This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Please help

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

AVG continually finds something called jkhhe.exe (or something), deletes it, and finds it again a day or so down the road. I'm assuming there is a virus that is re-installing this file. In addition, I have a lot of spyware symptoms, including lots of normal site ads replaced with "you are infected" ads, and sometimes a new browser window opening on its own with a "scan your computer" prompt. Also get some occasional browser windows opening on their own to advertizements for pornography. Here are the log files… I am currently running a selective startup in msconfig with no enabled startup items so as to slow things down… I haven't run anything except an AVG rootkit scan (which came up empty) since my last reboot. Thanks in advance for any help. :)

Logfile of HijackThis v1.99.1
Scan saved at 6:27:38 PM, on 1/6/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\ehome\RMSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [url="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=PRESARIO&pf=desktop"]http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop[/url]
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [url="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PRESARIO&pf=desktop"]http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop[/url]
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = [url="http://www.comcast.net/toolbar2.0/search/"]http://www.comcast.net/toolbar2.0/search/[/url]
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = [url="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PRESARIO&pf=desktop"]http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop[/url]
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [url="http://www.comcast.net/comcast.html"]http://www.comcast.net/comcast.html[/url]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [url="http://go.microsoft.com/fwlink/?LinkId=69157"]http://go.microsoft.com/fwlink/?LinkId=69157[/url]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [url="http://go.microsoft.com/fwlink/?LinkId=54896"]http://go.microsoft.com/fwlink/?LinkId=54896[/url]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = [url="http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PRESARIO&pf=desktop"]http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop[/url]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [url="http://go.microsoft.com/fwlink/?LinkId=54896"]http://go.microsoft.com/fwlink/?LinkId=54896[/url]
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [url="http://go.microsoft.com/fwlink/?LinkId=69157"]http://go.microsoft.com/fwlink/?LinkId=69157[/url]
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = [url="http://www.comcast.net/toolbar2.0/search/"]http://www.comcast.net/toolbar2.0/search/[/url]
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {483EB14D-AF1C-4951-81B0-4E2B41829FF6} (QOLCheck Control) - [url="https://www.select2perform.com/cabs/QOLCheck.ocx"]https://www.select2perform.com/cabs/QOLCheck.ocx[/url]
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - [url="http://aolsvc.aol.com/onlinegames/trydinerdash2/DinerDash2.1.0.0.67.cab"]http://aolsvc.aol.com/onlinegames/trydiner…h2.1.0.0.67.cab[/url]
O16 - DPF: {6FE79ACA-A498-45E5-8BC4-1B9F380CE468} (Abx(gh) Control) - [url="http://aolsvc.aol.com/onlinegames/ghadventureball/abxgh.cab"]http://aolsvc.aol.com/onlinegames/ghadventureball/abxgh.cab[/url]
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - [url="http://mediaplayer.walmart.com/installer/install.cab"]http://mediaplayer.walmart.com/installer/install.cab[/url]
O16 - DPF: {74E4A24D-5224-4F05-8A41-99445E0FC22B} (GameHouse Games Player) - [url="http://aolsvc.aol.com/onlinegames/free-trial-mind-medley/gamehouseplayer.cab"]http://aolsvc.aol.com/onlinegames/free-tri…houseplayer.cab[/url]
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - [url="http://tsweb.covenanttransport.com/msrdp.cab"]http://tsweb.covenanttransport.com/msrdp.cab[/url]
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - [url="http://aolsvc.aol.com/onlinegames/free-trial-yahtzee/zylomplayer.cab"]http://aolsvc.aol.com/onlinegames/free-tri…zylomplayer.cab[/url]
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - [url="http://aolsvc.aol.com/onlinegames/popinsaniquarium/popcaploader_v10.cab"]http://aolsvc.aol.com/onlinegames/popinsan…ploader_v10.cab[/url]
O16 - DPF: {EA6246B4-F380-443F-8727-9AEA3371146C} (CPlayFirstWeddingDashControl Object) - [url="http://aolsvc.aol.com/onlinegames/free-trial-wedding-dash/WeddingDash.1.0.0.47.cab"]http://aolsvc.aol.com/onlinegames/free-tri…sh.1.0.0.47.cab[/url]
O17 - HKLM\System\CCS\Services\Tcpip\..\{21F89065-A8B4-4677-BBC4-B7B87A2FFE53}: NameServer = 85.255.116.157,85.255.112.166
O17 - HKLM\System\CCS\Services\Tcpip\..\{30E026DC-E3D4-4016-B6F3-4263E33ABBAD}: NameServer = 85.255.116.157,85.255.112.166
O17 - HKLM\System\CCS\Services\Tcpip\..\{892900FC-9814-4488-99C0-81491C1EE93D}: NameServer = 85.255.116.157,85.255.112.166
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.157 85.255.112.166
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.157 85.255.112.166
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
Hello smijer and welcome to the What the Tech Forums

My name is Trevuren and I will be helping you with your problem. You have several infections running at once so we will go after them once at a time.


A. Please just copy/paste your reports/logs into your replies instead of using codeboxes. It makes it easier on our eyes and enables us to get an easier global view of the situation.


B. Some trojans have a way of masking their presence from the HijackThis program when they recognise the name. I think that this is the case here because there are no 02 or 020 entries visible in your log.

Please locate the following file on your desktop: HijackThis.exe
Next, right click on the file and from the popup menu that appears, chose the RENAME option and rename the file Killer.exe.

From now on, when I ask you to start HijackThis, just click on the Killer.exe file.


C. Please download FixWareout from the following site:
http://download.bleepingcomputer.com/lonny/Fixwareout.exe

Save it to your desktop and run it. Click Next, then Install, make sure "Run fixit" is checked and click Finish.
The fix will begin; follow the prompts.
You will be asked to reboot your computer; please do so.
Your system may take longer than usual to load; this is normal.
Please post the text that will open (report.txt) and a new Hijackthis log.
I do very much appreciate your help. The logs you asked for:

Fixware:
Username "Compaq_Administrator" - 01/06/2008 20:57:35 [Fixwareout edited 9/01/2007]

~~~~~ Prerun check
HKLM\SOFTWARE\~\Winlogon\ "System"="kdkrm.exe"

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters
"nameserver"="85.255.116.157 85.255.112.166" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{21F89065-A8B4-4677-BBC4-B7B87A2FFE53}
"nameserver"="85.255.116.157,85.255.112.166" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{30E026DC-E3D4-4016-B6F3-4263E33ABBAD}
"nameserver"="85.255.116.157,85.255.112.166" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{892900FC-9814-4488-99C0-81491C1EE93D}
"nameserver"="85.255.116.157,85.255.112.166" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{30E026DC-E3D4-4016-B6F3-4263E33ABBAD}
"DhcpNameServer"="[removed],[removed]" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{4D589907-2D53-4DBA-8511-D302D05BE3EB}
"DhcpNameServer"="[removed],[removed]" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{892900FC-9814-4488-99C0-81491C1EE93D}
"DhcpNameServer"="[removed],[removed]"
Successfully flushed the DNS Resolver Cache.


System was rebooted successfully.

~~~~~ Postrun check
HKLM\SOFTWARE\~\Winlogon\ "system"=""
….
….
~~~~~ Misc files.
….
~~~~~ Checking for older varients.
….


C:\Program Files\UltimateBet < Found
Additional tools are recommended.

~~~~~ Current runs (hklm hkcu "run" Keys Only)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
….
Hosts file was reset, If you use a custom hosts file please replace it…
~~~~~ End report ~~~~~

and… killer:
Logfile of HijackThis v1.99.1
Scan saved at 9:05:33 PM, on 1/6/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\ehome\RMSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.comcast.net/toolbar2.0/search/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/comcast.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.comcast.net/toolbar2.0/search/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {483EB14D-AF1C-4951-81B0-4E2B41829FF6} (QOLCheck Control) - https://www.select2perform.com/cabs/QOLCheck.ocx
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - http://aolsvc.aol.com/onlinegames/trydiner…h2.1.0.0.67.cab
O16 - DPF: {6FE79ACA-A498-45E5-8BC4-1B9F380CE468} (Abx(gh) Control) - http://aolsvc.aol.com/onlinegames/ghadventureball/abxgh.cab
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
O16 - DPF: {74E4A24D-5224-4F05-8A41-99445E0FC22B} (GameHouse Games Player) - http://aolsvc.aol.com/onlinegames/free-tri…houseplayer.cab
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://tsweb.covenanttransport.com/msrdp.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://aolsvc.aol.com/onlinegames/free-tri…zylomplayer.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://aolsvc.aol.com/onlinegames/popinsan…ploader_v10.cab
O16 - DPF: {EA6246B4-F380-443F-8727-9AEA3371146C} (CPlayFirstWeddingDashControl Object) - http://aolsvc.aol.com/onlinegames/free-tri…sh.1.0.0.47.cab
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe


thanks again.
Please download ComboFix by sUBs from HERE or HERE
  • You must download it to and run it from your Desktop
  • First, physically disconnect your computer from the internet.
  • Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
  • Double click combofix.exe & follow the prompts.
  • When finished, it will produce a log. Please save that log to post in your next reply along with a fresh HJT log
  • Re-enable all the programs that were disabled during the running of ComboFix.
  • Now you may reconnect your machine to the internet and post the logs

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.
Combofix…

ComboFix 08-01-07.3 - Compaq_Administrator 2008-01-06 21:34:54.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.159 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\Common Files\Yazzle1552OinUninstaller.exe
C:\Program Files\WinBudget
C:\Program Files\WinBudget\bin\matrix.dat
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\ehhkj.ini
C:\WINDOWS\system32\ehhkj.ini2
C:\WINDOWS\system32\jkhhe.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\qxycqxsa.ini
C:\WINDOWS\system32\whgbluhx.ini
D:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2007-12-07 to 2008-01-07 )))))))))))))))))))))))))))))))
.

2008-01-06 21:32 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-06 18:18 . 2008-01-06 18:18 3,584 –a—— C:\WINDOWS\system32\jkhhe.exe
2008-01-06 18:15 . 2007-01-18 07:00 3,968 –a—— C:\WINDOWS\system32\drivers\AvgArCln.sys
2008-01-06 17:00 . 2008-01-06 17:00 d——– C:\Program Files\ComcastToolbar
2008-01-06 17:00 . 2008-01-06 18:00 d——– C:\Documents and Settings\Compaq_Administrator\Application Data\ComcastToolbar
2008-01-01 23:55 . 2008-01-01 23:55 18 –ah—– C:\SYSREST
2008-01-01 22:04 . 2008-01-06 17:05 d——– C:\Documents and Settings\Compaq_Administrator\Application Data\AVG7
2008-01-01 22:03 . 2008-01-01 22:03 d——– C:\Documents and Settings\LocalService\Application Data\AVG7
2008-01-01 22:03 . 2008-01-01 22:03 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-01 22:03 . 2008-01-01 22:20 d——– C:\Documents and Settings\All Users\Application Data\avg7
2008-01-01 21:27 . 2008-01-06 21:44 0 –a—— C:\$bootcln.sch
2008-01-01 21:10 . 2008-01-01 21:10 552 –a—— C:\WINDOWS\system32\d3d8caps.dat
2008-01-01 20:02 . 2008-01-01 20:02 d——– C:\Documents and Settings\All Users\Application Data\McAfee
2007-12-29 18:03 . 2008-01-01 23:39 d——– C:\Program Files\Windows Defender
2007-12-24 20:43 . 2007-12-24 20:43 d——– C:\Program Files\VstPlugins
2007-12-24 20:43 . 2002-07-07 18:14 1,294,336 –a—— C:\WINDOWS\system32\vorbis.acm
2007-12-24 20:43 . 2003-04-07 06:07 217,088 –a—— C:\WINDOWS\system32\rewire.dll
2007-12-24 20:42 . 2007-12-24 20:45 d——– C:\Program Files\Image-Line

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-06 22:01 ——— d—–w C:\Program Files\Common Files\Scanner
2008-01-03 01:02 ——— d—–w C:\Program Files\QuickTime
2007-12-30 00:05 ——— d—–w C:\Documents and Settings\Compaq_Administrator\Application Data\HP
2007-12-29 23:57 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2007-12-29 23:57 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2007-12-29 23:53 ——— d—–w C:\Program Files\Symantec
2007-12-27 21:21 4,350 —-a-w C:\Documents and Settings\Compaq_Administrator\Application Data\wklnhst.dat
2007-12-11 22:29 ——— d—–w C:\Program Files\America Online 9.0
2007-11-28 13:07 ——— d—–w C:\Program Files\InterActual
2007-11-25 23:57 ——— d—–w C:\Documents and Settings\Compaq_Administrator\Application Data\CoreFTP
2007-11-20 02:53 ——— d—–w C:\Documents and Settings\All Users\Application Data\GameHouse
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-09 15:50 ——— d—–w C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird
2007-11-09 15:49 ——— d—–w C:\Program Files\Mozilla Thunderbird
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{256a70c2-7dab-4baf-8777-4b9261ef6f2b}]
C:\WINDOWS\system32\qijqtsic.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-05-09 17:50 7311360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [ ]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-01-01 22:03 219136]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wvuvstq]
wvuvstq.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Extender Resource Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Extender Resource Monitor.lnk
backup=C:\WINDOWS\pss\Extender Resource Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlwaysReady Power Message APP]
——— 2005-08-03 01:19 77312 C:\WINDOWS\arpwrmsg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\d017a75f]
C:\WINDOWS\system32\xhulbghw.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
–a—— 2005-08-05 22:56 64512 C:\WINDOWS\ehome\ehtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ftutil2]
–a—— 2004-06-07 16:05 106496 C:\WINDOWS\system32\ftutil2.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
C:\Program Files\Common Files\AOL\1171923455\ee\AOLSoftware.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]
–a—— 2008-01-06 18:18 3584 C:\WINDOWS\system32\jkhhe.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]
C:\Program Files\MySpace\IM\MySpaceIM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a—— 2006-05-09 17:50 7311360 C:\WINDOWS\system32\NvCpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
–a—— 2006-05-09 17:50 1519616 C:\WINDOWS\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCDrProfiler]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
C:\WINDOWS\SMINST\RECGUARD.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
–a—— 2006-06-13 22:05 16239616 C:\WINDOWS\RTHDCPL.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
C:\Program Files\Windows Defender\MSASCui.exe

R2 RMSvc;Media Center Extender Resource Monitor;C:\WINDOWS\ehome\RMSvc.exe [2005-10-20 18:55]
S3 QWAVE;QWAVE service;C:\WINDOWS\system32\svchost.exe [2004-08-09 23:00]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
QWAVE REG_MULTI_SZ QWAVE

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480

.
Contents of the 'Scheduled Tasks' folder
"2008-01-07 02:03:33 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-06 21:45:14
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-06 21:46:31 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-07 02:46:23
.
2007-12-29 22:49:00 — E O F —


Then HJT…


Logfile of HijackThis v1.99.1
Scan saved at 9:49:32 PM, on 1/6/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\ehome\RMSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Netscape\Netscape Browser\netscape.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/comcast.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: {b2f6fe16-29b4-7778-fab4-bad72c07a652} - {256a70c2-7dab-4baf-8777-4b9261ef6f2b} - C:\WINDOWS\system32\qijqtsic.dll (file missing)
O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: hpWebHelper Class - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {483EB14D-AF1C-4951-81B0-4E2B41829FF6} (QOLCheck Control) - https://www.select2perform.com/cabs/QOLCheck.ocx
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - http://aolsvc.aol.com/onlinegames/trydiner…h2.1.0.0.67.cab
O16 - DPF: {6FE79ACA-A498-45E5-8BC4-1B9F380CE468} (Abx(gh) Control) - http://aolsvc.aol.com/onlinegames/ghadventureball/abxgh.cab
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
O16 - DPF: {74E4A24D-5224-4F05-8A41-99445E0FC22B} (GameHouse Games Player) - http://aolsvc.aol.com/onlinegames/free-tri…houseplayer.cab
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://tsweb.covenanttransport.com/msrdp.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://aolsvc.aol.com/onlinegames/free-tri…zylomplayer.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://aolsvc.aol.com/onlinegames/popinsan…ploader_v10.cab
O16 - DPF: {EA6246B4-F380-443F-8727-9AEA3371146C} (CPlayFirstWeddingDashControl Object) - http://aolsvc.aol.com/onlinegames/free-tri…sh.1.0.0.47.cab
O20 - Winlogon Notify: wvuvstq - wvuvstq.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
A. Please provide a list of uninstallable programs.

To Provide a List of Installed Programs
  • Run HijackThis.
  • Click Config>>Miscellaneous Tools>>Open Uninstall Manager>>Save List
  • Save list to Desktop
  • Copy the Notepad list and Paste it into this thread.


I need to eliminate the possibility of another serious infection before continuing. This scan will take about one hour.


B. Please use the Internet Explorer browser, and do an online scan with Kaspersky Online Scanner
First, choose "Global" from the drop down box at the top of the page
Click Yes, when prompted to install its ActiveX component.
(Note.. for Internet Explorer 7 users: If at any time you have trouble with the "Accept" button of the license, click on the "Zoom" tool located at the bottom right of the IE window and set the zoom to 75 %. Once the license has been accepted, reset to 100%.)
The program launches and downloads the latest definition files.
  • Once the files are downloaded click on Next
  • Click on Scan Settings and configure as follows:
    • Scan using the following Anti-Virus database:
      • Extended
    • Scan Options:Scan Archives
      Scan Mail Bases
  • Click OK and, under select a target to scan, select My Computer
When the scan is done, in the Scan is completed window (below), any infection is displayed.
There is no option to clean/disinfect, however, we need to analyze the information on the report.
[external image: Posted Image]
[external image: Posted Image]
To obtain the report:
Click on: Save Report As (above - red blinking arrow)
Next, in the Save as prompt, Save in area, select: Desktop
In the File name area, use KScan, or something similar
In Save as type, click the drop arrow and select: Text file [*.txt]
Then, click: Save
Please post the Kaspersky Online Scanner Report in your reply, along with a fresh HijackThis log

Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the license, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.
Ok, The Kaspersky scan is running now. I may have to wait until the a.m. to post the results of that, because it's late out east, and I'm getting in trouble w/ my wife for being up too late. I'll go ahead & post the uninstall list now: Adobe Flash Player ActiveX Adobe Reader 7.0.5 AOL Coach Version 2.0(Build:20041026.5 en) AOL Uninstaller (Choose which Products to Remove) AOL You've Got Pictures Screensaver Apple Software Update AVG 7.5 AVG Anti-Rootkit Free Boggle Supreme (remove only) Collab Comcast Toolbar Compaq Connections (remove only) Core FTP LE 1.3c Customer Experience Enhancement Data Fax SoftModem with SmartCP Doppler Easy Internet Sign-up Empire XP 5 FL Studio 5 GemMaster Mystic High Definition Audio Driver Package - KB888111 Hijackthis 1.99.1 HijackThis 1.99.1 Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB893357) Hotfix for Windows XP (KB906569) Hotfix for Windows XP (KB912024) Hotfix for Windows XP (KB915865) Hotfix for Windows XP (KB926239) Hotfix for Windows XP (KB935448) HP Boot Optimizer HP Deskjet 3900 series HP DVD Play 2.1 HP Imaging Device Functions 7.0 HP Photosmart Essential HP Photosmart Premier Software 6.5 HP Software Update HP Solution Center & Imaging Support Tools 5.0 HP Support Overview HP Web Helper InterActual Player J2SE Runtime Environment 5.0 Update 6 LiveUpdate 3.0 (Symantec Corporation) LiveUpdate Notice (Symantec Corporation) Media Center Extender Media Center Extender Microsoft .NET Framework 1.0 Hotfix (KB887998) Microsoft .NET Framework 1.0 Hotfix (KB930494) Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Flight Simulator X Demo Microsoft Internationalized Domain Names Mitigation APIs Microsoft Money 2006 Microsoft National Language Support Downlevel APIs Microsoft Office Standard Edition 2003 60 days trial Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 Redistributable Microsoft Works Mozilla Firefox (2.0.0.6) Mozilla Thunderbird (2.0.0.6) MSN MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 Parser and SDK My HP Games MySpaceIM Netscape Browser (remove only) NVIDIA Drivers Otto Outerworlds 3D PC-Doctor 5 for Windows Python 2.2 pywin32 extensions (build 203) Python 2.2.3 Quicken 2006 QuickTime RealPlayer Realtek High Definition Audio Driver Remove WeatherBug Installer Rhapsody SecondLife (remove only) Security Update for Step By Step Interactive Training (KB898458) Security Update for Step By Step Interactive Training (KB923723) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896422) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896424) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB908531) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB912812) Security Update for Windows XP (KB912919) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917422) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921398) Security Update for Windows XP (KB921503) Security Update for Windows XP (KB922616) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB923694) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924191) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925454) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926255) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928090) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB929123) Security Update for Windows XP (KB929969) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931768) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB932168) Security Update for Windows XP (KB933566) Security Update for Windows XP (KB933729) Security Update for Windows XP (KB935839) Security Update for Windows XP (KB935840) Security Update for Windows XP (KB936021) Security Update for Windows XP (KB937143) Security Update for Windows XP (KB937894) Security Update for Windows XP (KB938127) Security Update for Windows XP (KB938829) Security Update for Windows XP (KB939653) Security Update for Windows XP (KB941202) Security Update for Windows XP (KB941568) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB942615) Security Update for Windows XP (KB943460) Security Update for Windows XP (KB944653) Sonic Express Labeler Sonic MyDVD Plus Sonic RecordNow Audio Sonic RecordNow Copy Sonic RecordNow Data Sonic Update Manager Symantec KB-DocID:2003093015493306 The Battle for Middle-earth ™ UltimateBet Unreal Tournament 2004 Demo Update for Windows Media Player 10 (KB913800) Update for Windows Media Player 10 (KB926251) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB910437) Update for Windows XP (KB911280) Update for Windows XP (KB912945) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Update for Windows XP (KB927891) Update for Windows XP (KB929338) Update for Windows XP (KB930916) Update for Windows XP (KB931836) Update for Windows XP (KB933360) Update for Windows XP (KB938828) Update for Windows XP (KB942763) Update for Windows XP (KB942840) VCW VicMan's Photo Editor 8.0 Viewpoint Media Player Wal-Mart Music Downloads Store WildTangent Web Driver WinAce Archiver Windows Defender Windows Installer 3.1 (KB893803) Windows Internet Explorer 7 Windows Media Connect Windows Media Format 11 runtime Windows Media Format 11 runtime Windows Media Player 11 Windows Media Player 11 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB883667 Windows XP Hotfix - KB885250 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB887742 Windows XP Hotfix - KB888113 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890175 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB891781 Windows XP Hotfix - KB892050 Windows XP Hotfix - KB893066 Windows XP Media Center Edition 2005 KB905589 Windows XP Media Center Edition 2005 KB908246 Windows XP Media Center Edition 2005 KB925766 Yahoo! Toolbar for Internet Explorer I want to thank you again for all your time and help.
That's fine. I will leave you with some homework to do for tomorrow before posting the Kaspersky and HJT logs. Please make sure that the HJT log is produced after all the following is finished.

I would like to bring the following to your attention. You are currently running two programs on your computer that I strongly recommend you UNINSTALL via the Add/Remove Programs module in your Control Panel:

UltimateBet
WildTangent Web Driver


Justification for the above can be found here: http://www.bleepingcomputer.com/uninstall/Cat-U.html

and

http://www.bleepingcomputer.com/uninstall/Cat-W.html

Also, your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. A malicious site could render Java content under older, vulnerable versions of Sun's software if the user has not removed them. Please follow these steps to remove older version Java components and update:
  • Download the latest version of Java Runtime Environment (JRE) 6 Update 3 and save it to your desktop.
  • Scroll down to where it says "Java Runtime Environment (JRE) 6u3…allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Read the License Agreement and then check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Settings > Control Panel > Add/Remove Programs, double-click on and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u3-windows-i586-p.exe to install the newest version.

Now to Clean out the Java cache:

Go into the Control Panel and double-click the Java Icon.
  • Under Temporary Internet Files, click the Delete Files button.
  • There are three options in the window to clear the cache - Leave ALL 3 Checked
    • Downloaded Applets
      Downloaded Applications
      Other Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Java Control Panel.
Thanks - I will get to work on it when I get home tonight. Apparently, my machine rebooted itself after the Kaspersky scan ran last night, so I'll have to redo that, too. I quit using ultimate bet a long time ago, so no problem removing that one & I don't even know what the other one is for.
Missions accomplished.

Here's the HJT file:


Logfile of HijackThis v1.99.1
Scan saved at 10:16:42 PM, on 1/7/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\ehome\RMSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.comcast.net/toolbar2.0/search/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/comcast.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf;=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.comcast.net/toolbar2.0/search/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: {b2f6fe16-29b4-7778-fab4-bad72c07a652} - {256a70c2-7dab-4baf-8777-4b9261ef6f2b} - C:\WINDOWS\system32\qijqtsic.dll (file missing)
O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: hpWebHelper Class - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {483EB14D-AF1C-4951-81B0-4E2B41829FF6} (QOLCheck Control) - https://www.select2perform.com/cabs/QOLCheck.ocx
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - http://aolsvc.aol.com/onlinegames/trydiner…h2.1.0.0.67.cab
O16 - DPF: {6FE79ACA-A498-45E5-8BC4-1B9F380CE468} (Abx(gh) Control) - http://aolsvc.aol.com/onlinegames/ghadventureball/abxgh.cab
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
O16 - DPF: {74E4A24D-5224-4F05-8A41-99445E0FC22B} (GameHouse Games Player) - http://aolsvc.aol.com/onlinegames/free-tri…houseplayer.cab
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://tsweb.covenanttransport.com/msrdp.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://aolsvc.aol.com/onlinegames/free-tri…zylomplayer.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://aolsvc.aol.com/onlinegames/popinsan…ploader_v10.cab
O16 - DPF: {EA6246B4-F380-443F-8727-9AEA3371146C} (CPlayFirstWeddingDashControl Object) - http://aolsvc.aol.com/onlinegames/free-tri…sh.1.0.0.47.cab
O20 - Winlogon Notify: wvuvstq - wvuvstq.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe



And here's the Kespersky Scan file:

——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Monday, January 07, 2008 9:53:43 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 7/01/2008
Kaspersky Anti-Virus database records: 503957
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 134914
Number of viruses found: 9
Number of infected objects: 102
Number of suspicious objects: 3
Duration of the scan process: 01:52:48

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Administrator\Application Data\desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Intuit\Quicken\Log\qw.log Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\Address Book\Administrator.wab Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\Address Book\Administrator.wab~ Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\CLR Security Config\v1.0.3705\security.config Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\CLR Security Config\v1.0.3705\security.config.cch Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\CLR Security Config\v1.0.3705\security.config.old Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\CLR Security Config\v1.1.4322\security.config Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\CLR Security Config\v1.1.4322\security.config.cch Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\CryptnetUrlCache\Content\E6024EAC88E6B6165D49FE3C95ADD735 Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\CryptnetUrlCache\MetaData\E6024EAC88E6B6165D49FE3C95ADD735 Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\brndlog.bak Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\brndlog.txt Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Desktop.htt Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\DISCover My Games™.lnk Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Media Center.lnk Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\My HP Games.lnk Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\MySpaceIM.lnk Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Netscape Browser.lnk Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\RealPlayer.lnk Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Rhapsody.lnk Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\Protect\CREDHIST Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\Protect\S-1-5-21-527237240-179605362-725345543-500\0712e85f-9046-4e12-85a7-95a6e0228066 Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Microsoft\Protect\S-1-5-21-527237240-179605362-725345543-500\Preferred Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\pluginreg.dat Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\bookmarkbackups\bookmarks-2007-12-29.html Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\bookmarks.bak Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\bookmarks.html Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\cert8.db Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\chrome\userChrome-example.css Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\chrome\userContent-example.css Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\compatibility.ini Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\compreg.dat Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\cookies.txt Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\extensions.cache Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\extensions.ini Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\extensions.rdf Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\formhistory.dat Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\history.dat Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\key3.db Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\localstore.rdf Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\mimeTypes.rdf Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\prefs.js Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\search.rdf Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\secmod.db Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\xpti.dat Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\profiles.ini Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Real\Msg\Category.dat Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Real\Msg\Messages.dat Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Real\Msg\SCategory.dat Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Real\RealPlayer\ErrorLogs\CDBurning.log Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Real\RealPlayer\ErrorLogs\GenDevices.log Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Real\RealPlayer\ErrorLogs\pdgenctnomad.log Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Real\RealPlayer\ErrorLogs\pdgenwmdm.log Object is locked skipped
C:\Documents and Settings\Administrator\Application Data\Real\rnadmin\rnsystem.dat Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\administrator@82.98.235[1].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\administrator@live[1].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\administrator@msnportal.112.2o7[1].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\administrator@msn[1].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\[removed][2].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\[removed][2].txt Object is locked skipped
C:\Documents and Settings\Administrator\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Favorites\Desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\Favorites\Links\Customize Links.url Object is locked skipped
C:\Documents and Settings\Administrator\Favorites\Links\Free Hotmail.url Object is locked skipped
C:\Documents and Settings\Administrator\Favorites\Links\Windows Marketplace.url Object is locked skipped
C:\Documents and Settings\Administrator\Favorites\Links\Windows Media.url Object is locked skipped
C:\Documents and Settings\Administrator\Favorites\Links\Windows.url Object is locked skipped
C:\Documents and Settings\Administrator\Favorites\MSN.com.url Object is locked skipped
C:\Documents and Settings\Administrator\Favorites\Radio Station Guide.url Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\ApplicationHistory\DiscStreamHub.exe.fddeaf63.ini.inuse Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\ApplicationHistory\DiscUpdMgr.exe.f0c5ac89.ini.inuse Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\ApplicationHistory\HPBWSetup.exe.fe2aa224.ini Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\ApplicationHistory\IEActivex.exe.cccdbce.ini Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\ApplicationHistory\MCInstaller.exe.c95982a.ini Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\ApplicationHistory\ngen.exe.2c05686e.ini Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\ApplicationHistory\PostInstallExecuter.exe.2c6c3c60.ini Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\ApplicationHistory\RegAsm.exe.ca35bcc8.ini Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\ApplicationHistory\RegisterMCEApp.exe.19d07aaf.ini Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\ApplicationHistory\SL52.tmp.fc211826.ini Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\fusioncache.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\IconCache.db Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\MSIMGSIZ.DAT Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Media Player\CurrentDatabase_59R.wmdb Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\usrclass.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNS.DTD Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNS.XML Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Works\Portfolio\wsbsamp.wsb Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\Cache\336821BAd01 Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\Cache\37D43D53d01 Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\Cache\39F11C47d01 Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\Cache\418D2535d01 Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\Cache\44B6D53Ed01 Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\Cache\4FDFD63Ad01 Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\Cache\7B3D56E5d01 Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\Cache\7CA2AEB3d01 Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\Cache\857298CDd01 Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\Cache\880D7418d01 Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\Cache\8F07CDDBd01 Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\Cache\9973A8BEd01 Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\Cache\A3ABF103d01 Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\Cache\A3ACF103d01 Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\Cache\A3ADF103d01 Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\Cache\A3AEF103d01 Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\Cache\A89F4DBCd01 Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\Cache\B070FE70d01 Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\Cache\B9F6EBA7d01 Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\Cache\DF0A55A8d01 Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\Cache\E428FA07d01 Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\Cache\EC38A6C7d01 Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\Cache\F8A07804d01 Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\Cache\FE8DF379d01 Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\XPC.mfl Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\w7wpktj0.default\XUL.mfl Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Wildtangent\Cdacache\cdacache.odds Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\{3248F0A6-6813-11D6-A77B-00B0D0150060}\1033.MST Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\{3248F0A6-6813-11D6-A77B-00B0D0150060}\J2SE Runtime Environment 5.0 Update 6.msi Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\History\desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\MSHist012007122920071230\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temp\avg7inst.log Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\I5GVUF2B\A121608C121F215F4F8FA2A07D5442[1].swf Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\I5GVUF2B\BB465BB572931D6E516DF3258536[1].jpg Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\I5GVUF2B\bg_b[2].gif Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\I5GVUF2B\desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\I5GVUF2B\ieW[2].css Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\I5GVUF2B\s_code[2].js Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OJYH0X8D\32E46DE281A68B9C33FC582D2569D[1].gif Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OJYH0X8D\7FB68024149A682253702689EF7E[1].jpg Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OJYH0X8D\CALPMRS9.htm Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OJYH0X8D\dap[2].js Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OJYH0X8D\desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OJYH0X8D\E34914D81787A1473037CBC55DB6A4[1].jpg Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OJYH0X8D\ovrW[1].css Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OJYH0X8D\pipe[1].gif Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OJYH0X8D\t[1].gif Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\UNS18Z0T\674356CFD982FF2EDFB3B0155E1A3F[1].jpg Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\UNS18Z0T\6CDE404B4BFEC334D023E5422081E0[1].gif Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\UNS18Z0T\desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\UNS18Z0T\hptg[2].js Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\UNS18Z0T\primedns[1].gif Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\UZEFYD4F\65A79CDEE98867C04BF29316D4B272[1].jpg Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\UZEFYD4F\7CE57843948D6DF13E79A2DE4E15C[1].gif Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\UZEFYD4F\86F1396496DFE1BAD68AB5F28409[1].gif Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\UZEFYD4F\blu[2].css Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\UZEFYD4F\CACC628765BC548396C35985548097[1].jpg Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\UZEFYD4F\desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\UZEFYD4F\glow_b[1].gif Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\UZEFYD4F\t[2].gif Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\UZEFYD4F\ushpw[1].css Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\UZEFYD4F\WL_b[1].gif Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\My Documents\desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\My Documents\My Music\Desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\My Documents\My Music\Sample Music.lnk Object is locked skipped
C:\Documents and Settings\Administrator\My Documents\My Pictures\Desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\My Documents\My Pictures\IMG0.JPG Object is locked skipped
C:\Documents and Settings\Administrator\My Documents\My Pictures\IMG1.jpg Object is locked skipped
C:\Documents and Settings\Administrator\My Documents\My Pictures\IMG10.jpg Object is locked skipped
C:\Documents and Settings\Administrator\My Documents\My Pictures\IMG11.jpg Object is locked skipped
C:\Documents and Settings\Administrator\My Documents\My Pictures\IMG12.jpg Object is locked skipped
C:\Documents and Settings\Administrator\My Documents\My Pictures\IMG13.jpg Object is locked skipped
C:\Documents and Settings\Administrator\My Documents\My Pictures\IMG2.JPG Object is locked skipped
C:\Documents and Settings\Administrator\My Documents\My Pictures\IMG3.JPG Object is locked skipped
C:\Documents and Settings\Administrator\My Documents\My Pictures\IMG4.JPG Object is locked skipped
C:\Documents and Settings\Administrator\My Documents\My Pictures\IMG5.jpg Object is locked skipped
C:\Documents and Settings\Administrator\My Documents\My Pictures\IMG6.jpg Object is locked skipped
C:\Documents and Settings\Administrator\My Documents\My Pictures\IMG7.jpg Object is locked skipped
C:\Documents and Settings\Administrator\My Documents\My Pictures\IMG8.JPG Object is locked skipped
C:\Documents and Settings\Administrator\My Documents\My Pictures\IMG9.JPG Object is locked skipped
C:\Documents and Settings\Administrator\My Documents\My Pictures\Sample Pictures.lnk Object is locked skipped
C:\Documents and Settings\Administrator\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Administrator\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Administrator\ntuser.ini Object is locked skipped
C:\Documents and Settings\Administrator\Recent\b1e9c6d8017ece41a7cc.lnk Object is locked skipped
C:\Documents and Settings\Administrator\Recent\Desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\Recent\msxml4-KB927978-enu.lnk Object is locked skipped
C:\Documents and Settings\Administrator\Recent\playground.lnk Object is locked skipped
C:\Documents and Settings\Administrator\Recent\PRESARIO ©.lnk Object is locked skipped
C:\Documents and Settings\Administrator\Recent\VETlog.lnk Object is locked skipped
C:\Documents and Settings\Administrator\SendTo\Compressed (zipped) Folder.ZFSendToTarget Object is locked skipped
C:\Documents and Settings\Administrator\SendTo\Desktop (create shortcut).DeskLink Object is locked skipped
C:\Documents and Settings\Administrator\SendTo\desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\SendTo\Mail Recipient.MAPIMail Object is locked skipped
C:\Documents and Settings\Administrator\SendTo\My Documents.mydocs Object is locked skipped
C:\Documents and Settings\Administrator\Start Menu\desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Accessibility\desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Accessibility\Magnifier.lnk Object is locked skipped
C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk Object is locked skipped
C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk Object is locked skipped
C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Accessibility\Utility Manager.lnk Object is locked skipped
C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Address Book.lnk Object is locked skipped
C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Command Prompt.lnk Object is locked skipped
C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Entertainment\desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Entertainment\RealPlayer.lnk Object is locked skipped
C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Notepad.lnk Object is locked skipped
C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Program Compatibility Wizard.lnk Object is locked skipped
C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Synchronize.lnk Object is locked skipped
C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Tour Windows XP.lnk Object is locked skipped
C:\Documents and Settings\Administrator\Start Menu\Programs\Accessories\Windows Explorer.lnk Object is locked skipped
C:\Documents and Settings\Administrator\Start Menu\Programs\desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\Start Menu\Programs\Internet Explorer.lnk Object is locked skipped
C:\Documents and Settings\Administrator\Start Menu\Programs\Online Services\Easy Internet Sign-up.lnk Object is locked skipped
C:\Documents and Settings\Administrator\Start Menu\Programs\Outlook Express.lnk Object is locked skipped
C:\Documents and Settings\Administrator\Start Menu\Programs\Remote Assistance.lnk Object is locked skipped
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\desktop.ini Object is locked skipped
C:\Documents and Settings\Administrator\Templates\amipro.sam Object is locked skipped
C:\Documents and Settings\Administrator\Templates\excel.xls Object is locked skipped
C:\Documents and Settings\Administrator\Templates\excel4.xls Object is locked skipped
C:\Documents and Settings\Administrator\Templates\lotus.wk4 Object is locked skipped
C:\Documents and Settings\Administrator\Templates\powerpnt.ppt Object is locked skipped
C:\Documents and Settings\Administrator\Templates\presenta.shw Object is locked skipped
C:\Documents and Settings\Administrator\Templates\quattro.wb2 Object is locked skipped
C:\Documents and Settings\Administrator\Templates\sndrec.wav Object is locked skipped
C:\Documents and Settings\Administrator\Templates\winword.doc Object is locked skipped
C:\Documents and Settings\Administrator\Templates\winword2.doc Object is locked skipped
C:\Documents and Settings\Administrator\Templates\wordpfct.wpd Object is locked skipped
C:\Documents and Settings\Administrator\Templates\wordpfct.wpg Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\ACS\1.0\ph Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\ACS\1.0\variable Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0\idb\barbie657\MyDB.idx Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0\idb\barbie657\toolbar.lst Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0\idb\SNMaster.idx Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0\organize\barbie657 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0\organize\barbie657.abi Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0\organize\barbie657.aby Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0\organize\CACHE\barbie600 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0\ShopAssist\DataStore\global\clientcache.adb Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\C_America Online 9.0\ShopAssist\DataStore\users\BARBIE657.adb Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\aolstderr.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\aolstdout.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\aoltsmon.lock Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\cache.db Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\server.lock Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\eHome\logs\ehRecvr.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-12292007-180403.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2008-01-07_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\17EE6586.cab/UWA7P_0001_N91M0809NetInstaller.exe Infected: not-a-virus:Downloader.Win32.WinFixer.o skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\17EE6586.cab CAB: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\17EE6586.cab CryptFF: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1B6370A9.tmp Infected: Email-Worm.Win32.Zhelatin.cs skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1DA7319A.tmp Infected: Email-Worm.Win32.Zhelatin.cs skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\29A5741D.tmp Infected: Email-Worm.Win32.Zhelatin.cs skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\AOL\C_America Online 9.0\IDB\Apps.Lst Object is locked skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\AOL\C_America Online 9.0\IDB\art.idx Object is locked skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\AOL\C_America Online 9.0\IDB\sap.dat Object is locked skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\AOL\C_America Online 9.0\IDB\spool.lst Object is locked skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\AOL\C_America Online 9.0\IDB\sysnews.lst Object is locked skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\java.class-1b38e2d0-54917765.class Infected: Exploit.Java.Gimsh.a skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Sun\Java\Deployment\log\plugin150_06.trace Object is locked skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2 … … /[Fr … /[From Sho … /[From Johanna Lackey C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2 … … /[Fr … /[From Sho … /[From Johanna Lackey <[removed]>][Date Thu, 29 Mar 2007 17:55:54 -0400]/text Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2 … … /[Fr … /[From Shopping Spree p .. … /[From "Mortgage Company" <[removed]>][Date Thu, 29 Mar 2007 02:58:29 +0500]/html Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2 … … /[Fr … /[From Shopping Spree p … /[From Trade-In <[removed]>][Date Sun, 25 Mar 2007 07:58:04 -0800 (PST)]/text Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2 … … /[Fr … /[From Shopping Spree p … /[F … /[From "mika kopil" <[removed]>][Date Sun, 25 Mar 2007 16:56:01 +0200]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2 … … /[Fr … /[From Shopping Spree p … /[F … /[From successor or <[removed]>][Date Sat, 25 Mar 2006 11:14:46 -0300]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2 … … /[Fr … /[From Shopping Spree p … /[From "Emilemg Saenz" <[removed]>][Date Sun, 25 Mar 2007 11:12:59 -0300]/text Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2 … … /[Fr … /[From Shopping Spree p … /[From "Zb … /[From Šó <[removed]>][Date Sun, 25 Mar 2007 14:52:49 +0100]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2 … … /[Fr … /[From Shopping Spree p … /[From "Zbcatsup selfish" <[removed]>][Date Sun, 25 Mar 2007 21:59:40 +0800]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2 … … /[Fr … /[From Shopping Spree promotion <[removed]>][Date Sun, 25 Mar 2007 05:14:17 MST]/html Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2 … … /[From cum hard from nast … … /[From "Speaker Nancy Pelosi, DCCC" <[removed]>][Date Thu, 22 Mar 2007 10:07:21 -0500]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2 … … /[From cum hard from nast … … … /[From "Jenny Miller" <[removed]>][Date Sat, 24 Mar 2007 07:25:51 -0500]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2 … … /[From cum hard from nast … … … /[From Payday <[removed]>][Date Thu, 22 Mar 2007 02:52:17 -0800 (PST)]/text Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2 … … /[From cum hard from nast … … /[From "Guildo Rex" <[removed]>][Date Thu, 22 Mar 2007 09:16:07 +0000]/text Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2 … … /[From cum hard from nast … /[From Yso-2022- … /[From Dating <[removed]>][Date Thu, 22 Mar 2007 01:22:14 EST]/html Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2 … … /[From cum hard from nast … /[From Yso-2022-jp?B?GyRCO3ZMMzZJGyhC?([removed]>][Date Wed, 21 Mar 2007 16:42:45 +0900]/text Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2 … … /[From cum hard from nasty … /[From chift-jis?B?aW5mb3JtYXRpb24- <[removed]>][Date Thu, 22 Mar 2007 01:06:04 -0400]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2 … … /[From cum hard from nasty voyeur sex t … /[From "Broussard" <[removed]>][Date Thu, 22 Mar 2007 03:44:37 +0100]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2 … … /[From cum hard from nasty voyeur sex that will entice you. message from Donnell Copeland][Date Thu, 22 Mar 2007 13:29:27 +0000]/text Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2 … /[From "Richard Anders … /[From "Gu … … /[Fr … … /[From [removed]][Date Wed, 21 Mar 2007 18:58:38 -0400]/text Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2 … /[From "Richard Anders … /[From "Gu … … /[Fr … /[From Mora" <[removed]>][Date 21 Mar 2007 22:17:11 -0100]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2 … /[From "Richard Anders … /[From "Gu … … /[From Jerry <[removed]>][Date Wed, 21 Mar 2007 23:06:43 +0200]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2 … /[From "Richard Anders … /[From "Gu … … /[From Smileys <[removed]>][Date Wed, 21 Mar 2007 12:26:37 -0800 (PST)]/html Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2 … /[From "Richard Anders … /[From "Gu … /[From … /[From lawyer an <[removed]>][Date Thu, 22 Mar 2007 04:08:24 +0900]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2 … /[From "Richard Anders … /[From "Gu … /[From Warren" <[removed]>][Date 21 Mar 2007 17:19:55 -0100]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2 … /[From "Richard Anders … /[From "Guide To Cabinet Refacing" <[removed]>][Date Wed, 21 Mar 2007 10:12:59 -0400]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2 … /[From "Richard Anderson( … /[From "Per … /[Fro … /[From "Annie" <[removed]>][Date Thu, 22 Mar 2007 15:06:04 +0000]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2 … /[From "Richard Anderson( … /[From "Per … /[From Kent" <[removed]>][Date 21 Mar 2007 14:38:14 -0800]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2 … /[From "Richard Anderson( … /[From "PerfectImageCenter.com" <[removed]>][Date Wed, 21 Mar 2007 06:44:11 -0800 (PST)]/html Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2 … /[From "Richard Anderson(C … … /[F … /[From … /[From rights" <[removed]>][Date 21 Mar 2007 14:27:16 +0100]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2 … /[From "Richard Anderson(C … … /[F … /[From "“y‰® ˆ¤" <[removed]>][Date Wed, 21 Mar 2007 07:23:27 -0500]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2 … /[From "Richard Anderson(C … … /[From Rewards Gateway <[removed]>][Date Wed, 21 Mar 2007 06:09:33 MST]/html Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2 … /[From "Richard Anderson(C … /[From "Jaden Rodriguez" <[removed]>][Date Wed, 21 Mar 2007 13:43:39 +0300]/text Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2 … /[From "Richard Anderson(Confirm … /[From English" <[removed]>][Date 21 Mar 2007 08:22:07 -0100]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2 … /[From "Richard Anderson(Confirm. Dep … /[Fr . .. … /[From Payday <[removed]>][Date Wed, 21 Mar 2007 03:28:32 EST]/html Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2 … /[From "Richard Anderson(Confirm. Dep … /[Fr . … /[From Corinth" <[removed]>][Date 21 Mar 2007 08:59:39 +0100]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2 … /[From "Richard Anderson(Confirm. Dep … /[Fr … … /[From "Yjncalculate mescal" <[removed]>][Date %M5DATE]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2 … /[From "Richard Anderson(Confirm. Dep … /[Fr … /[From Weight Loss <[removed]>][Date Wed, 21 Mar 2007 08:09:31 +0300]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2 … /[From "Richard Anderson(Confirm. Dep … /[From "Dcapetown varnish" <[removed]>][Date Tue, 1 Jan 2002 02:33:58 +0800]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2 … /[From "Richard Anderson(Confirm. Dept.)" <[removed]>][Date Thu, 22 Mar 2007 23:22:03 -0500]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2007 10:57:08 +0300]/UNNA … /[From extreme anima … /[From " … /[From Austin <[removed]>][Date Wed, 21 Mar 2007 08:00:35 +0700]/text Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2007 10:57:08 +0300]/UNNA … /[From extreme anima … /[From "Cabral Antonio" <[removed]>][Date Tue, 20 Mar 2007 23:30:49 +0000]/text Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2007 10:57:08 +0300]/UNNA … /[From extreme animal porn … /[From "Walter" <[removed]>][Date Wed, 21 Mar 2007 08:22:56 +0100]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2007 10:57:08 +0300]/UNNA … /[From extreme animal porn with young girls message from Israel Massey][Date Tue, 20 Mar 2007 23:24:49 +0000]/text Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2007 10:57:08 +0300]/UNNA … /[From Local Satelli … /[From Debt-Wizard <[removed]>][Date Tue, 20 Mar 2007 16:56:20 -0400]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2007 10:57:08 +0300]/UNNA … /[From Local Satellite Source … … /[From [removed]][Date Tue, 20 Mar 2007 15:28:53 -0400]/text Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2007 10:57:08 +0300]/UNNA … /[From Local Satellite Source … /[From [removed]][Date Tue, 20 Mar 2007 12:30:50 -0400]/text Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2007 10:57:08 +0300]/UNNA … /[From Local Satellite Source <[removed]>][Date Mon, 19 Mar 2007 22:46:34 EST]/html Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2007 10:57:08 +0300]/UNNAMED/[From … /[F … /[F .. … … /[From Power" <[removed]>][Date 19 Mar 2007 19:13:50 +0800]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2007 10:57:08 +0300]/UNNAMED/[From … /[F … /[F .. … /[From "Yang Harry" <[removed]>][Date Mon, 19 Mar 2007 18:57:50 -0800]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2007 10:57:08 +0300]/UNNAMED/[From … /[F … /[F … /[From "Lucas I. Susan" <[removed]>][Date Tue, 20 Mar 2007 01:58:54 +0100]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2007 10:57:08 +0300]/UNNAMED/[From … /[F … /[From "Ypretext marginalia" <[removed]>][Date Tue, 20 Mar 2007 08:46:33 +0800]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2007 10:57:08 +0300]/UNNAMED/[From … /[From Ins … /[F … /[From "Amos" <[removed]>][Date Thu, 5 Apr 2007 03:08:33 -0500]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2007 10:57:08 +0300]/UNNAMED/[From … /[From Ins … /[From HiTechStuff <[removed]>][Date Wed, 4 Apr 2007 23:59:28 EST]/html Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2007 10:57:08 +0300]/UNNAMED/[From … /[From I .. . … /[From Abuse Team <[removed]>][Date Thu, 12 Apr 2007 21:19:23 -0700]/UNNAMED Infected: Email-Worm.Win32.Zhelatin.ct skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2007 10:57:08 +0300]/UNNAMED/[From … /[From I .. … /[From "E … /[From [removed]][Date Fri, 13 Apr 2007 00:47:29 -0400]/text Infected: Email-Worm.Win32.Zhelatin.ct skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2007 10:57:08 +0300]/UNNAMED/[From … /[From I .. … /[From "Elsa Frank" <[removed]>][Date Fri, 13 Apr 2007 10:42:04 +0900]/UNNAMED Infected: Email-Worm.Win32.Zhelatin.ct skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2007 10:57:08 +0300]/UNNAMED/[From … /[From I … /[From Mcgee" <[removed]>][Date 13 Apr 2007 00:11:16 -0100]/UNNAMED Infected: Email-Worm.Win32.Zhelatin.ct skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2007 10:57:08 +0300]/UNNAMED/[From … /[From Instan … /[From "MortCompany" <[removed]>][Date Thu, 12 Apr 2007 21:38:20 -0300]/html Infected: Email-Worm.Win32.Zhelatin.ct skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2007 10:57:08 +030 … /[From PerfectPa … /[From "BB&T;" <[removed]>][Date Thu, 01 Mar 2007 00:24:55 -0500]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2007 10:57:08 +030 … /[From PerfectPairs <[removed]>][Date Wed, 28 Feb 2007 18:19:39 -0800]/html Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2007 10:57:08 +0300]/ … /[From Yso-2022-jp?B?G … /[From "Viola … /[From order" <[removed]>][Date 1 Mar 2007 12:12:17 +0800]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2007 10:57:08 +0300]/ … /[From Yso-2022-jp?B?G … /[From "Viola Glass" <[removed] >][Date Thu, 01 Mar 2007 05:33:02 +0200]/html Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2007 10:57:08 +0300]/ … /[From Yso-2022-jp?B?GyRCOzNFRCEhOS1KczJdGyhC?([removed]>][Date Wed, 28 Feb 2007 19:25:49 -0500]/html Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2007 10:57:08 +0300]/UNNAMED/[From … /[From … /[From "R … /[From [removed]][Date Wed, 28 Feb 2007 18:18:31 -0500]/text Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2007 10:57:08 +0300]/UNNAMED/[From … /[From … /[From "Rep. John Lewis, DCCC" <[removed]>][Date Wed, 28 Feb 2007 13:10:57 -0500]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2007 10:57:08 +0300]/UNNAMED/[From … /[From Instant Health … /[From Clement" <[removed]>][Date 28 Feb 2007 18:41:03 +0100]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2007 10:57:08 +0300]/UNNAMED/[From … /[Fro … /[From "Hattie Posey" <[removed]>][Date Wed, 07 Mar 2007 03:48:08 +0000]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2007 10:57:08 +0300]/UNNAMED/[From … /[From Instant Hea … /[From - Mon Jan 1 00:00:00 1965][Date Wed, 7 Mar 2007 06:45:57 +0900 (JST)]/text Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2007 10:57:08 +0300]/UNNAMED/[From … /[From Instant Health Quotes <[removed]>][Date Tue, 13 Mar 2007 04:06:47 -0800 (PST)]/html Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2007 10:57:08 +0300]/UNNAMED/[From Hot Ringtones <[removed]>][Date Tue, 13 Mar 2007 04:20:03 EST]/html Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html/[From "Bonita Wells" <[removed]>][Date Tue, 13 Mar 2007 10:57:08 +0300]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text/[From Vonage <[removed]>][Date Tue, 13 Mar 2007 02:29:05 EST]/html Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED/[From "Sebastian Perry" <[removed]>][Date Tue, 13 Mar 2007 12:47:16 +0500]/text Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters/[From Roger Mcmillan <[removed]>][Date Mon, 12 Mar 2007 23:40:05 -0800]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird\Profiles\atgj2okg.default\Mail\Local Folders\Inbox.sbd\letters Mail Berkeley mbox: infected - 75 skipped
C:\Documents and Settings\Compaq_Administrator\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Compaq_Administrator\Desktop\codecaddon1107.exe/stream/Script Infected: Trojan.Win32.DNSChanger.ir skipped
C:\Documents and Settings\Compaq_Administrator\Desktop\codecaddon1107.exe/stream Infected: Trojan.Win32.DNSChanger.ir skipped
C:\Documents and Settings\Compaq_Administrator\Desktop\codecaddon1107.exe NSIS: infected - 2 skipped
C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\Identities\{D190EE07-1887-4595-8F62-6253114299D2}\Microsoft\Outlook Express\letters.dbx/[From Support Team Robot <[removed]>][Date Fri, 13 Apr 2007 02:32:17 +0530]/UNNAMED/hotfix-79740.zip/hotfix-79740.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\Identities\{D190EE07-1887-4595-8F62-6253114299D2}\Microsoft\Outlook Express\letters.dbx/[From Support Team Robot <[removed]>][Date Fri, 13 Apr 2007 02:32:17 +0530]/UNNAMED/hotfix-79740.zip Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\Identities\{D190EE07-1887-4595-8F62-6253114299D2}\Microsoft\Outlook Express\letters.dbx/[From Support Team Robot <[removed]>][Date Fri, 13 Apr 2007 02:32:17 +0530]/UNNAMED Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\Identities\{D190EE07-1887-4595-8F62-6253114299D2}\Microsoft\Outlook Express\letters.dbx/[From Abuse Team <[removed]>][Date Thu, 12 Apr 2007 21:19:23 -0700]/UNNAMED/bugfix-48975.zip Infected: Email-Worm.Win32.Zhelatin.ct skipped
C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\Identities\{D190EE07-1887-4595-8F62-6253114299D2}\Microsoft\Outlook Express\letters.dbx/[From Abuse Team <[removed]>][Date Thu, 12 Apr 2007 21:19:23 -0700]/UNNAMED Infected: Email-Worm.Win32.Zhelatin.ct skipped
C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\Identities\{D190EE07-1887-4595-8F62-6253114299D2}\Microsoft\Outlook Express\letters.dbx Mail MS Outlook 5: infected - 2, suspicious - 3 skipped
C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Compaq_Administrator\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Compaq_Administrator\Local Settings\Temp\hsperfdata_Compaq_Administrator\3824 Object is locked skipped
C:\Documents and Settings\Compaq_Administrator\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Compaq_Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Compaq_Administrator\ntuser.dat Object is locked skipped
C:\Documents and Settings\Compaq_Administrator\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\hp\bin\wbug\CompaqPresario_Spring06.exe/WISE0015.BIN Infected: not-a-virus:AdWare.Win32.WeatherBug.a skipped
C:\hp\bin\wbug\CompaqPresario_Spring06.exe/WISE0016.BIN Infected: not-a-virus:AdWare.Win32.WeatherBug.a skipped
C:\hp\bin\wbug\CompaqPresario_Spring06.exe WiseSFX: infected - 2 skipped
C:\hp\bin\wbug\CompaqPresario_Spring06.exe WiseSFXDropper: infected - 2 skipped
C:\Program Files\AOL Games\Boggle Supreme\Dictionaries\Index.ifl Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP0\A0000033.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP0\A0000034.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP0\A0000035.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP0\A0000043.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP0\A0000046.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP0\A0000047.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP0\A0000048.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1\A0000055.dll Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1\A0000057.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1\A0000061.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1\A0000064.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1\A0000067.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1\A0000068.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1\A0000069.EXE Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1\A0000072.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1\A0000073.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1\A0000075.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1\A0000087.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1\A0000098.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1\A0000100.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1\A0000102.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1\A0000110.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1\A0000173.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1\A0000174.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1\A0000175.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1\A0000181.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1\A0000182.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1\A0000183.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1\A0000189.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1\A0000190.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1\A0000191.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP11\change.log Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP2\A0000193.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP2\A0000194.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP2\A0000195.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP2\A0000212.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP2\A0000213.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP2\A0000214.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP2\A0000215.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP2\A0000216.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP2\A0000217.EXE Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP2\A0000218.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP2\A0000219.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP2\A0000220.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP2\A0000232.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP2\A0000235.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP3\A0000446.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP3\A0000451.dll Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP3\A0000452.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP3\A0000454.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP3\A0000459.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP3\A0000461.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP3\A0000462.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP3\A0000466.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP3\A0000467.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP3\A0000468.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP3\A0000469.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP3\A0000470.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP3\A0000471.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP3\A0000472.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP3\A0000473.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP3\A0000474.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP3\A0000475.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP3\A0000476.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP3\A0000477.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP3\A0000478.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP3\A0000479.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP3\A0000480.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP3\A0000481.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP3\A0000482.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP3\A0000483.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP3\A0000484.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP3\A0000485.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP3\A0000486.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP3\A0000487.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP3\A0000488.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP3\A0000489.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP3\A0000490.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP3\A0000491.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP3\A0000492.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP3\A0000493.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP3\A0000494.EXE Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP3\A0000495.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP3\A0000496.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP3\A0000497.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP3\A0000498.dll Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP3\A0000499.dll Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP3\A0000500.dll Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP5\A0002514.exe Object is locked skipped
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP7\A0004577.exe Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Downloaded Program Files\popcaploader.dll Infected: not-a-virus:Downloader.Win32.PopCap.b skipped
C:\WINDOWS\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{2CF15D10-2211-4996-8248-C11D2E419276}.crmlog Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\Media Ce.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\jkhhe.exe Object is locked skipped
C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_1fc.dat Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\I386\APPS\APP18873\src\CompaqPresario_Spring06.exe/WISE0015.BIN Infected: not-a-virus:AdWare.Win32.WeatherBug.a skipped
D:\I386\APPS\APP18873\src\CompaqPresario_Spring06.exe/WISE0016.BIN Infected: not-a-virus:AdWare.Win32.WeatherBug.a skipped
D:\I386\APPS\APP18873\src\CompaqPresario_Spring06.exe WiseSFX: infected - 2 skipped
D:\I386\APPS\APP18873\src\CompaqPresario_Spring06.exe WiseSFXDropper: infected - 2 skipped
D:\I386\APPS\APP18873\src\HPPavillion_Spring06.exe/WISE0015.BIN Infected: not-a-virus:AdWare.Win32.WeatherBug.a skipped
D:\I386\APPS\APP18873\src\HPPavillion_Spring06.exe/WISE0016.BIN Infected: not-a-virus:AdWare.Win32.WeatherBug.a skipped
D:\I386\APPS\APP18873\src\HPPavillion_Spring06.exe WiseSFX: infected - 2 skipped
D:\I386\APPS\APP18873\src\HPPavillion_Spring06.exe WiseSFXDropper: infected - 2 skipped

Scan process completed.


Thanks!
1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\WINDOWS\system32\jkhhe.exe
C:\WINDOWS\system32\d3d8caps.dat
C:\$bootcln.sch
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\17EE6586.cab
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1B6370A9.tmp
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1DA7319A.tmp
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\29A5741D.tmp
C:\Documents and Settings\Compaq_Administrator\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\java.class-1b38e2d0-54917765.class
C:\Documents and Settings\Compaq_Administrator\Desktop\codecaddon1107.exe
C:\hp\bin\wbug\CompaqPresario_Spring06.exe
C:\WINDOWS\Downloaded Program Files\popcaploader.dll
D:\I386\APPS\APP18873\src\CompaqPresario_Spring06.exe
D:\I386\APPS\APP18873\src\HPPavillion_Spring06.exe

Folder::
C:\SYSREST

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{256a70c2-7dab-4baf-8777-4b9261ef6f2b}]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wvuvstq]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\d017a75f]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCDrProfiler]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]

KillAll::
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Save the above as CFScript.txt

4. Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.

5. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

6. ComboFix will automatically REBOOT your machine when the KillAll:: switch is used..

7. Next, re-enable all the programs that you disabled prior to running ComboFix.

8. Post the following logs/Reports:
  • ComboFix.txt
  • Fresh HijackThis log run after all the other tools have performed their cleanup.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
ComboFix says:

ComboFix 08-01-07.3 - Compaq_Administrator 2008-01-07 23:26:37.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.142 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Compaq_Administrator\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\$bootcln.sch
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\17EE6586.cab
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1B6370A9.tmp
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1DA7319A.tmp
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\29A5741D.tmp
C:\Documents and Settings\Compaq_Administrator\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\java.class-1b38e2d0-54917765.class
C:\Documents and Settings\Compaq_Administrator\Desktop\codecaddon1107.exe
C:\hp\bin\wbug\CompaqPresario_Spring06.exe
C:\WINDOWS\Downloaded Program Files\popcaploader.dll
C:\WINDOWS\system32\d3d8caps.dat
C:\WINDOWS\system32\jkhhe.exe
D:\I386\APPS\APP18873\src\CompaqPresario_Spring06.exe
D:\I386\APPS\APP18873\src\HPPavillion_Spring06.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\$bootcln.sch
C:\Documents and Settings\Compaq_Administrator\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\java.class-1b38e2d0-54917765.class
C:\Documents and Settings\Compaq_Administrator\Desktop\codecaddon1107.exe
C:\hp\bin\wbug\CompaqPresario_Spring06.exe
C:\SYSREST\
C:\WINDOWS\Downloaded Program Files\popcaploader.dll
C:\WINDOWS\system32\d3d8caps.dat
C:\WINDOWS\system32\jkhhe.exe
D:\I386\APPS\APP18873\src\CompaqPresario_Spring06.exe
D:\I386\APPS\APP18873\src\HPPavillion_Spring06.exe

.
((((((((((((((((((((((((( Files Created from 2007-12-08 to 2008-01-08 )))))))))))))))))))))))))))))))
.

2008-01-07 22:10 . 2008-01-07 22:10 d——– C:\Program Files\Sun
2008-01-07 22:10 . 2007-09-24 23:31 69,632 –a—— C:\WINDOWS\system32\javacpl.cpl
2008-01-06 22:36 . 2008-01-06 22:36 d——– C:\WINDOWS\system32\Kaspersky Lab
2008-01-06 22:36 . 2008-01-06 22:36 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-01-06 21:32 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-06 18:15 . 2007-01-18 07:00 3,968 –a—— C:\WINDOWS\system32\drivers\AvgArCln.sys
2008-01-06 17:00 . 2008-01-06 17:00 d——– C:\Program Files\ComcastToolbar
2008-01-06 17:00 . 2008-01-07 23:22 d——– C:\Documents and Settings\Compaq_Administrator\Application Data\ComcastToolbar
2008-01-01 23:55 . 2008-01-01 23:55 18 –ah—– C:\SYSREST
2008-01-01 22:04 . 2008-01-06 17:05 d——– C:\Documents and Settings\Compaq_Administrator\Application Data\AVG7
2008-01-01 22:03 . 2008-01-01 22:03 d——– C:\Documents and Settings\LocalService\Application Data\AVG7
2008-01-01 22:03 . 2008-01-01 22:03 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-01 22:03 . 2008-01-01 22:20 d——– C:\Documents and Settings\All Users\Application Data\avg7
2008-01-01 20:02 . 2008-01-01 20:02 d——– C:\Documents and Settings\All Users\Application Data\McAfee
2007-12-29 18:03 . 2008-01-01 23:39 d——– C:\Program Files\Windows Defender
2007-12-24 20:43 . 2007-12-24 20:43 d——– C:\Program Files\VstPlugins
2007-12-24 20:43 . 2002-07-07 18:14 1,294,336 –a—— C:\WINDOWS\system32\vorbis.acm
2007-12-24 20:43 . 2003-04-07 06:07 217,088 –a—— C:\WINDOWS\system32\rewire.dll
2007-12-24 20:42 . 2007-12-24 20:45 d——– C:\Program Files\Image-Line

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-08 03:10 ——— d—–w C:\Program Files\Java
2008-01-08 02:56 ——— d—–w C:\Program Files\GemMaster
2008-01-06 22:01 ——— d—–w C:\Program Files\Common Files\Scanner
2008-01-03 01:02 ——— d—–w C:\Program Files\QuickTime
2007-12-30 00:05 ——— d—–w C:\Documents and Settings\Compaq_Administrator\Application Data\HP
2007-12-29 23:57 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2007-12-29 23:57 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2007-12-29 23:53 ——— d—–w C:\Program Files\Symantec
2007-12-27 21:21 4,350 —-a-w C:\Documents and Settings\Compaq_Administrator\Application Data\wklnhst.dat
2007-12-11 22:29 ——— d—–w C:\Program Files\America Online 9.0
2007-11-28 13:07 ——— d—–w C:\Program Files\InterActual
2007-11-25 23:57 ——— d—–w C:\Documents and Settings\Compaq_Administrator\Application Data\CoreFTP
2007-11-20 02:53 ——— d—–w C:\Documents and Settings\All Users\Application Data\GameHouse
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-09 15:50 ——— d—–w C:\Documents and Settings\Compaq_Administrator\Application Data\Thunderbird
2007-11-09 15:49 ——— d—–w C:\Program Files\Mozilla Thunderbird
.

((((((((((((((((((((((((((((( snapshot@2008-01-06_21.46.13.93 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-03-06 01:22:41 213,216 -c—-w C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c—-w C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\updspapi.dll
+ 2007-08-13 23:54:10 765,952 -c—-w C:\WINDOWS\ie7updates\KB938127-IE7\vgx.dll
+ 2007-08-13 23:39:00 123,904 -c—-w C:\WINDOWS\ie7updates\KB942615-IE7\advpack.dll
+ 2007-08-13 23:35:38 214,528 -c—-w C:\WINDOWS\ie7updates\KB942615-IE7\dxtrans.dll
+ 2007-08-13 23:54:10 131,584 -c—-w C:\WINDOWS\ie7updates\KB942615-IE7\extmgr.dll
+ 2007-08-13 23:36:26 61,952 -c—-w C:\WINDOWS\ie7updates\KB942615-IE7\icardie.dll
+ 2007-08-13 23:39:06 54,784 -c—-w C:\WINDOWS\ie7updates\KB942615-IE7\ie4uinit.exe
+ 2007-08-13 23:39:26 152,064 -c—-w C:\WINDOWS\ie7updates\KB942615-IE7\ieakeng.dll
+ 2007-08-13 23:39:54 229,376 -c—-w C:\WINDOWS\ie7updates\KB942615-IE7\ieaksie.dll
+ 2007-08-13 22:56:54 161,792 -c—-w C:\WINDOWS\ie7updates\KB942615-IE7\ieakui.dll
+ 2007-02-12 21:10:12 2,451,312 -c—-w C:\WINDOWS\ie7updates\KB942615-IE7\ieapfltr.dat
+ 2007-07-11 17:27:48 383,488 -c—-w C:\WINDOWS\ie7updates\KB942615-IE7\ieapfltr.dll
+ 2007-08-13 23:39:50 382,976 -c—-w C:\WINDOWS\ie7updates\KB942615-IE7\iedkcs32.dll
+ 2007-08-13 23:54:10 6,049,280 -c—-w C:\WINDOWS\ie7updates\KB942615-IE7\ieframe.dll
+ 2007-08-13 23:39:10 43,008 -c—-w C:\WINDOWS\ie7updates\KB942615-IE7\iernonce.dll
+ 2007-08-13 23:34:04 266,752 -c—-w C:\WINDOWS\ie7updates\KB942615-IE7\iertutil.dll
+ 2007-08-13 23:39:10 13,312 -c—-w C:\WINDOWS\ie7updates\KB942615-IE7\ieudinit.exe
+ 2007-08-13 23:43:56 622,080 -c—-w C:\WINDOWS\ie7updates\KB942615-IE7\iexplore.exe
+ 2007-08-13 23:54:10 27,136 -c—-w C:\WINDOWS\ie7updates\KB942615-IE7\jsproxy.dll
+ 2007-08-13 23:54:10 458,752 -c—-w C:\WINDOWS\ie7updates\KB942615-IE7\msfeeds.dll
+ 2007-08-13 23:54:10 50,688 -c—-w C:\WINDOWS\ie7updates\KB942615-IE7\msfeedsbs.dll
+ 2007-08-13 23:54:12 3,578,368 -c—-w C:\WINDOWS\ie7updates\KB942615-IE7\mshtml.dll
+ 2007-08-13 23:54:10 475,648 -c—-w C:\WINDOWS\ie7updates\KB942615-IE7\mshtmled.dll
+ 2007-08-13 23:44:26 192,000 -c—-w C:\WINDOWS\ie7updates\KB942615-IE7\msrating.dll
+ 2007-08-13 23:54:10 670,720 -c—-w C:\WINDOWS\ie7updates\KB942615-IE7\mstime.dll
+ 2007-08-13 23:44:06 101,376 -c—-w C:\WINDOWS\ie7updates\KB942615-IE7\occache.dll
+ 2007-03-06 01:22:41 213,216 -c—-w C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c—-w C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\updspapi.dll
+ 2007-08-13 23:44:30 105,984 -c—-w C:\WINDOWS\ie7updates\KB942615-IE7\url.dll
+ 2007-08-13 23:54:10 1,162,240 -c—-w C:\WINDOWS\ie7updates\KB942615-IE7\urlmon.dll
+ 2007-08-13 23:54:10 231,424 -c—-w C:\WINDOWS\ie7updates\KB942615-IE7\webcheck.dll
+ 2007-08-13 23:54:10 818,688 -c—-w C:\WINDOWS\ie7updates\KB942615-IE7\wininet.dll
- 2007-08-13 23:39:00 123,904 —-a-w C:\WINDOWS\system32\advpack.dll
+ 2007-10-10 23:55:51 124,928 —-a-w C:\WINDOWS\system32\advpack.dll
- 2007-08-13 23:39:00 123,904 —-a-w C:\WINDOWS\system32\dllcache\advpack.dll
+ 2007-10-10 23:55:51 124,928 —-a-w C:\WINDOWS\system32\dllcache\advpack.dll
- 2007-08-13 23:35:38 214,528 —-a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
+ 2007-10-10 23:55:51 214,528 —-a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
- 2007-08-13 23:54:10 131,584 —-a-w C:\WINDOWS\system32\dllcache\extmgr.dll
+ 2007-10-10 23:55:51 132,608 —-a-w C:\WINDOWS\system32\dllcache\extmgr.dll
+ 2007-10-10 23:55:51 63,488 ——w C:\WINDOWS\system32\dllcache\icardie.dll
- 2007-08-13 23:39:06 54,784 —-a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
+ 2007-10-10 10:59:40 70,656 —-a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
- 2007-08-13 23:39:26 152,064 —-a-w C:\WINDOWS\system32\dllcache\ieakeng.dll
+ 2007-10-10 23:55:51 153,088 —-a-w C:\WINDOWS\system32\dllcache\ieakeng.dll
- 2007-08-13 23:39:54 229,376 —-a-w C:\WINDOWS\system32\dllcache\ieaksie.dll
+ 2007-10-10 23:55:51 230,400 —-a-w C:\WINDOWS\system32\dllcache\ieaksie.dll
- 2007-08-13 22:56:54 161,792 —-a-w C:\WINDOWS\system32\dllcache\ieakui.dll
+ 2007-10-10 05:46:55 161,792 —-a-w C:\WINDOWS\system32\dllcache\ieakui.dll
+ 2007-07-01 03:31:33 2,455,488 ——w C:\WINDOWS\system32\dllcache\ieapfltr.dat
+ 2007-10-10 23:55:52 383,488 ——w C:\WINDOWS\system32\dllcache\ieapfltr.dll
- 2007-08-13 23:39:50 382,976 —-a-w C:\WINDOWS\system32\dllcache\iedkcs32.dll
+ 2007-10-10 23:55:52 384,512 —-a-w C:\WINDOWS\system32\dllcache\iedkcs32.dll
+ 2007-10-10 23:55:54 6,065,664 ——w C:\WINDOWS\system32\dllcache\ieframe.dll
- 2007-08-13 23:39:10 43,008 —-a-w C:\WINDOWS\system32\dllcache\iernonce.dll
+ 2007-10-10 23:55:55 44,544 —-a-w C:\WINDOWS\system32\dllcache\iernonce.dll
+ 2007-10-10 23:55:55 267,776 ——w C:\WINDOWS\system32\dllcache\iertutil.dll
+ 2007-10-10 10:59:40 13,824 ——w C:\WINDOWS\system32\dllcache\ieudinit.exe
- 2007-08-13 23:43:56 622,080 —-a-w C:\WINDOWS\system32\dllcache\iexplore.exe
+ 2007-10-10 10:59:52 625,152 —-a-w C:\WINDOWS\system32\dllcache\iexplore.exe
- 2007-08-13 23:54:10 27,136 —-a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
+ 2007-10-10 23:55:56 27,648 —-a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
+ 2007-10-10 23:55:56 459,264 ——w C:\WINDOWS\system32\dllcache\msfeeds.dll
+ 2007-10-10 23:55:56 52,224 ——w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
- 2007-08-13 23:54:12 3,578,368 —-a-w C:\WINDOWS\system32\dllcache\mshtml.dll
+ 2007-10-30 23:42:28 3,590,656 —-a-w C:\WINDOWS\system32\dllcache\mshtml.dll
- 2007-08-13 23:54:10 475,648 —-a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
+ 2007-10-10 23:55:58 478,208 —-a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
- 2007-08-13 23:44:26 192,000 —-a-w C:\WINDOWS\system32\dllcache\msrating.dll
+ 2007-10-10 23:55:58 193,024 —-a-w C:\WINDOWS\system32\dllcache\msrating.dll
- 2007-08-13 23:54:10 670,720 —-a-w C:\WINDOWS\system32\dllcache\mstime.dll
+ 2007-10-10 23:55:59 671,232 —-a-w C:\WINDOWS\system32\dllcache\mstime.dll
- 2007-08-13 23:44:06 101,376 —-a-w C:\WINDOWS\system32\dllcache\occache.dll
+ 2007-10-10 23:55:59 102,400 —-a-w C:\WINDOWS\system32\dllcache\occache.dll
- 2007-08-13 23:44:30 105,984 —-a-w C:\WINDOWS\system32\dllcache\url.dll
+ 2007-10-10 23:55:59 105,984 —-a-w C:\WINDOWS\system32\dllcache\url.dll
- 2007-08-13 23:54:10 1,162,240 —-a-w C:\WINDOWS\system32\dllcache\urlmon.dll
+ 2007-10-10 23:56:00 1,159,680 —-a-w C:\WINDOWS\system32\dllcache\urlmon.dll
- 2007-08-13 23:54:10 765,952 —-a-w C:\WINDOWS\system32\dllcache\VGX.dll
+ 2007-07-12 23:31:54 765,952 —-a-w C:\WINDOWS\system32\dllcache\vgx.dll
- 2007-08-13 23:54:10 231,424 —-a-w C:\WINDOWS\system32\dllcache\webcheck.dll
+ 2007-10-10 23:56:00 232,960 —-a-w C:\WINDOWS\system32\dllcache\webcheck.dll
- 2007-08-13 23:54:10 818,688 —-a-w C:\WINDOWS\system32\dllcache\wininet.dll
+ 2007-10-10 23:56:00 824,832 —-a-w C:\WINDOWS\system32\dllcache\wininet.dll
- 2007-08-13 23:35:38 214,528 —-a-w C:\WINDOWS\system32\dxtrans.dll
+ 2007-10-10 23:55:51 214,528 —-a-w C:\WINDOWS\system32\dxtrans.dll
- 2007-08-13 23:54:10 131,584 —-a-w C:\WINDOWS\system32\extmgr.dll
+ 2007-10-10 23:55:51 132,608 —-a-w C:\WINDOWS\system32\extmgr.dll
- 2007-08-13 23:36:26 61,952 —-a-w C:\WINDOWS\system32\icardie.dll
+ 2007-10-10 23:55:51 63,488 —-a-w C:\WINDOWS\system32\icardie.dll
- 2007-08-13 23:39:06 54,784 —-a-w C:\WINDOWS\system32\ie4uinit.exe
+ 2007-10-10 10:59:40 70,656 —-a-w C:\WINDOWS\system32\ie4uinit.exe
- 2007-08-13 23:39:26 152,064 —-a-w C:\WINDOWS\system32\ieakeng.dll
+ 2007-10-10 23:55:51 153,088 —-a-w C:\WINDOWS\system32\ieakeng.dll
- 2007-08-13 23:39:54 229,376 —-a-w C:\WINDOWS\system32\ieaksie.dll
+ 2007-10-10 23:55:51 230,400 —-a-w C:\WINDOWS\system32\ieaksie.dll
- 2007-08-13 22:56:54 161,792 —-a-w C:\WINDOWS\system32\ieakui.dll
+ 2007-10-10 05:46:55 161,792 —-a-w C:\WINDOWS\system32\ieakui.dll
- 2007-02-12 21:10:12 2,451,312 —-a-w C:\WINDOWS\system32\ieapfltr.dat
+ 2007-07-01 03:31:33 2,455,488 —-a-w C:\WINDOWS\system32\ieapfltr.dat
- 2007-07-11 17:27:48 383,488 —-a-w C:\WINDOWS\system32\ieapfltr.dll
+ 2007-10-10 23:55:52 383,488 —-a-w C:\WINDOWS\system32\ieapfltr.dll
- 2007-08-13 23:39:50 382,976 —-a-w C:\WINDOWS\system32\iedkcs32.dll
+ 2007-10-10 23:55:52 384,512 —-a-w C:\WINDOWS\system32\iedkcs32.dll
- 2007-08-13 23:54:10 6,049,280 —-a-w C:\WINDOWS\system32\ieframe.dll
+ 2007-10-10 23:55:54 6,065,664 —-a-w C:\WINDOWS\system32\ieframe.dll
- 2007-08-13 23:39:10 43,008 —-a-w C:\WINDOWS\system32\iernonce.dll
+ 2007-10-10 23:55:55 44,544 —-a-w C:\WINDOWS\system32\iernonce.dll
- 2007-08-13 23:34:04 266,752 —-a-w C:\WINDOWS\system32\iertutil.dll
+ 2007-10-10 23:55:55 267,776 —-a-w C:\WINDOWS\system32\iertutil.dll
- 2007-08-13 23:39:10 13,312 —-a-w C:\WINDOWS\system32\ieudinit.exe
+ 2007-10-10 10:59:40 13,824 —-a-w C:\WINDOWS\system32\ieudinit.exe
- 2005-11-11 01:27:06 49,248 —-a-w C:\WINDOWS\system32\java.exe
+ 2007-09-25 03:30:28 135,168 —-a-w C:\WINDOWS\system32\java.exe
- 2005-11-11 01:27:16 49,250 —-a-w C:\WINDOWS\system32\javaw.exe
+ 2007-09-25 03:30:30 135,168 —-a-w C:\WINDOWS\system32\javaw.exe
- 2005-11-11 03:03:54 127,078 —-a-w C:\WINDOWS\system32\javaws.exe
+ 2007-09-25 04:31:42 139,264 —-a-w C:\WINDOWS\system32\javaws.exe
- 2007-08-13 23:54:10 27,136 —-a-w C:\WINDOWS\system32\jsproxy.dll
+ 2007-10-10 23:55:56 27,648 —-a-w C:\WINDOWS\system32\jsproxy.dll
+ 2005-05-24 17:27:16 213,048 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 20:47:20 94,208 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 20:49:54 950,272 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
- 2007-08-13 23:54:10 458,752 —-a-w C:\WINDOWS\system32\msfeeds.dll
+ 2007-10-10 23:55:56 459,264 —-a-w C:\WINDOWS\system32\msfeeds.dll
- 2007-08-13 23:54:10 50,688 —-a-w C:\WINDOWS\system32\msfeedsbs.dll
+ 2007-10-10 23:55:56 52,224 —-a-w C:\WINDOWS\system32\msfeedsbs.dll
- 2007-08-13 23:54:12 3,578,368 —-a-w C:\WINDOWS\system32\mshtml.dll
+ 2007-10-30 23:42:28 3,590,656 —-a-w C:\WINDOWS\system32\mshtml.dll
- 2007-08-13 23:54:10 475,648 —-a-w C:\WINDOWS\system32\mshtmled.dll
+ 2007-10-10 23:55:58 478,208 —-a-w C:\WINDOWS\system32\mshtmled.dll
- 2007-08-13 23:44:26 192,000 —-a-w C:\WINDOWS\system32\msrating.dll
+ 2007-10-10 23:55:58 193,024 —-a-w C:\WINDOWS\system32\msrating.dll
- 2007-08-13 23:54:10 670,720 —-a-w C:\WINDOWS\system32\mstime.dll
+ 2007-10-10 23:55:59 671,232 —-a-w C:\WINDOWS\system32\mstime.dll
- 2007-08-13 23:44:06 101,376 —-a-w C:\WINDOWS\system32\occache.dll
+ 2007-10-10 23:55:59 102,400 —-a-w C:\WINDOWS\system32\occache.dll
- 2007-08-13 23:44:30 105,984 —-a-w C:\WINDOWS\system32\url.dll
+ 2007-10-10 23:55:59 105,984 —-a-w C:\WINDOWS\system32\url.dll
- 2007-08-13 23:54:10 1,162,240 —-a-w C:\WINDOWS\system32\urlmon.dll
+ 2007-10-10 23:56:00 1,159,680 —-a-w C:\WINDOWS\system32\urlmon.dll
- 2007-08-13 23:54:10 231,424 —-a-w C:\WINDOWS\system32\webcheck.dll
+ 2007-10-10 23:56:00 232,960 —-a-w C:\WINDOWS\system32\webcheck.dll
- 2007-08-13 23:54:10 818,688 —-a-w C:\WINDOWS\system32\wininet.dll
+ 2007-10-10 23:56:00 824,832 —-a-w C:\WINDOWS\system32\wininet.dll
+ 2008-01-08 04:34:55 16,384 —-atw C:\WINDOWS\Temp\Perflib_Perfdata_134.dat
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-05-09 17:50 7311360]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-01-01 22:03 219136]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Extender Resource Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Extender Resource Monitor.lnk
backup=C:\WINDOWS\pss\Extender Resource Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlwaysReady Power Message APP]
——— 2005-08-03 01:19 77312 C:\WINDOWS\arpwrmsg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
–a—— 2005-08-05 22:56 64512 C:\WINDOWS\ehome\ehtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ftutil2]
–a—— 2004-06-07 16:05 106496 C:\WINDOWS\system32\ftutil2.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]
C:\WINDOWS\system32\jkhhe.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a—— 2006-05-09 17:50 7311360 C:\WINDOWS\system32\NvCpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
–a—— 2006-05-09 17:50 1519616 C:\WINDOWS\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
–a—— 2006-06-13 22:05 16239616 C:\WINDOWS\RTHDCPL.EXE

R2 RMSvc;Media Center Extender Resource Monitor;C:\WINDOWS\ehome\RMSvc.exe [2005-10-20 18:55]
S3 QWAVE;QWAVE service;C:\WINDOWS\system32\svchost.exe [2004-08-09 23:00]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
QWAVE REG_MULTI_SZ QWAVE

.
Contents of the 'Scheduled Tasks' folder
"2008-01-07 17:54:08 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-07 23:36:03
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-07 23:37:56 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-08 04:37:48
ComboFix2.txt 2008-01-07 02:46:32
.
2008-01-07 08:01:18 — E O F —


And HJT:

Logfile of HijackThis v1.99.1
Scan saved at 11:39:03 PM, on 1/7/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\ehome\RMSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/comcast.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: hpWebHelper Class - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {483EB14D-AF1C-4951-81B0-4E2B41829FF6} (QOLCheck Control) - https://www.select2perform.com/cabs/QOLCheck.ocx
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - http://aolsvc.aol.com/onlinegames/trydiner…h2.1.0.0.67.cab
O16 - DPF: {6FE79ACA-A498-45E5-8BC4-1B9F380CE468} (Abx(gh) Control) - http://aolsvc.aol.com/onlinegames/ghadventureball/abxgh.cab
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
O16 - DPF: {74E4A24D-5224-4F05-8A41-99445E0FC22B} (GameHouse Games Player) - http://aolsvc.aol.com/onlinegames/free-tri…houseplayer.cab
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://tsweb.covenanttransport.com/msrdp.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://aolsvc.aol.com/onlinegames/free-tri…zylomplayer.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://aolsvc.aol.com/onlinegames/popinsan…ploader_v10.cab
O16 - DPF: {EA6246B4-F380-443F-8727-9AEA3371146C} (CPlayFirstWeddingDashControl Object) - http://aolsvc.aol.com/onlinegames/free-tri…sh.1.0.0.47.cab
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
A. Open Notepad and copy and paste the following quotebox into a new text document. (Don't forget to copy and paste REGEDIT4!)

REGEDIT4

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]

Save this as fix.reg Choose to save as *all files and place it on your Desktop.
It should look like this: [external image: Posted Image]
Double-click on it and when it asks you if you want to merge the contents to the registry, click Yes/OK.



B. Please tell me how your system is running. If everything appears to be in order, give me the OK and we will proceed with the final but essential cleanup procedures.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI