Thread: Malware Galore
View Single Post
Old 09-26-2006, 10:18 PM   #9 (permalink)
wyrdrune
Registered User
 
Join Date: Sep 2006
Posts: 19
OS: XP


COMBOFIX LOG

Puraj - 06-09-26 21:12:46.58 Service Pack 1
ComboFix 06.09.25 - Running from: "C:\Documents and Settings\Puraj\Desktop"

((((((((((((((((((((((((((((((( Files Created from 2006-08-26 to 2006-09-26 ))))))))))))))))))))))))))))))))))


2006-09-26 03:27 1,721 --a------ C:\system.exe
2006-09-26 01:35 9,216 --a------ C:\WINDOWS\SYSTEM32\dgflib.dll
2006-09-26 01:35 7,680 --a------ C:\WINDOWS\rundll.exe
2006-09-06 00:16 1,060,864 --a------ C:\WINDOWS\SYSTEM32\mfc71.dll
2006-09-05 15:14 68,608 --a------ C:\WINDOWS\SYSTEM32\olecli32.dll
2006-09-05 15:14 275,456 --a------ C:\WINDOWS\SYSTEM32\rpcss.dll
2006-09-05 15:14 1,190,400 --a------ C:\WINDOWS\SYSTEM32\ole32.dll


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-09-26 19:41 -------- d-------- C:\Program Files\Windows NT
2006-09-26 19:40 -------- d-------- C:\Program Files\ComPlus Applications
2006-09-26 19:40 -------- d-------- C:\Program Files\Common Files
2006-09-26 00:05 -------- d-------- C:\Program Files\PokerStars
2006-09-25 17:48 -------- d-------- C:\Program Files\Dell
2006-09-25 15:06 -------- d-------- C:\Program Files\Microsoft AntiSpyware
2006-09-25 07:35 -------- d-------- C:\Program Files\QuickTime
2006-09-25 07:35 -------- d-------- C:\Program Files\iTunes
2006-09-25 07:35 -------- d-------- C:\Program Files\Apoint
2006-09-21 19:27 -------- d-------- C:\Program Files\SpywareBlaster
2006-09-20 14:00 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-09-06 13:19 -------- d--h----- C:\Program Files\WindowsUpdate
2006-09-06 12:54 -------- d-------- C:\Program Files\Lavasoft
2006-09-06 12:54 -------- d-------- C:\Documents and Settings\Puraj\Application Data\Lavasoft
2006-09-06 11:53 -------- d-------- C:\Program Files\PCFriendly
2006-09-06 00:30 -------- d-------- C:\Program Files\Common Files\InstallShield
2006-09-06 00:26 -------- d-------- C:\Documents and Settings\Puraj\Application Data\SystemDoctor 2006 Free
2006-08-15 13:10 -------- d-------- C:\Documents and Settings\Puraj\Application Data\Adobe
2006-08-14 10:10 -------- d-------- C:\Program Files\Google
2006-08-13 20:04 -------- d-------- C:\Documents and Settings\Puraj\Application Data\AdobeUM
2006-08-13 20:00 -------- d-------- C:\Program Files\Adobe


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinampAgent"="\"C:\\Program Files\\Winamp3\\winampa.exe\""
"vptray"="C:\\PROGRA~1\\SYMANT~1\\SYMANT~1\\vptray.exe"
"TCASUTIEXE"="TCAUDIAG -off"
"nwiz"="nwiz.exe /installquiet"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"
"NAV Agent"="C:\\PROGRA~1\\NORTON~1\\navapw32.exe"
"Apoint"="C:\\Program Files\\Apoint\\Apoint.exe"
"iTunesHelper"="C:\\Program Files\\iTunes\\iTunesHelper.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000004

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,40,01,00,00,00,00,00,00,00,05,00,00,b0,04,00,00,ec,\
03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=dword:c0000004
"OriginalStateInfo"=hex:18,00,00,00,40,01,00,00,00,00,00,00,00,05,00,00,b0,04,\
00,00,04,00,00,c0
"RestoredStateInfo"=hex:18,00,00,00,40,01,00,00,00,00,00,00,00,05,00,00,b0,04,\
00,00,01,00,00,00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
"System"="{45673737-D1D1-4ECA-8760-AD3EFE7B0541}"


HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders
securityproviders REG_SZ msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll


Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Symantec NetDetect.job

Completion time: Tue 09/26/2006 21:14:46.37
ComboFix.txt
ComboFix2.txt
ComboFix3.txt


KASPERSKY LOG

KASPERSKY ONLINE SCANNER REPORT
Tuesday, September 26, 2006 9:11:22 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 1 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 27/09/2006
Kaspersky Anti-Virus database records: 226646


Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true

Scan Target My Computer
A:\
C:\
D:\

Scan Statistics
Total number of scanned objects 66931
Number of viruses found 74
Number of infected objects 227 / 0
Number of suspicious objects 1
Duration of the scan process 01:15:32

Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\00BC0000.VBN Infected: Trojan-Downloader.Win32.Intexp.b skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\00BC0001.VBN Infected: Trojan-Downloader.Win32.Qoologic.ax skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\00BC0002.VBN Infected: Trojan-Downloader.Win32.Qoologic.ax skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\00BC0003.VBN Infected: Trojan-Downloader.Win32.Qoologic.ax skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\00BC0005.VBN Infected: Trojan-Downloader.Win32.Qoologic.ax skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\00BC0006.VBN Infected: Trojan-Downloader.Win32.Qoologic.ax skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\00C80000.VBN Infected: Email-Worm.Win32.LovGate.f skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\00D00001.VBN Infected: Trojan-Downloader.Win32.Qoologic.ax skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\00D00002.VBN Infected: Trojan-Downloader.Win32.Adload.fg skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\00D40000.VBN Infected: Trojan.Win32.VB.tg skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\00D40001.VBN Infected: Trojan-Downloader.Win32.Qoologic.ax skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\00D80000.VBN Infected: Trojan-Downloader.Win32.Qoologic.ax skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\00DC0000.VBN Infected: Trojan-Downloader.Win32.Qoologic.ax skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\00DC0001.VBN Infected: Trojan-Downloader.Win32.Qoologic.ax skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\00DC0002.VBN Infected: Trojan-Downloader.Win32.Qoologic.ax skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\00DC0003.VBN Infected: Trojan-Downloader.Win32.Adload.fg skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\00DC0004.VBN Infected: Trojan-Downloader.Win32.Adload.ff skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\00DC0005.VBN Infected: Trojan.Win32.VB.tg skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\00E00000.VBN Infected: Trojan-Downloader.Win32.Qoologic.ax skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\00E00001.VBN Infected: Trojan-Downloader.Win32.Adload.ff skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\00E40000.VBN Infected: Trojan-Downloader.Win32.Virtumonde.b skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\00F80000.VBN Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\01300000.VBN Infected: Backdoor.Win32.Rbot.azl skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\01340000.VBN Infected: P2P-Worm.Win32.SpyBot.gw skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\01980000.VBN Infected: Trojan.Win32.VB.tg skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\019C0000.VBN Infected: Trojan.Win32.VB.tg skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\01B00000.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.f skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\01E40000.VBN Infected: Trojan.Win32.VB.tg skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\01EC0000.VBN Infected: Exploit.HTML.Mht skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\01F00000.VBN Infected: Backdoor.Win32.Agobot.gen skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\01F00001.VBN Infected: Net-Worm.Win32.Sasser.a skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\01F00002.VBN Infected: Backdoor.Win32.Agobot.tu skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\01F40000.VBN Infected: Backdoor.Win32.Agobot.lq skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\05180000.VBN Infected: Trojan-PSW.Win32.PdPinch.bs skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\05380000.VBN Infected: Trojan-Downloader.Win32.VB.wz skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\053C0000.VBN Infected: Trojan-Downloader.Win32.Qoologic.ax skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\053C0001.VBN Infected: Trojan-Downloader.Win32.Qoologic.ax skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\053C0002.VBN Infected: Trojan-Downloader.Win32.Small.cyh skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\053C0003.VBN Infected: Trojan-Downloader.Win32.Small.cyh skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\053C0004.VBN/page.htm Infected: not-a-virus:AdWare.Win32.MediaMotor.p skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\053C0004.VBN/SystemDoctor2006FreeInstall.cab/USDR6_0001_D08M0404NetInstaller.exe Infected: not-a-virus:Downloader.Win32.WinFixer.l skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\053C0004.VBN/SystemDoctor2006FreeInstall.cab Infected: not-a-virus:Downloader.Win32.WinFixer.l skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\053C0004.VBN CHM: infected - 3 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\053C0004.VBN CryptZ: infected - 3 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\053C0005.VBN Infected: Trojan-Downloader.Win32.VB.wz skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\053C0006.VBN Infected: Trojan-Downloader.Win32.Qoologic.ax skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\053C0007.VBN Infected: Trojan.Win32.VB.tg skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\05480000.VBN Infected: Trojan-Clicker.Win32.VB.is skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\05480002.VBN Infected: Trojan-Downloader.Win32.VB.nw skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\05480003.VBN Infected: Trojan-Downloader.Win32.Qoologic.ax skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\05480004.VBN/page.htm Infected: not-a-virus:AdWare.Win32.MediaMotor.p skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\05480004.VBN/SystemDoctor2006FreeInstall.cab/USDR6_0001_D08M0404NetInstaller.exe Infected: not-a-virus:Downloader.Win32.WinFixer.l skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\05480004.VBN/SystemDoctor2006FreeInstall.cab Infected: not-a-virus:Downloader.Win32.WinFixer.l skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\05480004.VBN CHM: infected - 3 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\05480004.VBN CryptZ: infected - 3 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\055C0000.VBN Infected: Trojan-Downloader.Win32.Qoologic.ax skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\05640000.VBN Infected: Trojan-PSW.Win32.Sinowal.k skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\05700000.VBN Infected: Trojan-PSW.Win32.Sinowal.az skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\05740000.VBN Infected: Trojan-Downloader.Win32.Qoologic.ax skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\05740001.VBN Infected: Trojan-Downloader.Win32.Qoologic.ax skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\05780000.VBN Infected: Trojan-Downloader.Win32.Qoologic.ax skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\05800000.VBN/page.htm Infected: not-a-virus:AdWare.Win32.MediaMotor.p skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\05800000.VBN/SystemDoctor2006FreeInstall.cab/USDR6_0001_D08M0404NetInstaller.exe Infected: not-a-virus:Downloader.Win32.WinFixer.l skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\05800000.VBN/SystemDoctor2006FreeInstall.cab Infected: not-a-virus:Downloader.Win32.WinFixer.l skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\05800000.VBN CHM: infected - 3 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\05800000.VBN CryptZ: infected - 3 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\05800001.VBN Infected: Trojan-Downloader.Win32.VB.wz skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\05800002.VBN Infected: Trojan-Downloader.Win32.Qoologic.ax skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\05800003.VBN Infected: Trojan-Downloader.Win32.Qoologic.ax skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\05880000.VBN Infected: Trojan-Clicker.Win32.VB.ij skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\05880001.VBN Infected: Trojan-Downloader.Win32.Small.cyh skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\05880002.VBN Infected: Trojan-Downloader.Win32.Qoologic.ax skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\05880003.VBN Infected: Trojan-Downloader.Win32.Qoologic.ax skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\05980000.VBN Infected: Trojan-PSW.Win32.PdPinch.bs skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\05D40000.VBN Infected: Backdoor.Win32.Agobot.gen skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\06940000.VBN Infected: Trojan.Win32.KillFiles.fz skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07080000.VBN/BlackBox.class Infected: Exploit.Java.ByteVerify skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07080000.VBN/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07080000.VBN/Dummy.class Infected: Trojan.Java.ClassLoader.Dummy.d skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07080000.VBN/Beyond.class Infected: Trojan.Java.Needy.a skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07080000.VBN ZIP: infected - 4 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07080000.VBN CryptZ: infected - 4 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07140000.VBN Infected: Trojan-Downloader.Win32.Intexp.b skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07140001.VBN Infected: Trojan-Downloader.Win32.Virtumonde.b skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07440000.VBN Infected: Trojan-Dropper.Win32.Mudrop.bq skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07440001.VBN/data0002 Infected: Trojan.Win32.VB.tg skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07440001.VBN/data0005 Infected: Trojan.Win32.VB.tg skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07440001.VBN/data0006 Infected: Trojan.Win32.VB.tg skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07440001.VBN NSIS: infected - 3 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07440001.VBN CryptZ: infected - 3 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07440002.VBN Infected: Trojan-Downloader.Win32.Small.cyh skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07480000.VBN Infected: Trojan-Downloader.Win32.Dyfuca.fb skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\074C0001.VBN Infected: Trojan-Downloader.Win32.Dyfuca.fb skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07500000.VBN Infected: Trojan-Dropper.Win32.Mudrop.bq skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07D00000.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.f skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07D40000.VBN Infected: Trojan.Win32.KillFiles.fz skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07DC0000.VBN Infected: Trojan.Win32.KillFiles.fz skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07DC0001.VBN Infected: Trojan-Downloader.Win32.Qoologic.ax skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07DC0002.VBN Infected: Trojan-Downloader.Win32.Qoologic.ax skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07DC0003.VBN Infected: Trojan-Downloader.Win32.Qoologic.ax skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07DC0004.VBN Infected: Trojan-Downloader.Win32.Qoologic.ax skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07E00000.VBN Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07E00001.VBN Infected: Trojan-Downloader.Win32.Qoologic.ax skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07E00002.VBN Infected: Trojan-Downloader.Win32.Qoologic.ax skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07E00003.VBN Infected: Trojan-Downloader.Win32.Qoologic.ax skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07E40000.VBN Infected: Trojan-Downloader.Win32.Qoologic.ax skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07E40001.VBN Infected: Trojan-Downloader.Win32.Qoologic.ax skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07E40002.VBN Infected: Trojan-Downloader.Win32.Qoologic.ax skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07E40003.VBN Infected: Trojan-Downloader.Win32.Qoologic.ax skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07E40004.VBN Infected: Trojan-Downloader.Win32.Qoologic.ax skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07E80000.VBN Infected: Trojan.Win32.KillFiles.fz skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07E80001.VBN Infected: Trojan-Spy.Win32.Agent.l skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\08640000.VBN Infected: Trojan-Downloader.Win32.Qoologic.ax skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\08640001.VBN Infected: Trojan-Downloader.Win32.Qoologic.ax skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\08680000.VBN Infected: Trojan-Downloader.Win32.Qoologic.ax skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\08800000.VBN Infected: Trojan-Downloader.Win32.Qoologic.ax skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\08800001.VBN Infected: Trojan-Downloader.Win32.Qoologic.ax skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\08840000.VBN Infected: Trojan-Downloader.Win32.Qoologic.ax skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\08880000.VBN Infected: Trojan-Downloader.Win32.Qoologic.ax skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\08880001.VBN Infected: Trojan-Downloader.Win32.Qoologic.ax skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\08880002.VBN Infected: Trojan-Downloader.Win32.Qoologic.ax skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\08880003.VBN Infected: Trojan-Downloader.Win32.Qoologic.ax skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0BE80000.VBN/data0002 Infected: Trojan.Win32.VB.tg skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0BE80000.VBN/data0005 Infected: Trojan.Win32.VB.tg skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0BE80000.VBN/data0006 Infected: Trojan.Win32.VB.tg skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0BE80000.VBN NSIS: infected - 3 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0BE80000.VBN CryptZ: infected - 3 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0BE80001.VBN/data0002 Infected: Trojan.Win32.VB.tg skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0BE80001.VBN/data0005 Infected: Trojan.Win32.VB.tg skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0BE80001.VBN/data0006 Infected: Trojan.Win32.VB.tg skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0BE80001.VBN NSIS: infected - 3 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0BE80001.VBN CryptZ: infected - 3 skipped

C:\Documents and Settings\LocalService\Cookies\INDEX.DAT Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT Object is locked skipped

C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\Puraj\.jpi_cache\jar\1.0\ar.jar-24cf9bc8-33edae6e.zip/B.class Infected: Trojan.Java.ClassLoader.Dummy.e skipped

C:\Documents and Settings\Puraj\.jpi_cache\jar\1.0\ar.jar-24cf9bc8-33edae6e.zip/V.class Infected: Trojan.Java.ClassLoader.a skipped

C:\Documents and Settings\Puraj\.jpi_cache\jar\1.0\ar.jar-24cf9bc8-33edae6e.zip/Dummy.class Infected: Trojan.Java.ClassLoader.Dummy.c skipped

C:\Documents and Settings\Puraj\.jpi_cache\jar\1.0\ar.jar-24cf9bc8-33edae6e.zip/A.class Infected: Trojan-Dropper.Java.Xideo.e skipped

C:\Documents and Settings\Puraj\.jpi_cache\jar\1.0\ar.jar-24cf9bc8-33edae6e.zip ZIP: infected - 4 skipped

C:\Documents and Settings\Puraj\.jpi_cache\jar\1.0\archive.jar-6b861be4-3e7f1dab.zip/A.class Infected: Exploit.Java.ByteVerify skipped

C:\Documents and Settings\Puraj\.jpi_cache\jar\1.0\archive.jar-6b861be4-3e7f1dab.zip ZIP: infected - 1 skipped

C:\Documents and Settings\Puraj\.jpi_cache\jar\1.0\arr3.jar-53b20017-7e0db73a.zip/Counter.class Infected: Trojan.Java.ClassLoader.i skipped

C:\Documents and Settings\Puraj\.jpi_cache\jar\1.0\arr3.jar-53b20017-7e0db73a.zip/VerifierBug.class Infected: Trojan.Java.ClassLoader.k skipped

C:\Documents and Settings\Puraj\.jpi_cache\jar\1.0\arr3.jar-53b20017-7e0db73a.zip/Beyond.class Infected: Trojan.Java.ClassLoader.k skipped

C:\Documents and Settings\Puraj\.jpi_cache\jar\1.0\arr3.jar-53b20017-7e0db73a.zip ZIP: infected - 3 skipped

C:\Documents and Settings\Puraj\Cookies\INDEX.DAT Object is locked skipped

C:\Documents and Settings\Puraj\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\Puraj\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\Puraj\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped

C:\Documents and Settings\Puraj\Local Settings\Temp\3fe7.$$$ Infected: Trojan-PSW.Win32.Sinowal.az skipped

C:\Documents and Settings\Puraj\Local Settings\Temporary Internet Files\Content.IE5\6J5IPZWG\popup[2].php Infected: Trojan-Clicker.HTML.Agent.a skipped

C:\Documents and Settings\Puraj\Local Settings\Temporary Internet Files\Content.IE5\GVP7YAZ1\gc2[1] Infected: Exploit.JS.ADODB.Stream.v skipped

C:\Documents and Settings\Puraj\Local Settings\Temporary Internet Files\Content.IE5\GVP7YAZ1\vw[1].dat Infected: Trojan-PSW.Win32.Sinowal.az skipped

C:\Documents and Settings\Puraj\Local Settings\Temporary Internet Files\Content.IE5\H4Y66UCR\popup[1].php Infected: Trojan-Clicker.HTML.Agent.a skipped

C:\Documents and Settings\Puraj\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Puraj\Local Settings\Temporary Internet Files\Content.IE5\T047H5ST\popup[2].php Infected: Trojan-Clicker.HTML.Agent.a skipped

C:\Documents and Settings\Puraj\Local Settings\Temporary Internet Files\Content.IE5\T047H5ST\popup[3].php Infected: Trojan-Clicker.HTML.Agent.a skipped

C:\Documents and Settings\Puraj\Local Settings\Temporary Internet Files\Content.IE5\T047H5ST\start[1].exe Infected: Trojan-Downloader.Win32.Small.dul skipped

C:\Documents and Settings\Puraj\Local Settings\Temporary Internet Files\Content.IE5\YPR8LSBI\popup[2].php Infected: Trojan-Clicker.HTML.Agent.a skipped

C:\Documents and Settings\Puraj\Local Settings\Temporary Internet Files\Content.IE5\YPR8LSBI\sp352452548[1].php Suspicious: Trojan-Downloader.JS.gen skipped

C:\Documents and Settings\Puraj\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\Puraj\ntuser.dat.LOG Object is locked skipped

C:\Program Files\Apoint\Apoint.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe Infected: Trojan-PSW.Win32.Sinowal.ay skipped

C:\Program Files\iTunes\iTunesHelper.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\Program Files\QuickTime\qttask.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\vptray.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP636\A0353790.exe/stream Infected: Trojan-Downloader.Win32.IstBar.no skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP636\A0353790.exe NSIS: infected - 1 skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP636\A0353790.exe UPX: infected - 1 skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP645\A0356979.ocx Infected: not-a-virus:AdWare.Win32.MediaMotor.m skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP645\A0356980.ocx Infected: not-a-virus:AdWare.Win32.MediaMotor.m skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0357021.exe Infected: Trojan-Downloader.Win32.Qoologic.at skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0357022.ocx Infected: not-a-virus:AdWare.Win32.MediaMotor.m skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0357024.exe Infected: not-a-virus:AdWare.Win32.MediaTickets.u skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0357113.exe/InpB/SskBho.dll Infected: not-a-virus:AdWare.Win32.SurfSide.ay skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0357113.exe/InpB/SskCore.dll Infected: not-a-virus:AdWare.Win32.SurfSide.ay skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0357113.exe/InpB/Ssk.exe Infected: not-a-virus:AdWare.Win32.SurfSide.av skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0357113.exe/InpB/Ssk3RepairInstall.exe Infected: not-a-virus:AdWare.Win32.SurfSide.az skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0357113.exe/InpB Infected: not-a-virus:AdWare.Win32.SurfSide.az skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0357113.exe CAB: infected - 5 skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0357115.DLL Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0357116.dll Infected: not-a-virus:AdWare.Win32.SurfSide.ap skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0357117.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0357147.dll Infected: not-a-virus:AdWare.Win32.PurityScan.ak skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0357148.exe Infected: not-a-virus:AdWare.Win32.PurityScan.eu skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0357171.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0358171.dll Infected: Trojan-Downloader.Win32.Agent.agw skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0358172.exe Infected: Trojan-Downloader.Win32.Qoologic.c skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0358197.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Softomate.r skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0358197.exe/stream Infected: not-a-virus:AdWare.Win32.Softomate.r skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0358197.exe NSIS: infected - 2 skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0358202.exe Infected: Trojan-Downloader.Win32.VB.alg skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0358204.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0358216.exe Infected: Trojan-Downloader.Win32.Adload.fg skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0358217.exe Infected: Trojan-Downloader.Win32.VB.amb skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0358221.exe Infected: Trojan-Downloader.Win32.Dyfuca.ey skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0358222.exe Infected: Trojan-Downloader.Win32.Dyfuca.ey skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0358223.exe Infected: not-a-virus:AdWare.Win32.MediaMotor.o skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0358224.exe Infected: Trojan-Downloader.Win32.Qoologic.c skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0358227.exe Infected: not-a-virus:AdWare.Win32.SaveNow.bj skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.MediaMotor.p skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\snapshot\MFEX-2.DAT Infected: not-a-virus:AdWare.Win32.MediaMotor.p skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP647\A0358247.dll Infected: not-a-virus:AdWare.Win32.PurityScan.ak skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP649\A0358283.dll Infected: not-a-virus:AdWare.Win32.SurfSide.ap skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP649\A0358293.exe/stream/data0003 Infected: not-a-virus:AdWare.Win32.Agent.y skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP649\A0358293.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Softomate.q skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP649\A0358293.exe/stream Infected: not-a-virus:AdWare.Win32.Softomate.q skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP649\A0358293.exe NSIS: infected - 3 skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP649\A0358294.exe Infected: not-a-virus:AdWare.Win32.SaveNow.bj skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP649\A0358295.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP649\A0358301.dll Infected: not-a-virus:AdWare.Win32.Mirar.a skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP649\A0358321.exe Infected: not-a-virus:AdWare.Win32.Agent.ag skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP649\A0358327.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.s skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP649\A0358328.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP649\A0358336.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP649\A0358340.exe/msnmsgrs.exe Infected: Backdoor.Win32.Rbot.azl skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP649\A0358340.exe/wuauclts.exe Infected: P2P-Worm.Win32.SpyBot.gw skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP649\A0358340.exe CreateInstall: infected - 2 skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP649\A0358401.exe Infected: not-a-virus:AdWare.Win32.SaveNow.bj skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP649\A0358406.dll Infected: not-a-virus:AdWare.Win32.Softomate.r skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP651\A0360424.exe Infected: not-a-virus:AdWare.Win32.SaveNow.bj skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP651\A0360457.dll Infected: not-a-virus:AdWare.Win32.TrafficSol.c skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP651\A0360458.dll Infected: not-a-virus:AdWare.Win32.TrafficSol.c skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP654\A0361482.exe Infected: not-a-virus:AdWare.Win32.Agent.y skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP654\A0361618.dll Infected: not-a-virus:AdWare.Win32.PurityScan.ak skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP654\A0361622.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP654\A0361623.exe Infected: Trojan-Downloader.Win32.PurityScan.cx skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP654\A0361624.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP654\A0361625.exe Infected: not-a-virus:AdWare.Win32.PurityScan.eu skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP655\A0361667.rbf Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP655\A0361750.exe Infected: Trojan-Downloader.Win32.Agent.awf skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP656\A0361788.dll Infected: Packed.Win32.Klone.k skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP656\change.log Object is locked skipped

C:\system.exe Infected: Trojan-Downloader.Win32.Small.dul skipped

C:\WINDOWS\bookmarks.exe Infected: Trojan.Win32.StartPage.hw skipped

C:\WINDOWS\Debug\oakley.log Object is locked skipped

C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

C:\WINDOWS\LastGood\amm06.ocx Infected: not-a-virus:AdWare.Win32.MediaMotor.m skipped

C:\WINDOWS\remtm3.exe Infected: not-a-virus:AdWare.Win32.BetterInternet skipped

C:\WINDOWS\SchedLgU.Txt Object is locked skipped

C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped

C:\WINDOWS\Sti_Trace.log Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\AppEvent.Evt Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SAM Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SecEvent.Evt Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SECURITY Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SysEvent.Evt Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG Object is locked skipped

C:\WINDOWS\SYSTEM32\H323LOG.TXT Object is locked skipped

C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.BTR Object is locked skipped

C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.DATA Object is locked skipped

C:\WINDOWS\WIADEBUG.LOG Object is locked skipped

C:\WINDOWS\WIASERVC.LOG Object is locked skipped

C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.


HJT LOG


Logfile of HijackThis v1.99.1
Scan saved at 9:16:13 PM, on 9/26/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Puraj\IOGuyou.exe
C:\WINDOWS\System32\notepad.exe
C:\unzipped\hijackthis[1]\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com
F2 - REG:system.ini: Shell=explorer.exe "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp3\winampa.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [TCASUTIEXE] TCAUDIAG -off
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 7.0 Tray Icon.lnk = C:\Program Files\America Online 7.0\aoltray.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar3.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar3.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar3.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar3.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar3.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar3.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english...an_unicode.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O21 - SSODL: System - {45673737-D1D1-4ECA-8760-AD3EFE7B0541} - dgflib.dll (file missing)
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe (file missing)
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

THANKS!
wyrdrune is offline