46 d——– C:\Program Files\SUPERAntiSpyware
2008-01-03 14:57 . 2008-01-03 17:13 d——– C:\Program Files\RogueRemover FREE
2008-01-03 13:38 . 2008-01-03 13:38 d——– C:\Documents and Settings\Bryce Helsel\Application Data\PrevxCSI
2008-01-03 13:38 . 2008-01-03 13:38 d——– C:\Documents and Settings\All Users\Application Data\Prevx
2008-01-03 13:32 . 2007-12-04 09:53 23,152 –a—— C:\WINDOWS\system32\drivers\aswRdr.sys
2008-01-03 13:31 . 2007-12-04 08:04 837,496 –a—— C:\WINDOWS\system32\aswBoot.exe
2008-01-03 13:31 . 2004-01-09 04:13 380,928 –a—— C:\WINDOWS\system32\actskin4.ocx
2008-01-03 13:31 . 2007-12-04 07:54 95,608 –a—— C:\WINDOWS\system32\AVASTSS.scr
2008-01-03 13:31 . 2007-12-04 09:55 94,544 –a—— C:\WINDOWS\system32\drivers\aswmon2.sys
2008-01-03 13:31 . 2007-12-04 09:56 93,264 –a—— C:\WINDOWS\system32\drivers\aswmon.sys
2008-01-03 13:31 . 2007-12-04 09:51 42,912 –a—— C:\WINDOWS\system32\drivers\aswTdi.sys
2008-01-03 13:31 . 2007-12-04 09:49 26,624 –a—— C:\WINDOWS\system32\drivers\aavmker4.sys
2008-01-02 01:49 . 2008-01-02 01:49 d——– C:\Program Files\Lavasoft
2008-01-02 01:49 . 2008-01-02 01:49 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-02 01:45 . 2008-01-03 17:15 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-01-02 01:19 . 2008-01-04 13:21 258,048 –a—— C:\WINDOWS\system32\00THotkey .exe
2007-12-31 20:53 . 2007-12-31 20:53 d——– C:\Documents and Settings\Bryce Helsel\Incomplete
2007-12-31 20:51 . 2007-12-31 20:51 147,456 –a—— C:\WINDOWS\system32\vbzip10.dll
2007-12-31 20:46 . 2008-01-03 11:41 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-31 19:51 . 2007-12-31 19:51 d——– C:\WINDOWS\Cache
2007-12-31 17:05 . 2004-11-15 15:37 264,440 –a—— C:\WINDOWS\system32\drivers\stac97.sys
2007-12-30 18:34 . 2007-12-31 15:39 d——– C:\Program Files\Tunebite
2007-12-30 18:32 . 2007-12-30 18:32 d——– C:\Program Files\BitZipper
2007-12-30 18:32 . 2007-12-30 18:32 d——– C:\Documents and Settings\Bryce Helsel\Application Data\BitZipper
2007-12-30 17:09 . 2007-12-30 17:09 d——– C:\Documents and Settings\Bryce Helsel\Application Data\RTPlayer
2007-12-30 16:59 . 2007-12-31 15:37 d——– C:\Documents and Settings\Bryce Helsel\Application Data\tunebite
2007-12-26 22:33 . 2007-12-26 22:33 d——– C:\Program Files\NCH Software
2007-12-26 22:33 . 2007-12-26 22:33 d——– C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
2007-12-26 22:29 . 2007-12-26 22:46 d——– C:\Program Files\NCH Swift Sound
2007-12-26 22:29 . 2007-12-26 22:39 d——– C:\Documents and Settings\Bryce Helsel\Application Data\NCH Swift Sound
2007-12-26 21:33 . 2007-12-26 21:33 d——– C:\Program Files\Western Digital Technologies
2007-12-26 21:12 . 2007-12-26 21:12 d——– C:\Program Files\Common Files\ArcSoft
2007-12-26 21:12 . 2007-12-26 21:15 d——– C:\Documents and Settings\Bryce Helsel\Application Data\ArcSoft
2007-12-26 21:12 . 2005-02-23 14:58 11,776 –a—— C:\WINDOWS\system32\drivers\afc.sys
2007-12-26 21:11 . 2007-12-26 21:11 d——– C:\WINDOWS\system32\PhotoImpression Slideshow
2007-12-26 21:11 . 2007-12-26 21:11 d——– C:\Program Files\ArcSoft
2007-12-26 21:11 . 2005-04-27 16:36 245,408 –a—— C:\WINDOWS\system32\unicows.dll
2007-12-26 21:11 . 1995-08-01 04:44 212,480 –a—— C:\WINDOWS\PCDLIB32.DLL
2007-12-26 21:11 . 2006-10-20 16:11 126,976 –a—— C:\WINDOWS\system32\PhotoImpression Slideshow.scr
2007-12-17 15:53 . 2008-01-05 10:45 d——– C:\Program Files\QuickTime
2007-12-11 17:34 . 2007-12-11 17:34 1,044,480 –a—— C:\WINDOWS\system32\libdivx.dll
2007-12-11 17:34 . 2007-12-11 17:34 200,704 –a—— C:\WINDOWS\system32\ssldivx.dll
2007-12-11 16:56 . 2007-12-11 16:56 d——– C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
2007-12-11 10:57 . 2007-12-11 10:57 65,536 –a—— C:\WINDOWS\system32\QuickTimeVR.qtx
2007-12-11 10:57 . 2007-12-11 10:57 49,152 –a—— C:\WINDOWS\system32\QuickTime.qts
2007-12-08 19:14 . 2007-12-08 19:14 d——– C:\Program Files\iPod
2007-12-08 19:13 . 2007-12-08 19:14 d——– C:\Program Files\iTunes
2007-12-08 19:03 . 2007-12-08 19:03 d——– C:\Program Files\Common Files\Apple
2007-12-08 17:44 . 2007-12-08 17:44 d——– C:\Program Files\Windows Live Toolbar

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-05 15:46 ——— d—–w C:\Program Files\X3watchpro
2008-01-05 15:45 ——— d—–w C:\Program Files\Apoint2K
2008-01-04 18:27 ——— d—–w C:\Documents and Settings\Bryce Helsel\Application Data\Skype
2008-01-04 17:19 ——— d—–w C:\Program Files\Java
2008-01-04 08:16 ——— d–h–w C:\Documents and Settings\Bryce Helsel\Application Data\x3watchpro
2008-01-03 16:47 ——— d—–w C:\Documents and Settings\Bryce Helsel\Application Data\LimeWire
2008-01-01 21:00 ——— d—–w C:\Documents and Settings\Bryce Helsel\Application Data\Ruckus Network
2007-12-31 22:09 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-31 22:09 ——— d—–w C:\Program Files\SigmaTel
2007-12-31 21:49 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-12-31 06:58 ——— d—–w C:\Documents and Settings\Bryce Helsel\Application Data\uTorrent
2007-12-19 23:25 ——— d—–w C:\Program Files\DivX
2007-11-29 21:24 ——— d—–w C:\Documents and Settings\All Users\Application Data\Nero
2007-11-29 13:40 ——— d—–w C:\Program Files\MSXML 4.0
2007-11-28 01:29 ——— d—–w C:\Documents and Settings\Bryce Helsel\Application Data\Nero
2007-11-15 20:24 ——— d—–w C:\Program Files\MagicDisc
2007-11-15 05:46 ——— d—–w C:\Documents and Settings\Bryce Helsel\Application Data\MSN6
2007-11-15 05:03 ——— d—–w C:\Program Files\Creative
2007-11-15 04:42 ——— d—–w C:\Documents and Settings\All Users\Application Data\WinZip
2007-11-14 07:07 ——— d—–w C:\Program Files\Microsoft Works
2007-11-14 07:06 ——— d—–w C:\Program Files\MSBuild
2007-11-14 07:03 ——— d—–w C:\Program Files\Microsoft.NET
2007-11-14 06:53 ——— d—–w C:\Program Files\Microsoft Visual Studio 8
2007-11-14 06:07 ——— d—–w C:\Program Files\MagicISO
2007-11-14 06:04 223,128 —-a-w C:\WINDOWS\system32\drivers\vaxscsi.sys
2007-11-14 06:00 ——— d—–w C:\Program Files\Google
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2004-06-09 06:01 1,822,848 —-a-w C:\Documents and Settings\DLA Writing.temp\INSNTMSI.EXE
2004-06-09 06:01 1,709,160 —-a-w C:\Documents and Settings\DLA Writing.temp\INS9XMSI.EXE
2004-01-23 07:00 462,848 —-a-w C:\Documents and Settings\DLA Writing.temp\Setup.exe
2006-01-02 17:49 321 –sha-w C:\WINDOWS\system32\ospcont.dat
.
——w			79,224 2008-01-04 18:22:44  C:\Program Files\Alwil Software\Avast4\ashDisp .exe
—-a-w		   258,048 2008-01-04 18:21:38  C:\WINDOWS\system32\00THotkey .exe


((((((((((((((((((((((((((((( snapshot@2008-01-04_13.50.49.52 )))))))))))))))))))))))))))))))))))))))))
.
- 2004-08-04 07:56:48 15,360 —-a-w C:\WINDOWS\system32\ctfmon.exe
+ 2008-01-03 22:35:29 15,360 —-a-w C:\WINDOWS\system32\ctfmon.exe
+ 2008-01-04 18:21:34 122,939 —-a-w C:\WINDOWS\system32\dla\tfswctrl.exe
- 2004-08-04 07:56:48 15,360 -c–a-w C:\WINDOWS\system32\dllcache\ctfmon.exe
+ 2008-01-03 22:35:29 15,360 -c–a-w C:\WINDOWS\system32\dllcache\ctfmon.exe
+ 2005-05-24 17:27:16 213,048 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 20:47:20 94,208 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 20:49:54 950,272 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2008-01-04 13:22 65536]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-01-04 13:24 22880040]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-01-03 17:35 15360]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2008-01-04 13:23 313472]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-01-04 13:23 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"00THotkey"="C:\WINDOWS\system32\00THotkey.exe" [ ]
"000StTHK"="000StTHK.exe" [2001-06-23 20:28 24576 C:\WINDOWS\system32\000StTHK.exe]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2008-01-04 13:21 192512]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2008-01-04 13:21 122939]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2008-01-04 13:21 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2008-01-04 13:21 118784]
"SigmaTel StacMon"="C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe" [2008-01-04 13:21 86073]
"AGRSMMSG"="AGRSMMSG.exe" [2004-02-20 15:00 88363 C:\WINDOWS\agrsmmsg.exe]
"PadTouch"="C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe" [2008-01-04 13:22 1089589]
"PINGER"="C:\TOSHIBA\IVP\ISM\pinger.exe" [2008-01-04 13:22 151552]
"TPSMain"="TPSMain.exe" [2004-06-01 20:43 278528 C:\WINDOWS\system32\TPSMain.exe]
"x3watchpro"="C:\Program Files\X3watchpro\x3watchpro.exe" [2008-01-04 13:22 409600]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-01-04 13:22 33648]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 08:00 79224]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2008-01-04 13:22 132496]

C:\Documents and Settings\Bryce Helsel\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50]
Webshots.lnk - C:\Program Files\Webshots\Launcher.exe [2006-07-19 22:13:20]

S3 Camdrv30;Philips ToUcam XS;C:\WINDOWS\system32\Drivers\camdrv30.sys [2001-01-25 02:40]
S3 tbhsd;Tunebite High-Speed Dubbing;C:\WINDOWS\system32\drivers\tbhsd.sys []

.
Contents of the 'Scheduled Tasks' folder
"2007-12-29 23:35:13 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-05 18:49:00 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-01-05 14:14:30 C:\WINDOWS\Tasks\User_Feed_Synchronization-{EC38B375-0340-4869-8D44-280E8199B66E}.job"
- C:\WINDOWS\system32\msfeedssync.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-05 14:00:36
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-05 14:04:25
ComboFix-quarantined-files.txt 2008-01-05 19:03:59
ComboFix2.txt 2008-01-05 17:28:24
ComboFix3.txt 2008-01-04 23:07:14
ComboFix4.txt 2008-01-04 18:51:09
.
2007-12-12 04:26:47 — E O F —


HERE IS THE HIJACKTHIS LOG:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:30:41 PM, on 1/5/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\System32\svchost.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\TPSMain.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Trend Micro\HijackThis\iseeu.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/1me10enus/2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/1me10enus/2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/1me10enus/2
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: (no name) - {736b5468-bdad-41be-92d0-22ae2ddf7bcb} - (no file)
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\system32\00THotkey.exe
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SigmaTel StacMon] C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [PINGER] C:\TOSHIBA\IVP\ISM\pinger.exe /run
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [x3watchpro] C:\Program Files\X3watchpro\x3watchpro.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O8 - Extra context menu item: &Windows; Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {2B1AA38D-2D12-11D5-AAD0-00C04FA03D78} (LocalExec Control) - https://my.uga.edu/nps/portal/gadgets/com.n…t/LocalExec.CAB
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo…toUploader3.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1132753115798
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1132847722513
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe

–
End of file - 9393 bytes

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI