[quote name=\'guestolo\' post=\'385041\' date=\'Sep 4 2007, 02:40 PM\']I'll be busy for a bit, drywalling the spareroom, so I have to finish some sanding, get it ready to prime
In the meantime, can you do the following please
Do a "System scan only" with Hijackthis and put a check next to this entry
O24 - Desktop Component 0: (no name) - C:\Program Files\WindowsUpdate\progyrtaq.html
After you have ticked the above entries, close
All other open windows
Including this oneLeave Hijackthis open and click FIX CHECKED
OK the prompt and exit Hijackthis
Download
[color=\"blue\"]OTMoveIt[/color] by OldTimer:
- Save it to your desktop.
- Please double-click OTMoveIt.exe to run it.
- Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose "Copy"):
================================================
C:\WINDOWS\system32\IBD4
C:\WINDOWS\system32\drvfig32
C:\WINDOWS\YWE
C:\Temp
======================================================
- Return to OTMoveIt, right-click on the "Paste List of Files/Folders to be Moved" window and choose "Paste".
- Click the red "[color=\"red\"]MoveIt![/color]" button.
- Close OTMoveIt.
[color=\"red\"]
Note[/color]: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose "
Yes".
If you are not required to reboot, can you manually reboot anyways please
OTMoveIt will create a log here
C:\_OTMoveIt\MovedFiles\mmddyyyy_hhmmss.logI'll need to see it later
Again, temporarily disable Avast's Standard Shield
Using IE to run this scan
Go to this link
http://www.bitdefender.com/Once there select "Scan now" under Scan online on the left hand side
Agree to the agreement and follow the prompts to load
After the scan post back the results back here
along with the log from OTMoveit and another fresh hijackthis log
Let me know how things are running[/quote]
Everything is great and working fine, no pop-ups
BitDefender Online Scanner
Scan report generated at: Tue, Sep 04, 2007 - 17:56:06
Scan path: A:\;C:\

:\;
Statistics
Time
00:34:45
Files
90005
Folders
3057
Boot Sectors
2
Archives
751
Packed Files
3343
Results
Identified Viruses
25
Infected Files
87
Suspect Files
0
Warnings
0
Disinfected
0
Deleted Files
93
Engines Info
Virus Definitions
775856
Engine build
AVCORE v1.0 (build 2411) (i386) (Jul 9 2007 12:10:22)
Scan plugins
14
Archive plugins
38
Unpack plugins
7
E-mail plugins
6
System plugins
1
Scan Settings
First Action
Disinfect
Second Action
Delete
Heuristics
Yes
Enable Warnings
Yes
Scanned Extensions
*;
Exclude Extensions
Scan Emails
Yes
Scan Archives
Yes
Scan Packed
Yes
Scan Files
Yes
Scan Boot
Yes
Scanned File
Status
C:\Program Files\TrojanHunter 4.7\Quarantine\26l.dat
Infected with: Trojan.Fotomoto.E
C:\Program Files\TrojanHunter 4.7\Quarantine\26l.dat
Disinfection failed
C:\Program Files\TrojanHunter 4.7\Quarantine\26l.dat
Deleted
C:\Program Files\TrojanHunter 4.7\Quarantine\410xHC.dat
Infected with: Trojan.Downloader.Winfixer.T
C:\Program Files\TrojanHunter 4.7\Quarantine\410xHC.dat
Disinfection failed
C:\Program Files\TrojanHunter 4.7\Quarantine\410xHC.dat
Deleted
C:\Program Files\TrojanHunter 4.7\Quarantine\hJt3al.dat
Detected with: Application.Winfixer.EG
C:\Program Files\TrojanHunter 4.7\Quarantine\hJt3al.dat
Disinfection failed
C:\Program Files\TrojanHunter 4.7\Quarantine\hJt3al.dat
Deleted
C:\Program Files\TrojanHunter 4.7\Quarantine\Jz3Mu.dat
Detected with: Adware.TTC.B
C:\Program Files\TrojanHunter 4.7\Quarantine\Jz3Mu.dat
Disinfection failed
C:\Program Files\TrojanHunter 4.7\Quarantine\Jz3Mu.dat
Deleted
C:\Program Files\TrojanHunter 4.7\Quarantine\zXesbw.dat
Infected with: Trojan.Vundo.DMV
C:\Program Files\TrojanHunter 4.7\Quarantine\zXesbw.dat
Disinfection failed
C:\Program Files\TrojanHunter 4.7\Quarantine\zXesbw.dat
Deleted
C:\qoobox\Quarantine\C\Program Files\WinAntiSpyware 2007\AsAgents.dll.vir
Detected with: Application.Winfixer.DK
C:\qoobox\Quarantine\C\Program Files\WinAntiSpyware 2007\AsAgents.dll.vir
Disinfection failed
C:\qoobox\Quarantine\C\Program Files\WinAntiSpyware 2007\AsAgents.dll.vir
Deleted
C:\qoobox\Quarantine\C\Program Files\WinAntiSpyware 2007\fopnl.dll.vir
Detected with: Application.Winfixer.EB
C:\qoobox\Quarantine\C\Program Files\WinAntiSpyware 2007\fopnl.dll.vir
Disinfection failed
C:\qoobox\Quarantine\C\Program Files\WinAntiSpyware 2007\fopnl.dll.vir
Deleted
C:\qoobox\Quarantine\C\Program Files\WinAntiSpyware 2007\InstUp.exe.vir=>(Instyler o)=>(Instyler Module 0)
Infected with: Trojan.Fakealert.BX
C:\qoobox\Quarantine\C\Program Files\WinAntiSpyware 2007\InstUp.exe.vir=>(Instyler o)=>(Instyler Module 0)
Disinfection failed
C:\qoobox\Quarantine\C\Program Files\WinAntiSpyware 2007\InstUp.exe.vir=>(Instyler o)=>(Instyler Module 0)
Deleted
C:\qoobox\Quarantine\C\Program Files\WinAntiSpyware 2007\InstUp.exe.vir=>(Instyler o)
Update failed
C:\qoobox\Quarantine\C\Program Files\WinAntiSpyware 2007\InstUp.exe.vir=>(Instyler o)=>(Instyler Module 1)
Infected with: Trojan.Downloader.Winfixer.T
C:\qoobox\Quarantine\C\Program Files\WinAntiSpyware 2007\InstUp.exe.vir=>(Instyler o)=>(Instyler Module 1)
Disinfection failed
C:\qoobox\Quarantine\C\Program Files\WinAntiSpyware 2007\InstUp.exe.vir=>(Instyler o)=>(Instyler Module 1)
Deleted
C:\qoobox\Quarantine\C\Program Files\WinAntiSpyware 2007\InstUp.exe.vir=>(Instyler o)
Update failed
C:\qoobox\Quarantine\C\Program Files\WinAntiSpyware 2007\quaratine.dat\28f6c107b57b459912009692\a70c21b6df0644f4d6aaf0a5\#data.vir=>(Quarantine-PE)
Infected with: Trojan.VB.Agent.K
C:\qoobox\Quarantine\C\Program Files\WinAntiSpyware 2007\quaratine.dat\28f6c107b57b459912009692\a70c21b6df0644f4d6aaf0a5\#data.vir=>(Quarantine-PE)
Disinfection failed
C:\qoobox\Quarantine\C\Program Files\WinAntiSpyware 2007\quaratine.dat\28f6c107b57b459912009692\a70c21b6df0644f4d6aaf0a5\#data.vir=>(Quarantine-PE)
Deleted
C:\qoobox\Quarantine\C\Program Files\WinAntiSpyware 2007\quaratine.dat\8f760c6ffc1c447b687ee781\f90641db5d4b4012ef956997\#data.vir=>(Quarantine-PE)
Infected with: Trojan.Proxy.493
C:\qoobox\Quarantine\C\Program Files\WinAntiSpyware 2007\quaratine.dat\8f760c6ffc1c447b687ee781\f90641db5d4b4012ef956997\#data.vir=>(Quarantine-PE)
Disinfection failed
C:\qoobox\Quarantine\C\Program Files\WinAntiSpyware 2007\quaratine.dat\8f760c6ffc1c447b687ee781\f90641db5d4b4012ef956997\#data.vir=>(Quarantine-PE)
Deleted
C:\qoobox\Quarantine\C\Program Files\WinAntiSpyware 2007\quaratine.dat\b94938d9a5b54daef14d82b9\84f798977798414f37e6ecad\#data.vir=>(Quarantine-PE)
Infected with: Trojan.Vundo.DMV
C:\qoobox\Quarantine\C\Program Files\WinAntiSpyware 2007\quaratine.dat\b94938d9a5b54daef14d82b9\84f798977798414f37e6ecad\#data.vir=>(Quarantine-PE)
Disinfection failed
C:\qoobox\Quarantine\C\Program Files\WinAntiSpyware 2007\quaratine.dat\b94938d9a5b54daef14d82b9\84f798977798414f37e6ecad\#data.vir=>(Quarantine-PE)
Deleted
C:\qoobox\Quarantine\C\Program Files\WinAntiSpyware 2007\quaratine.dat\bc810fd532654c35dd327ead\771bdc1bc9434127ecaacc91\#data.vir=>(Quarantine-PE)
Infected with: DeepScan:Generic.Virtumonde.1.16A22705
C:\qoobox\Quarantine\C\Program Files\WinAntiSpyware 2007\quaratine.dat\bc810fd532654c35dd327ead\771bdc1bc9434127ecaacc91\#data.vir=>(Quarantine-PE)
Disinfection failed
C:\qoobox\Quarantine\C\Program Files\WinAntiSpyware 2007\quaratine.dat\bc810fd532654c35dd327ead\771bdc1bc9434127ecaacc91\#data.vir=>(Quarantine-PE)
Deleted
C:\qoobox\Quarantine\C\Program Files\WinAntiSpyware 2007\quaratine.dat\f378d3fb27b34650e1174aa499e1e2ec3134eb99ce3e88f\#data.vir=>(Quarantine-PE)
Infected with: Trojan.Spy.Agent.NHK
C:\qoobox\Quarantine\C\Program Files\WinAntiSpyware 2007\quaratine.dat\f378d3fb27b34650e1174aa499e1e2ec3134eb99ce3e88f\#data.vir=>(Quarantine-PE)
Disinfection failed
C:\qoobox\Quarantine\C\Program Files\WinAntiSpyware 2007\quaratine.dat\f378d3fb27b34650e1174aa499e1e2ec3134eb99ce3e88f\#data.vir=>(Quarantine-PE)
Deleted
C:\qoobox\Quarantine\C\Program Files\WinAntiSpyware 2007\quaratine.dat\f378d3fb27b34650e1174aa4\2851bdf800bb4754909456a6\#data.vir=>(Quarantine-PE)
Infected with: Trojan.Spy.Agent.NHK
C:\qoobox\Quarantine\C\Program Files\WinAntiSpyware 2007\quaratine.dat\f378d3fb27b34650e1174aa4\2851bdf800bb4754909456a6\#data.vir=>(Quarantine-PE)
Disinfection failed
C:\qoobox\Quarantine\C\Program Files\WinAntiSpyware 2007\quaratine.dat\f378d3fb27b34650e1174aa4\2851bdf800bb4754909456a6\#data.vir=>(Quarantine-PE)
Deleted
C:\qoobox\Quarantine\C\Program Files\WinAntiSpyware 2007\was7.exe.vir
Detected with: Application.Winfixer.DY
C:\qoobox\Quarantine\C\Program Files\WinAntiSpyware 2007\was7.exe.vir
Disinfection failed
C:\qoobox\Quarantine\C\Program Files\WinAntiSpyware 2007\was7.exe.vir
Deleted
C:\qoobox\Quarantine\C\WINDOWS\system32\cifrsmsw.exe.vir
Infected with: Trojan.Fotomoto.E
C:\qoobox\Quarantine\C\WINDOWS\system32\cifrsmsw.exe.vir
Disinfection failed
C:\qoobox\Quarantine\C\WINDOWS\system32\cifrsmsw.exe.vir
Deleted
C:\qoobox\Quarantine\C\WINDOWS\system32\cplpekvh.exe.vir
Infected with: Trojan.Fotomoto.E
C:\qoobox\Quarantine\C\WINDOWS\system32\cplpekvh.exe.vir
Disinfection failed
C:\qoobox\Quarantine\C\WINDOWS\system32\cplpekvh.exe.vir
Deleted
C:\qoobox\Quarantine\C\WINDOWS\system32\drivers\Rtte57.sys.vir
Infected with: Trojan.Srizbi.G
C:\qoobox\Quarantine\C\WINDOWS\system32\drivers\Rtte57.sys.vir
Disinfection failed
C:\qoobox\Quarantine\C\WINDOWS\system32\drivers\Rtte57.sys.vir
Deleted
C:\qoobox\Quarantine\C\WINDOWS\system32\drivers\symavc32.sys.vir
Infected with: Trojan.Srizbi.G
C:\qoobox\Quarantine\C\WINDOWS\system32\drivers\symavc32.sys.vir
Disinfection failed
C:\qoobox\Quarantine\C\WINDOWS\system32\drivers\symavc32.sys.vir
Deleted
C:\qoobox\Quarantine\C\WINDOWS\system32\gcttigdl.exe.vir
Infected with: Trojan.Fotomoto.E
C:\qoobox\Quarantine\C\WINDOWS\system32\gcttigdl.exe.vir
Disinfection failed
C:\qoobox\Quarantine\C\WINDOWS\system32\gcttigdl.exe.vir
Deleted
C:\qoobox\Quarantine\C\WINDOWS\system32\giydfenf.exe.vir
Infected with: Trojan.Fotomoto.E
C:\qoobox\Quarantine\C\WINDOWS\system32\giydfenf.exe.vir
Disinfection failed
C:\qoobox\Quarantine\C\WINDOWS\system32\giydfenf.exe.vir
Deleted
C:\qoobox\Quarantine\C\WINDOWS\system32\gnqsps.dll.vir
Infected with: Trojan.Spambot.BXB
C:\qoobox\Quarantine\C\WINDOWS\system32\gnqsps.dll.vir
Disinfection failed
C:\qoobox\Quarantine\C\WINDOWS\system32\gnqsps.dll.vir
Deleted
C:\qoobox\Quarantine\C\WINDOWS\system32\KB24182794.exe.vir
Infected with: Trojan.Srizbi.G
C:\qoobox\Quarantine\C\WINDOWS\system32\KB24182794.exe.vir
Disinfection failed
C:\qoobox\Quarantine\C\WINDOWS\system32\KB24182794.exe.vir
Deleted
C:\qoobox\Quarantine\C\WINDOWS\system32\KB48559630.exe.vir
Infected with: Trojan.Srizbi.G
C:\qoobox\Quarantine\C\WINDOWS\system32\KB48559630.exe.vir
Disinfection failed
C:\qoobox\Quarantine\C\WINDOWS\system32\KB48559630.exe.vir
Deleted
C:\qoobox\Quarantine\C\WINDOWS\system32\qvjpkkmp.dll.vir
Infected with: Trojan.Vundo.DMP
C:\qoobox\Quarantine\C\WINDOWS\system32\qvjpkkmp.dll.vir
Deleted
C:\qoobox\Quarantine\C\WINDOWS\system32\uuuyewby.dll.vir
Infected with: Trojan.Vundo.DMP
C:\qoobox\Quarantine\C\WINDOWS\system32\uuuyewby.dll.vir
Deleted
C:\qoobox\Quarantine\C\WINDOWS\system32\vturs.dll.vir
Infected with: DeepScan:Generic.Virtumonde.1.D3832B16
C:\qoobox\Quarantine\C\WINDOWS\system32\vturs.dll.vir
Disinfection failed
C:\qoobox\Quarantine\C\WINDOWS\system32\vturs.dll.vir
Deleted
C:\qoobox\Quarantine\C\WINDOWS\system32\xsfofkwf.exe.vir
Infected with: Trojan.Fotomoto.E
C:\qoobox\Quarantine\C\WINDOWS\system32\xsfofkwf.exe.vir
Disinfection failed
C:\qoobox\Quarantine\C\WINDOWS\system32\xsfofkwf.exe.vir
Deleted
C:\qoobox\Quarantine\catchme2007-09-04_ 74302.60.zip=>mllmk.dll
Infected with: DeepScan:Generic.Virtumonde.1.D3832B16
C:\qoobox\Quarantine\catchme2007-09-04_ 74302.60.zip=>mllmk.dll
Disinfection failed
C:\qoobox\Quarantine\catchme2007-09-04_ 74302.60.zip=>mllmk.dll
Deleted
C:\qoobox\Quarantine\catchme2007-09-04_ 74302.60.zip
Updated
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP139\A0011769.dll
Infected with: DeepScan:Generic.Virtumonde.1.D3832B16
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP139\A0011769.dll
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP139\A0011769.dll
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP139\A0011887.dll
Infected with: DeepScan:Generic.Virtumonde.1.D3832B16
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP139\A0011887.dll
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP139\A0011887.dll
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP139\A0012143.exe
Infected with: Trojan.Downloader.Winfixer.T
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP139\A0012143.exe
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP139\A0012143.exe
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP139\A0012145.dll
Detected with: Application.Winfixer.EG
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP139\A0012145.dll
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP139\A0012145.dll
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP139\A0012146.exe
Infected with: MemScan:Trojan.Downloader.Tibs.GXL
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP139\A0012146.exe
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP139\A0012146.exe
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP139\A0012149.dll
Infected with: Trojan.Vundo.DMV
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP139\A0012149.dll
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP139\A0012149.dll
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP189\A0016959.dll
Infected with: Trojan.Vundo.DMP
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP189\A0016959.dll
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP191\A0017983.exe=>(NSIS o)=>zlib_nsis0000
Infected with: Trojan.Clicker.Small.YD
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP191\A0017983.exe=>(NSIS o)=>zlib_nsis0000
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP191\A0017983.exe=>(NSIS o)=>zlib_nsis0000
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP191\A0017983.exe=>(NSIS o)
Update failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP191\A0017983.exe=>(NSIS o)=>zlib_nsis0002
Infected with: Trojan.Clicker.Small.YD
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP191\A0017983.exe=>(NSIS o)=>zlib_nsis0002
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP191\A0017983.exe=>(NSIS o)=>zlib_nsis0002
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP191\A0017983.exe=>(NSIS o)
Update failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP191\A0017983.exe=>(NSIS o)=>zlib_nsis0003
Infected with: Trojan.Clicker.Small.AV
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP191\A0017983.exe=>(NSIS o)=>zlib_nsis0003
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP191\A0017983.exe=>(NSIS o)=>zlib_nsis0003
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP191\A0017983.exe=>(NSIS o)
Update failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP191\A0017993.dll
Infected with: Trojan.Vundo.DMP
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP191\A0017993.dll
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP191\A0018005.exe
Detected with: Adware.TTC.B
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP191\A0018005.exe
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP191\A0018005.exe
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP191\A0018008.exe
Infected with: Trojan.Proxy.Xorpix.BH
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP191\A0018008.exe
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP191\A0018008.exe
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP191\A0018009.exe
Infected with: Trojan.Proxy.Xorpix.BH
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP191\A0018009.exe
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP191\A0018009.exe
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP191\A0018010.dll
Infected with: Trojan.Vundo.DMV
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP191\A0018010.dll
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP191\A0018010.dll
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP192\A0018055.dll
Infected with: Trojan.Vundo.DMX
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP192\A0018055.dll
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP192\A0018055.dll
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018101.exe
Infected with: Trojan.Srizbi.G
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018101.exe
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018101.exe
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018102.exe
Infected with: Trojan.Srizbi.G
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018102.exe
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018102.exe
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018104.exe
Infected with: Trojan.Fotomoto.E
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018104.exe
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018104.exe
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018105.exe
Infected with: Trojan.Fotomoto.E
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018105.exe
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018105.exe
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018106.exe
Infected with: Trojan.Fotomoto.E
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018106.exe
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018106.exe
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018107.exe
Infected with: Trojan.Fotomoto.E
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018107.exe
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018107.exe
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018108.exe
Infected with: Trojan.Fotomoto.E
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018108.exe
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018108.exe
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018109.dll
Infected with: Trojan.Spambot.BXB
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018109.dll
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018109.dll
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018110.dll
Infected with: DeepScan:Generic.Virtumonde.1.D3832B16
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018110.dll
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018110.dll
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018112.dll
Infected with: Trojan.Vundo.DMP
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018112.dll
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018114.dll
Infected with: Trojan.Vundo.DMP
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018114.dll
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018121.dll
Detected with: Application.Winfixer.DK
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018121.dll
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018121.dll
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018123.dll
Detected with: Application.Winfixer.EB
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018123.dll
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018123.dll
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018124.exe=>(Instyler o)=>(Instyler Module 0)
Infected with: Trojan.Fakealert.BX
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018124.exe=>(Instyler o)=>(Instyler Module 0)
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018124.exe=>(Instyler o)=>(Instyler Module 0)
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018124.exe=>(Instyler o)
Update failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018124.exe=>(Instyler o)=>(Instyler Module 1)
Infected with: Trojan.Downloader.Winfixer.T
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018124.exe=>(Instyler o)=>(Instyler Module 1)
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018124.exe=>(Instyler o)=>(Instyler Module 1)
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018124.exe=>(Instyler o)
Update failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018134.exe
Detected with: Application.Winfixer.DY
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018134.exe
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018134.exe
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018148.dll
Infected with: DeepScan:Generic.Virtumonde.1.D3832B16
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018148.dll
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP193\A0018148.dll
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP194\A0018270.sys
Infected with: Trojan.Srizbi.G
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP194\A0018270.sys
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP194\A0018270.sys
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP194\A0018271.sys
Infected with: Trojan.Srizbi.G
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP194\A0018271.sys
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP194\A0018271.sys
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP66\A0002446.dll
Detected with: Application.Winfixer.DK
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP66\A0002446.dll
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP66\A0002446.dll
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP66\A0002447.exe=>(Instyler o)=>(Instyler Module 0)
Infected with: Trojan.Fakealert.BX
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP66\A0002447.exe=>(Instyler o)=>(Instyler Module 0)
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP66\A0002447.exe=>(Instyler o)=>(Instyler Module 0)
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP66\A0002447.exe=>(Instyler o)
Update failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP66\A0002447.exe=>(Instyler o)=>(Instyler Module 1)
Infected with: Trojan.Downloader.Winfixer.T
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP66\A0002447.exe=>(Instyler o)=>(Instyler Module 1)
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP66\A0002447.exe=>(Instyler o)=>(Instyler Module 1)
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP66\A0002447.exe=>(Instyler o)
Update failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP66\A0002448.dll
Detected with: Application.Winfixer.EB
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP66\A0002448.dll
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP66\A0002448.dll
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP66\A0002449.exe
Detected with: Application.Winfixer.DY
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP66\A0002449.exe
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP66\A0002449.exe
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP66\A0002455.dll
Detected with: Application.Winfixer.EG
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP66\A0002455.dll
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP66\A0002455.dll
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP66\A0006471.dll
Infected with: Trojan.Vundo.DMP
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP66\A0006471.dll
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP66\A0006474.exe
Infected with: Trojan.Popwin.DE
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP66\A0006474.exe
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP66\A0006474.exe
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP66\A0006477.dll
Detected with: Application.Winfixer.EG
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP66\A0006477.dll
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP66\A0006477.dll
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP69\snapshot\MFEX-1.DAT
Infected with: Trojan.Downloader.Winfixer.T
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP69\snapshot\MFEX-1.DAT
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP69\snapshot\MFEX-1.DAT
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP70\snapshot\MFEX-1.DAT
Infected with: Trojan.Downloader.Winfixer.T
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP70\snapshot\MFEX-1.DAT
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP70\snapshot\MFEX-1.DAT
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP71\snapshot\MFEX-1.DAT
Infected with: Trojan.Downloader.Winfixer.T
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP71\snapshot\MFEX-1.DAT
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP71\snapshot\MFEX-1.DAT
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP72\snapshot\MFEX-1.DAT
Infected with: Trojan.Downloader.Winfixer.T
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP72\snapshot\MFEX-1.DAT
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP72\snapshot\MFEX-1.DAT
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP73\A0008476.dll
Infected with: DeepScan:Generic.Virtumonde.1.16A22705
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP73\A0008476.dll
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP73\A0008476.dll
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP73\A0008480.exe
Infected with: Trojan.VB.Agent.K
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP73\A0008480.exe
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP73\A0008480.exe
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP73\A0008481.exe
Infected with: Trojan.Downloader.Winfixer.T
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP73\A0008481.exe
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP73\A0008481.exe
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP73\A0008491.dll
Infected with: Trojan.Vundo.DMP
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP73\A0008491.dll
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP73\A0008492.dll
Infected with: DeepScan:Generic.Virtumonde.1.D3832B16
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP73\A0008492.dll
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP73\A0008492.dll
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP73\A0008493.dll
Infected with: Trojan.Vundo.DMV
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP73\A0008493.dll
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP73\A0008493.dll
Deleted
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP73\snapshot\MFEX-1.DAT
Infected with: Trojan.Downloader.Winfixer.T
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP73\snapshot\MFEX-1.DAT
Disinfection failed
C:\System Volume Information\_restore{536A84B1-23FF-427D-877C-E7F33498F4D6}\RP73\snapshot\MFEX-1.DAT
Deleted
C:\_OTMoveIt\MovedFiles\WINDOWS\system32\drvfig32\r3w2821.exe
Infected with: Trojan.Downloader.Small.AAEU
C:\_OTMoveIt\MovedFiles\WINDOWS\system32\drvfig32\r3w2821.exe
Disinfection failed
C:\_OTMoveIt\MovedFiles\WINDOWS\system32\drvfig32\r3w2821.exe
Deleted
C:\_OTMoveIt\MovedFiles\WINDOWS\system32\IBD4\rru22011.exe
Infected with: Trojan.Agent.ABLK
C:\_OTMoveIt\MovedFiles\WINDOWS\system32\IBD4\rru22011.exe
Disinfection failed
C:\_OTMoveIt\MovedFiles\WINDOWS\system32\IBD4\rru22011.exe
Deleted
C:\WINDOWS\system32\IBD4 moved successfully.
C:\WINDOWS\system32\drvfig32 moved successfully.
C:\WINDOWS\YWE moved successfully.
C:\Temp moved successfully.
Created on 09/04/2007 16:54:57
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:24:27 PM, on 9/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Documents and Settings\Administrator\Desktop\AntiVirus\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\PROGRA~1\MICROS~3\wcescomm.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Documents and Settings\Administrator\Desktop\AntiVirus\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.com/customize/ie/defaul...rch/search.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.comR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.com/customize/ie/defaul...rch/search.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.comR1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.comR1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Documents and Settings\Administrator\Desktop\AntiVirus\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\PROGRA~1\MICROS~3\wcescomm.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) -
http://downloads.ewido.net/ewidoOnlineScan.cabO16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) -
http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cabO16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -
http://download.bitdefender.com/resources/scan8/oscan8.cabO23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Documents and Settings\Administrator\Desktop\AntiVirus\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: spkrmon - Unknown owner - C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
--
End of file - 6414 bytes