This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] thought i had this fixed...guess not

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

can somone please help me get rid of this nuisance.any help will be deeply appreciated.here are my logs

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:15:48 AM, on 9/25/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Linksys\WUSB300N\WLService.exe
C:\Program Files\Linksys\WUSB300N\WUSB300N.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\Twain_32\CA561A\SnapDetect.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ps2.exe
C:\WINDOWS\ALCXMNTR.EXE
c:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\HP_Owner\Desktop\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: MPBarOpener Class - {8FD66659-A7AF-4641-9999-C56607D3A0AB} - C:\Program Files\Mpire\Mpire Plugin\MPBand.dll
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [ICTC] E:\Setup.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: SnapDetect.lnk = ?
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file://C:\Program Files\Wedding Dash\Images\stg_drm.ocx
O16 - DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} - http://www.trendsecure.com/framework/contr…vex/TmHcmsX.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Mystery%20P.I.%20-%20The%20Lottery%20Ticket/Images/armhelper.ocx
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - http://cafecam.heerenvanbeijerland.nl/activex/AMC.cab
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: WUSB300NSvc - Unknown owner - C:\Program Files\Linksys\WUSB300N\WLService.exe

–
End of file - 5664 bytes


Malwarebytes' Anti-Malware 1.26
Database version: 1119
Windows 5.1.2600 Service Pack 2

9/25/2008 5:44:12 AM
mbam-log-2008-09-25 (05-44-11).txt

Scan type: Quick Scan
Objects scanned: 40347
Time elapsed: 11 minute(s), 34 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
My computer keeps getting redirected when i click on a website i want to go to.it tells me i am infected with a virus do i want to go on to the website.i click ok when i tells me address not found.then if i click to go back to the previous page the sight i wanted to go on comes up.



my logs

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:42:52 PM, on 9/28/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Linksys\WUSB300N\WLService.exe
C:\Program Files\Linksys\WUSB300N\WUSB300N.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\Twain_32\CA561A\SnapDetect.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\ps2.exe
C:\WINDOWS\ALCXMNTR.EXE
c:\windows\system\hpsysdrv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\HP_Owner\Desktop\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: MPBarOpener Class - {8FD66659-A7AF-4641-9999-C56607D3A0AB} - C:\Program Files\Mpire\Mpire Plugin\MPBand.dll
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [ICTC] E:\Setup.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: SnapDetect.lnk = ?
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file://C:\Program Files\Wedding Dash\Images\stg_drm.ocx
O16 - DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} - http://www.trendsecure.com/framework/contr…vex/TmHcmsX.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Mystery%20P.I.%20-%20The%20Lottery%20Ticket/Images/armhelper.ocx
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - http://cafecam.heerenvanbeijerland.nl/activex/AMC.cab
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: WUSB300NSvc - Unknown owner - C:\Program Files\Linksys\WUSB300N\WLService.exe

–
End of file - 5738 bytes



avira antivirus





Avira AntiVir Personal
Report file date: Sunday, September 28, 2008 20:02

Scanning for 1646460 virus strains and unwanted programs.

Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Boot mode: Normally booted
Username: SYSTEM
Computer name: YOUR-F78BF48CE2

Version information:
BUILD.DAT : 8.1.0.331 16934 Bytes 8/12/2008 11:46:00
AVSCAN.EXE : 8.1.4.7 315649 Bytes 6/26/2008 15:57:53
AVSCAN.DLL : 8.1.4.0 40705 Bytes 5/26/2008 14:56:40
LUKE.DLL : 8.1.4.5 164097 Bytes 6/12/2008 19:44:19
LUKERES.DLL : 8.1.4.0 12033 Bytes 5/26/2008 14:58:52
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 7/18/2007 17:33:34
ANTIVIR1.VDF : 7.0.5.1 8182784 Bytes 6/24/2008 20:54:15
ANTIVIR2.VDF : 7.0.6.217 3773440 Bytes 9/26/2008 00:54:50
ANTIVIR3.VDF : 7.0.6.220 16384 Bytes 9/28/2008 00:54:59
Engineversion : 8.1.1.35
AEVDF.DLL : 8.1.0.5 102772 Bytes 2/25/2008 16:58:21
AESCRIPT.DLL : 8.1.0.76 319867 Bytes 9/29/2008 00:56:39
AESCN.DLL : 8.1.0.23 119156 Bytes 7/10/2008 19:44:49
AERDL.DLL : 8.1.1.2 438644 Bytes 9/29/2008 00:56:35
AEPACK.DLL : 8.1.2.3 364918 Bytes 9/29/2008 00:56:01
AEOFFICE.DLL : 8.1.0.25 196986 Bytes 9/29/2008 00:55:51
AEHEUR.DLL : 8.1.0.59 1438071 Bytes 9/29/2008 00:55:48
AEHELP.DLL : 8.1.0.15 115063 Bytes 7/10/2008 19:44:48
AEGEN.DLL : 8.1.0.36 315764 Bytes 9/29/2008 00:55:34
AEEMU.DLL : 8.1.0.7 430452 Bytes 7/31/2008 15:33:21
AECORE.DLL : 8.1.1.11 172406 Bytes 9/29/2008 00:55:04
AEBB.DLL : 8.1.0.1 53617 Bytes 7/10/2008 19:44:48
AVWINLL.DLL : 1.0.0.12 15105 Bytes 7/9/2008 15:40:05
AVPREF.DLL : 8.0.2.0 38657 Bytes 5/16/2008 16:28:01
AVREP.DLL : 8.0.0.2 98344 Bytes 9/29/2008 00:55:01
AVREG.DLL : 8.0.0.1 33537 Bytes 5/9/2008 18:26:40
AVARKT.DLL : 1.0.0.23 307457 Bytes 2/12/2008 15:29:23
AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 6/12/2008 19:27:49
SQLITE3.DLL : 3.3.17.1 339968 Bytes 1/23/2008 00:28:02
SMTPLIB.DLL : 1.2.0.23 28929 Bytes 6/12/2008 19:49:40
NETNT.DLL : 8.0.0.1 7937 Bytes 1/25/2008 19:05:10
RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 6/12/2008 20:48:07
RCTEXT.DLL : 8.0.52.0 86273 Bytes 6/27/2008 20:34:37

Configuration settings for the scan:
Jobname……………………..: Complete system scan
Configuration file……………: c:\program files\avira\antivir personaledition classic\sysscan.avp
Logging……………………..: low
Primary action……………….: interactive
Secondary action……………..: ignore
Scan master boot sector……….: on
Scan boot sector……………..: on
Boot sectors…………………: C:, D:,
Process scan…………………: on
Scan registry………………..: on
Search for rootkits…………..: off
Scan all files……………….: Intelligent file selection
Scan archives………………..: on
Recursion depth………………: 20
Smart extensions……………..: on
Macro heuristic………………: on
File heuristic……………….: medium

Start of the scan: Sunday, September 28, 2008 20:02

The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'firefox.exe' - '1' Module(s) have been scanned
Scan process 'hpsysdrv.exe' - '1' Module(s) have been scanned
Scan process 'ALCXMNTR.EXE' - '1' Module(s) have been scanned
Scan process 'ps2.EXE' - '1' Module(s) have been scanned
Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'LimeWire.exe' - '1' Module(s) have been scanned
Scan process 'SnapDetect.exe' - '1' Module(s) have been scanned
Scan process 'TeaTimer.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'jusched.exe' - '1' Module(s) have been scanned
Scan process 'hkcmd.exe' - '1' Module(s) have been scanned
Scan process 'WUSB300N.exe' - '1' Module(s) have been scanned
Scan process 'WLService.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'tcpsvcs.exe' - '1' Module(s) have been scanned
Scan process 'HPZipm12.exe' - '1' Module(s) have been scanned
Scan process 'MDM.EXE' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
36 processes with 36 modules were scanned

Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Master boot sector HD1
[INFO] No virus was found!
[WARNING] System error [21]: The device is not ready.
Master boot sector HD2
[INFO] No virus was found!
[WARNING] System error [21]: The device is not ready.
Master boot sector HD3
[INFO] No virus was found!
[WARNING] System error [21]: The device is not ready.
Master boot sector HD4
[INFO] No virus was found!
[WARNING] System error [21]: The device is not ready.

Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Boot sector 'D:\'
[INFO] No virus was found!

Starting to scan the registry.
The registry was scanned ( '57' files ).


Starting the file scan:

Begin scan in 'C:\'
C:\hiberfil.sys
[WARNING] The file could not be opened!
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\Documents and Settings\All Users\Application Data\iWin Games\DesktopAlerts\DesktopAlerts.exe
[DETECTION] Is the TR/Crypt.CFI.Gen Trojan
[NOTE] The file was deleted!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\A0068126.dll.bac_a01088
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\A0068126.dll.bac_a01088
[DETECTION] Is the TR/Dldr.MFA Trojan
[NOTE] The file was deleted!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\AtlBrowser.exe.bac_a02840
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\AtlBrowser.exe.bac_a02840
[DETECTION] Contains recognition pattern of the DIAL/90112 dialer
[NOTE] The file was deleted!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\aupd.exe.bac_a01228
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\aupd.exe.bac_a01228
[DETECTION] Contains recognition pattern of the DR/BHO.afj dropper
[NOTE] The file was moved to '49502b3c.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\aupd.exe.bac_a03316
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\aupd.exe.bac_a03316
[DETECTION] Contains recognition pattern of the DR/BHO.afj dropper
[NOTE] The file was moved to '49502b3f.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\capesnp.1.bac_a01424
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\capesnp.1.bac_a01424
[DETECTION] Is the TR/BHO.abo.9 Trojan
[NOTE] The file was moved to '49502b2e.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\capesnp.dll.bac_a00580
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\capesnp.dll.bac_a00580
[DETECTION] Is the TR/BHO.abo.9 Trojan
[NOTE] The file was moved to '49502b31.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\capesnp.dll.bac_a02840
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\capesnp.dll.bac_a02840
[DETECTION] Is the TR/BHO.abo.9 Trojan
[NOTE] The file was moved to '49502b33.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\edwssz.exe.bac_a01088
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\edwssz.exe.bac_a01088
[DETECTION] Contains recognition pattern of the DR/Agent.MA dropper
[NOTE] The file was moved to '49572b39.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\fupd.exe.bac_a01228
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\fupd.exe.bac_a01228
[DETECTION] Contains recognition pattern of the DR/Agent.ZM.3 dropper
[NOTE] The file was moved to '49502b4c.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\fupd.exe.bac_a03316
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\fupd.exe.bac_a03316
[DETECTION] Contains recognition pattern of the DR/Agent.ZM.3 dropper
[NOTE] The file was moved to '49502b4e.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\MediaTubeCodec_ver1.1226.0.exe.bac_a03316
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\MediaTubeCodec_ver1.1226.0.exe.bac_a03316
[DETECTION] Is the TR/Dldr.Zlob.mnm Trojan
[NOTE] The file was moved to '49442b45.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\nsu13.tmp.bac_a01088
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\nsu13.tmp.bac_a01088
[DETECTION] Is the TR/Dldr.MFA Trojan
[NOTE] The file was moved to '49552b55.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\PowerVideo.dll.bac_a01180
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\PowerVideo.dll.bac_a01180
[DETECTION] Is the TR/Spy.238080 Trojan
[NOTE] The file was moved to '49572b54.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\s1cg.bac_a01228
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\s1cg.bac_a01228
[DETECTION] Is the TR/Drop.BHQ Trojan
[NOTE] The file was moved to '49432b1d.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\s1cg.bac_a01544
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\s1cg.bac_a01544
[DETECTION] Is the TR/Drop.BHQ Trojan
[NOTE] The file was moved to '48c8a91e.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\s1cg.bac_a03316
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\s1cg.bac_a03316
[DETECTION] Is the TR/Drop.BHQ Trojan
[NOTE] The file was moved to '49432b1f.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\s1fk.bac_a01228
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\s1fk.bac_a01228
[DETECTION] Contains recognition pattern of the DR/TrafficSol.K.1 dropper
[NOTE] The file was moved to '49462b1e.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\s1fk.bac_a03316
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\s1fk.bac_a03316
[DETECTION] Contains recognition pattern of the DR/TrafficSol.K.1 dropper
[NOTE] The file was moved to '48cda91f.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\s2mg.bac_a01228
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\s2mg.bac_a01228
[DETECTION] Contains recognition pattern of the DR/Agent.ZM.6 dropper
[NOTE] The file was moved to '494d2b1f.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\s2mg.bac_a03316
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\s2mg.bac_a03316
[DETECTION] Contains recognition pattern of the DR/Agent.ZM.6 dropper
[NOTE] The file was moved to '494d2b20.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\s36s.5.exe.bac_a01228
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\s36s.5.exe.bac_a01228
[DETECTION] Contains recognition pattern of the DR/Agent.ZM.3 dropper
[NOTE] The file was moved to '49162b21.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\s36s.5.exe.bac_a03316
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\s36s.5.exe.bac_a03316
[DETECTION] Contains recognition pattern of the DR/Agent.ZM.3 dropper
[NOTE] The file was moved to '489da922.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\s3h8.2.exe.bac_a01228
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\s3h8.2.exe.bac_a01228
[DETECTION] Contains recognition pattern of the DR/Agent.ABM.6 dropper
[NOTE] The file was moved to '49482b22.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\s3h8.2.exe.bac_a03308
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\s3h8.2.exe.bac_a03308
[DETECTION] Contains recognition pattern of the DR/Agent.ABM.6 dropper
[NOTE] The file was moved to '48c3a923.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\s3h8.2.exe.bac_a03316
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\s3h8.2.exe.bac_a03316
[DETECTION] Contains recognition pattern of the DR/Agent.ABM.6 dropper
[NOTE] The file was moved to '49482b24.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\s3h8.g.bac_a01228
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\s3h8.g.bac_a01228
[DETECTION] Contains recognition pattern of the DR/Agent.ZM.12 dropper
[NOTE] The file was moved to '49482b23.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\s3h8.g.bac_a03316
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\s3h8.g.bac_a03316
[DETECTION] Contains recognition pattern of the DR/Agent.ZM.12 dropper
[NOTE] The file was moved to '48c3a924.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\s3l0.bac_a01228
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\s3l0.bac_a01228
[DETECTION] Contains recognition pattern of the DR/NewWeb.AR.2 dropper
[NOTE] The file was moved to '494c2b23.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\s3l0.bac_a03316
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\s3l0.bac_a03316
[DETECTION] Contains recognition pattern of the DR/NewWeb.AR.2 dropper
[NOTE] The file was moved to '494c2b24.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\s3ok.5.exe.bac_a01228
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\s3ok.5.exe.bac_a01228
[DETECTION] Contains recognition pattern of the DR/Vapsup.awu.1 dropper
[NOTE] The file was moved to '494f2b24.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\s3ok.5.exe.bac_a03316
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\s3ok.5.exe.bac_a03316
[DETECTION] Contains recognition pattern of the DR/Vapsup.awu.1 dropper
[NOTE] The file was moved to '494f2b25.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\sac.bac_a01228
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\sac.bac_a01228
[DETECTION] Contains recognition pattern of the DR/TrafficSol.K dropper
[NOTE] The file was moved to '49432b53.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\sac.bac_a03316
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\sac.bac_a03316
[DETECTION] Contains recognition pattern of the DR/TrafficSol.K dropper
[NOTE] The file was moved to '48c8a954.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\sfo.bac_a01228
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\sfo.bac_a01228
[DETECTION] Contains recognition pattern of the DR/TrafficSol.N dropper
[NOTE] The file was moved to '494f2b59.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\sfo.bac_a03316
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\sfo.bac_a03316
[DETECTION] Contains recognition pattern of the DR/TrafficSol.N dropper
[NOTE] The file was moved to '48c4a95a.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\su0.bac_a01228
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\su0.bac_a01228
[DETECTION] Is the TR/Dldr.Agent.9876 Trojan
[NOTE] The file was moved to '49102b6d.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\su0.bac_a03316
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\su0.bac_a03316
[DETECTION] Is the TR/Dldr.Agent.9876 Trojan
[NOTE] The file was moved to '489ba96e.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\tmp3C4.tmp.bac_a01228
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\tmp3C4.tmp.bac_a01228
[DETECTION] Contains recognition pattern of the DR/Agent.ZM.8 dropper
[NOTE] The file was moved to '49502b66.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\tmp3C4.tmp.bac_a03316
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\tmp3C4.tmp.bac_a03316
[DETECTION] Contains recognition pattern of the DR/Agent.ZM.8 dropper
[NOTE] The file was moved to '49502b67.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\tmp3C6.tmp.bac_a01228
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\tmp3C6.tmp.bac_a01228
[DETECTION] Contains recognition pattern of the DR/Agent.ZM.8 dropper
[NOTE] The file was moved to '48dba968.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\tmp3C6.tmp.bac_a03316
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\tmp3C6.tmp.bac_a03316
[DETECTION] Contains recognition pattern of the DR/Agent.ZM.8 dropper
[NOTE] The file was moved to '49502b68.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\tmp3CE.tmp.bac_a01228
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\tmp3CE.tmp.bac_a01228
[DETECTION] Contains recognition pattern of the DR/Agent.ZM.8 dropper
[NOTE] The file was moved to '48dba969.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\tmp3CE.tmp.bac_a03316
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\tmp3CE.tmp.bac_a03316
[DETECTION] Contains recognition pattern of the DR/Agent.ZM.8 dropper
[NOTE] The file was moved to '49502b6a.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\tmp3D3.tmp.bac_a01228
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\tmp3D3.tmp.bac_a01228
[DETECTION] Contains recognition pattern of the DR/Agent.ZM.5 dropper
[NOTE] The file was moved to '49502b69.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\tmp3D3.tmp.bac_a03316
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\tmp3D3.tmp.bac_a03316
[DETECTION] Contains recognition pattern of the DR/Agent.ZM.5 dropper
[NOTE] The file was moved to '48dba96a.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\tmp3E5.tmp.bac_a01228
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\tmp3E5.tmp.bac_a01228
[DETECTION] Contains recognition pattern of the DR/Agent.ZM.5 dropper
[NOTE] The file was moved to '49502b6b.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\tmp3E5.tmp.bac_a03316
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\tmp3E5.tmp.bac_a03316
[DETECTION] Contains recognition pattern of the DR/Agent.ZM.5 dropper
[NOTE] The file was moved to '48dba96b.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\tmp3FA.tmp.bac_a01228
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\tmp3FA.tmp.bac_a01228
[DETECTION] Contains recognition pattern of the DR/Agent.ZM.5 dropper
[NOTE] The file was moved to '49502b6c.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\tmp3FA.tmp.bac_a03316
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\tmp3FA.tmp.bac_a03316
[DETECTION] Contains recognition pattern of the DR/Agent.ZM.5 dropper
[NOTE] The file was moved to '48dba96d.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\tmp4D7.tmp.bac_a01228
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\tmp4D7.tmp.bac_a01228
[DETECTION] Contains recognition pattern of the DR/Agent.ZM.8 dropper
[NOTE] The file was moved to '49502b6e.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\tmp4D7.tmp.bac_a03316
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\tmp4D7.tmp.bac_a03316
[DETECTION] Contains recognition pattern of the DR/Agent.ZM.8 dropper
[NOTE] The file was moved to '48dba96c.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\tmp5A1.tmp.bac_a01228
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\tmp5A1.tmp.bac_a01228
[DETECTION] Contains recognition pattern of the DR/Agent.ZM.8 dropper
[NOTE] The file was moved to '49502b6d.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\tmp5A1.tmp.bac_a03316
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\tmp5A1.tmp.bac_a03316
[DETECTION] Contains recognition pattern of the DR/Agent.ZM.8 dropper
[NOTE] The file was moved to '48dba96f.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\tmp5A5.tmp.bac_a01228
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\tmp5A5.tmp.bac_a01228
[DETECTION] Contains recognition pattern of the DR/Agent.ZM.5 dropper
[NOTE] The file was moved to '49502b70.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\tmp5A5.tmp.bac_a03316
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\tmp5A5.tmp.bac_a03316
[DETECTION] Contains recognition pattern of the DR/Agent.ZM.5 dropper
[NOTE] The file was moved to '48dba971.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\tmp637.tmp.bac_a01228
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\tmp637.tmp.bac_a01228
[DETECTION] Contains recognition pattern of the DR/Agent.ZM.8 dropper
[NOTE] The file was moved to '49502b72.qua'!
C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\tmp637.tmp.bac_a03316
[0] Archive type: HIDDEN
–> FIL\\\?\C:\Documents and Settings\HP_Owner\.housecall6.6\Quarantine\tmp637.tmp.bac_a03316
[DETECTION] Contains recognition pattern of the DR/Agent.ZM.8 dropper
[NOTE] The file was moved to '48dba96e.qua'!
C:\Documents and Settings\HP_Owner\Application Data\Sun\Java\Deployment\cache\6.0\32\7836d960-30e99ea4
[0] Archive type: ZIP
–> BnnnnBaa.class
[DETECTION] Is the TR/Java.Downloader.Gen Trojan
–> VaannnaaBaa.class
[DETECTION] Is the TR/ClassLoader Trojan
–> Dnnny.class
[DETECTION] Contains recognition pattern of the JAVA/Exploit.Bytverify.5 Java virus
–> Bnnnnn.class
[DETECTION] Is the TR/Java.ClassLoader.AS Trojan
–> Den.class
[DETECTION] Is the TR/Exploit.Bytverify Trojan
–> Din.class
[DETECTION] Is the TR/Exploit.Bytverify.A Trojan
–> Dun.class
[DETECTION] Is the TR/Exploit.Bytverify.B Trojan
[NOTE] The file was moved to '49132b9a.qua'!
C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\BEJ73V7W\law[1].htm
[DETECTION] Is the TR/HTML.Downloader.Agent.NAH Trojan
[NOTE] The file was moved to '49572c28.qua'!
C:\Program Files\Mozilla Firefox\extensions\[removed]\page.html
[DETECTION] Is the TR/Dldr.FraudLoa.NC Trojan
[NOTE] The file was moved to '4947300c.qua'!
Begin scan in 'D:\'


End of the scan: Sunday, September 28, 2008 20:54
Used time: 51:36 Minute(s)

The scan has been done completely.

7440 Scanning directories
344278 Files were scanned
60 viruses and/or unwanted programs were found
7 Files were classified as suspicious:
3 files were deleted
0 files were repaired
58 files were moved to quarantine
0 files were renamed
2 Files cannot be scanned
344209 Files not concerned
13981 Archives were scanned
6 Warnings
61 Notes
Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.


(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:

Download ComboFix from Here or Here to your Desktop.
**Note: In the event you already have Combofix, please delete it from your desktop and download this new version . It is important that it is saved directly to your desktop**
——————————————————————–
  • Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • WARNING: IF you have not already done so Combofix will disconnect your machine from the Internet when it starts
  • Please do not re-connect your machine back to the Internet until Combofix has completely finished.
——————————————————————–

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review

****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

Give it atleast 20-30 minutes to finish if needed.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI