Thank you for your response. My computer is seriously hosed. I can only browse the web without issues while I'm in Safe Mode as I am now. When I try to operate in normal mode on XP SP1, my internet experience is extremely slow. It take a few minutes when I click on a link and even then the browser gets redirected to a web site selling something like www.go211.com. Also, I keep getting pop up dialog boxes that say things like, "Winanonymous may find dangerous traces that need to be cleaned. Don't let your privacy and reputation to be ruined by them. Click "ok" to start WinAnonymous scanner to remove compromising traces and set up controls to protect your privacy by cleaning or removing dangerous information". I never hit "ok" , instead I hit the X to close the dialog boxes and it takes me to the Winanonymous web site. I also am on a trial version of Kaspersky. I had AVAST but I unstalled it because I was disappointed it didn't prevent this virus. Kaspersky has found a number of viruses like Packed.win32.monder.gen, Trojan-Downloader.win32.homless.bb, and most recently Virtumonde.pil. When I start the computer in normal mode, Kaspersky keeps finding viruses, deletes them, but I still have problems with the browser running slow and being redirected.
Below is the Hijack this log. After that is the Kaspersky log. Both were run when the computer was in Normal mode. Thank you very much for your help!
----------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:30:28 AM, on 4/21/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Funk Software\Odyssey Client\odClientService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ISS\issSensors\DesktopProtection\blackd.exe
C:\Program Files\ESPN VPN\ESPN VPN Client\cvpnd.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Novadigm\radexecd.exe
C:\Program Files\Novadigm\radsched.exe
C:\Program Files\Novadigm\Radstgms.exe
C:\Program Files\Sprint\Sprint PCS Connection Manager\CMSPCSUtilSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Citrix\ICA Client\ssonsvr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\WINDOWS\VM303_STI.EXE
C:\Program Files\Funk Software\Odyssey Client\OdTray.exe
C:\Program Files\eFax Messenger 4.1\J2GDllCmd.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\ISS\issSensors\DesktopProtection\blackice.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Java\jre1.5.0_10\bin\jucheck.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
https://email.secureserver.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,c:\Program Files\Passlogix\v-GO SSO\ssoshell.exe /background,C:\WINDOWS\System32\ntos.exe,
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [BigDog303] C:\WINDOWS\VM303_STI.EXE VIMICRO USB PC Camera 301PLH
O4 - HKLM\..\Run: [OdTray.exe] "C:\Program Files\Funk Software\Odyssey Client\OdTray.exe"
O4 - HKLM\..\Run: [eFax 4.1] "C:\Program Files\eFax Messenger 4.1\J2GDllCmd.exe" /R
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O4 - HKLM\..\Run: [BM07e436a1] Rundll32.exe "C:\WINDOWS\System32\ocbybcfd.dll",s
O4 - HKLM\..\Run: [04d7053d] rundll32.exe "C:\WINDOWS\System32\ikbfsgnc.dll",b
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [userinit] C:\WINDOWS\System32\ntos.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Startup: scratchpad.txt
O4 - Global Startup: RealSecure® Desktop Protector.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O17 - HKLM\System\CCS\Services\Tcpip\Parameters:
O17 - HKLM\Software\..\Telephony: DomainName =
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain =
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain =
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
O23 - Service: BlackICE - Internet Security Systems, Inc. - C:\Program Files\ISS\issSensors\DesktopProtection\blackd.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Odyssey Client (odClientService) - Funk Software, Inc. - C:\Program Files\Funk Software\Odyssey Client\odClientService.exe
O23 - Service: Radia Notify Daemon (radexecd) - Hewlett-Packard - C:\Program Files\Novadigm\radexecd.exe
O23 - Service: Radia Scheduler Daemon (radsched) - Hewlett-Packard - C:\Program Files\Novadigm\radsched.exe
O23 - Service: Radia MSI Redirector (Radstgms) - Hewlett-Packard - C:\Program Files\Novadigm\Radstgms.exe
O23 - Service: RapApp - Internet Security Systems, Inc. - C:\Program Files\ISS\issSensors\DesktopProtection\RapApp.exe
O23 - Service: Sprint PCS v3 Utility Service - Sprint Spectrum, L.L.C - C:\Program Files\Sprint\Sprint PCS Connection Manager\CMSPCSUtilSvc.exe
--
End of file - 7690 bytes
Protection : running
--------------------
Total scanned: 7333
Detected: 26
Untreated: 0
Start time: 4/21/2008 9:09:43 AM
Duration: 00:07:49
Detected
--------
Status Object
------ ------
deleted: virus Packed.Win32.Monder.gen File: C:\WINDOWS\system32\urqRKCsp.dll//PE_Patch
deleted: virus Packed.Win32.Monder.gen File: C:\WINDOWS\system32\awtsTLCv.dll//PE_Patch
deleted: Trojan program Trojan-Downloader.Win32.Homles.bb File: C:\WINDOWS\mrofinu572.exe//PE_Patch.Upolyx//PE_Patch.UPX//UPX
deleted: virus Packed.Win32.Monder.gen File: C:\WINDOWS\system32\khfDwwxU.dll//PE_Patch
deleted: virus Packed.Win32.Monder.gen File: C:\WINDOWS\system32\xxyawvSm.dll//PE_Patch
deleted: Trojan program Trojan-Downloader.Win32.Homles.bb File: C:\WINDOWS\mrofinu572.exe.tmp//PE_Patch.Upolyx//PE_Patch.UPX//UPX
detected: virus Heur.Invader (modification) URL:
http://downloads.and...Fix/catchme.exe
deleted: Trojan program Trojan.Win32.KillAV.rf File: C:\Documents and Settings\knopfm\Local Settings\Temporary Internet Files\Content.IE5\J8R1WCJ2\zrt20080408[1]
detected: Trojan program Trojan.Win32.KillAV.rf URL:
http://82.98.235.78/...u...E4&rid=wen5
deleted: Trojan program Trojan.Win32.KillAV.rf File: C:\DOCUME~1\knopfm\LOCALS~1\Temp\gqdlitrs.dll
deleted: Trojan program Trojan.Win32.KillAV.rf File: C:\Documents and Settings\knopfm\Local Settings\Temporary Internet Files\Content.IE5\05QRWLQZ\zrt20080408[1]
deleted: Trojan program Trojan.Win32.KillAV.rf File: C:\WINDOWS\system32\oegdwdtv.dll
deleted: Trojan program Trojan.Win32.KillAV.rf File: C:\WINDOWS\system32\yqtrbcnu.dll
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.nvf File: C:\Documents and Settings\knopfm\Local Settings\Temporary Internet Files\Content.IE5\J8R1WCJ2\kriv[1]//PE_Patch
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.nvf File: C:\WINDOWS\SYSTEM32\NXIDUARP.DLL//PE_Patch
deleted: Trojan program Trojan.Win32.KillAV.rf File: C:\DOCUME~1\knopfm\LOCALS~1\Temp\cvxqstxw.dll
deleted: Trojan program Trojan.Win32.KillAV.rf File: C:\Documents and Settings\knopfm\Local Settings\Temporary Internet Files\Content.IE5\O167GTYF\zrt20080408[1]
deleted: riskware not-a-virus:Downloader.Win32.WinFixer.au File: C:\Documents and Settings\knopfm\Local Settings\Temp\ICD1.tmp\UGA6P_0001_N122M2802NetInstaller.exe
deleted: Trojan program Trojan.Win32.KillAV.rf File: C:\Documents and Settings\knopfm\Local Settings\Temporary Internet Files\Content.IE5\IGTRJTU7\zrt20080408[1]
deleted: riskware not-a-virus:Downloader.Win32.WinFixer.au File: C:\WINDOWS\Downloaded Program Files\UGA6P_0001_N122M2802NetInstaller.exe
deleted: Trojan program Trojan.Win32.KillAV.rf File: C:\WINDOWS\system32\liccltrq.dll
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.okj File: C:\WINDOWS\SYSTEM32\EUGNXYJP.DLL
detected: riskware Invader (loader) Running process: C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
detected: riskware Invader (loader) Running process: C:\WINDOWS\system32\rundll32.exe
detected: riskware Invader (loader) Running process: C:\WINDOWS\explorer.exe
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.pil File: C:\WINDOWS\SYSTEM32\UMNUCCLC.DLL
Below is Kaspersky report
Events
------
Time Event
---- -----
4/11/2008 10:21:26 AM Kaspersky Anti-Virus is not activated. You are advised to activate the application as soon as possible.
4/11/2008 10:21:27 AM You are advised to perform a full computer scan as soon as possible.
4/11/2008 10:21:38 AM Database is out of date, leaving your computer at risk of infection. Please update your database.
4/11/2008 10:21:39 AM Protection of your computer is enabled.
4/11/2008 10:27:21 AM File C:\WINDOWS\system32\urqRKCsp.dll//PE_Patch: detected: virus 'Packed.Win32.Monder.gen'. User: CORP\NY6MOB905403L$, computer: localhost.
4/11/2008 10:27:21 AM Security threats have been detected. You are advised to neutralize them immediately.
4/11/2008 10:27:22 AM Update completed successfully
4/11/2008 10:27:42 AM File C:\WINDOWS\system32\awtsTLCv.dll//PE_Patch: detected: virus 'Packed.Win32.Monder.gen'.
4/11/2008 10:28:28 AM File C:\WINDOWS\system32\urqRKCsp.dll//PE_Patch: detected: virus 'Packed.Win32.Monder.gen'.
4/11/2008 10:28:28 AM File C:\WINDOWS\system32\urqRKCsp.dll//PE_Patch: is still infected, cannot be disinfected.
4/11/2008 10:28:30 AM File C:\WINDOWS\system32\urqRKCsp.dll//PE_Patch: detected: virus 'Packed.Win32.Monder.gen'.
4/11/2008 10:28:30 AM File C:\WINDOWS\system32\urqRKCsp.dll will be deleted on system restart.
4/11/2008 10:28:30 AM Startup object HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\urqRKCsp\urqRKCsp: deleted.
4/11/2008 10:28:31 AM Startup object HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{24E9519B-3F70-429B-99BC-4B2B49B96F66}\{24E9519B-3F70-429B-99BC-4B2B49B96F66}: deleted.
4/11/2008 10:28:37 AM File C:\WINDOWS\system32\urqRKCsp.dll//PE_Patch: detected: virus 'Packed.Win32.Monder.gen'.
4/11/2008 10:28:57 AM File C:\WINDOWS\system32\awtsTLCv.dll//PE_Patch: is still infected, cannot be disinfected.
4/11/2008 10:28:59 AM File C:\WINDOWS\System32\urqRKCsp.dll//PE_Patch: detected: virus 'Packed.Win32.Monder.gen'.
4/11/2008 10:29:07 AM File C:\WINDOWS\system32\urqRKCsp.dll will be deleted on system restart.
4/11/2008 10:29:07 AM File C:\WINDOWS\System32\urqRKCsp.dll//PE_Patch: detected: virus 'Packed.Win32.Monder.gen'. User: CORP\KnopfM, computer: localhost.
4/11/2008 10:29:10 AM File C:\WINDOWS\system32\awtsTLCv.dll: deleted.
4/11/2008 10:29:20 AM File C:\WINDOWS\mrofinu572.exe//PE_Patch.Upolyx//PE_Patch.UPX//UPX: detected: Trojan program 'Trojan-Downloader.Win32.Homles.bb'.
4/11/2008 10:29:20 AM Security threats have been detected. You are advised to neutralize them immediately.
4/11/2008 10:29:20 AM File C:\WINDOWS\mrofinu572.exe will be deleted on system restart.
4/11/2008 10:29:29 AM File C:\WINDOWS\system32\khfDwwxU.dll//PE_Patch: detected: virus 'Packed.Win32.Monder.gen'.
4/11/2008 10:29:29 AM Security threats have been detected. You are advised to neutralize them immediately.
4/11/2008 10:30:21 AM File c:\windows\system32\urqrkcsp.dll//PE_Patch: detected: virus 'Packed.Win32.Monder.gen'.
4/11/2008 10:31:06 AM File C:\WINDOWS\system32\khfDwwxU.dll//PE_Patch: is still infected, skipped by user.
4/11/2008 10:31:37 AM File C:\WINDOWS\system32\urqRKCsp.dll//PE_Patch: detected: virus 'Packed.Win32.Monder.gen'.
4/11/2008 10:31:37 AM File C:\WINDOWS\system32\urqRKCsp.dll//PE_Patch: detected: virus 'Packed.Win32.Monder.gen'. User: CORP\NY6MOB905403L$, computer: localhost.
4/11/2008 10:31:53 AM File C:\WINDOWS\system32\xxyawvSm.dll//PE_Patch: detected: virus 'Packed.Win32.Monder.gen'.
4/11/2008 10:31:53 AM File C:\WINDOWS\system32\xxyawvSm.dll//PE_Patch: is still infected, skipped by user.
4/11/2008 10:32:01 AM Protection of your computer is not running. You are advised to resume protection.
4/11/2008 10:33:36 AM Kaspersky Anti-Virus is not activated. You are advised to activate the application as soon as possible.
4/11/2008 10:33:37 AM You are advised to perform a full computer scan as soon as possible.
4/11/2008 10:33:50 AM Security threats have been detected. You are advised to neutralize them immediately.
4/11/2008 10:33:50 AM Protection of your computer is enabled.
4/11/2008 10:36:09 AM The application C:\Program Files\Network Associates\Common Framework\FrameworkService.exe cannot establish connection with server 172.22.232.176. Please check your internet connection settings. If you have a firewall installed, check that the application avp.exe is allowed internet access.
4/11/2008 11:11:54 AM Process (PID 1120) tried to access Kaspersky Anti-Virus process (PID 1756), but the action has been blocked by the Self-Defense component. No action on your part is required.
4/11/2008 12:08:25 PM File C:\WINDOWS\mrofinu572.exe.tmp//PE_Patch.Upolyx//PE_Patch.UPX//UPX: detected: Trojan program 'Trojan-Downloader.Win32.Homles.bb'.
4/11/2008 12:08:25 PM Security threats have been detected. You are advised to neutralize them immediately.
4/11/2008 12:08:25 PM File C:\WINDOWS\mrofinu572.exe.tmp//PE_Patch.Upolyx//PE_Patch.UPX//UPX: is still infected, postponed.
4/11/2008 12:42:52 PM Update cannot be started because of an error: no license key
4/11/2008 12:52:28 PM Process (PID 2804) tried to access Kaspersky Anti-Virus process (PID 1756), but the action has been blocked by the Self-Defense component. No action on your part is required.
4/11/2008 12:52:28 PM Process (PID 2804) tried to access Kaspersky Anti-Virus process (PID 4056), but the action has been blocked by the Self-Defense component. No action on your part is required.
4/11/2008 1:03:33 PM Update completed successfully
4/11/2008 3:04:58 PM Update completed successfully
4/11/2008 3:28:00 PM Process (PID 3548) tried to access Kaspersky Anti-Virus process (PID 4056), but the action has been blocked by the Self-Defense component. No action on your part is required.
4/11/2008 3:28:00 PM Process (PID 3548) tried to access Kaspersky Anti-Virus process (PID 1756), but the action has been blocked by the Self-Defense component. No action on your part is required.
4/11/2008 3:42:11 PM Protection of your computer is enabled.
4/11/2008 3:42:25 PM Process (PID 452) tried to access Kaspersky Anti-Virus process (PID 1912), but the action has been blocked by the Self-Defense component. No action on your part is required.
4/11/2008 3:45:04 PM The application C:\Program Files\Network Associates\Common Framework\FrameworkService.exe cannot establish connection with server 172.22.232.176. Please check your internet connection settings. If you have a firewall installed, check that the application avp.exe is allowed internet access.
4/11/2008 4:45:33 PM Process (PID 2684) tried to access Kaspersky Anti-Virus process (PID 3000), but the action has been blocked by the Self-Defense component. No action on your part is required.
4/11/2008 4:45:34 PM Process (PID 2684) tried to access Kaspersky Anti-Virus process (PID 1912), but the action has been blocked by the Self-Defense component. No action on your part is required.
4/11/2008 5:13:33 PM Protection of your computer is enabled.
4/11/2008 5:14:37 PM Update completed successfully
4/11/2008 5:26:35 PM Malicious HTTP object <
http://downloads.and...x/catchme.exe>: detected new variant of virus 'Heur.Invader'.
4/11/2008 5:26:35 PM Malicious HTTP object <
http://downloads.and...x/catchme.exe>: access denied.
4/11/2008 5:58:56 PM Protection of your computer is not running. You are advised to resume protection.
4/14/2008 9:16:38 AM Database is out of date, leaving your computer at risk of infection. Please update your database.
4/14/2008 9:16:38 AM Protection of your computer is enabled.
4/14/2008 9:17:55 AM Update completed successfully
4/14/2008 9:19:33 AM Databases are up to date
4/14/2008 9:20:04 AM File C:\Documents and Settings\knopfm\Local Settings\Temporary Internet Files\Content.IE5\J8R1WCJ2\zrt20080408[1]: detected: Trojan program 'Trojan.Win32.KillAV.rf'. User: CORP\KnopfM, computer: localhost.
4/14/2008 9:20:04 AM Security threats have been detected. You are advised to neutralize them immediately.
4/14/2008 9:20:32 AM File C:\Documents and Settings\knopfm\Local Settings\Temporary Internet Files\Content.IE5\J8R1WCJ2\zrt20080408[1]: deleted.
4/14/2008 9:20:48 AM Malicious HTTP object <
http://82.98.235.78/...7AE4&rid=wen5>: detected: Trojan program 'Trojan.Win32.KillAV.rf'.
4/14/2008 9:20:48 AM !NOLOC! StatusId(0) EventID(7)
4/14/2008 9:20:48 AM File C:\DOCUME~1\knopfm\LOCALS~1\Temp\gqdlitrs.dll: detected: Trojan program 'Trojan.Win32.KillAV.rf'.
4/14/2008 9:20:48 AM Security threats have been detected. You are advised to neutralize them immediately.
4/14/2008 9:20:58 AM File C:\DOCUME~1\knopfm\LOCALS~1\Temp\gqdlitrs.dll: deleted.
4/14/2008 9:21:05 AM File C:\Documents and Settings\knopfm\Local Settings\Temporary Internet Files\Content.IE5\05QRWLQZ\zrt20080408[1]: detected: Trojan program 'Trojan.Win32.KillAV.rf'.
4/14/2008 9:21:05 AM Security threats have been detected. You are advised to neutralize them immediately.
4/14/2008 9:21:05 AM File C:\Documents and Settings\knopfm\Local Settings\Temporary Internet Files\Content.IE5\05QRWLQZ\zrt20080408[1]: deleted.
4/14/2008 11:37:19 AM Update completed successfully
4/14/2008 1:44:15 PM File C:\WINDOWS\system32\oegdwdtv.dll: detected: Trojan program 'Trojan.Win32.KillAV.rf'. User: NT AUTHORITY\NETWORK SERVICE, computer: localhost.
4/14/2008 1:44:15 PM Security threats have been detected. You are advised to neutralize them immediately.
4/14/2008 1:44:15 PM File C:\WINDOWS\system32\oegdwdtv.dll: deleted.
4/14/2008 1:44:40 PM File C:\WINDOWS\system32\yqtrbcnu.dll: detected: Trojan program 'Trojan.Win32.KillAV.rf'. User: NT AUTHORITY\NETWORK SERVICE, computer: localhost.
4/14/2008 1:44:40 PM Security threats have been detected. You are advised to neutralize them immediately.
4/14/2008 1:44:40 PM File C:\WINDOWS\system32\yqtrbcnu.dll: deleted.
4/14/2008 1:57:19 PM Update completed successfully
4/14/2008 4:17:22 PM Update completed successfully
4/14/2008 6:38:14 PM Update completed successfully
4/14/2008 6:45:34 PM File C:\Documents and Settings\knopfm\Local Settings\Temporary Internet Files\Content.IE5\J8R1WCJ2\kriv[1]//PE_Patch: detected: adware 'not-a-virus:AdWare.Win32.Virtumonde.nvf'.
4/14/2008 6:45:34 PM Security threats have been detected. You are advised to neutralize them immediately.
4/14/2008 6:45:34 PM File C:\Documents and Settings\knopfm\Local Settings\Temporary Internet Files\Content.IE5\J8R1WCJ2\kriv[1]//PE_Patch: is still infected, postponed.
4/14/2008 7:14:45 PM File C:\WINDOWS\SYSTEM32\NXIDUARP.DLL//PE_Patch: detected: adware 'not-a-virus:AdWare.Win32.Virtumonde.nvf'. User: CORP\KnopfM, computer: localhost.
4/14/2008 7:15:06 PM File C:\WINDOWS\SYSTEM32\NXIDUARP.DLL//PE_Patch: detected: adware 'not-a-virus:AdWare.Win32.Virtumonde.nvf'.
4/14/2008 8:01:48 PM Your evaluation period will end in 26 days. To ensure uninterrupted protection, please <a v(buy)>click here to purchase</a>.
4/14/2008 8:59:46 PM Update completed successfully
4/14/2008 9:02:19 PM File C:\WINDOWS\system32\nxiduarp.dll//PE_Patch: detected: adware 'not-a-virus:AdWare.Win32.Virtumonde.nvf'.
4/14/2008 9:02:19 PM File C:\WINDOWS\system32\nxiduarp.dll//PE_Patch: is still infected, postponed.
4/14/2008 9:07:33 PM File c:\documents and settings\knopfm\local settings\temporary internet files\content.ie5\j8r1wcj2\kriv[1]//PE_Patch: detected: adware 'not-a-virus:AdWare.Win32.Virtumonde.nvf'.
4/14/2008 11:18:26 PM Update completed successfully
4/15/2008 1:37:26 AM Update completed successfully
4/15/2008 3:57:41 AM Update completed successfully
4/15/2008 6:17:28 AM Update completed successfully
4/15/2008 8:37:56 AM Update completed successfully
4/15/2008 9:16:37 AM File C:\WINDOWS\SYSTEM32\NXIDUARP.DLL//PE_Patch: detected: adware 'not-a-virus:AdWare.Win32.Virtumonde.nvf'.
4/15/2008 9:16:37 AM File C:\WINDOWS\SYSTEM32\NXIDUARP.DLL will be deleted on system restart.
4/15/2008 9:17:13 AM File C:\WINDOWS\System32\nxiduarp.dll//PE_Patch: detected: adware 'not-a-virus:AdWare.Win32.Virtumonde.nvf'.
4/15/2008 9:17:41 AM File c:\documents and settings\knopfm\local settings\temporary internet files\content.ie5\j8r1wcj2\kriv[1]: deleted.
4/15/2008 9:17:41 AM File c:\windows\system32\nxiduarp.dll//PE_Patch: detected: adware 'not-a-virus:AdWare.Win32.Virtumonde.nvf'.
4/15/2008 9:19:54 AM Protection of your computer is not running. You are advised to resume protection.
4/15/2008 9:21:29 AM Your evaluation period will end in 26 days. To ensure uninterrupted protection, please <a v(buy)>click here to purchase</a>.
4/15/2008 9:21:29 AM Protection of your computer is enabled.
4/15/2008 9:22:57 AM Malicious HTTP object <
http://82.98.235.78/...7AE4&rid=wen5>: detected: Trojan program 'Trojan.Win32.KillAV.rf'.
4/15/2008 9:22:57 AM !NOLOC! StatusId(0) EventID(7)
4/15/2008 9:23:01 AM File C:\DOCUME~1\knopfm\LOCALS~1\Temp\cvxqstxw.dll: detected: Trojan program 'Trojan.Win32.KillAV.rf'.
4/15/2008 9:23:01 AM Security threats have been detected. You are advised to neutralize them immediately.
4/15/2008 9:23:07 AM File C:\DOCUME~1\knopfm\LOCALS~1\Temp\cvxqstxw.dll: deleted.
4/15/2008 9:23:17 AM File C:\Documents and Settings\knopfm\Local Settings\Temporary Internet Files\Content.IE5\O167GTYF\zrt20080408[1]: detected: Trojan program 'Trojan.Win32.KillAV.rf'.
4/15/2008 9:23:17 AM Security threats have been detected. You are advised to neutralize them immediately.
4/15/2008 9:23:19 AM File C:\Documents and Settings\knopfm\Local Settings\Temporary Internet Files\Content.IE5\O167GTYF\zrt20080408[1]: deleted.
4/15/2008 9:52:41 AM Protection of your computer is not running. You are advised to resume protection.
4/15/2008 9:54:22 AM Your evaluation period will end in 26 days. To ensure uninterrupted protection, please <a v(buy)>click here to purchase</a>.
4/15/2008 9:54:23 AM Protection of your computer is enabled.
4/15/2008 9:58:02 AM The application C:\Program Files\Network Associates\Common Framework\FrameworkService.exe cannot establish connection with server 172.22.232.176. Please check your internet connection settings. If you have a firewall installed, check that the application avp.exe is allowed internet access.
4/15/2008 10:55:25 AM Protection of your computer is not running. You are advised to resume protection.
4/15/2008 10:56:43 AM Your evaluation period will end in 26 days. To ensure uninterrupted protection, please <a v(buy)>click here to purchase</a>.
4/15/2008 10:56:43 AM Protection of your computer is enabled.
4/15/2008 11:16:43 AM Update completed successfully
4/15/2008 11:30:30 AM Protection of your computer is not running. You are advised to resume protection.
4/15/2008 11:31:56 AM Your evaluation period will end in 26 days. To ensure uninterrupted protection, please <a v(buy)>click here to purchase</a>.
4/15/2008 11:31:56 AM Protection of your computer is enabled.
4/15/2008 3:53:55 PM Your evaluation period will end in 26 days. To ensure uninterrupted protection, please <a v(buy)>click here to purchase</a>.
4/15/2008 3:53:55 PM System is running in safe mode. Some protection components are disabled.
4/15/2008 3:53:56 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/15/2008 3:56:00 PM Scan startup objects cannot be started because of an error: task cannot be started in the safe mode
4/15/2008 4:14:01 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/15/2008 4:34:01 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/15/2008 4:54:01 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/15/2008 5:14:01 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/15/2008 5:34:01 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/15/2008 5:54:01 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/15/2008 6:14:01 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/15/2008 6:34:01 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/15/2008 6:54:02 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/15/2008 7:14:02 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/15/2008 7:34:01 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/15/2008 7:54:02 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/15/2008 8:14:02 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/15/2008 8:34:05 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/15/2008 8:54:32 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/15/2008 9:14:02 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/15/2008 9:34:05 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/15/2008 9:54:02 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/15/2008 10:14:02 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/15/2008 10:34:02 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/15/2008 10:54:02 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/15/2008 11:14:02 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/15/2008 11:34:02 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/15/2008 11:54:02 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 12:14:02 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 12:34:03 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 12:54:03 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 1:14:03 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 1:34:03 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 1:54:06 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 2:14:03 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 2:34:03 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 2:54:03 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 3:14:03 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 3:34:03 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 3:54:03 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 4:14:03 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 4:34:04 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 4:54:03 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 5:14:04 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 5:34:03 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 5:54:04 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 6:14:04 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 6:34:04 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 6:54:04 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 7:14:04 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 7:34:04 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 7:54:04 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 8:14:04 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 8:34:04 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 8:54:04 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 9:14:04 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 3:08:09 PM System is running in safe mode. Some protection components are disabled.
4/16/2008 3:08:13 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 3:10:14 PM Scan startup objects cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 3:30:44 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 3:50:45 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 4:10:45 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 4:30:44 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 4:50:44 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 5:10:45 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 5:18:30 PM File C:\Documents and Settings\knopfm\Local Settings\Temp\ICD1.tmp\UGA6P_0001_N122M2802NetInstaller.exe: detected: riskware 'not-a-virus:Downloader.Win32.WinFixer.au'.
4/16/2008 5:18:30 PM Security threats have been detected. You are advised to neutralize them immediately.
4/16/2008 5:18:30 PM File C:\Documents and Settings\knopfm\Local Settings\Temp\ICD1.tmp\UGA6P_0001_N122M2802NetInstaller.exe: is still infected, postponed.
4/16/2008 5:29:54 PM File C:\Documents and Settings\knopfm\Local Settings\Temporary Internet Files\Content.IE5\IGTRJTU7\zrt20080408[1]: detected: Trojan program 'Trojan.Win32.KillAV.rf'.
4/16/2008 5:29:54 PM File C:\Documents and Settings\knopfm\Local Settings\Temporary Internet Files\Content.IE5\IGTRJTU7\zrt20080408[1]: is still infected, postponed.
4/16/2008 5:30:45 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 5:50:44 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 6:10:45 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 6:30:45 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 6:50:45 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 7:10:45 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 7:21:42 PM File C:\WINDOWS\Downloaded Program Files\UGA6P_0001_N122M2802NetInstaller.exe: detected: riskware 'not-a-virus:Downloader.Win32.WinFixer.au'.
4/16/2008 7:21:42 PM Security threats have been detected. You are advised to neutralize them immediately.
4/16/2008 7:21:42 PM File C:\WINDOWS\Downloaded Program Files\UGA6P_0001_N122M2802NetInstaller.exe: is still infected, postponed.
4/16/2008 7:28:56 PM File C:\WINDOWS\system32\liccltrq.dll: detected: Trojan program 'Trojan.Win32.KillAV.rf'.
4/16/2008 7:28:56 PM File C:\WINDOWS\system32\liccltrq.dll: is still infected, postponed.
4/16/2008 7:30:45 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 7:50:15 PM File c:\windows\downloaded program files\uga6p_0001_n122m2802netinstaller.exe: detected: riskware 'not-a-virus:Downloader.Win32.WinFixer.au'.
4/16/2008 7:50:45 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 8:10:45 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 8:30:45 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 8:50:45 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 9:10:45 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 9:30:45 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 9:50:45 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 10:10:45 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 10:30:45 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 10:50:45 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 11:10:46 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 11:30:46 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/16/2008 11:50:46 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 12:10:46 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 12:30:46 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 12:50:46 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 1:10:46 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 1:30:46 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 1:50:46 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 2:10:46 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 2:30:46 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 2:50:46 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 3:10:46 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 3:30:47 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 3:50:47 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 4:10:47 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 4:30:47 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 4:50:47 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 5:10:47 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 5:30:48 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 5:50:47 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 6:10:47 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 6:30:47 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 6:50:47 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 7:10:47 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 7:30:47 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 7:50:47 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 8:10:47 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 8:30:48 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 8:51:09 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 9:09:18 AM Database is out of date, leaving your computer at risk of infection. Please update your database.
4/17/2008 9:11:11 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 9:18:16 AM File c:\windows\downloaded program files\uga6p_0001_n122m2802netinstaller.exe: deleted.
4/17/2008 9:18:16 AM File c:\windows\system32\liccltrq.dll: detected: Trojan program 'Trojan.Win32.KillAV.rf'.
4/17/2008 9:18:16 AM File c:\windows\system32\liccltrq.dll: deleted.
4/17/2008 9:30:48 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 9:50:48 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 10:10:48 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 10:30:48 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 10:50:48 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 11:10:48 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 11:30:48 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 11:50:48 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 12:10:48 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 12:30:48 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 12:50:48 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 1:10:48 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 1:30:48 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 1:50:49 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 2:10:49 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 2:30:49 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 2:50:49 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 3:10:49 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 3:30:49 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 3:50:49 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 4:10:49 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 4:30:49 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 4:50:49 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 5:10:49 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 5:30:49 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/17/2008 5:47:50 PM Database is out of date, leaving your computer at risk of infection. Please update your database.
4/17/2008 5:47:51 PM Protection of your computer is enabled.
4/17/2008 5:48:23 PM Process (PID 332) tried to access Kaspersky Anti-Virus process (PID 1888), but the action has been blocked by the Self-Defense component. No action on your part is required.
4/17/2008 5:48:23 PM Process (PID 332) tried to access Kaspersky Anti-Virus process (PID 312), but the action has been blocked by the Self-Defense component. No action on your part is required.
4/17/2008 5:48:37 PM Please restart your computer to complete the installation of new or updated protection components.
4/17/2008 5:48:39 PM Update completed successfully
4/17/2008 5:50:02 PM File C:\WINDOWS\SYSTEM32\EUGNXYJP.DLL: detected: adware 'not-a-virus:AdWare.Win32.Virtumonde.okj'.
4/17/2008 5:50:02 PM Security threats have been detected. You are advised to neutralize them immediately.
4/17/2008 5:50:02 PM File C:\WINDOWS\SYSTEM32\EUGNXYJP.DLL: is still infected, skipped by user.
4/17/2008 6:07:56 PM File C:\WINDOWS\SYSTEM32\EUGNXYJP.DLL: detected: adware 'not-a-virus:AdWare.Win32.Virtumonde.okj'.
4/17/2008 6:07:56 PM File C:\WINDOWS\SYSTEM32\EUGNXYJP.DLL: is still infected, skipped by user.
4/17/2008 6:10:16 PM File C:\WINDOWS\system32\eugnxyjp.dll: detected: adware 'not-a-virus:AdWare.Win32.Virtumonde.okj'.
4/17/2008 6:10:16 PM File C:\WINDOWS\system32\eugnxyjp.dll: is still infected, skipped by user.
4/17/2008 6:11:27 PM File C:\WINDOWS\SYSTEM32\EUGNXYJP.DLL: detected: adware 'not-a-virus:AdWare.Win32.Virtumonde.okj'.
4/17/2008 6:11:27 PM File C:\WINDOWS\SYSTEM32\EUGNXYJP.DLL: is still infected, skipped by user.
4/17/2008 8:02:58 PM Your evaluation period will end in 23 days. To ensure uninterrupted protection, please <a v(buy)>click here to purchase</a>.
4/17/2008 8:08:23 PM Process (PID 332) tried to access Kaspersky Anti-Virus process (PID 1696), but the action has been blocked by the Self-Defense component. No action on your part is required.
4/17/2008 8:08:34 PM Update completed successfully
4/17/2008 10:28:24 PM Process (PID 332) tried to access Kaspersky Anti-Virus process (PID 3700), but the action has been blocked by the Self-Defense component. No action on your part is required.
4/17/2008 10:28:45 PM Update completed successfully
4/18/2008 12:48:25 AM Process (PID 332) tried to access Kaspersky Anti-Virus process (PID 460), but the action has been blocked by the Self-Defense component. No action on your part is required.
4/18/2008 12:48:34 AM Update completed successfully
4/18/2008 3:08:26 AM Process (PID 332) tried to access Kaspersky Anti-Virus process (PID 1040), but the action has been blocked by the Self-Defense component. No action on your part is required.
4/18/2008 3:08:33 AM Update completed successfully
4/18/2008 5:28:27 AM Process (PID 332) tried to access Kaspersky Anti-Virus process (PID 3604), but the action has been blocked by the Self-Defense component. No action on your part is required.
4/18/2008 5:28:39 AM Update completed successfully
4/18/2008 7:48:28 AM Process (PID 332) tried to access Kaspersky Anti-Virus process (PID 2716), but the action has been blocked by the Self-Defense component. No action on your part is required.
4/18/2008 7:48:38 AM Update completed successfully
4/18/2008 9:16:12 AM File C:\WINDOWS\SYSTEM32\EUGNXYJP.DLL: detected: adware 'not-a-virus:AdWare.Win32.Virtumonde.okj'. User: CORP\KnopfM, computer: localhost.
4/18/2008 9:16:12 AM File C:\WINDOWS\SYSTEM32\EUGNXYJP.DLL: is still infected, skipped by user.
4/18/2008 9:16:38 AM File C:\WINDOWS\SYSTEM32\EUGNXYJP.DLL: detected: adware 'not-a-virus:AdWare.Win32.Virtumonde.okj'.
4/18/2008 9:17:01 AM File C:\WINDOWS\SYSTEM32\EUGNXYJP.DLL cannot be deleted.
4/18/2008 9:18:17 AM Update completed successfully
4/18/2008 9:19:47 AM Protection of your computer is not running. You are advised to resume protection.
4/18/2008 9:21:17 AM Your evaluation period will end in 23 days. To ensure uninterrupted protection, please <a v(buy)>click here to purchase</a>.
4/18/2008 9:21:18 AM Protection of your computer is enabled.
4/18/2008 9:22:00 AM Process (PID 1032) tried to access Kaspersky Anti-Virus process (PID 1112), but the action has been blocked by the Self-Defense component. No action on your part is required.
4/18/2008 9:22:33 AM The application C:\Program Files\Network Associates\Common Framework\FrameworkService.exe cannot establish connection with server 172.22.232.176. Please check your internet connection settings. If you have a firewall installed, check that the application avp.exe is allowed internet access.
4/18/2008 9:27:47 AM Protection of your computer is not running. You are advised to resume protection.
4/18/2008 9:30:24 AM Your evaluation period will end in 23 days. To ensure uninterrupted protection, please <a v(buy)>click here to purchase</a>.
4/18/2008 9:30:25 AM System is running in safe mode. Some protection components are disabled.
4/18/2008 9:32:29 AM Scan startup objects cannot be started because of an error: task cannot be started in the safe mode
4/18/2008 9:32:55 AM File Anti-Virus cannot be started because of an error: task cannot be started in the safe mode
4/18/2008 11:33:01 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/18/2008 11:53:00 AM Update cannot be started because of an error: task cannot be started in the safe mode
4/18/2008 12:13:01 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/18/2008 12:33:00 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/18/2008 12:53:00 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/18/2008 1:13:01 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/18/2008 1:33:01 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/18/2008 1:53:01 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/18/2008 2:13:01 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/18/2008 2:33:01 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/18/2008 2:53:01 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/18/2008 3:13:01 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/18/2008 3:33:01 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/18/2008 3:53:01 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/18/2008 4:13:01 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/18/2008 4:33:01 PM Update cannot be started because of an error: task cannot be started in the safe mode
4/21/2008 9:09:43 AM Database is out of date, leaving your computer at risk of infection. Please update your database.
4/21/2008 9:09:43 AM Protection of your computer is enabled.
4/21/2008 9:10:09 AM Process C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (PID: 2164): attempt to perform suspicious actions allowed.
4/21/2008 9:10:19 AM Process C:\WINDOWS\system32\rundll32.exe (PID: 2740): attempt to perform suspicious actions allowed.
4/21/2008 9:10:20 AM Process C:\WINDOWS\explorer.exe (PID: 1888): attempt to perform suspicious actions allowed.
4/21/2008 9:10:52 AM Update completed successfully
4/21/2008 9:12:35 AM Databases are up to date
4/21/2008 9:15:15 AM File C:\WINDOWS\SYSTEM32\UMNUCCLC.DLL: detected: adware 'not-a-virus:AdWare.Win32.Virtumonde.pil'. User: CORP\KnopfM, computer: localhost.
4/21/2008 9:15:15 AM Security threats have been detected. You are advised to neutralize them immediately.
4/21/2008 9:15:32 AM File C:\WINDOWS\SYSTEM32\UMNUCCLC.DLL: deleted.
Reports
-------
Component Status Start Finish Size
--------- ------ ----- ------ ----
Proactive Defense running 4/21/2008 9:09:43 AM 21.3 KB
Mail Anti-Virus running 4/21/2008 9:09:43 AM 0 bytes
Web Anti-Virus running 4/21/2008 9:09:43 AM 23.7 KB
File Anti-Virus running 4/21/2008 9:09:43 AM 928.4 KB
Update completed 4/21/2008 9:09:45 AM 4/21/2008 9:10:51 AM 0 bytes
Update completed 4/21/2008 9:11:36 AM 4/21/2008 9:12:35 AM 0 bytes
Scan startup objects completed 4/21/2008 9:11:46 AM 4/21/2008 9:15:45 AM 389.6 KB
Update stopped 4/21/2008 9:12:41 AM 4/21/2008 9:13:35 AM 10.2 KB
Quarantine
----------
Status Object Size Added
------ ------ ---- -----
Backup
------
Status Object Size
------ ------ ----
Infected: Trojan program Trojan-Downloader.Win32.Homles.bb C:\WINDOWS\mrofinu572.exe 37.5 KB
Infected: Trojan program Trojan.Win32.KillAV.rf c:\windows\system32\liccltrq.dll 3.6 KB
Infected: adware not-a-virus:AdWare.Win32.Virtumonde.pil C:\WINDOWS\SYSTEM32\UMNUCCLC.DLL 94 KB
Infected: riskware not-a-virus:Downloader.Win32.WinFixer.au c:\documents and settings\knopfm\local settings\temp\icd1.tmp\uga6p_0001_n122m2802netinstaller.exe 181 KB
Infected: virus Packed.Win32.Monder.gen C:\WINDOWS\system32\urqRKCsp.dll 36 KB
Infected: adware not-a-virus:AdWare.Win32.Virtumonde.nvf c:\documents and settings\knopfm\local settings\temporary internet files\content.ie5\j8r1wcj2\kriv[1] 83 KB
Infected: Trojan program Trojan.Win32.KillAV.rf C:\Documents and Settings\knopfm\Local Settings\Temporary Internet Files\Content.IE5\05QRWLQZ\zrt20080408[1] 3.5 KB
Infected: Trojan program Trojan.Win32.KillAV.rf C:\DOCUME~1\knopfm\LOCALS~1\Temp\gqdlitrs.dll 3.6 KB
Infected: Trojan program Trojan-Downloader.Win32.Homles.bb c:\windows\mrofinu572.exe.tmp 37.5 KB
Infected: virus Packed.Win32.Monder.gen C:\WINDOWS\system32\awtsTLCv.dll 36 KB
Infected: Trojan program Trojan.Win32.KillAV.rf C:\WINDOWS\system32\yqtrbcnu.dll 3.6 KB
Infected: virus Packed.Win32.Monder.gen c:\windows\system32\khfdwwxu.dll 36 KB
Infected: virus Packed.Win32.Monder.gen c:\windows\system32\xxyawvsm.dll 36 KB
Infected: Trojan program Trojan.Win32.KillAV.rf C:\Documents and Settings\knopfm\Local Settings\Temporary Internet Files\Content.IE5\O167GTYF\zrt20080408[1] 3.5 KB
Infected: Trojan program Trojan.Win32.KillAV.rf C:\DOCUME~1\knopfm\LOCALS~1\Temp\cvxqstxw.dll 3.6 KB
Infected: adware not-a-virus:AdWare.Win32.Virtumonde.nvf C:\WINDOWS\SYSTEM32\NXIDUARP.DLL 83 KB
Infected: Trojan program Trojan.Win32.KillAV.rf c:\documents and settings\knopfm\local settings\temporary internet files\content.ie5\igtrjtu7\zrt20080408[1] 3.5 KB
Infected: adware not-a-virus:AdWare.Win32.Virtumonde.okj c:\windows\system32\eugnxyjp.dll 94 KB
Infected: Trojan program Trojan.Win32.KillAV.rf C:\WINDOWS\system32\oegdwdtv.dll 3.6 KB
Infected: Trojan program Trojan.Win32.KillAV.rf C:\Documents and Settings\knopfm\Local Settings\Temporary Internet Files\Content.IE5\J8R1WCJ2\zrt20080408[1] 3.5 KB
Infected: riskware not-a-virus:Downloader.Win32.WinFixer.au c:\windows\downloaded program files\uga6p_0001_n122m2802netinstaller.exe 181 KB
b