The 2 files I scanned on the Jotti website were both OK as nothing was found.
Here are all the logs from Kaspersky and HJT. I am also going to post a link again for the ComboFix because it is too long to post in multiple replies.
ComboFix.txt
http://download.yous...951323E0372C0EA
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
2008-01-25 18:28
Operating System: Microsoft Windows XP Professional, Service Pack 1 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 25/01/2008
Kaspersky Anti-Virus database records: 532950
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: false
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
Scan Statistics:
Total number of scanned objects: 88900
Number of viruses found: 25
Number of infected objects: 91
Number of suspicious objects: 0
Duration of the scan process: 00:46:41
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Jonathan Fong\.housecall\Quarantine\delprot.sys.bac_a03168 Infected: Trojan.Win32.Delprot.a skipped
C:\Documents and Settings\Jonathan Fong\.housecall\Quarantine\UWFX5NetInstaller.exe.bac_a03168 Infected: not-a-virus:Downloader.Win32.Agent.d skipped
C:\Documents and Settings\Jonathan Fong\.housecall6.6\Quarantine\delprot.sys.bac_a03168 Infected: Trojan.Win32.Delprot.a skipped
C:\Documents and Settings\Jonathan Fong\.housecall6.6\Quarantine\MirarSetup_876075.exe.bac_a02632 Infected: not-a-virus:AdWare.Win32.SaveNow.bj skipped
C:\Documents and Settings\Jonathan Fong\.housecall6.6\Quarantine\mmxsnet.exe.bac_a01068 Infected: not-a-virus:AdWare.Win32.MediaMotor.q skipped
C:\Documents and Settings\Jonathan Fong\.housecall6.6\Quarantine\NNBar_VCSetup_876075.exe.bac_a01068 Infected: not-a-virus:AdWare.Win32.Mirar.a skipped
C:\Documents and Settings\Jonathan Fong\.housecall6.6\Quarantine\UWA5PNetInstaller.exe.bac_a01068 Infected: not-a-virus:Downloader.Win32.Agent.e skipped
C:\Documents and Settings\Jonathan Fong\.housecall6.6\Quarantine\UWFX5NetInstaller.exe.bac_a03168 Infected: not-a-virus:Downloader.Win32.Agent.d skipped
C:\Documents and Settings\Jonathan Fong\Application Data\mIRC\logs\status.log Object is locked skipped
C:\Documents and Settings\Jonathan Fong\Application Data\Mozilla\Firefox\Profiles\zqk5i52n.default\cert8.db Object is locked skipped
C:\Documents and Settings\Jonathan Fong\Application Data\Mozilla\Firefox\Profiles\zqk5i52n.default\history.dat Object is locked skipped
C:\Documents and Settings\Jonathan Fong\Application Data\Mozilla\Firefox\Profiles\zqk5i52n.default\key3.db Object is locked skipped
C:\Documents and Settings\Jonathan Fong\Application Data\Mozilla\Firefox\Profiles\zqk5i52n.default\parent.lock Object is locked skipped
C:\Documents and Settings\Jonathan Fong\Application Data\Mozilla\Firefox\Profiles\zqk5i52n.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Jonathan Fong\Application Data\Mozilla\Firefox\Profiles\zqk5i52n.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Jonathan Fong\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Jonathan Fong\Desktop\Anti Virus\backups\backup-20080118-095457-227.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.dxb skipped
C:\Documents and Settings\Jonathan Fong\Desktop\Anti Virus\backups\backup-20080118-095457-448.dll Infected: not-a-virus:AdWare.Win32.PurityScan.gt skipped
C:\Documents and Settings\Jonathan Fong\Desktop\Anti Virus\backups\backup-20080118-112938-471.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.dxb skipped
C:\Documents and Settings\Jonathan Fong\Desktop\Anti Virus\backups\backup-20080118-112938-699.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.dyx skipped
C:\Documents and Settings\Jonathan Fong\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Jonathan Fong\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Jonathan Fong\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Jonathan Fong\Local Settings\Application Data\Mozilla\Firefox\Profiles\zqk5i52n.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Jonathan Fong\Local Settings\Application Data\Mozilla\Firefox\Profiles\zqk5i52n.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Jonathan Fong\Local Settings\Application Data\Mozilla\Firefox\Profiles\zqk5i52n.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Jonathan Fong\Local Settings\Application Data\Mozilla\Firefox\Profiles\zqk5i52n.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Jonathan Fong\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Jonathan Fong\Local Settings\History\History.IE5\MSHist012008012520080126\index.dat Object is locked skipped
C:\Documents and Settings\Jonathan Fong\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Jonathan Fong\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Jonathan Fong\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\root\Application Data\Aim\oikfqrqj\n1njafong\cert8.db Object is locked skipped
C:\Documents and Settings\root\Application Data\Aim\oikfqrqj\n1njafong\key3.db Object is locked skipped
C:\Documents and Settings\root\Application Data\Aim\oikfqrqj\n1njafong\Resources\CurrentSettings.xml Object is locked skipped
C:\Documents and Settings\root\Application Data\Aim\oikfqrqj\n1njafong\secmod.db Object is locked skipped
C:\Documents and Settings\root\Application Data\Aim\oikfqrqj\Resources\CurrentSettings.xml Object is locked skipped
C:\Documents and Settings\root\Application Data\desktop.ini Object is locked skipped
C:\Documents and Settings\root\Application Data\Microsoft\Internet Explorer\brndlog.bak Object is locked skipped
C:\Documents and Settings\root\Application Data\Microsoft\Internet Explorer\brndlog.txt Object is locked skipped
C:\Documents and Settings\root\Application Data\Microsoft\Internet Explorer\Desktop.htt Object is locked skipped
C:\Documents and Settings\root\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini Object is locked skipped
C:\Documents and Settings\root\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk Object is locked skipped
C:\Documents and Settings\root\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf Object is locked skipped
C:\Documents and Settings\root\Application Data\Microsoft\Protect\CREDHIST Object is locked skipped
C:\Documents and Settings\root\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\root\Favorites\Desktop.ini Object is locked skipped
C:\Documents and Settings\root\Favorites\Links\Customize Links.url Object is locked skipped
C:\Documents and Settings\root\Favorites\Links\Free Hotmail.url Object is locked skipped
C:\Documents and Settings\root\Favorites\Links\Windows Media.url Object is locked skipped
C:\Documents and Settings\root\Favorites\Links\Windows.url Object is locked skipped
C:\Documents and Settings\root\Favorites\MSN.com.url Object is locked skipped
C:\Documents and Settings\root\Favorites\Radio Station Guide.url Object is locked skipped
C:\Documents and Settings\root\Local Settings\Application Data\IconCache.db Object is locked skipped
C:\Documents and Settings\root\Local Settings\Application Data\Microsoft\Internet Explorer\MSIMGSIZ.DAT Object is locked skipped
C:\Documents and Settings\root\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\root\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\root\Local Settings\desktop.ini Object is locked skipped
C:\Documents and Settings\root\Local Settings\History\desktop.ini Object is locked skipped
C:\Documents and Settings\root\Local Settings\History\History.IE5\desktop.ini Object is locked skipped
C:\Documents and Settings\root\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\root\Local Settings\Temp\PerfectNavBHOLog.tmp Object is locked skipped
C:\Documents and Settings\root\Local Settings\Temporary Internet Files\Content.IE5\09MR0L67\desktop.ini Object is locked skipped
C:\Documents and Settings\root\Local Settings\Temporary Internet Files\Content.IE5\49Q30TQZ\desktop.ini Object is locked skipped
C:\Documents and Settings\root\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini Object is locked skipped
C:\Documents and Settings\root\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\root\Local Settings\Temporary Internet Files\Content.IE5\IPPVNE62\desktop.ini Object is locked skipped
C:\Documents and Settings\root\Local Settings\Temporary Internet Files\Content.IE5\OTT0RG2I\desktop.ini Object is locked skipped
C:\Documents and Settings\root\Local Settings\Temporary Internet Files\desktop.ini Object is locked skipped
C:\Documents and Settings\root\My Documents\desktop.ini Object is locked skipped
C:\Documents and Settings\root\My Documents\My Music\Desktop.ini Object is locked skipped
C:\Documents and Settings\root\My Documents\My Music\Sample Music.lnk Object is locked skipped
C:\Documents and Settings\root\My Documents\My Pictures\Desktop.ini Object is locked skipped
C:\Documents and Settings\root\My Documents\My Pictures\Sample Pictures.lnk Object is locked skipped
C:\Documents and Settings\root\NetHood\familyPhotos on computer in master study room (Masterstudy)\Desktop.ini Object is locked skipped
C:\Documents and Settings\root\NetHood\familyPhotos on computer in master study room (Masterstudy)\target.lnk Object is locked skipped
C:\Documents and Settings\root\NetHood\My Pictures on computer in master study room (Masterstudy)\Desktop.ini Object is locked skipped
C:\Documents and Settings\root\NetHood\My Pictures on computer in master study room (Masterstudy)\target.lnk Object is locked skipped
C:\Documents and Settings\root\NetHood\SharedDocs on computer in master study room (Masterstudy)\Desktop.ini Object is locked skipped
C:\Documents and Settings\root\NetHood\SharedDocs on computer in master study room (Masterstudy)\target.lnk Object is locked skipped
C:\Documents and Settings\root\NetHood\SharedDocs on Jon's computer (Jfong)\Desktop.ini Object is locked skipped
C:\Documents and Settings\root\NetHood\SharedDocs on Jon's computer (Jfong)\target.lnk Object is locked skipped
C:\Documents and Settings\root\NetHood\SharedDocs on selfBuildInStudy (Public)\Desktop.ini Object is locked skipped
C:\Documents and Settings\root\NetHood\SharedDocs on selfBuildInStudy (Public)\target.lnk Object is locked skipped
C:\Documents and Settings\root\NetHood\SharedDocs on Sony vaio computer in bo's room (Boboroom)\Desktop.ini Object is locked skipped
C:\Documents and Settings\root\NetHood\SharedDocs on Sony vaio computer in bo's room (Boboroom)\target.lnk Object is locked skipped
C:\Documents and Settings\root\NetHood\wow on Jon's computer (Jfong)\Desktop.ini Object is locked skipped
C:\Documents and Settings\root\NetHood\wow on Jon's computer (Jfong)\target.lnk Object is locked skipped
C:\Documents and Settings\root\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\root\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\root\ntuser.ini Object is locked skipped
C:\Documents and Settings\root\Recent\Desktop.ini Object is locked skipped
C:\Documents and Settings\root\SendTo\Compressed (zipped) Folder.ZFSendToTarget Object is locked skipped
C:\Documents and Settings\root\SendTo\Desktop (create shortcut).DeskLink Object is locked skipped
C:\Documents and Settings\root\SendTo\desktop.ini Object is locked skipped
C:\Documents and Settings\root\SendTo\Mail Recipient.MAPIMail Object is locked skipped
C:\Documents and Settings\root\SendTo\My Documents.mydocs Object is locked skipped
C:\Documents and Settings\root\Start Menu\desktop.ini Object is locked skipped
C:\Documents and Settings\root\Start Menu\Programs\Accessories\Accessibility\desktop.ini Object is locked skipped
C:\Documents and Settings\root\Start Menu\Programs\Accessories\Accessibility\Magnifier.lnk Object is locked skipped
C:\Documents and Settings\root\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk Object is locked skipped
C:\Documents and Settings\root\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk Object is locked skipped
C:\Documents and Settings\root\Start Menu\Programs\Accessories\Accessibility\Utility Manager.lnk Object is locked skipped
C:\Documents and Settings\root\Start Menu\Programs\Accessories\Address Book.lnk Object is locked skipped
C:\Documents and Settings\root\Start Menu\Programs\Accessories\Command Prompt.lnk Object is locked skipped
C:\Documents and Settings\root\Start Menu\Programs\Accessories\desktop.ini Object is locked skipped
C:\Documents and Settings\root\Start Menu\Programs\Accessories\Entertainment\desktop.ini Object is locked skipped
C:\Documents and Settings\root\Start Menu\Programs\Accessories\Entertainment\Windows Media Player.lnk Object is locked skipped
C:\Documents and Settings\root\Start Menu\Programs\Accessories\Notepad.lnk Object is locked skipped
C:\Documents and Settings\root\Start Menu\Programs\Accessories\Program Compatibility Wizard.lnk Object is locked skipped
C:\Documents and Settings\root\Start Menu\Programs\Accessories\Synchronize.lnk Object is locked skipped
C:\Documents and Settings\root\Start Menu\Programs\Accessories\Tour Windows XP.lnk Object is locked skipped
C:\Documents and Settings\root\Start Menu\Programs\Accessories\Windows Explorer.lnk Object is locked skipped
C:\Documents and Settings\root\Start Menu\Programs\desktop.ini Object is locked skipped
C:\Documents and Settings\root\Start Menu\Programs\Internet Explorer.lnk Object is locked skipped
C:\Documents and Settings\root\Start Menu\Programs\Outlook Express.lnk Object is locked skipped
C:\Documents and Settings\root\Start Menu\Programs\Remote Assistance.lnk Object is locked skipped
C:\Documents and Settings\root\Start Menu\Programs\Startup\desktop.ini Object is locked skipped
C:\Documents and Settings\root\Start Menu\Programs\Windows Media Player.lnk Object is locked skipped
C:\Documents and Settings\root\Templates\amipro.sam Object is locked skipped
C:\Documents and Settings\root\Templates\excel.xls Object is locked skipped
C:\Documents and Settings\root\Templates\excel4.xls Object is locked skipped
C:\Documents and Settings\root\Templates\lotus.wk4 Object is locked skipped
C:\Documents and Settings\root\Templates\powerpnt.ppt Object is locked skipped
C:\Documents and Settings\root\Templates\presenta.shw Object is locked skipped
C:\Documents and Settings\root\Templates\quattro.wb2 Object is locked skipped
C:\Documents and Settings\root\Templates\sndrec.wav Object is locked skipped
C:\Documents and Settings\root\Templates\winword.doc Object is locked skipped
C:\Documents and Settings\root\Templates\winword2.doc Object is locked skipped
C:\Documents and Settings\root\Templates\wordpfct.wpd Object is locked skipped
C:\Documents and Settings\root\Templates\wordpfct.wpg Object is locked skipped
C:\Pstools\psexec.exe Infected: not-a-virus:RiskTool.Win32.PsExec.153 skipped
C:\Pstools\pskill.exe Infected: not-a-virus:RiskTool.Win32.PsKill.1101 skipped
C:\Pstools\rkipii.exe.tmp Object is locked skipped
C:\QooBox\Quarantine\C\Documents and Settings\Jonathan Fong\Application Data\STEM32~1\ѕеrvices.exe.vir Infected: not-a-virus:AdWare.Win32.PurityScan.gs skipped
C:\QooBox\Quarantine\C\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas .exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\WINDOWS\mrofinu1000106.exe.vir Infected: Trojan-Downloader.Win32.Agent.hql skipped
C:\QooBox\Quarantine\C\WINDOWS\mrofinu572.exe.tmp.vir Infected: Trojan-Downloader.Win32.Agent.hql skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\ctfmon.exe.tmp.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\gebca.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\idfutfrf.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.ebw skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\qommnll.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.dxb skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\RCX9.tmp.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{D3588862-74A2-4FEF-8D1F-4895922D1A26}\RP1159\A0191701.exe Infected: Trojan-Downloader.Win32.Agent.hql skipped
C:\System Volume Information\_restore{D3588862-74A2-4FEF-8D1F-4895922D1A26}\RP1160\A0191719.exe Infected: Trojan-Downloader.Win32.Agent.hql skipped
C:\System Volume Information\_restore{D3588862-74A2-4FEF-8D1F-4895922D1A26}\RP1161\A0191732.exe Infected: Trojan.Win32.Scapur.k skipped
C:\System Volume Information\_restore{D3588862-74A2-4FEF-8D1F-4895922D1A26}\RP1163\A0191856.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.dxb skipped
C:\System Volume Information\_restore{D3588862-74A2-4FEF-8D1F-4895922D1A26}\RP1165\A0191896.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.dyx skipped
C:\System Volume Information\_restore{D3588862-74A2-4FEF-8D1F-4895922D1A26}\RP1165\A0191961.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.dyx skipped
C:\System Volume Information\_restore{D3588862-74A2-4FEF-8D1F-4895922D1A26}\RP1165\A0191968.dll Infected: not-a-virus:AdWare.Win32.PurityScan.gt skipped
C:\System Volume Information\_restore{D3588862-74A2-4FEF-8D1F-4895922D1A26}\RP1167\A0194085.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{D3588862-74A2-4FEF-8D1F-4895922D1A26}\RP1169\A0196062.exe Infected: Trojan.Win32.Agent.eco skipped
C:\System Volume Information\_restore{D3588862-74A2-4FEF-8D1F-4895922D1A26}\RP1169\A0196063.exe Infected: not-a-virus:FraudTool.Win32.DrAntispy.ag skipped
C:\System Volume Information\_restore{D3588862-74A2-4FEF-8D1F-4895922D1A26}\RP1170\A0201060.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D3588862-74A2-4FEF-8D1F-4895922D1A26}\RP1171\A0201073.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D3588862-74A2-4FEF-8D1F-4895922D1A26}\RP1171\A0202060.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D3588862-74A2-4FEF-8D1F-4895922D1A26}\RP1172\A0202076.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{D3588862-74A2-4FEF-8D1F-4895922D1A26}\RP1172\A0202078.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D3588862-74A2-4FEF-8D1F-4895922D1A26}\RP1172\A0202082.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.dnn skipped
C:\System Volume Information\_restore{D3588862-74A2-4FEF-8D1F-4895922D1A26}\RP1172\A0202083.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.dyx skipped
C:\System Volume Information\_restore{D3588862-74A2-4FEF-8D1F-4895922D1A26}\RP1172\A0202084.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.dnn skipped
C:\System Volume Information\_restore{D3588862-74A2-4FEF-8D1F-4895922D1A26}\RP1172\A0203097.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D3588862-74A2-4FEF-8D1F-4895922D1A26}\RP1172\A0204097.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D3588862-74A2-4FEF-8D1F-4895922D1A26}\RP1172\A0204101.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D3588862-74A2-4FEF-8D1F-4895922D1A26}\RP1172\A0204105.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.dyx skipped
C:\System Volume Information\_restore{D3588862-74A2-4FEF-8D1F-4895922D1A26}\RP1172\A0204106.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.dnn skipped
C:\System Volume Information\_restore{D3588862-74A2-4FEF-8D1F-4895922D1A26}\RP1172\A0204108.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.dnn skipped
C:\System Volume Information\_restore{D3588862-74A2-4FEF-8D1F-4895922D1A26}\RP1173\A0204123.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{D3588862-74A2-4FEF-8D1F-4895922D1A26}\RP1173\A0204149.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D3588862-74A2-4FEF-8D1F-4895922D1A26}\RP1173\A0205148.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D3588862-74A2-4FEF-8D1F-4895922D1A26}\RP1173\A0205149.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D3588862-74A2-4FEF-8D1F-4895922D1A26}\RP1173\A0206154.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.dnn skipped
C:\System Volume Information\_restore{D3588862-74A2-4FEF-8D1F-4895922D1A26}\RP1173\A0206156.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.dyx skipped
C:\System Volume Information\_restore{D3588862-74A2-4FEF-8D1F-4895922D1A26}\RP1173\A0206157.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.dnn skipped
C:\System Volume Information\_restore{D3588862-74A2-4FEF-8D1F-4895922D1A26}\RP1174\A0206168.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{D3588862-74A2-4FEF-8D1F-4895922D1A26}\RP1174\A0206199.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D3588862-74A2-4FEF-8D1F-4895922D1A26}\RP1174\A0207163.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D3588862-74A2-4FEF-8D1F-4895922D1A26}\RP1174\A0207164.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D3588862-74A2-4FEF-8D1F-4895922D1A26}\RP1174\A0207320.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D3588862-74A2-4FEF-8D1F-4895922D1A26}\RP1174\A0207325.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D3588862-74A2-4FEF-8D1F-4895922D1A26}\RP1175\A0207352.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D3588862-74A2-4FEF-8D1F-4895922D1A26}\RP1176\A0207353.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D3588862-74A2-4FEF-8D1F-4895922D1A26}\RP1176\A0207356.exe Infected: Trojan-Downloader.Win32.Agent.hql skipped
C:\System Volume Information\_restore{D3588862-74A2-4FEF-8D1F-4895922D1A26}\RP1176\A0207357.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D3588862-74A2-4FEF-8D1F-4895922D1A26}\RP1176\A0207358.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ebw skipped
C:\System Volume Information\_restore{D3588862-74A2-4FEF-8D1F-4895922D1A26}\RP1176\A0207359.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.dxb skipped
C:\System Volume Information\_restore{D3588862-74A2-4FEF-8D1F-4895922D1A26}\RP1176\A0207362.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{D3588862-74A2-4FEF-8D1F-4895922D1A26}\RP1176\A0207363.exe Infected: not-a-virus:AdWare.Win32.PurityScan.gs skipped
C:\System Volume Information\_restore{D3588862-74A2-4FEF-8D1F-4895922D1A26}\RP1176\A0207369.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.dyx skipped
C:\System Volume Information\_restore{D3588862-74A2-4FEF-8D1F-4895922D1A26}\RP1178\change.log Object is locked skipped
C:\VundoFix Backups\ajxrbeys.exe.bad Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\VundoFix Backups\ddcayvv.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.dxb skipped
C:\VundoFix Backups\ejlvwuli.exe.bad Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\VundoFix Backups\gebyw.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.dyx skipped
C:\VundoFix Backups\jkhhf.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.dyx skipped
C:\VundoFix Backups\jkhhf.exe.bad Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\VundoFix Backups\jktakapq.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.dnn skipped
C:\VundoFix Backups\jnvogvuq.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.dnn skipped
C:\VundoFix Backups\kanrsqtc.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.dnn skipped
C:\VundoFix Backups\mljgg.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.dyx skipped
C:\VundoFix Backups\mlljj.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.dyx skipped
C:\VundoFix Backups\npidpxch.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.dnn skipped
C:\VundoFix Backups\qommnll.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.dxb skipped
C:\VundoFix Backups\ssttr.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.dyx skipped
C:\VundoFix Backups\ssttr.exe.bad Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\VundoFix Backups\sylrgxno.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.dnn skipped
C:\VundoFix Backups\xsstaihd.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.dnn skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Downloaded Program Files\webinst.dll Infected: Trojan-Downloader.Win32.Adload.pi skipped
C:\WINDOWS\MEMORY.DMP Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\windows_tobedeleted_old Infected: Trojan.Win32.Zapchast.dt skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.62 skipped
D:\Program Files\mIRC1\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.631 skipped
D:\Program Files\Steam\Steam.log Object is locked skipped
D:\Program Files\Steam\SteamApps\winui.gcf Object is locked skipped
D:\System Volume Information\_restore{D3588862-74A2-4FEF-8D1F-4895922D1A26}\RP1178\change.log Object is locked skipped
Scan process completed.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:30, on 2008-01-25
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\ctfmon.exe
D:\program files\steam\steam.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Ventrilo\Ventrilo.exe
D:\Program Files\mIRC1\mirc.exe
C:\Documents and Settings\Jonathan Fong\Desktop\scanner.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas .exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Steam] "d:\program files\steam\steam.exe" -silent
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\Program Files\AIM\aim.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky...can_unicode.cab
O16 - DPF: {1A26F07F-0D60-4835-91CF-1E1766A0EC56} -
http://scanner2.malw...tup/webinst.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AutoComplete Service (Autocomplete) - Unknown owner - C:\Program Files\Acesoft\Tracks Eraser Pro\autocomp.exe (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: RadClock - Unknown owner - C:\WINDOWS\system32\RadClock.exe (file missing)
--
End of file - 3489 bytes