This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] trojan virtumonde infection

23 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer has been infected with trojan virtumonde and now suffering from slow operation pop-ups,have tried lots of spyware removal programs with no joy can anyone help please ?
Hello stacey t and welcome to the What the Tech Forums

My name is Trevuren and I will be helping you with your problem.


Download HijackThis from Here .
  • Choose the default location of C:\Program Files\Trend Micro\HijackThis as the destination. HJT needs to be in its own folder so that the program itself isn't deleted by accident. Having the backups could be VITAL to restoring your system if something went wrong in the FIX process!
  • Click the Install button.
  • Accept the license agreement .
  • Click Do a system scan and save a log file. A Notepad file will open.
  • Select all the text by hitting the [Ctrl+A] keys, then copy your selection to the clipboard by pressing the [Ctrl+C] keys.
  • Paste the log into this thread by hitting the [Ctrl+V] keys.
  • when you click Save Log) (Ctrl-A to'select all', Ctrl-C to 'copy')
  • POST the log into this thread using 'Add Reply' (Ctrl-V to 'paste')


DO NOT MAKE ANY CHANGES OR CLICK "FIX CHECKED" UNTIL WE CHECK THE LOG, AS MOST OF THE FILES ARE LEGIT AND VITAL TO THE FUNCTION OF YOUR COMPUTER
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:04:09, on 16/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\UAService7.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\QTTask.exe
C:\WINDOWS\PixArt\PAC207\Monitor.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\wvcsvc.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\kdx\KHost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0seenus/saos01
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://orange.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60327
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60327
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Wanadoo
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
O3 - Toolbar: Wanadoo - {8B68564D-53FD-4293-B80C-993A9F3988EE} - C:\PROGRA~1\Wanadoo\WSBar\WSBar.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [Windows Video Component] wvcsvc.exe
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\RunServices: [update] adaware.exe
O4 - HKCU\..\Run: [kdx] C:\WINDOWS\kdx\KHost.exe -all
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-1083674592-805428932-3470337186-1009\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit (User 'adam')
O4 - HKUS\S-1-5-21-1083674592-805428932-3470337186-1009\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'adam')
O4 - HKUS\S-1-5-21-1083674592-805428932-3470337186-1009\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'adam')
O4 - HKUS\S-1-5-21-1083674592-805428932-3470337186-1009\..\Run: [msnmsgr] ~"C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'adam')
O4 - HKUS\S-1-5-21-1083674592-805428932-3470337186-1009\..\Run: [DAEMON Tools Pro Agent] "C:\Program Files\DAEMON Tools Pro\DTProAgent.exe" (User 'adam')
O4 - HKUS\S-1-5-21-1083674592-805428932-3470337186-1009\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe (User 'adam')
O4 - HKUS\S-1-5-21-1083674592-805428932-3470337186-1009\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized (User 'adam')
O4 - HKUS\S-1-5-21-1083674592-805428932-3470337186-1009\..\Run: [AdwareAlert] C:\Program Files\AdwareAlert\AdwareAlert.exe -boot (User 'adam')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Search with Wanadoo - res://C:\PROGRA~1\Wanadoo\WSBar\WSBar.dll/VSearch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - blank (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - blank (file missing)
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.explorertool.net/redirect.php (file missing)
O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.explorertool.net/redirect.php (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://www.wanadoo.co.uk
O16 - DPF: LEGO Stormrunner - http://mindstorms.lego.com/stormrunner/stormrunner1-1-0.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1095767088234
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1127331239812
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O16 - DPF: {BAE1D8DF-0B35-47E3-A1E7-EEB3FF2ECD19} (CPlayFirstddfotgControl Object) - http://www.freeworldgroup.com/games6/diner…tg.1.0.0.33.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - https://ukplay.toontown.com/download/sv1.0.21.10/ttinst.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe

–
End of file - 13368 bytes
Please download ComboFix by sUBs from HERE or HERE directly to your Desktop.

Note: If you already have a current version of ComboFix on your machine, please DELETE it from your desktop before downloading the newest version.

Go to [external image: Posted Image] -> Run -> copy/paste the following single line command in the runbox & click OK

indent]"%userprofile%\desktop\combofix.exe" /killall
[external image: Posted Image]
  • ComboFix will automatically start. Any monitoring programs will be shut down like your antivirus, antispyware programs for example.
  • ComboFix may restart your computer, this is normal.
  • When finished, it will produce a log, ComboFix.txt.
  • Please post ComboFix.txt in your next reply along with a new HijackThis log.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
thanks for the help here as the logs as requested.
stacey


ComboFix 08-02-17.2 - stacey 2008-02-17 12:26:06.2 - FAT32x86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-01-17 to 2008-02-17 )))))))))))))))))))))))))))))))
.

2008-02-16 13:03 . 2008-02-16 13:03 d——– C:\Program Files\Trend Micro
2008-02-16 08:59 . 2008-02-16 11:03 354 —hs—- C:\WINDOWS\system32\dihoqdtl.ini
2008-02-15 12:49 . 2008-02-15 12:49 232 –ah—– C:\sqmdata10.sqm
2008-02-15 11:54 . 2008-02-15 11:54 232 –ah—– C:\sqmdata09.sqm
2008-02-15 11:52 . 2008-02-15 11:52 232 –ah—– C:\sqmdata08.sqm
2008-02-15 09:41 . 2008-02-15 09:41 232 –ah—– C:\sqmdata07.sqm
2008-02-15 09:36 . 2008-02-15 09:36 232 –ah—– C:\sqmdata06.sqm
2008-02-15 09:05 . 2008-02-15 09:05 232 –ah—– C:\sqmdata05.sqm
2008-02-15 08:35 . 2008-02-15 08:35 244 –ah—– C:\sqmnoopt19.sqm
2008-02-15 08:35 . 2008-02-15 08:35 232 –ah—– C:\sqmdata04.sqm
2008-02-15 08:28 . 2008-02-15 08:28 244 –ah—– C:\sqmnoopt18.sqm
2008-02-15 08:28 . 2008-02-15 08:28 232 –ah—– C:\sqmdata03.sqm
2008-02-15 08:21 . 2008-02-15 08:21 244 –ah—– C:\sqmnoopt17.sqm
2008-02-15 08:21 . 2008-02-15 08:21 232 –ah—– C:\sqmdata02.sqm
2008-02-14 21:56 . 2008-02-14 21:56 d——– C:\Program Files\AdwareAlert
2008-02-14 08:59 . 2008-02-14 08:59 294 —hs—- C:\WINDOWS\system32\ccjbqydy.ini
2008-02-14 05:08 . 2008-02-14 05:08 d——– C:\VundoFix Backups
2008-02-13 19:44 . 2008-02-13 19:44 d——– C:\Program Files\Sotfone
2008-02-12 20:12 . 2008-02-12 20:12 0 —hs—- C:\WINDOWS\SDA5D3FA8.tmp
2008-02-12 20:00 . 2008-02-12 20:00 d——– C:\Program Files\Ace Utilities
2008-02-12 14:00 . 2008-02-12 14:00 717 –a—— C:\WINDOWS\system32\SDRemoveDB.db
2008-02-12 13:59 . 2008-02-12 13:59 63 –a—— C:\WINDOWS\system\SysSD.dll
2008-02-12 13:48 . 2008-02-12 13:48 d——– C:\WINDOWS\048298C9A4D3490B9FF9AB023A9238F3.TMP
2008-02-12 13:44 . 2008-02-12 13:44 d——– C:\Documents and Settings\stacey\Application Data\AdwareAlert
2008-02-12 09:40 . 2008-02-12 14:33 654 —hs—- C:\WINDOWS\system32\cvfdsbap.ini
2008-02-11 17:31 . 2008-02-11 17:31 d——– C:\Documents and Settings\adam\Application Data\AdwareAlert
2008-02-11 16:37 . 2008-02-11 16:37 d——– C:\Program Files\Enigma Software Group
2008-02-09 16:03 . 2008-02-09 17:31 834 —hs—- C:\WINDOWS\system32\gostmmvu.ini
2008-02-08 15:56 . 2008-02-09 15:57 654 —hs—- C:\WINDOWS\system32\xpmiwtob.ini
2008-02-08 11:56 . 2008-02-08 11:56 230,432 –a—— C:\PA207.DAT
2008-02-08 10:15 . 2008-02-08 10:15 d——– C:\Program Files\Spyware Doctor
2008-02-08 10:15 . 2008-02-08 10:15 d——– C:\Documents and Settings\stacey\Application Data\PC Tools
2008-02-08 10:15 . 2007-12-10 14:53 81,288 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2008-02-08 10:15 . 2007-12-10 14:53 66,952 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2008-02-08 10:15 . 2007-12-10 14:53 41,864 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-02-08 10:15 . 2007-12-10 14:53 29,576 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2008-02-08 09:34 . 2008-02-08 09:34 294 —hs—- C:\WINDOWS\system32\sehsttdg.ini
2008-02-08 09:22 . 2008-02-08 10:37 2,048 –a—— C:\WINDOWS\system32\drivers\kgpfr.cfg
2008-02-08 09:16 . 2008-02-08 09:17 d——– C:\Documents and Settings\All Users\Application Data\SITEguard
2008-02-08 09:15 . 2008-02-08 09:15 d——– C:\Program Files\Common Files\iS3
2008-02-08 09:15 . 2008-02-08 09:15 d——– C:\Documents and Settings\All Users\Application Data\STOPzilla!
2008-02-07 16:51 . 2008-02-07 16:51 d–hs—- C:\FOUND.000
2008-02-06 10:51 . 2008-02-06 10:51 d——– C:\Program Files\Spybot - Search & Destroy
2008-02-06 10:51 . 2008-02-06 10:51 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-06 10:08 . 2008-02-06 10:08 d——– C:\Program Files\Digital Locker Assistant
2008-02-04 19:53 . 2008-02-04 19:53 d——– C:\Documents and Settings\sarah\Application Data\skypePM
2008-02-04 17:17 . 2008-02-04 17:15 15,773 -r-hs—- C:\WINDOWS\system32\wvcsvc.exe
2008-02-03 21:45 . 2008-02-03 21:46 d——– C:\Documents and Settings\sarah\Application Data\Skype
2008-02-02 13:48 . 2008-02-02 13:48 d——– C:\Documents and Settings\adam\Application Data\skypePM
2008-02-02 13:48 . 2008-02-02 13:48 32 –a—— C:\Documents and Settings\All Users\Application Data\ezsid.dat
2008-02-02 13:45 . 2008-02-02 13:45 d——– C:\Program Files\Skype
2008-02-02 13:45 . 2008-02-02 13:45 d——– C:\Program Files\Common Files\Skype
2008-01-24 20:22 . 2008-01-24 20:22 d——– C:\Program Files\Driving Test Success 2007-2008
2008-01-24 20:22 . 2008-01-24 20:22 d——– C:\Documents and Settings\All Users\Application Data\Driving Test Success

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-16 13:13 2,286 —-a-w C:\Documents and Settings\adam\Application Data\wklnhst.dat
2008-02-13 11:09 712 —-a-w C:\Documents and Settings\stacey\Application Data\wklnhst.dat
2008-02-04 17:52 10 —-a-w C:\Documents and Settings\All Users\Application Data\mmrpplic.dat
2008-01-15 09:54 10,537 —-a-w C:\WINDOWS\system32\drivers\COH_Mon.cat
2008-01-15 05:28 706 —-a-w C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-01-13 13:42 ——— d—–w C:\Documents and Settings\stacey\Application Data\Nero
2008-01-13 13:27 ——— d—–w C:\Documents and Settings\All Users\Application Data\Ahead
2008-01-13 12:03 ——— d—–w C:\Documents and Settings\stacey\Application Data\Ahead
2008-01-13 12:02 ——— d—–w C:\Program Files\Nero
2008-01-13 12:02 ——— d—–w C:\Program Files\Common Files\Ahead
2008-01-12 18:45 ——— d—–w C:\Program Files\Quick AVI Splitter
2008-01-12 18:32 23,904 —-a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-01-11 05:53 44,544 —-a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
2008-01-05 09:38 ——— d—–w C:\Program Files\Common Files\Blizzard Entertainment
2008-01-03 13:28 ——— d—–w C:\Program Files\MoparScape
2008-01-02 18:45 ——— d—–w C:\Program Files\Sun
2008-01-02 18:29 ——— d—–w C:\Documents and Settings\adam\Application Data\Hamachi
2008-01-02 18:27 25,280 —-a-w C:\WINDOWS\system32\drivers\hamachi.sys
2008-01-02 18:27 ——— d—–w C:\Program Files\Hamachi
2007-12-25 10:57 ——— d—–w C:\Documents and Settings\adam\Application Data\ArcSoft
2007-12-25 10:42 ——— d—–w C:\Program Files\Common Files\PAC207
2007-12-25 10:40 ——— d—–w C:\Program Files\Common Files\ArcSoft
2007-12-25 10:39 ——— d—–w C:\Program Files\ArcSoft
2007-12-25 10:38 ——— d—–w C:\Program Files\Trust
2007-12-23 12:00 ——— d—–w C:\Program Files\CamStudio
2007-12-19 23:01 347,136 —-a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-12-19 14:40 ——— d—–w C:\Program Files\Common Files\Sony Shared
2007-12-18 09:51 179,584 —-a-w C:\WINDOWS\system32\drivers\mrxdav.sys
2007-12-18 09:51 179,584 ——w C:\WINDOWS\system32\dllcache\mrxdav.sys
2007-12-17 17:36 ——— d—–w C:\Program Files\Datel
2007-12-08 05:21 3,592,192 —-a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-12-06 11:01 625,664 ——w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-12-06 11:00 70,656 ——w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-12-06 11:00 13,824 ——w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-12-06 04:59 161,792 —-a-w C:\WINDOWS\system32\dllcache\ieakui.dll
2007-12-05 09:24 60,800 —-a-w C:\WINDOWS\system32\S32EVNT1.DLL
2007-12-04 18:38 550,912 —-a-w C:\WINDOWS\system32\oleaut32.dll
2007-12-04 18:38 550,912 ——w C:\WINDOWS\system32\dllcache\oleaut32.dll
2007-10-16 23:20 3,406 —-a-w C:\Documents and Settings\sarah\Application Data\wklnhst.dat
2007-03-10 12:55 392 —-a-w C:\Documents and Settings\rebecca\Application Data\wklnhst.dat
2006-12-17 16:35 326 —ha-w C:\Documents and Settings\All Users\hpothb07.dat
2006-12-17 16:35 200 —ha-w C:\Documents and Settings\adam\hpothb07.dat
2006-12-17 16:35 200 —ha-w C:\Documents and Settings\ADAM 2\hpothb07.dat
2006-12-17 16:35 0 —ha-w C:\Documents and Settings\Default User\hpothb07.dat
2006-08-20 17:41 32 —-a-r C:\Documents and Settings\All Users\hash.dat
2005-04-20 17:01 161 —ha-w C:\Documents and Settings\stacey\hpothb07.dat
2007-11-02 17:36 848 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{10C52A42-DB8B-4ade-AA4A-CED6A8282B67}]
2008-02-13 19:44 14848 –a—— C:\Program Files\Sotfone\1202931891.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"kdx"="C:\WINDOWS\kdx\KHost.exe" [2007-05-11 09:46 2236416]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:56 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 06:24 286720]
"nwiz"="nwiz.exe" [2003-11-26 07:43 753664 C:\WINDOWS\system32\nwiz.exe]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-09-23 08:33 1838592]
"Monitor"="C:\WINDOWS\PixArt\PAC207\Monitor.exe" [2006-11-03 11:01 319488]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-09-03 08:04 84640]
"Windows Video Component"="wvcsvc.exe" [2008-02-04 17:15 15773 C:\WINDOWS\system32\wvcsvc.exe]
"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [2007-12-10 14:53 1103752]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2003-11-26 07:43 3022848]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"update"="adaware.exe" []

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 07:56 15360]
"ALUAlert"="C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe" [2006-09-03 00:36 100032]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2005-04-25 13:45 36040]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-04 07:56 53760 C:\WINDOWS\system32\narrator.exe]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\iifdebx]
iifdebx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\nnnnmnn]
nnnnmnn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\qommjhe]
qommjhe.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tuvvssr]
tuvvssr.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
path=
backup=

[HKLM\~\startupfolder\C:^Documents and Settings^adam^Start Menu^Programs^Startup^Adobe Gamma.lnk]
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^adam^Start Menu^Programs^Startup^hamachi.lnk]
backup=C:\WINDOWS\pss\hamachi.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
–a—— 2005-06-06 23:46 57344 C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CARPService]
–a—— 2003-06-11 11:54 4608 C:\WINDOWS\system32\carpserv.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
–a—— 2006-09-03 08:04 84640 C:\Program Files\Common Files\Symantec Shared\ccApp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]
–a—— 2005-01-19 11:05 221184 C:\WINDOWS\system32\LVCOMSX.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
–a—— 2003-04-14 19:30 1491216 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\osCheck]
–a—— 2006-09-06 02:22 26248 C:\Program Files\Norton Internet Security\osCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Power2GoExpress]
——— 2004-05-17 11:36 839770 C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
–a—— 2005-01-12 03:01 32768 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
-ra—— 2005-10-26 16:17 159744 C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
–a—— 2003-08-04 23:59 57344 C:\WINDOWS\SOUNDMAN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeedTouch USB Diagnostics]
–a—— 2004-01-26 11:38 866816 C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2007-09-25 01:11 132496 C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SupaDial]
–a—— 2003-08-26 16:40 286720 C:\Program Files\SupaDial\SupaDial.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM]
-ra—— 2007-10-14 18:09 103712 C:\Program Files\Macrogaming\SweetIM\SweetIM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
–a—— 2007-03-14 16:52 3770024 C:\Program Files\TomTom HOME\TomTomHOME.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
–a—— 2006-11-03 18:20 866584 C:\Program Files\Windows Defender\MSASCui.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Power2GoExpress"=C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"mmtask"=c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe

R1 kbfilter;Keyboard Filter Driver;C:\WINDOWS\system32\drivers\kbfilter.sys [2002-10-15 14:48]
R2 BT848;AVerMedia, AVerTV WDM Video Capture;C:\WINDOWS\system32\drivers\BT848.sys [2002-05-13 19:40]
R2 BTTUNER;AVerMedia, AVerTV WDM TvTuner;C:\WINDOWS\system32\drivers\BTTUNER.sys [2002-01-27 04:57]
R2 BTXBAR;AVerMedia, AVerTV WDM Crossbar;C:\WINDOWS\system32\drivers\BTXBAR.sys [2002-01-27 05:02]
R3 PAC207;Trust WB-1400T Webcam;C:\WINDOWS\system32\DRIVERS\PFC027.SYS [2007-05-14 10:26]
S2 Ca536av;DigitalCam Pro Video Camera Device;C:\WINDOWS\system32\Drivers\Ca536av.sys [2004-05-21 19:21]
S3 alcan5ln;SpeedTouch™ USB ADSL RFC1483 Networking Driver (NDIS);C:\WINDOWS\system32\DRIVERS\alcan5ln.sys [2003-12-08 11:53]
S3 USBCamera;DigitalCam Pro Still Camera Device;C:\WINDOWS\system32\Drivers\Bulk536.sys [2003-05-14 09:28]

*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-02-17 12:19:08 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2008-02-14 21:27:02 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1096057614.job"
- C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe4-I
"2008-02-14 21:57:34 C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job"
- C:\Program Files\AdwareAlert\AdwareAlert.ex
- C:\Program Files\AdwareAlert
"2008-02-15 20:00:02 C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - stacey.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exeh/TASK:
"2007-08-09 05:23:22 C:\WINDOWS\Tasks\RegCure.job"
- C:\Program Files\RegCure\RegCure.exe
"2008-02-17 12:17:58 C:\WINDOWS\Tasks\RegCure Program Check.job"
- C:\Program Files\RegCure\RegCure.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-17 12:32:50
Windows 5.1.2600 Service Pack 2 FAT NTAPI

detected NTDLL code modification:
ZwClose

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-17 12:35:33
ComboFix-quarantined-files.txt 2008-02-17 12:35:28
ComboFix2.txt 2008-02-17 12:10:52
.
2008-02-16 20:48:45 — E O F —
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:39:20, on 17/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\UAService7.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\PixArt\PAC207\Monitor.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\wvcsvc.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\kdx\KHost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://orange.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60327
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60327
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Sotfone Tracker Class - {10C52A42-DB8B-4ade-AA4A-CED6A8282B67} - C:\Program Files\Sotfone\1202931891.dll
O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll
O3 - Toolbar: Wanadoo - {8B68564D-53FD-4293-B80C-993A9F3988EE} - C:\PROGRA~1\Wanadoo\WSBar\WSBar.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [Windows Video Component] wvcsvc.exe
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\RunServices: [update] adaware.exe
O4 - HKCU\..\Run: [kdx] C:\WINDOWS\kdx\KHost.exe -all
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Search with Wanadoo - res://C:\PROGRA~1\Wanadoo\WSBar\WSBar.dll/VSearch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - blank (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - blank (file missing)
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.explorertool.net/redirect.php (file missing)
O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.explorertool.net/redirect.php (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://www.wanadoo.co.uk
O16 - DPF: LEGO Stormrunner - http://mindstorms.lego.com/stormrunner/stormrunner1-1-0.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1095767088234
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1127331239812
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O16 - DPF: {BAE1D8DF-0B35-47E3-A1E7-EEB3FF2ECD19} (CPlayFirstddfotgControl Object) - http://www.freeworldgroup.com/games6/diner…tg.1.0.0.33.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - https://ukplay.toontown.com/download/sv1.0.21.10/ttinst.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: iifdebx - iifdebx.dll (file missing)
O20 - Winlogon Notify: nnnnmnn - nnnnmnn.dll (file missing)
O20 - Winlogon Notify: qommjhe - qommjhe.dll (file missing)
O20 - Winlogon Notify: tuvvssr - tuvvssr.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe

–
End of file - 13681 bytes
A. Please RUN HijackThis
  • Click the SCAN button to produce a log.

  • Place a check mark beside each one of the following items:

    R0 - KCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    Ro - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
    O2 - BHO: Sotfone Tracker Class - {10C52A42-DB8B-4ade-AA4A-CED6A8282B67} - C:\Program Files\Sotfone\1202931891.dll
    O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll
    O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
    O4 - HKLM\..\Run: [Windows Video Component] wvcsvc.exe
    O4 - HKLM\..\RunServices: [update] adaware.exe
    O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.explorertool.net/redirect.php (file missing)
    O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.explorertool.net/redirect.php (file missing)
    O16 - DPF: {BAE1D8DF-0B35-47E3-A1E7-EEB3FF2ECD19} (CPlayFirstddfotgControl Object) - http://www.freeworldgroup.com/games6/diner…tg.1.0.0.33.cab
    O20 - Winlogon Notify: iifdebx - iifdebx.dll (file missing)
    O20 - Winlogon Notify: nnnnmnn - nnnnmnn.dll (file missing)
    O20 - Winlogon Notify: qommjhe - qommjhe.dll (file missing)
    O20 - Winlogon Notify: tuvvssr - tuvvssr.dll (file missing)


  • Now with all the items selected, and all windows closed except for HJT, delete them by clicking the FIX checked button. Close the HijackThis window.


B. 1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

KillAll::

File::
C:\WINDOWS\system32\dihoqdtl.ini
C:\sqmdata10.sqm
C:\sqmdata09.sqm
C:\sqmdata08.sqm
C:\sqmdata07.sqm
C:\sqmdata06.sqm
C:\sqmdata05.sqm
C:\sqmnoopt19.sqm
C:\sqmdata04.sqm
C:\sqmnoopt18.sqm
C:\sqmdata03.sqm
C:\sqmnoopt17.sqm
C:\sqmdata02.sqm
C:\WINDOWS\system32\ccjbqydy.ini
C:\WINDOWS\SDA5D3FA8.tmp
C:\WINDOWS\system32\SDRemoveDB.db
C:\WINDOWS\system\SysSD.dll
C:\WINDOWS\048298C9A4D3490B9FF9AB023A9238F3.TMP
C:\WINDOWS\system32\cvfdsbap.ini
C:\WINDOWS\system32\gostmmvu.ini
C:\WINDOWS\system32\xpmiwtob.ini
C:\PA207.DAT
C:\WINDOWS\system32\sehsttdg.ini
C:\FOUND.000
C:\WINDOWS\system32\wvcsvc.exe
C:\Documents and Settings\All Users\Application Data\mmrpplic.dat

Folder::
C:\Program Files\Macrogaming
C:\Program Files\Sotfone
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Save the above as CFScript.txt

4. Now drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

5. All your monitoring programs (Antivirus/Antispyware, Guards and Shields) will be stopped.

[external image: Posted Image]

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

6. ComboFix will automatically REBOOT your machine when the KillAll:: switch is used..

7. Post the following logs/Reports:
  • ComboFix.txt
  • Fresh HijackThis log run after all the other tools have performed their cleanup.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


C. Using Internet Explorer, please do a Kaspersky Online Scan

Answer Yes, when prompted to install an ActiveX component.
  • The program will then begin downloading the latest definition files.
  • Once the files have been downloaded click on NEXT
  • Locate the Scan Settings button & configure as follows:
    • Scan using the following Anti-Virus database:
      • Extended
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
  • Click OK & have it scan My Computer
  • Once the scan is complete, it will provide a report if your system is infected. It does not provide an option to clean/disinfect. We only require a report from it.

    [external image: Posted Image]

  • Click the Save as Text button to save the file to your desktop and post it in your next reply
* Turn off the real time scanner of any existing antivirus program while performing the online scan
ComboFix 08-02-17.2 - stacey 2008-02-17 20:33:44.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.163 [GMT 0:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\adam\Recent\CFScript.txt.lnk
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-01-17 to 2008-02-17 )))))))))))))))))))))))))))))))
.

2008-02-16 13:03 . 2008-02-16 13:03 d——– C:\Program Files\Trend Micro
2008-02-16 08:59 . 2008-02-16 11:03 354 —hs—- C:\WINDOWS\system32\dihoqdtl.ini
2008-02-15 12:49 . 2008-02-15 12:49 232 –ah—– C:\sqmdata10.sqm
2008-02-15 11:54 . 2008-02-15 11:54 232 –ah—– C:\sqmdata09.sqm
2008-02-15 11:52 . 2008-02-15 11:52 232 –ah—– C:\sqmdata08.sqm
2008-02-15 09:41 . 2008-02-15 09:41 232 –ah—– C:\sqmdata07.sqm
2008-02-15 09:36 . 2008-02-15 09:36 232 –ah—– C:\sqmdata06.sqm
2008-02-15 09:05 . 2008-02-15 09:05 232 –ah—– C:\sqmdata05.sqm
2008-02-15 08:35 . 2008-02-15 08:35 244 –ah—– C:\sqmnoopt19.sqm
2008-02-15 08:35 . 2008-02-15 08:35 232 –ah—– C:\sqmdata04.sqm
2008-02-15 08:28 . 2008-02-15 08:28 244 –ah—– C:\sqmnoopt18.sqm
2008-02-15 08:28 . 2008-02-15 08:28 232 –ah—– C:\sqmdata03.sqm
2008-02-15 08:21 . 2008-02-15 08:21 244 –ah—– C:\sqmnoopt17.sqm
2008-02-15 08:21 . 2008-02-15 08:21 232 –ah—– C:\sqmdata02.sqm
2008-02-14 21:56 . 2008-02-14 21:56 d——– C:\Program Files\AdwareAlert
2008-02-14 08:59 . 2008-02-14 08:59 294 —hs—- C:\WINDOWS\system32\ccjbqydy.ini
2008-02-14 05:08 . 2008-02-14 05:08 d——– C:\VundoFix Backups
2008-02-13 19:44 . 2008-02-13 19:44 d——– C:\Program Files\Sotfone
2008-02-12 20:12 . 2008-02-12 20:12 0 —hs—- C:\WINDOWS\SDA5D3FA8.tmp
2008-02-12 20:00 . 2008-02-12 20:00 d——– C:\Program Files\Ace Utilities
2008-02-12 14:00 . 2008-02-12 14:00 717 –a—— C:\WINDOWS\system32\SDRemoveDB.db
2008-02-12 13:59 . 2008-02-12 13:59 63 –a—— C:\WINDOWS\system\SysSD.dll
2008-02-12 13:48 . 2008-02-12 13:48 d——– C:\WINDOWS\048298C9A4D3490B9FF9AB023A9238F3.TMP
2008-02-12 13:44 . 2008-02-12 13:44 d——– C:\Documents and Settings\stacey\Application Data\AdwareAlert
2008-02-12 09:40 . 2008-02-12 14:33 654 —hs—- C:\WINDOWS\system32\cvfdsbap.ini
2008-02-11 17:31 . 2008-02-11 17:31 d——– C:\Documents and Settings\adam\Application Data\AdwareAlert
2008-02-11 16:37 . 2008-02-11 16:37 d——– C:\Program Files\Enigma Software Group
2008-02-09 16:03 . 2008-02-09 17:31 834 —hs—- C:\WINDOWS\system32\gostmmvu.ini
2008-02-08 15:56 . 2008-02-09 15:57 654 —hs—- C:\WINDOWS\system32\xpmiwtob.ini
2008-02-08 11:56 . 2008-02-08 11:56 230,432 –a—— C:\PA207.DAT
2008-02-08 10:15 . 2008-02-08 10:15 d——– C:\Program Files\Spyware Doctor
2008-02-08 10:15 . 2008-02-08 10:15 d——– C:\Documents and Settings\stacey\Application Data\PC Tools
2008-02-08 10:15 . 2007-12-10 14:53 81,288 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2008-02-08 10:15 . 2007-12-10 14:53 66,952 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2008-02-08 10:15 . 2007-12-10 14:53 41,864 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-02-08 10:15 . 2007-12-10 14:53 29,576 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2008-02-08 09:34 . 2008-02-08 09:34 294 —hs—- C:\WINDOWS\system32\sehsttdg.ini
2008-02-08 09:22 . 2008-02-08 10:37 2,048 –a—— C:\WINDOWS\system32\drivers\kgpfr.cfg
2008-02-08 09:16 . 2008-02-08 09:17 d——– C:\Documents and Settings\All Users\Application Data\SITEguard
2008-02-08 09:15 . 2008-02-08 09:15 d——– C:\Program Files\Common Files\iS3
2008-02-08 09:15 . 2008-02-08 09:15 d——– C:\Documents and Settings\All Users\Application Data\STOPzilla!
2008-02-07 16:51 . 2008-02-07 16:51 d–hs—- C:\FOUND.000
2008-02-06 10:51 . 2008-02-06 10:51 d——– C:\Program Files\Spybot - Search & Destroy
2008-02-06 10:51 . 2008-02-06 10:51 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-06 10:08 . 2008-02-06 10:08 d——– C:\Program Files\Digital Locker Assistant
2008-02-04 19:53 . 2008-02-04 19:53 d——– C:\Documents and Settings\sarah\Application Data\skypePM
2008-02-04 17:17 . 2008-02-04 17:15 15,773 -r-hs—- C:\WINDOWS\system32\wvcsvc.exe
2008-02-03 21:45 . 2008-02-03 21:46 d——– C:\Documents and Settings\sarah\Application Data\Skype
2008-02-02 13:48 . 2008-02-02 13:48 d——– C:\Documents and Settings\adam\Application Data\skypePM
2008-02-02 13:48 . 2008-02-02 13:48 32 –a—— C:\Documents and Settings\All Users\Application Data\ezsid.dat
2008-02-02 13:45 . 2008-02-02 13:45 d——– C:\Program Files\Skype
2008-02-02 13:45 . 2008-02-02 13:45 d——– C:\Program Files\Common Files\Skype
2008-01-24 20:22 . 2008-01-24 20:22 d——– C:\Program Files\Driving Test Success 2007-2008
2008-01-24 20:22 . 2008-01-24 20:22 d——– C:\Documents and Settings\All Users\Application Data\Driving Test Success

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-16 13:13 2,286 —-a-w C:\Documents and Settings\adam\Application Data\wklnhst.dat
2008-02-13 11:09 712 —-a-w C:\Documents and Settings\stacey\Application Data\wklnhst.dat
2008-02-04 17:52 10 —-a-w C:\Documents and Settings\All Users\Application Data\mmrpplic.dat
2008-01-15 09:54 10,537 —-a-w C:\WINDOWS\system32\drivers\COH_Mon.cat
2008-01-15 05:28 706 —-a-w C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-01-13 13:42 ——— d—–w C:\Documents and Settings\stacey\Application Data\Nero
2008-01-13 13:27 ——— d—–w C:\Documents and Settings\All Users\Application Data\Ahead
2008-01-13 12:03 ——— d—–w C:\Documents and Settings\stacey\Application Data\Ahead
2008-01-13 12:02 ——— d—–w C:\Program Files\Nero
2008-01-13 12:02 ——— d—–w C:\Program Files\Common Files\Ahead
2008-01-12 18:45 ——— d—–w C:\Program Files\Quick AVI Splitter
2008-01-12 18:32 23,904 —-a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-01-11 05:53 44,544 —-a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
2008-01-05 09:38 ——— d—–w C:\Program Files\Common Files\Blizzard Entertainment
2008-01-03 13:28 ——— d—–w C:\Program Files\MoparScape
2008-01-02 18:45 ——— d—–w C:\Program Files\Sun
2008-01-02 18:29 ——— d—–w C:\Documents and Settings\adam\Application Data\Hamachi
2008-01-02 18:27 25,280 —-a-w C:\WINDOWS\system32\drivers\hamachi.sys
2008-01-02 18:27 ——— d—–w C:\Program Files\Hamachi
2007-12-25 10:57 ——— d—–w C:\Documents and Settings\adam\Application Data\ArcSoft
2007-12-25 10:42 ——— d—–w C:\Program Files\Common Files\PAC207
2007-12-25 10:40 ——— d—–w C:\Program Files\Common Files\ArcSoft
2007-12-25 10:39 ——— d—–w C:\Program Files\ArcSoft
2007-12-25 10:38 ——— d—–w C:\Program Files\Trust
2007-12-23 12:00 ——— d—–w C:\Program Files\CamStudio
2007-12-19 23:01 347,136 —-a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-12-19 14:40 ——— d—–w C:\Program Files\Common Files\Sony Shared
2007-12-18 09:51 179,584 —-a-w C:\WINDOWS\system32\drivers\mrxdav.sys
2007-12-18 09:51 179,584 ——w C:\WINDOWS\system32\dllcache\mrxdav.sys
2007-12-17 17:36 ——— d—–w C:\Program Files\Datel
2007-12-08 05:21 3,592,192 —-a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-12-06 11:01 625,664 ——w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-12-06 11:00 70,656 ——w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-12-06 11:00 13,824 ——w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-12-06 04:59 161,792 —-a-w C:\WINDOWS\system32\dllcache\ieakui.dll
2007-12-05 09:24 60,800 —-a-w C:\WINDOWS\system32\S32EVNT1.DLL
2007-12-04 18:38 550,912 —-a-w C:\WINDOWS\system32\oleaut32.dll
2007-12-04 18:38 550,912 ——w C:\WINDOWS\system32\dllcache\oleaut32.dll
2007-10-16 23:20 3,406 —-a-w C:\Documents and Settings\sarah\Application Data\wklnhst.dat
2007-03-10 12:55 392 —-a-w C:\Documents and Settings\rebecca\Application Data\wklnhst.dat
2006-12-17 16:35 326 —ha-w C:\Documents and Settings\All Users\hpothb07.dat
2006-12-17 16:35 200 —ha-w C:\Documents and Settings\adam\hpothb07.dat
2006-12-17 16:35 200 —ha-w C:\Documents and Settings\ADAM 2\hpothb07.dat
2006-12-17 16:35 0 —ha-w C:\Documents and Settings\Default User\hpothb07.dat
2006-08-20 17:41 32 —-a-r C:\Documents and Settings\All Users\hash.dat
2005-04-20 17:01 161 —ha-w C:\Documents and Settings\stacey\hpothb07.dat
2007-11-02 17:36 848 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"kdx"="C:\WINDOWS\kdx\KHost.exe" [2007-05-11 09:46 2236416]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:56 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 06:24 286720]
"nwiz"="nwiz.exe" [2003-11-26 07:43 753664 C:\WINDOWS\system32\nwiz.exe]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-09-23 08:33 1838592]
"Monitor"="C:\WINDOWS\PixArt\PAC207\Monitor.exe" [2006-11-03 11:01 319488]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-09-03 08:04 84640]
"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [2007-12-10 14:53 1103752]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2003-11-26 07:43 3022848]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 07:56 15360]
"ALUAlert"="C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe" [2006-09-03 00:36 100032]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2005-04-25 13:45 36040]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-04 07:56 53760 C:\WINDOWS\system32\narrator.exe]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
path=
backup=

[HKLM\~\startupfolder\C:^Documents and Settings^adam^Start Menu^Programs^Startup^Adobe Gamma.lnk]
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^adam^Start Menu^Programs^Startup^hamachi.lnk]
backup=C:\WINDOWS\pss\hamachi.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
–a—— 2005-06-06 23:46 57344 C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CARPService]
–a—— 2003-06-11 11:54 4608 C:\WINDOWS\system32\carpserv.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
–a—— 2006-09-03 08:04 84640 C:\Program Files\Common Files\Symantec Shared\ccApp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]
–a—— 2005-01-19 11:05 221184 C:\WINDOWS\system32\LVCOMSX.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
–a—— 2003-04-14 19:30 1491216 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\osCheck]
–a—— 2006-09-06 02:22 26248 C:\Program Files\Norton Internet Security\osCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Power2GoExpress]
——— 2004-05-17 11:36 839770 C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
–a—— 2005-01-12 03:01 32768 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
-ra—— 2005-10-26 16:17 159744 C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
–a—— 2003-08-04 23:59 57344 C:\WINDOWS\SOUNDMAN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeedTouch USB Diagnostics]
–a—— 2004-01-26 11:38 866816 C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2007-09-25 01:11 132496 C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SupaDial]
–a—— 2003-08-26 16:40 286720 C:\Program Files\SupaDial\SupaDial.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM]
-ra—— 2007-10-14 18:09 103712 C:\Program Files\Macrogaming\SweetIM\SweetIM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
–a—— 2007-03-14 16:52 3770024 C:\Program Files\TomTom HOME\TomTomHOME.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
–a—— 2006-11-03 18:20 866584 C:\Program Files\Windows Defender\MSASCui.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Power2GoExpress"=C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"mmtask"=c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe

R1 kbfilter;Keyboard Filter Driver;C:\WINDOWS\system32\drivers\kbfilter.sys [2002-10-15 14:48]
R2 BT848;AVerMedia, AVerTV WDM Video Capture;C:\WINDOWS\system32\drivers\BT848.sys [2002-05-13 19:40]
R2 BTTUNER;AVerMedia, AVerTV WDM TvTuner;C:\WINDOWS\system32\drivers\BTTUNER.sys [2002-01-27 04:57]
R2 BTXBAR;AVerMedia, AVerTV WDM Crossbar;C:\WINDOWS\system32\drivers\BTXBAR.sys [2002-01-27 05:02]
R3 PAC207;Trust WB-1400T Webcam;C:\WINDOWS\system32\DRIVERS\PFC027.SYS [2007-05-14 10:26]
S2 Ca536av;DigitalCam Pro Video Camera Device;C:\WINDOWS\system32\Drivers\Ca536av.sys [2004-05-21 19:21]
S3 alcan5ln;SpeedTouch™ USB ADSL RFC1483 Networking Driver (NDIS);C:\WINDOWS\system32\DRIVERS\alcan5ln.sys [2003-12-08 11:53]
S3 USBCamera;DigitalCam Pro Still Camera Device;C:\WINDOWS\system32\Drivers\Bulk536.sys [2003-05-14 09:28]

*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-02-17 13:45:44 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2008-02-14 21:27:02 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1096057614.job"
- C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe4-I
"2008-02-14 21:57:34 C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job"
- C:\Program Files\AdwareAlert\AdwareAlert.ex
- C:\Program Files\AdwareAlert
"2008-02-15 20:00:02 C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - stacey.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exeh/TASK:
"2007-08-09 05:23:22 C:\WINDOWS\Tasks\RegCure.job"
- C:\Program Files\RegCure\RegCure.exe
"2008-02-17 20:25:26 C:\WINDOWS\Tasks\RegCure Program Check.job"
- C:\Program Files\RegCure\RegCure.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-17 20:42:56
Windows 5.1.2600 Service Pack 2 FAT NTAPI

detected NTDLL code modification:
ZwClose

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-17 20:46:13
ComboFix-quarantined-files.txt 2008-02-17 20:46:08
ComboFix3.txt 2008-02-17 12:10:52
ComboFix2.txt 2008-02-17 12:35:36
.
2008-02-16 20:48:45 — E O F —
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:48:41, on 17/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\UAService7.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\QuickTime\QTTask.exe
C:\WINDOWS\PixArt\PAC207\Monitor.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\kdx\KHost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://orange.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60327
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60327
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll
O3 - Toolbar: Wanadoo - {8B68564D-53FD-4293-B80C-993A9F3988EE} - C:\PROGRA~1\Wanadoo\WSBar\WSBar.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [kdx] C:\WINDOWS\kdx\KHost.exe -all
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-1083674592-805428932-3470337186-1009\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit (User 'adam')
O4 - HKUS\S-1-5-21-1083674592-805428932-3470337186-1009\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'adam')
O4 - HKUS\S-1-5-21-1083674592-805428932-3470337186-1009\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'adam')
O4 - HKUS\S-1-5-21-1083674592-805428932-3470337186-1009\..\Run: [msnmsgr] ~"C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'adam')
O4 - HKUS\S-1-5-21-1083674592-805428932-3470337186-1009\..\Run: [DAEMON Tools Pro Agent] "C:\Program Files\DAEMON Tools Pro\DTProAgent.exe" (User 'adam')
O4 - HKUS\S-1-5-21-1083674592-805428932-3470337186-1009\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe (User 'adam')
O4 - HKUS\S-1-5-21-1083674592-805428932-3470337186-1009\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized (User 'adam')
O4 - HKUS\S-1-5-21-1083674592-805428932-3470337186-1009\..\Run: [AdwareAlert] C:\Program Files\AdwareAlert\AdwareAlert.exe -boot (User 'adam')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Search with Wanadoo - res://C:\PROGRA~1\Wanadoo\WSBar\WSBar.dll/VSearch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - blank (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - blank (file missing)
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://www.wanadoo.co.uk
O16 - DPF: LEGO Stormrunner - http://mindstorms.lego.com/stormrunner/stormrunner1-1-0.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1095767088234
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1127331239812
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - https://ukplay.toontown.com/download/sv1.0.21.10/ttinst.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe

–
End of file - 13082 bytes
The file deletions did not occur… The file deletiond did not occur because you did not run the script as directed. Please see the following:

C:\Documents and Settings\adam\Recent\CFScript.txt.lnk

You are supposed to be running ComboFix from your desktop and CFScrip.txt is supposed to be located on your desktop so it can easily be dragged onto the ComboFix icon. You dragged a "shortcut" onto ComboFix.

Please redo the steps as outlined in my previous post and make sure to follow the directions to the letter. No improvisation please because the tool will not work.


Trevuren
ComboFix 08-02-17.2 - stacey 2008-02-18 3:40:11.2 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.225 [GMT 0:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\stacey\Desktop\cfscript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\Documents and Settings\All Users\Application Data\mmrpplic.dat
C:\FOUND.000
C:\PA207.DAT
C:\sqmdata02.sqm
C:\sqmdata03.sqm
C:\sqmdata04.sqm
C:\sqmdata05.sqm
C:\sqmdata06.sqm
C:\sqmdata07.sqm
C:\sqmdata08.sqm
C:\sqmdata09.sqm
C:\sqmdata10.sqm
C:\sqmnoopt17.sqm
C:\sqmnoopt18.sqm
C:\sqmnoopt19.sqm
C:\WINDOWS\048298C9A4D3490B9FF9AB023A9238F3.TMP
C:\WINDOWS\SDA5D3FA8.tmp
C:\WINDOWS\system\SysSD.dll
C:\WINDOWS\system32\ccjbqydy.ini
C:\WINDOWS\system32\cvfdsbap.ini
C:\WINDOWS\system32\dihoqdtl.ini
C:\WINDOWS\system32\gostmmvu.ini
C:\WINDOWS\system32\SDRemoveDB.db
C:\WINDOWS\system32\sehsttdg.ini
C:\WINDOWS\system32\wvcsvc.exe
C:\WINDOWS\system32\xpmiwtob.ini
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\mmrpplic.dat
C:\PA207.DAT
C:\Program Files\Macrogaming
C:\Program Files\Macrogaming\SweetIM\conf\adapter.xml
C:\Program Files\Macrogaming\SweetIM\conf\autoupdate.xml
C:\Program Files\Macrogaming\SweetIM\conf\logger.xml
C:\Program Files\Macrogaming\SweetIM\conf\messages.xml
C:\Program Files\Macrogaming\SweetIM\conf\sweetim.xml
C:\Program Files\Macrogaming\SweetIM\conf\sweetimapp.xml
C:\Program Files\Macrogaming\SweetIM\conf\users\[removed]\emoticons_shortcut.xml
C:\Program Files\Macrogaming\SweetIM\conf\users\[removed]\lastuse_SpecialFX.xml
C:\Program Files\Macrogaming\SweetIM\conf\users\[removed]\user_config.xml
C:\Program Files\Macrogaming\SweetIM\conf\users\main_user_config.xml
C:\Program Files\Macrogaming\SweetIM\conf\users\[removed]\emoticons_shortcut.xml
C:\Program Files\Macrogaming\SweetIM\conf\users\[removed]\user_config.xml
C:\Program Files\Macrogaming\SweetIM\conf\users\[removed]\emoticons_shortcut.xml
C:\Program Files\Macrogaming\SweetIM\conf\users\[removed]\user_config.xml
C:\Program Files\Macrogaming\SweetIM\conf\users\[removed]\emoticons_shortcut.xml
C:\Program Files\Macrogaming\SweetIM\conf\users\[removed]\user_config.xml
C:\Program Files\Macrogaming\SweetIM\conf\users\[removed]\emoticons_shortcut.xml
C:\Program Files\Macrogaming\SweetIM\conf\users\[removed]\user_config.xml
C:\Program Files\Macrogaming\SweetIM\data\contentdb\000100D9.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\00010106.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\00010857.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\00010859.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\0001085D.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\00010867.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\0001088F.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\00010893.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\000108A8.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\000108A9.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\000108BB.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\000108BF.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\0002005D.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\0002006A.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\00020071.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\00020072.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\00020075.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\00020077.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\0002008A.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\0002013F.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\00020163.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\00020175.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\00020180.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\00020186.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\0002018F.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\0003003E.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\00030040.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\0003004D.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\00030056.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\0003005C.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\0003005D.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\0003005E.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\0003005F.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\00030061.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\00030062.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\00030063.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\0004001F.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\00040022.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\0004002B.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\0004003C.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\0004005A.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\00040063.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\000400A3.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\000400C4.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\00050004.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\00050005.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\00050007.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\01050001.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\01050002.dat
C:\Program Files\Macrogaming\SweetIM\data\contentdb\cache_indx.dat
C:\Program Files\Macrogaming\SweetIM\default.xml
C:\Program Files\Macrogaming\SweetIM\mgAdaptersProxy.dll
C:\Program Files\Macrogaming\SweetIM\mgAIMAuto.dll
C:\Program Files\Macrogaming\SweetIM\mgAIMMessengerAdapter.dll
C:\Program Files\Macrogaming\SweetIM\mgArchive.dll
C:\Program Files\Macrogaming\SweetIM\mgcommon.dll
C:\Program Files\Macrogaming\SweetIM\mgcommunication.dll
C:\Program Files\Macrogaming\SweetIM\mgconfig.dll
C:\Program Files\Macrogaming\SweetIM\mgFlashPlayer.dll
C:\Program Files\Macrogaming\SweetIM\mghooking.dll
C:\Program Files\Macrogaming\SweetIM\mgIEPlayer.dll
C:\Program Files\Macrogaming\SweetIM\mglogger.dll
C:\Program Files\Macrogaming\SweetIM\mgMediaPlayer.dll
C:\Program Files\Macrogaming\SweetIM\mgMsnAuto.dll
C:\Program Files\Macrogaming\SweetIM\mgMsnMessengerAdapter.dll
C:\Program Files\Macrogaming\SweetIM\mgSweetIM.dll
C:\Program Files\Macrogaming\SweetIM\mgUpdateSupport.dll
C:\Program Files\Macrogaming\SweetIM\mgxml_wrapper.dll
C:\Program Files\Macrogaming\SweetIM\mgYahooAuto.dll
C:\Program Files\Macrogaming\SweetIM\mgYahooMessengerAdapter.dll
C:\Program Files\Macrogaming\SweetIM\msvcp71.dll
C:\Program Files\Macrogaming\SweetIM\msvcr71.dll
C:\Program Files\Macrogaming\SweetIM\resources\images\AudibleButton.png
C:\Program Files\Macrogaming\SweetIM\resources\images\DisplayPicturesButton.png
C:\Program Files\Macrogaming\SweetIM\resources\images\EmoticonButton.png
C:\Program Files\Macrogaming\SweetIM\resources\images\NudgeButton.png
C:\Program Files\Macrogaming\SweetIM\resources\images\SoundFxButton.png
C:\Program Files\Macrogaming\SweetIM\resources\images\WinksButton.png
C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
C:\Program Files\Macrogaming\SweetIMBarForIE\affid.dat
C:\Program Files\Macrogaming\SweetIMBarForIE\basis.xml
C:\Program Files\Macrogaming\SweetIMBarForIE\Bookmarks_23x18.bmp
C:\Program Files\Macrogaming\SweetIMBarForIE\Cache\cd2005c66fba47ff715ecc444d3bc1fb.xml
C:\Program Files\Macrogaming\SweetIMBarForIE\Email_23x18.bmp
C:\Program Files\Macrogaming\SweetIMBarForIE\Games_23x18.bmp
C:\Program Files\Macrogaming\SweetIMBarForIE\Greetingcards_23x18.bmp
C:\Program Files\Macrogaming\SweetIMBarForIE\Mobile_23x18.bmp
C:\Program Files\Macrogaming\SweetIMBarForIE\Music_23x18.bmp
C:\Program Files\Macrogaming\SweetIMBarForIE\News_23x18.bmp
C:\Program Files\Macrogaming\SweetIMBarForIE\Shoping_23x18.bmp
C:\Program Files\Macrogaming\SweetIMBarForIE\SmileySmile.bmp
C:\Program Files\Macrogaming\SweetIMBarForIE\SmileyWink.bmp
C:\Program Files\Macrogaming\SweetIMBarForIE\sweetimicons.bmp
C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.crc
C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.xml
C:\Program Files\Macrogaming\SweetIMBarForIE\version.txt
C:\Program Files\Sotfone
C:\Program Files\Sotfone\1202931840.dll
C:\sqmdata02.sqm
C:\sqmdata03.sqm
C:\sqmdata04.sqm
C:\sqmdata05.sqm
C:\sqmdata06.sqm
C:\sqmdata07.sqm
C:\sqmdata08.sqm
C:\sqmdata09.sqm
C:\sqmdata10.sqm
C:\sqmnoopt17.sqm
C:\sqmnoopt18.sqm
C:\sqmnoopt19.sqm
C:\WINDOWS\SDA5D3FA8.tmp . . . . failed to delete
C:\WINDOWS\system\SysSD.dll
C:\WINDOWS\system32\ccjbqydy.ini
C:\WINDOWS\system32\cvfdsbap.ini
C:\WINDOWS\system32\dihoqdtl.ini
C:\WINDOWS\system32\gostmmvu.ini
C:\WINDOWS\system32\SDRemoveDB.db
C:\WINDOWS\system32\sehsttdg.ini
C:\WINDOWS\system32\wvcsvc.exe
C:\WINDOWS\system32\xpmiwtob.ini
C:\WINDOWS\SDA5D3FA8.tmp . . . . failed to delete

.
((((((((((((((((((((((((( Files Created from 2008-01-18 to 2008-02-18 )))))))))))))))))))))))))))))))
.

2008-02-18 03:50 . 2008-02-18 03:50 0 ——— C:\WINDOWS\SDA5D3FA8.tmp
2008-02-17 20:51 . 2008-02-17 20:51 d——– C:\WINDOWS\system32\Kaspersky Lab
2008-02-17 20:51 . 2008-02-17 20:51 d——– C:\WINDOWS\LastGood.Tmp
2008-02-17 20:51 . 2008-02-17 20:51 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-02-16 13:03 . 2008-02-16 13:03 d——– C:\Program Files\Trend Micro
2008-02-14 21:56 . 2008-02-14 21:56 d——– C:\Program Files\AdwareAlert
2008-02-14 05:08 . 2008-02-14 05:08 d——– C:\VundoFix Backups
2008-02-12 20:00 . 2008-02-12 20:00 d——– C:\Program Files\Ace Utilities
2008-02-12 13:48 . 2008-02-12 13:48 d——– C:\WINDOWS\048298C9A4D3490B9FF9AB023A9238F3.TMP
2008-02-12 13:44 . 2008-02-12 13:44 d——– C:\Documents and Settings\stacey\Application Data\AdwareAlert
2008-02-11 17:31 . 2008-02-11 17:31 d——– C:\Documents and Settings\adam\Application Data\AdwareAlert
2008-02-11 16:37 . 2008-02-11 16:37 d——– C:\Program Files\Enigma Software Group
2008-02-08 10:15 . 2008-02-08 10:15 d——– C:\Program Files\Spyware Doctor
2008-02-08 10:15 . 2008-02-08 10:15 d——– C:\Documents and Settings\stacey\Application Data\PC Tools
2008-02-08 10:15 . 2007-12-10 14:53 81,288 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2008-02-08 10:15 . 2007-12-10 14:53 66,952 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2008-02-08 10:15 . 2007-12-10 14:53 41,864 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-02-08 10:15 . 2007-12-10 14:53 29,576 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2008-02-08 09:22 . 2008-02-08 10:37 2,048 –a—— C:\WINDOWS\system32\drivers\kgpfr.cfg
2008-02-08 09:16 . 2008-02-08 09:17 d——– C:\Documents and Settings\All Users\Application Data\SITEguard
2008-02-08 09:15 . 2008-02-08 09:15 d——– C:\Program Files\Common Files\iS3
2008-02-08 09:15 . 2008-02-08 09:15 d——– C:\Documents and Settings\All Users\Application Data\STOPzilla!
2008-02-07 16:51 . 2008-02-07 16:51 d–hs—- C:\FOUND.000
2008-02-06 10:51 . 2008-02-06 10:51 d——– C:\Program Files\Spybot - Search & Destroy
2008-02-06 10:51 . 2008-02-06 10:51 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-06 10:08 . 2008-02-06 10:08 d——– C:\Program Files\Digital Locker Assistant
2008-02-04 19:53 . 2008-02-04 19:53 d——– C:\Documents and Settings\sarah\Application Data\skypePM
2008-02-03 21:45 . 2008-02-03 21:46 d——– C:\Documents and Settings\sarah\Application Data\Skype
2008-02-02 13:48 . 2008-02-02 13:48 d——– C:\Documents and Settings\adam\Application Data\skypePM
2008-02-02 13:48 . 2008-02-02 13:48 32 –a—— C:\Documents and Settings\All Users\Application Data\ezsid.dat
2008-02-02 13:45 . 2008-02-02 13:45 d——– C:\Program Files\Skype
2008-02-02 13:45 . 2008-02-02 13:45 d——– C:\Program Files\Common Files\Skype
2008-01-24 20:22 . 2008-01-24 20:22 d——– C:\Program Files\Driving Test Success 2007-2008
2008-01-24 20:22 . 2008-01-24 20:22 d——– C:\Documents and Settings\All Users\Application Data\Driving Test Success

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-16 13:13 2,286 —-a-w C:\Documents and Settings\adam\Application Data\wklnhst.dat
2008-02-13 11:09 712 —-a-w C:\Documents and Settings\stacey\Application Data\wklnhst.dat
2008-01-15 09:54 10,537 —-a-w C:\WINDOWS\system32\drivers\COH_Mon.cat
2008-01-15 05:28 706 —-a-w C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-01-13 13:42 ——— d—–w C:\Documents and Settings\stacey\Application Data\Nero
2008-01-13 13:27 ——— d—–w C:\Documents and Settings\All Users\Application Data\Ahead
2008-01-13 12:03 ——— d—–w C:\Documents and Settings\stacey\Application Data\Ahead
2008-01-13 12:02 ——— d—–w C:\Program Files\Nero
2008-01-13 12:02 ——— d—–w C:\Program Files\Common Files\Ahead
2008-01-12 18:45 ——— d—–w C:\Program Files\Quick AVI Splitter
2008-01-12 18:32 23,904 —-a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-01-11 05:53 44,544 —-a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
2008-01-05 09:38 ——— d—–w C:\Program Files\Common Files\Blizzard Entertainment
2008-01-03 13:28 ——— d—–w C:\Program Files\MoparScape
2008-01-02 18:45 ——— d—–w C:\Program Files\Sun
2008-01-02 18:29 ——— d—–w C:\Documents and Settings\adam\Application Data\Hamachi
2008-01-02 18:27 25,280 —-a-w C:\WINDOWS\system32\drivers\hamachi.sys
2008-01-02 18:27 ——— d—–w C:\Program Files\Hamachi
2007-12-25 10:57 ——— d—–w C:\Documents and Settings\adam\Application Data\ArcSoft
2007-12-25 10:42 ——— d—–w C:\Program Files\Common Files\PAC207
2007-12-25 10:40 ——— d—–w C:\Program Files\Common Files\ArcSoft
2007-12-25 10:39 ——— d—–w C:\Program Files\ArcSoft
2007-12-25 10:38 ——— d—–w C:\Program Files\Trust
2007-12-23 12:00 ——— d—–w C:\Program Files\CamStudio
2007-12-19 23:01 347,136 —-a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-12-19 14:40 ——— d—–w C:\Program Files\Common Files\Sony Shared
2007-12-18 09:51 179,584 —-a-w C:\WINDOWS\system32\drivers\mrxdav.sys
2007-12-18 09:51 179,584 ——w C:\WINDOWS\system32\dllcache\mrxdav.sys
2007-12-08 05:21 3,592,192 —-a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-12-06 11:01 625,664 ——w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-12-06 11:00 70,656 ——w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-12-06 11:00 13,824 ——w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-12-06 04:59 161,792 —-a-w C:\WINDOWS\system32\dllcache\ieakui.dll
2007-12-05 09:24 60,800 —-a-w C:\WINDOWS\system32\S32EVNT1.DLL
2007-12-04 18:38 550,912 —-a-w C:\WINDOWS\system32\oleaut32.dll
2007-12-04 18:38 550,912 ——w C:\WINDOWS\system32\dllcache\oleaut32.dll
2007-10-16 23:20 3,406 —-a-w C:\Documents and Settings\sarah\Application Data\wklnhst.dat
2007-03-10 12:55 392 —-a-w C:\Documents and Settings\rebecca\Application Data\wklnhst.dat
2006-12-17 16:35 326 —ha-w C:\Documents and Settings\All Users\hpothb07.dat
2006-12-17 16:35 200 —ha-w C:\Documents and Settings\adam\hpothb07.dat
2006-12-17 16:35 200 —ha-w C:\Documents and Settings\ADAM 2\hpothb07.dat
2006-12-17 16:35 0 —ha-w C:\Documents and Settings\Default User\hpothb07.dat
2006-08-20 17:41 32 —-a-r C:\Documents and Settings\All Users\hash.dat
2005-04-20 17:01 161 —ha-w C:\Documents and Settings\stacey\hpothb07.dat
2007-11-02 17:36 848 –sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"kdx"="C:\WINDOWS\kdx\KHost.exe" [2007-05-11 09:46 2236416]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:56 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 06:24 286720]
"nwiz"="nwiz.exe" [2003-11-26 07:43 753664 C:\WINDOWS\system32\nwiz.exe]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-09-23 08:33 1838592]
"Monitor"="C:\WINDOWS\PixArt\PAC207\Monitor.exe" [2006-11-03 11:01 319488]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-09-03 08:04 84640]
"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [2007-12-10 14:53 1103752]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2003-11-26 07:43 3022848]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 07:56 15360]
"ALUAlert"="C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe" [2006-09-03 00:36 100032]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2005-04-25 13:45 36040]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-04 07:56 53760 C:\WINDOWS\system32\narrator.exe]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
path=
backup=

[HKLM\~\startupfolder\C:^Documents and Settings^adam^Start Menu^Programs^Startup^Adobe Gamma.lnk]
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^adam^Start Menu^Programs^Startup^hamachi.lnk]
backup=C:\WINDOWS\pss\hamachi.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
–a—— 2005-06-06 23:46 57344 C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CARPService]
–a—— 2003-06-11 11:54 4608 C:\WINDOWS\system32\carpserv.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
–a—— 2006-09-03 08:04 84640 C:\Program Files\Common Files\Symantec Shared\ccApp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]
–a—— 2005-01-19 11:05 221184 C:\WINDOWS\system32\LVCOMSX.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
–a—— 2003-04-14 19:30 1491216 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\osCheck]
–a—— 2006-09-06 02:22 26248 C:\Program Files\Norton Internet Security\osCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Power2GoExpress]
——— 2004-05-17 11:36 839770 C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
–a—— 2005-01-12 03:01 32768 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
-ra—— 2005-10-26 16:17 159744 C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
–a—— 2003-08-04 23:59 57344 C:\WINDOWS\SOUNDMAN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeedTouch USB Diagnostics]
–a—— 2004-01-26 11:38 866816 C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2007-09-25 01:11 132496 C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SupaDial]
–a—— 2003-08-26 16:40 286720 C:\Program Files\SupaDial\SupaDial.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM]
C:\Program Files\Macrogaming\SweetIM\SweetIM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
–a—— 2007-03-14 16:52 3770024 C:\Program Files\TomTom HOME\TomTomHOME.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
–a—— 2006-11-03 18:20 866584 C:\Program Files\Windows Defender\MSASCui.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Power2GoExpress"=C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"mmtask"=c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe

R1 kbfilter;Keyboard Filter Driver;C:\WINDOWS\system32\drivers\kbfilter.sys [2002-10-15 14:48]
R2 BT848;AVerMedia, AVerTV WDM Video Capture;C:\WINDOWS\system32\drivers\BT848.sys [2002-05-13 19:40]
R2 BTTUNER;AVerMedia, AVerTV WDM TvTuner;C:\WINDOWS\system32\drivers\BTTUNER.sys [2002-01-27 04:57]
R2 BTXBAR;AVerMedia, AVerTV WDM Crossbar;C:\WINDOWS\system32\drivers\BTXBAR.sys [2002-01-27 05:02]
R3 PAC207;Trust WB-1400T Webcam;C:\WINDOWS\system32\DRIVERS\PFC027.SYS [2007-05-14 10:26]
S2 Ca536av;DigitalCam Pro Video Camera Device;C:\WINDOWS\system32\Drivers\Ca536av.sys [2004-05-21 19:21]
S3 alcan5ln;SpeedTouch™ USB ADSL RFC1483 Networking Driver (NDIS);C:\WINDOWS\system32\DRIVERS\alcan5ln.sys [2003-12-08 11:53]
S3 USBCamera;DigitalCam Pro Still Camera Device;C:\WINDOWS\system32\Drivers\Bulk536.sys [2003-05-14 09:28]

*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-02-18 04:03:08 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2008-02-17 21:27:02 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1096057614.job"
- C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe4-I
"2008-02-18 03:00:02 C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job"
- C:\Program Files\AdwareAlert\AdwareAlert.ex
- C:\Program Files\AdwareAlert
"2008-02-15 20:00:02 C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - stacey.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exeh/TASK:
"2007-08-09 05:23:22 C:\WINDOWS\Tasks\RegCure.job"
- C:\Program Files\RegCure\RegCure.exe
"2008-02-18 04:03:46 C:\WINDOWS\Tasks\RegCure Program Check.job"
- C:\Program Files\RegCure\RegCure.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-18 04:00:45
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\UAService7.exe
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\Program Files\Symantec\LiveUpdate\AUPDATE.EXE
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
.
**************************************************************************
.
Completion time: 2008-02-18 4:07:08 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-18 04:06:58
ComboFix4.txt 2008-02-17 12:10:52
ComboFix3.txt 2008-02-17 12:35:36
ComboFix2.txt 2008-02-17 20:46:16
.
2008-02-16 20:48:45 — E O F —
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 04:09:56, on 18/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\QuickTime\QTTask.exe
C:\WINDOWS\PixArt\PAC207\Monitor.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\kdx\KHost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\UAService7.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://orange.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60327
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60327
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll
O3 - Toolbar: Wanadoo - {8B68564D-53FD-4293-B80C-993A9F3988EE} - C:\PROGRA~1\Wanadoo\WSBar\WSBar.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [kdx] C:\WINDOWS\kdx\KHost.exe -all
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Search with Wanadoo - res://C:\PROGRA~1\Wanadoo\WSBar\WSBar.dll/VSearch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - blank (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - blank (file missing)
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://www.wanadoo.co.uk
O16 - DPF: LEGO Stormrunner - http://mindstorms.lego.com/stormrunner/stormrunner1-1-0.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1095767088234
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1127331239812
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - https://ukplay.toontown.com/download/sv1.0.21.10/ttinst.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe

–
End of file - 12358 bytes
——————————————————————————- KASPERSKY ONLINE SCANNER REPORT Monday, February 18, 2008 9:18:24 AM Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.98.0 Kaspersky Anti-Virus database last update: 18/02/2008 Kaspersky Anti-Virus database records: 570328 ——————————————————————————- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: A:\ C:\ D:\ E:\ F:\ G:\ H:\ Scan Statistics: Total number of scanned objects: 175592 Number of viruses found: 16 Number of infected objects: 370 Number of suspicious objects: 0 Duration of the scan process: 02:40:56 Infected Object Name / Virus Name / Last Action C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\DEFAULT Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped C:\WINDOWS\system32\config\SYSTEM Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\Internet.evt Object is locked skipped C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped C:\WINDOWS\TEMP\MpCmdRun.log Object is locked skipped C:\WINDOWS\TEMP\TMP0000003D63F4BB93330A4040 Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\wiaservc.log Object is locked skipped C:\WINDOWS\wiadebug.log Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SDA5D3FA8.tmp Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-02022007-130114.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2008-02-18_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SubEng\submissions.idx Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\Shared\QBackup\index.qbs Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtViEvt.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtNvEvt.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtMoEvt.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtScEvt.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtErEvt.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtTxFEvt.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\040E32E7.TMP Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\AE3A0484.TMP Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPPolicy.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPStart.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPStop.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBValid.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBConfig.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBRefr.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBNotify.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetCfg.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetCfg2.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetUsr.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBStHash.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetLoc.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetDev.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBDetect.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBDebug.log Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat Object is locked skipped C:\Documents and Settings\stacey\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\stacey\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\stacey\Local Settings\History\History.IE5\MSHist012008021820080219\index.dat Object is locked skipped C:\Documents and Settings\stacey\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\stacey\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped C:\Documents and Settings\stacey\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\stacey\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\stacey\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped C:\Documents and Settings\stacey\Local Settings\Temp\~DF1C34.tmp Object is locked skipped C:\Documents and Settings\stacey\Cookies\index.dat Object is locked skipped C:\Documents and Settings\stacey\ntuser.dat Object is locked skipped C:\Documents and Settings\adam\My Documents\My Received Files\facebkpic2.zip/picture032.JPEG_www.facebook.com Infected: Backdoor.Win32.DsBot.ne skipped C:\Documents and Settings\adam\My Documents\My Received Files\facebkpic2.zip ZIP: infected - 1 skipped C:\Documents and Settings\rebecca\My Documents\RemxLnd05-15.sap/Ogg License(ACCEPT TERMS OF USE FIRST!).exe/stream/data0004 Infected: Trojan-Downloader.Win32.IstBar.ny skipped C:\Documents and Settings\rebecca\My Documents\RemxLnd05-15.sap/Ogg License(ACCEPT TERMS OF USE FIRST!).exe/stream/data0006 Infected: Trojan-Downloader.Win32.IstBar.ns skipped C:\Documents and Settings\rebecca\My Documents\RemxLnd05-15.sap/Ogg License(ACCEPT TERMS OF USE FIRST!).exe/stream Infected: Trojan-Downloader.Win32.IstBar.ns skipped C:\Documents and Settings\rebecca\My Documents\RemxLnd05-15.sap/Ogg License(ACCEPT TERMS OF USE FIRST!).exe Infected: Trojan-Downloader.Win32.IstBar.ns skipped C:\Documents and Settings\rebecca\My Documents\RemxLnd05-15.sap RAR: infected - 4 skipped C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped C:\Program Files\Common Files\Symantec Shared\NFWEVT.LOG Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SNDSYS.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SNDFW.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SNDCON.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SNDALRT.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SNDIDS.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SNDDBG.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\logs\sw_ae-20080218-040046.log Object is locked skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\AVVirus.log Object is locked skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\AVApp.log Object is locked skipped C:\Program Files\Norton Internet Security\Norton AntiVirus\AVError.log Object is locked skipped C:\Program Files\Trend Micro\HijackThis\backups\backup-20080217-201254-207.dll Infected: not-a-virus:AdWare.Win32.BHO.zc skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP175\A0022563.exe Infected: not-a-virus:AdWare.Win32.Trymedia.d skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP180\A0024684.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP180\A0024685.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP180\A0024809.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP180\A0024810.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP180\A0024811.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP180\A0024812.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP180\A0024813.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP180\A0024815.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP180\A0024816.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP181\A0024826.DLL Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP181\A0024830.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP181\A0024831.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP181\A0024832.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP184\A0024888.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP184\A0024889.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP184\A0025062.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP184\A0025063.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP184\A0025064.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP184\A0025065.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP189\A0025264.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP189\A0025265.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP189\A0025343.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP189\A0025345.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP193\A0026446.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP193\A0026447.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP193\A0026451.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP193\A0026452.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP193\A0026453.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP193\A0026454.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP193\A0026455.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP193\A0026456.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP193\A0026457.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP193\A0026458.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP193\A0026459.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP193\A0026460.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP193\A0026465.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP193\A0026466.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP194\A0026543.DLL Infected: Trojan-Downloader.Win32.Small.idy skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP194\A0026544.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP194\A0026554.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP197\A0026647.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP197\A0026648.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP197\A0026649.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP197\A0026650.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP198\A0027672.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP198\A0027678.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP198\A0027679.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP198\A0027680.DLL Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP198\A0027688.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP198\A0027717.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP198\A0027718.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP198\A0027719.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP198\A0027720.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP198\A0027721.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP199\A0027758.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.imh skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP199\A0027759.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.imh skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP199\A0027760.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.imh skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP199\A0027761.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.imh skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP199\A0027762.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.imh skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP199\A0027763.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.imh skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP199\A0027764.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.imh skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP199\A0027765.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.imh skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP199\A0027842.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP203\A0030779.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP203\A0030846.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP203\A0030847.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP203\A0030848.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.imh skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP203\A0030849.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.imh skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP203\A0030850.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.imh skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP203\A0030851.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.imh skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP203\A0030852.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.imh skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP203\A0030853.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.imh skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP203\A0030854.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.imh skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP203\A0030855.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.imh skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP203\A0030856.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.imh skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP203\A0030858.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP209\A0032502.exe Infected: Trojan-Downloader.Win32.Zlob.hpu skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP209\A0032503.dll Infected: Trojan-Downloader.Win32.Zlob.hpi skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP209\A0032504.exe Infected: Trojan-Downloader.Win32.Zlob.hpk skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP212\A0032582.rbf Infected: not-a-virus:FraudTool.Win32.AntiSpyware.f skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP212\A0032588.exe Infected: Trojan-Downloader.Win32.Zlob.hpu skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP212\A0032589.dll Infected: Trojan-Downloader.Win32.Zlob.hpi skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP212\A0032590.exe Infected: Trojan-Downloader.Win32.Zlob.hpk skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032633.exe Infected: Trojan-Downloader.Win32.Zlob.hpu skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032634.dll Infected: Trojan-Downloader.Win32.Zlob.hpi skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032635.exe Infected: Trojan-Downloader.Win32.Zlob.hpk skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032646.exe Infected: Trojan-Downloader.Win32.Zlob.hpu skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032647.dll Infected: Trojan-Downloader.Win32.Zlob.hpi skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032648.exe Infected: Trojan-Downloader.Win32.Zlob.hpk skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032655.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032656.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032657.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032658.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032659.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032660.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032661.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.hxh skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032662.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032663.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032664.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032665.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032666.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032667.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032668.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032669.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032670.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.hxh skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032671.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032672.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.hxh skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032673.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032674.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032675.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032676.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032677.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032678.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032679.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032680.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032681.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032682.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032683.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032684.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032685.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032686.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032687.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032688.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032689.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032690.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032691.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.hxh skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032692.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032693.dll Infected: Trojan-Downloader.Win32.Small.idy skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032694.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032695.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032696.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032697.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032698.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032699.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032700.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032701.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.hxh skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032702.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032703.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.hxh skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032704.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032705.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032706.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032707.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032708.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032709.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032710.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032711.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032712.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032713.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032714.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032715.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032716.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032717.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032718.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032727.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032728.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032729.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032730.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032731.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.hxh skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032732.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032733.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032734.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032735.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032736.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032737.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.imh skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032738.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032739.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032740.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032741.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032742.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.hxh skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032743.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032744.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032745.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032746.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032747.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032748.dll Infected: Trojan-Downloader.Win32.Small.idy skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032749.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032750.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.hxh skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032751.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032752.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032753.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.hxh skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032754.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032755.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032756.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032757.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032758.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032759.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.hxh skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032760.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032761.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.hxh skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032762.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032763.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032764.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032765.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032766.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032767.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.hxh skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032768.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032769.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032770.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.hxh skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032771.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032772.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032773.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032774.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032775.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032776.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032777.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032778.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032782.exe Infected: Trojan-Downloader.Win32.Zlob.hpu skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032783.dll Infected: Trojan-Downloader.Win32.Zlob.hpi skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032784.exe Infected: Trojan-Downloader.Win32.Zlob.hpk skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032788.exe Infected: Trojan-Downloader.Win32.Zlob.hpu skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032789.dll Infected: Trojan-Downloader.Win32.Zlob.hpi skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032790.exe Infected: Trojan-Downloader.Win32.Zlob.hpk skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032792.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032794.DLL Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032797.exe Infected: Trojan-Downloader.Win32.Zlob.hpu skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032798.dll Infected: Trojan-Downloader.Win32.Zlob.hpi skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032799.exe Infected: Trojan-Downloader.Win32.Zlob.hpk skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032818.exe Infected: Trojan-Downloader.Win32.Zlob.hpu skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032819.dll Infected: Trojan-Downloader.Win32.Zlob.hpi skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0032820.exe Infected: Trojan-Downloader.Win32.Zlob.hpk skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0033807.exe Infected: Trojan-Downloader.Win32.Zlob.hpu skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0033808.dll Infected: Trojan-Downloader.Win32.Zlob.hpi skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0033809.exe Infected: Trojan-Downloader.Win32.Zlob.hpk skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0033813.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0033815.exe Infected: Trojan-Downloader.Win32.Zlob.hpu skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0033818.dll Infected: Trojan-Downloader.Win32.Zlob.hpi skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0033819.exe Infected: Trojan-Downloader.Win32.Zlob.hpk skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0033821.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0033823.exe Infected: Trojan-Downloader.Win32.Zlob.hpu skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0033824.dll Infected: Trojan-Downloader.Win32.Zlob.hpi skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0033825.exe Infected: Trojan-Downloader.Win32.Zlob.hpk skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0033829.exe Infected: Trojan-Downloader.Win32.Zlob.hpn skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0033833.exe Infected: Trojan-Downloader.Win32.Zlob.hpu skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0033836.dll Infected: Trojan-Downloader.Win32.Zlob.hpi skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0033837.exe Infected: Trojan-Downloader.Win32.Zlob.hpk skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0033859.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0033860.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0033862.exe Infected: Trojan-Downloader.Win32.Zlob.hpu skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0033865.dll Infected: Trojan-Downloader.Win32.Zlob.hpi skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP213\A0033866.exe Infected: Trojan-Downloader.Win32.Zlob.hpk skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP216\A0033895.exe Infected: Trojan-Downloader.Win32.Zlob.hpu skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP216\A0033896.dll Infected: Trojan-Downloader.Win32.Zlob.hpi skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP216\A0033897.exe Infected: Trojan-Downloader.Win32.Zlob.hpk skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP217\A0033910.exe Infected: Trojan-Downloader.Win32.Zlob.hpk skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP217\A0033915.exe Infected: Trojan-Downloader.Win32.Zlob.hpu skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP217\A0033916.dll Infected: Trojan-Downloader.Win32.Zlob.hpi skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP217\A0033917.exe Infected: Trojan-Downloader.Win32.Zlob.hpk skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP217\A0033918.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP217\A0033919.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP217\A0033920.exe Infected: Trojan-Downloader.Win32.Zlob.hpo skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP217\A0033921.exe Infected: Trojan-Downloader.Win32.Zlob.hrj skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034858.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034859.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034860.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034861.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034862.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034863.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034864.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034865.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034866.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034867.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034868.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034869.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034870.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034871.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034872.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034873.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034874.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034875.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034876.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034877.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034878.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034879.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034880.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034881.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034882.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034883.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034884.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034885.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034886.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034887.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034888.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034889.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034890.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034891.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034892.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034893.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034894.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034895.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034896.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034897.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034898.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034899.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034900.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034901.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034902.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034903.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034904.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034905.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034906.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034907.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034908.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP235\A0034909.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP238\A0035941.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP238\A0036060.dll Infected: not-a-virus:AdWare.Win32.BHO.zc skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP240\A0036178.dll Infected: not-a-virus:AdWare.Win32.BHO.zc skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP240\A0036185.exe Infected: Backdoor.Win32.DsBot.ne skipped C:\System Volume Information\_restore{7EF804EE-2781-4B4C-BD05-F6669D2CD1E1}\RP240\change.log Object is locked skipped C:\VundoFix Backups\awtqnkh.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\awtsqpq.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\byxvspm.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\byxxvsr.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\byxxxvu.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\byxyvvv.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\cbxwtss.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\cbxywus.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\ddcawtt.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\ddccdab.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\ddcdaaw.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\ddcddcc.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\ddcywvt.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\efcbxuu.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\fccaxxy.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\fccbaxx.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\fccyxus.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\gebxyxv.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\hggeedb.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\hgggfcy.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\hggghgg.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\iifcaax.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\iifedca.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\jkkljif.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\jkkllih.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\ljjgdeb.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\ljjgfgd.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\ljjggfe.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\ljjhebx.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\mljhfde.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\nnnkhef.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\nnnmnom.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\nnnnomm.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\opnkjkj.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\opnlkhe.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\pmkhe.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.imh skipped C:\VundoFix Backups\pmnlkkh.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\qomjjhe.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\qomkjjh.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\qomnkkj.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\rqrpmmk.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\rqrropm.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\ssqoopm.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\tinwlild.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\tuvtrqo.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\urqopol.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\vturpqp.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\vtuspnk.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\wvuvtut.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\xxyabcc.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\xxyaxvt.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\VundoFix Backups\yayvspp.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\QooBox\Quarantine\C\WINDOWS\system32\nnoslfmi.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\QooBox\Quarantine\C\WINDOWS\system32\wvcsvc.exe.vir Infected: Backdoor.Win32.DsBot.ne skipped C:\QooBox\Quarantine\C\Program Files\Sotfone\1202931840.dll.vir Infected: not-a-virus:AdWare.Win32.BHO.zc skipped Scan process completed.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI