OTMoveit
File/Folder C:\WINDOWS\system32\wamilqvn.exe not found.
File/Folder C:\WINDOWS\system32\wryafqwe.exe not found.
File/Folder C:\WINDOWS\system32\wshvpnhu.exe not found.
File/Folder C:\WINDOWS\system32\xbckvfdo.exe not found.
File/Folder C:\WINDOWS\system32\xlvlaxap.exe not found.
File/Folder C:\WINDOWS\system32\xobbsvip.exe not found.
File/Folder C:\WINDOWS\system32\xokrmyvd.exe not found.
File/Folder C:\WINDOWS\system32\xurqyxkv.exe not found.
File/Folder C:\WINDOWS\system32\xwctnyxc.exe not found.
File/Folder C:\WINDOWS\system32\ytcekcdh.exe not found.
File/Folder C:\WINDOWS\system32\yxghwhui.exe not found.
File/Folder C:\WINDOWS\system32\yygqlcjj.exe not found.
OTMoveIt2 by OldTimer - Version 1.0.21 log created on 03172008_162242
Kaspersky Log
KASPERSKY ONLINE SCANNER REPORTKASPERSKY ONLINE SCANNER REPORT
Monday, March 17, 2008 7:49:46 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build
2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 17/03/2008
Kaspersky Anti-Virus database records: 636169
Scan Settings
Scan using the following antivirus databaseextended
Scan Archivestrue
Scan Mail Basestrue
Scan TargetMy Computer
C:\
D:\
E:\
Scan Statistics
Total number of scanned objects135147
Number of viruses found21
Number of infected objects203
Number of suspicious objects0
Duration of the scan process02:28:56
Infected Object NameVirus NameLast Action
C:\Documents and Settings\All Users\Application
Data\McAfee\SpamKiller\Logs\Filtering.log Object is locked skipped
C:\Documents and Settings\All Users\Application
Data\McAfee.com\Agent\Logs\TaskScheduler\McTskshd000.log Object is locked
skipped
C:\Documents and Settings\All Users\Application
Data\Microsoft\Crypto\RSA\MachineKeys\3ad391678a806ec4d691e83aaa393b6f_24adf822-76f7-4481-b30b-ff1b40f8687f
Object is locked skipped
C:\Documents and Settings\All Users\Application
Data\Microsoft\eHome\logs\ehRecvr.log Object is locked skipped
C:\Documents and Settings\All Users\Application
Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application
Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application
Data\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.1.Crwl
Object is locked skipped
C:\Documents and Settings\All Users\Application
Data\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.1.gthr
Object is locked skipped
C:\Documents and Settings\All Users\Application
Data\Microsoft\Search\Data\Applications\Windows\MSS.log Object is locked
skipped
C:\Documents and Settings\All Users\Application
Data\Microsoft\Search\Data\Applications\Windows\MSStmp.log Object is
locked skipped
C:\Documents and Settings\All Users\Application
Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000A.ci
Object is locked skipped
C:\Documents and Settings\All Users\Application
Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000A.wid
Object is locked skipped
C:\Documents and Settings\All Users\Application
Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000A.wsb
Object is locked skipped
C:\Documents and Settings\All Users\Application
Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\INDEX.000
Object is locked skipped
C:\Documents and Settings\All Users\Application
Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.000
Object is locked skipped
C:\Documents and Settings\All Users\Application
Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\Used0000.000
Object is locked skipped
C:\Documents and Settings\All Users\Application
Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore\CiST0000.000
Object is locked skipped
C:\Documents and Settings\All Users\Application
Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.chk1.gthr
Object is locked skipped
C:\Documents and Settings\All Users\Application
Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.chk2.gthr
Object is locked skipped
C:\Documents and Settings\All Users\Application
Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.Ntfy2.gthr
Object is locked skipped
C:\Documents and Settings\All Users\Application
Data\Microsoft\Search\Data\Applications\Windows\tmp.edb Object is locked
skipped
C:\Documents and Settings\All Users\Application
Data\Microsoft\Search\Data\Applications\Windows\Windows.edb Object is
locked skipped
C:\Documents and Settings\All Users\Application
Data\Microsoft\Search\Data\Temp\usgthrsvc\Ntf1.tmp Object is locked
skipped
C:\Documents and Settings\All Users\Application
Data\Microsoft\Search\Data\Temp\usgthrsvc\Ntf2.tmp Object is locked
skipped
C:\Documents and Settings\All Users\Application
Data\Microsoft\Search\Data\Temp\usgthrsvc\Perflib_Perfdata_bcc.dat Object
is locked skipped
C:\Documents and Settings\Mathew\Application
Data\Mozilla\Firefox\Profiles\arnd8egj.default\cert8.db Object is locked
skipped
C:\Documents and Settings\Mathew\Application
Data\Mozilla\Firefox\Profiles\arnd8egj.default\formhistory.dat Object is
locked skipped
C:\Documents and Settings\Mathew\Application
Data\Mozilla\Firefox\Profiles\arnd8egj.default\history.dat Object is
locked skipped
C:\Documents and Settings\Mathew\Application
Data\Mozilla\Firefox\Profiles\arnd8egj.default\key3.db Object is locked
skipped
C:\Documents and Settings\Mathew\Application
Data\Mozilla\Firefox\Profiles\arnd8egj.default\search.sqlite Object is
locked skipped
C:\Documents and Settings\Mathew\Application
Data\Mozilla\Firefox\Profiles\arnd8egj.default\urlclassifier2.sqlite
Object is locked skipped
C:\Documents and Settings\Mathew\Cookies\index.dat Object is locked
skipped
C:\Documents and Settings\Mathew\Local Settings\Application
Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\Mathew\Local Settings\Application
Data\Microsoft\Messenger\joelm4jcEmail Removed\SharingMetadata\Logs\Dfsr00005.log
Object is locked skipped
C:\Documents and Settings\Mathew\Local Settings\Application
Data\Microsoft\Messenger\joelm4jcEmail Removed\SharingMetadata\pending.dat
Object is locked skipped
C:\Documents and Settings\Mathew\Local Settings\Application
Data\Microsoft\Messenger\joelm4jcEmail Removed\SharingMetadata\Working\database_208_4679_846_6BAB\dfsr.db
Object is locked skipped
C:\Documents and Settings\Mathew\Local Settings\Application
Data\Microsoft\Messenger\joelm4jcEmail Removed\SharingMetadata\Working\database_208_4679_846_6BAB\fsr.log
Object is locked skipped
C:\Documents and Settings\Mathew\Local Settings\Application
Data\Microsoft\Messenger\joelm4jcEmail Removed\SharingMetadata\Working\database_208_4679_846_6BAB\fsrtmp.log
Object is locked skipped
C:\Documents and Settings\Mathew\Local Settings\Application
Data\Microsoft\Messenger\joelm4jcEmail Removed\SharingMetadata\Working\database_208_4679_846_6BAB\tmp.edb
Object is locked skipped
C:\Documents and Settings\Mathew\Local Settings\Application
Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Mathew\Local Settings\Application
Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Mathew\Local Settings\Application
Data\Microsoft\Windows Live Contacts\joelm4jcEmail Removed\real\members.stg
Object is locked skipped
C:\Documents and Settings\Mathew\Local Settings\Application
Data\Mozilla\Firefox\Profiles\arnd8egj.default\Cache\_CACHE_001_ Object is
locked skipped
C:\Documents and Settings\Mathew\Local Settings\Application
Data\Mozilla\Firefox\Profiles\arnd8egj.default\Cache\_CACHE_002_ Object is
locked skipped
C:\Documents and Settings\Mathew\Local Settings\Application
Data\Mozilla\Firefox\Profiles\arnd8egj.default\Cache\_CACHE_003_ Object is
locked skipped
C:\Documents and Settings\Mathew\Local Settings\Application
Data\Mozilla\Firefox\Profiles\arnd8egj.default\Cache\_CACHE_MAP_ Object is
locked skipped
C:\Documents and Settings\Mathew\Local
Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Mathew\Local
Settings\History\History.IE5\MSHist012008031720080318\index.dat Object is
locked skipped
C:\Documents and Settings\Mathew\Local Settings\Temp\snapsnet.exe/data0006
Infected: Trojan-Downloader.Win32.VB.caw skipped
C:\Documents and Settings\Mathew\Local Settings\Temp\snapsnet.exe NSIS:
infected - 1 skipped
C:\Documents and Settings\Mathew\Local Settings\Temp\~DF2B3D.tmp Object is
locked skipped
C:\Documents and Settings\Mathew\Local Settings\Temp\~DF702E.tmp Object is
locked skipped
C:\Documents and Settings\Mathew\Local Settings\Temp\~DF7039.tmp Object is
locked skipped
C:\Documents and Settings\Mathew\Local Settings\Temporary Internet
Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is
locked skipped
C:\Documents and Settings\Mathew\Local Settings\Temporary Internet
Files\Content.IE5\0WY8F8TH\wavvsnet[1].exe Infected:
Trojan-Downloader.Win32.Small.swa skipped
C:\Documents and Settings\Mathew\Local Settings\Temporary Internet
Files\Content.IE5\74VE2V6T\17PHolmes[1].cmt Infected:
Trojan-Downloader.Win32.Agent.lbx skipped
C:\Documents and Settings\Mathew\Local Settings\Temporary Internet
Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Mathew\Local Settings\Temporary Internet
Files\Content.IE5\MA2TXEZJ\css4[1] Infected:
not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Documents and Settings\Mathew\Local Settings\Temporary Internet
Files\Content.IE5\MA2TXEZJ\hctp[1] Infected:
not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Documents and Settings\Mathew\Local Settings\Temporary Internet
Files\Content.IE5\NPAKQ9VN\ptch[1] Infected:
not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Documents and Settings\Mathew\Local Settings\Temporary Internet
Files\Content.IE5\WD388BOH\17PHolmes[1].cmt Infected:
Trojan-Downloader.Win32.Agent.lbx skipped
C:\Documents and Settings\Mathew\Local Settings\Temporary Internet
Files\Content.IE5\WD388BOH\rasesnet[1].exe Infected:
not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Documents and Settings\Mathew\Local Settings\Temporary Internet
Files\Content.IE5\YPHQMV20\iddqd[1] Infected:
not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Documents and Settings\Mathew\Local Settings\Temporary Internet
Files\Content.IE5\YPHQMV20\snapsnet[1].exe/data0006 Infected:
Trojan-Downloader.Win32.VB.caw skipped
C:\Documents and Settings\Mathew\Local Settings\Temporary Internet
Files\Content.IE5\YPHQMV20\snapsnet[1].exe NSIS: infected - 1 skipped
C:\Documents and Settings\Mathew\My Documents\My Music\iTunes\iTunes
Library.itl Object is locked skipped
C:\Documents and Settings\Mathew\ntuser.dat Object is locked skipped
C:\Documents and Settings\Mathew\ntuser.dat.LOG Object is locked skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\duruaknp.dll.vir Infected:
Trojan-Spy.Win32.VBStat.h skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\fravaxbv.dll.vir Infected:
Packed.Win32.Klone.j skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\gdrileax.dll.vir Infected:
Packed.Win32.Klone.j skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\jkkji.dll.vir Infected:
not-a-virus:AdWare.Win32.Virtumonde.dyx skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\jsnardlx.dll.vir Infected:
Packed.Win32.Klone.j skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\mdnsnjsd.dll.vir Infected:
Trojan-Spy.Win32.VBStat.h skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\oplsisoj.dll.vir Infected:
Trojan-Spy.Win32.VBStat.h skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\yosvesth.dll.vir Infected:
Packed.Win32.Klone.j skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\yrideqtt.dll.vir Infected:
Trojan-Spy.Win32.VBStat.h skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is
locked skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP492\A0131258.dll
Infected: Trojan.Win32.BHO.g skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP492\A0131259.dll
Infected: Trojan.Win32.BHO.o skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP625\A0145248.exe/data0002
Infected: not-a-virus:AdWare.Win32.PurityScan.gn skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP625\A0145248.exe
NSIS: infected - 1 skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP671\A0150502.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP671\A0150503.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP671\A0150504.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP671\A0150505.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP671\A0150506.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP671\A0150507.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP671\A0150508.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP671\A0150509.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP671\A0150510.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP671\A0150511.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP671\A0150512.dll
Infected: not-a-virus:AdWare.Win32.Virtumonde.dyx skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP671\A0150513.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP671\A0150514.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP671\A0150515.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP671\A0150516.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP671\A0150517.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP671\A0150518.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP671\A0150519.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP671\A0150520.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP671\A0150521.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP671\A0150522.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP671\A0150523.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP671\A0150524.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP671\A0150525.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP671\A0150526.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP671\A0150527.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP671\A0150528.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP671\A0150529.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP671\A0150530.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP673\A0150557.dll
Infected: Trojan-Spy.Win32.VBStat.h skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP673\A0150558.dll
Infected: Packed.Win32.Klone.j skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP673\A0150559.dll
Infected: Packed.Win32.Klone.j skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP673\A0150560.dll
Infected: not-a-virus:AdWare.Win32.Virtumonde.dyx skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP673\A0150561.dll
Infected: Packed.Win32.Klone.j skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP673\A0150562.dll
Infected: Trojan-Spy.Win32.VBStat.h skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP673\A0150563.dll
Infected: Trojan-Spy.Win32.VBStat.h skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP673\A0150564.dll
Infected: Packed.Win32.Klone.j skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP673\A0150565.dll
Infected: Trojan-Spy.Win32.VBStat.h skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP688\A0157105.dll
Infected: not-a-virus:AdTool.Win32.WhenU.r skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP688\A0157106.exe
Infected: not-a-virus:AdTool.Win32.WhenU.t skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP732\A0178911.exe
Infected: not-a-virus:AdWare.Win32.CommAd.a skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP732\A0178912.exe
Infected: Trojan.Win32.BHO.ab skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP732\A0178913.exe
Infected: Trojan-Downloader.Win32.PurityScan.fj skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP732\A0178914.exe
Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP732\A0178915.exe
Infected: Trojan-Downloader.Win32.VB.caw skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP732\A0178916.exe
Infected: Virus.Win32.Trats.d skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP732\A0178917.dll
Infected: Trojan.Win32.BHO.ab skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP732\A0178918.exe/data0001
Infected: not-a-virus:AdWare.Win32.PurityScan.gp skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP732\A0178918.exe
NSIS: infected - 1 skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP732\A0178919.dll
Infected: not-a-virus:AdWare.Win32.TTC.d skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP732\A0178920.exe/data0002
Infected: not-a-virus:AdWare.Win32.TTC.d skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP732\A0178920.exe
NSIS: infected - 1 skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP732\A0178921.exe
Infected: Trojan.Win32.Scapur.k skipped
C:\System Volume
Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP732\change.log
Object is locked skipped
C:\VundoFix Backups\aeuketyb.exe.bad Infected:
not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\aldbpxki.exe.bad Infected:
not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\bsiphhlh.exe.bad Infected:
not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\dkeklfqu.exe.bad Infected:
not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\dpllaehs.exe.bad Infected:
not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\dyjkjnor.exe.bad Infected:
not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\gryrgnyv.exe.bad Infected:
not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\hpkfnpgn.exe.bad Infected:
not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\hsoncatk.exe.bad Infected:
not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\ikaufucs.exe.bad Infected:
not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\jkkji.dll.bad Infected:
not-a-virus:AdWare.Win32.Virtumonde.dyx skipped
C:\VundoFix Backups\jngkwjjm.exe.bad Infected:
not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\jnrxdkbu.exe.bad Infected:
not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\mhyrwhnv.exe.bad Infected:
not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\mrsfpnet.exe.bad Infected:
not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\mrwfmwvp.exe.bad Infected:
not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\nncdfxer.exe.bad Infected:
not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\ogoluuoe.exe.bad Infected:
not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\pthyprtn.exe.bad Infected:
not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\rdbfjubl.exe.bad Infected:
not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\rwouqdwi.exe.bad Infected:
not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\tiftdcaf.exe.bad Infected:
not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\tkmgdgfr.exe.bad Infected:
not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\tkmyxdnr.exe.bad Infected:
not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\weumsjux.exe.bad Infected:
not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\woqgqnxl.exe.bad Infected:
not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\xwuxefbv.exe.bad Infected:
not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\ykiwcned.exe.bad Infected:
not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\ykuantjj.exe.bad Infected:
not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\ModemLog_Conexant D850 56K V.9x DFVc Modem.txt Object is locked
skipped
C:\WINDOWS\mrofinu1000106.exe Infected: Trojan-Downloader.Win32.Agent.lbx
skipped
C:\WINDOWS\mrofinu572.exe Infected: Trojan-Downloader.Win32.Agent.lbx
skipped
C:\WINDOWS\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{4CB64E7B-E236-4508-99F5-329990CB0A2A}.crmlog
Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked
skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\byddnslj.dll Infected:
not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\comyctgx.dll Infected:
not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\Media Ce.evt Object is locked skipped
C:\WINDOWS\system32\config\ODiag.evt Object is locked skipped
C:\WINDOWS\system32\config\OSession.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Local Settings\Application
Data\Microsoft\Desktop Search\Logs\UNCFATPHLog.txt Object is locked
skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\jkkll.dll Infected:
not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\louggdya(4).dll Infected: Packed.Win32.Klone.j skipped
C:\WINDOWS\system32\mnbmjort.dll Infected:
not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\sclfrbhw.exe Infected:
not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\system32\sehkywog.exe Infected:
not-a-virus:AdWare.Win32.Agent.at skipped
C:\WINDOWS\system32\vtuvuvt.dll Infected:
not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked
skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked
skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked
skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked
skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked
skipped
C:\WINDOWS\TWF0aGV3\asappsrv.dll Infected:
not-a-virus:AdWare.Win32.CommAd.a skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\afclphcl.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\aofhowyy.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\awmtyiop.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\axngxfum.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\bbjjseyv.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\bdpeqctw.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\brqpwybf.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\btjsvbaq.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\bxkselcu.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\bynedhug.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\cybkvget.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\dudfovud.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\dunfhdjs.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\duoonbvd.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\egvccocs.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\elowntrq.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\fcfokshy.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\fjuwbcsa.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\fowyhsxj.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\fwivhisp.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\gxphnjwt.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\hfdksuik.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\hlwpcugk.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\hnqdmvrg.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\hntgtvos.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\hqgsmriy.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\hvhmwiiy.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\ieroawar.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\ipllfccv.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\ippnefck.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\ivlmkvgn.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\jbugsbix.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\jeiipcsi.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\jnacioyq.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\jxnaorra.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\jydtqvbb.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\kfepkutf.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\kguhpelp.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\kkkduksp.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\leqpfbxa.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\lhephphs.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\louggdya(2).dll
Infected: Packed.Win32.Klone.j skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\louggdya(3).dll
Infected: Packed.Win32.Klone.j skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\mhkjyfxn.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\mitnheou.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\msbwkwqc.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\nebvrlkb.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\nfxloqyy.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\nllekavm.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\nnlvxtnh.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\nqdrfkrv.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\nythtitw.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\oumeseis.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\phyvbbvk.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\pnjuhkcr.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\pxkonjug.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\rjhhkwgb.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\rtlqrwwj.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\ruxhjjyy.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\sfsecrrw.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\slaeinkp.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\stokaygw.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\tgwcxqaw.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\ttcqlmmh.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\ttcuuktb.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\tyxcuwmf.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\ucxittxc.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\ufutgxpk.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\uyauncnt.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\virgsvje.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\vjjxpvtx.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\vplcglyp.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\vqxxgwxy.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\wryafqwe.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\wshvpnhu.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\xbckvfdo.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\xlvlaxap.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\xobbsvip.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\xokrmyvd.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\xurqyxkv.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\xwctnyxc.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\ytcekcdh.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02032008_001353\WINDOWS\system32\yxghwhui.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02052008_175017\WINDOWS\system32\wamilqvn.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\_OTMoveIt\MovedFiles\02052008_175017\WINDOWS\system32\yygqlcjj.exe
Infected: not-a-virus:AdWare.Win32.Agent.at skipped
Scan process completed.
Hijack This
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:52:34 PM, on 3/17/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\McAfee.com\Personal Firewall\MPFTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\Rundll32.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Rogers\SelfHealing\rogersagent.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MPFEXE] "C:\Program Files\McAfee.com\Personal Firewall\MPFTray.exe"
O4 - HKLM\..\Run: [SupportAnyPC] "C:\DOCUME~1\Mathew\LOCALS~1\Temp\winvnc.exe" -servicehelper
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [08466b04] rundll32.exe "C:\WINDOWS\system32\lioriqcd.dll",b
O4 - HKLM\..\Run: [BM0b755898] Rundll32.exe "C:\WINDOWS\system32\prdroerp.dll",s
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Run: [RogersAgent] c:\Program Files\Rogers\SelfHealing\rogersagent.exe
O4 - HKCU\..\Run: [SHS] "C:\Program Files\Rogers\SelfHealing\SHS.exe" /background
O4 - HKCU\..\Run: [Update Manager] "C:\Program Files\Rogers\Update Manager\UpdateManager.exe" /background
O4 - HKCU\..\Run: [Uaol] "C:\DOCUME~1\Mathew\APPLIC~1\SSEMBL~1\netdde.exe" -vt yazb
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra 'Tools' menuitem: McAfee Anti-Phishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky.com/kos/eng/partner/u...can_unicode.cabO16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://gfx2.Email Removed.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) -
http://cdn.scan.onecare.live.com/resource/...lscbase4009.cabO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdat...b?1155396204578O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~4\Office12\GR99D3~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\TWF0aGV3\command.exe (file missing)
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe (file missing)
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: SupportAnyPC Service (SupportAnyPC) - Out of the Box Consulting, Inc. - C:\DOCUME~1\Mathew\LOCALS~1\Temp\winvnc.exe
--
End of file - 10315 bytes
its been a while lol....