Thread: Malware Galore
View Single Post
Old 10-18-2006, 03:57 PM   #24 (permalink)
wyrdrune
Registered User
 
Join Date: Sep 2006
Posts: 19
OS: XP


COMBOFIX LOG

Puraj - 06-10-18 14:50:12.28 Service Pack 1
ComboFix 06.09.25 - Running from: "C:\Documents and Settings\Puraj\Desktop"

((((((((((((((((((((((((((((((( Files Created from 2006-09-18 to 2006-10-18 ))))))))))))))))))))))))))))))))))


2006-10-12 07:14 78,848 --a------ C:\WINDOWS\SYSTEM32\nsv3609.dll
2006-10-03 14:08 761,856 --a------ C:\WINDOWS\SYSTEM32\xvidcore.dll
2006-10-03 14:07 180,224 --a------ C:\WINDOWS\SYSTEM32\xvidvfw.dll


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-10-18 09:48 -------- d-------- C:\Program Files\CleanUp!
2006-10-17 13:41 -------- d-------- C:\Program Files\PokerStars
2006-10-11 00:30 -------- d-------- C:\Program Files\Grisoft
2006-10-06 08:05 -------- d-------- C:\Program Files\diabloII
2006-10-05 23:18 -------- d-------- C:\Program Files\Common Files
2006-10-05 19:09 -------- d-------- C:\Program Files\Microsoft Works
2006-10-05 19:09 -------- d-------- C:\Program Files\Microsoft Picture It! 2002
2006-10-05 19:09 -------- d-------- C:\Program Files\Messenger
2006-10-05 19:09 -------- d-------- C:\Program Files\Apoint
2006-10-03 14:11 -------- d-------- C:\Program Files\WinRAR
2006-10-03 14:08 -------- d-------- C:\Program Files\XviD
2006-09-28 16:42 -------- d-------- C:\Program Files\QuickTime
2006-09-28 16:41 -------- d-------- C:\Program Files\iTunes
2006-09-27 11:31 -------- d-------- C:\Program Files\Servant Salamander 2.0
2006-09-26 19:41 -------- d-------- C:\Program Files\Windows NT
2006-09-26 19:40 -------- d-------- C:\Program Files\ComPlus Applications
2006-09-25 17:48 -------- d-------- C:\Program Files\Dell
2006-09-25 15:06 -------- d-------- C:\Program Files\Microsoft AntiSpyware
2006-09-21 19:27 -------- d-------- C:\Program Files\SpywareBlaster
2006-09-20 14:00 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-09-06 13:19 -------- d--h----- C:\Program Files\WindowsUpdate
2006-09-06 12:54 -------- d-------- C:\Program Files\Lavasoft
2006-09-06 12:54 -------- d-------- C:\Documents and Settings\Puraj\Application Data\Lavasoft
2006-09-06 11:53 -------- d-------- C:\Program Files\PCFriendly
2006-09-06 00:30 -------- d-------- C:\Program Files\Common Files\InstallShield
2006-09-05 09:03 3968 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Works Update Detection"="C:\\Program Files\\Microsoft Works\\WkDetect.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinampAgent"="\"C:\\Program Files\\Winamp3\\winampa.exe\""
"vptray"="C:\\PROGRA~1\\SYMANT~1\\SYMANT~1\\vptray.exe"
"TCASUTIEXE"="TCAUDIAG -off"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"
"NAV Agent"="C:\\PROGRA~1\\NORTON~1\\navapw32.exe"
"Apoint"="C:\\Program Files\\Apoint\\Apoint.exe"
"iTunesHelper"="C:\\Program Files\\iTunes\\iTunesHelper.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000005

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,40,01,00,00,00,00,00,00,00,05,00,00,b0,04,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,c0
"OriginalStateInfo"=hex:18,00,00,00,40,01,00,00,00,00,00,00,00,05,00,00,b0,04,\
00,00,04,00,00,c0
"RestoredStateInfo"=hex:18,00,00,00,40,01,00,00,00,00,00,00,00,05,00,00,b0,04,\
00,00,01,00,00,00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"


HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders
securityproviders REG_SZ msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll


Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Symantec NetDetect.job

Completion time: Wed 10/18/2006 14:51:09.14
ComboFix.txt
ComboFix2.txt
ComboFix3.txt


HJT LOG

Logfile of HijackThis v1.99.1
Scan saved at 2:51:53 PM, on 10/18/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\notepad.exe
C:\unzipped\hijackthis[1]\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp3\winampa.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [TCASUTIEXE] TCAUDIAG -off
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 7.0 Tray Icon.lnk = C:\Program Files\America Online 7.0\aoltray.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar3.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar3.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar3.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar3.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar3.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar3.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english...an_unicode.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols3/fscax.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe (file missing)
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe


AVG SCAN

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 12:36:23 PM 10/18/2006

+ Scan result:



C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP649\A0358321.exe -> Adware.Agent : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP654\A0361482.exe -> Adware.Agent : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP662\A0365911.exe/AutoSearch.dll -> Adware.AutoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP673\A0368123.dll -> Adware.AutoSearch : Cleaned with backup (quarantined).
C:\unzipped\hijackthis[1]\backups\backup-20061018-095736-629.dll -> Adware.AutoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP656\A0361827.exe -> Adware.BetterInternet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP662\A0365953.dll -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP662\A0365954.exe -> Adware.CommAd : Cleaned with backup (quarantined).
HKU\S-1-5-21-2914288250-963918322-4271176276-1006\Software\Classes\AutoSearch.AutoSearchObj -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKU\S-1-5-21-2914288250-963918322-4271176276-1006\Software\Classes\AutoSearch.AutoSearchObj.1 -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKU\S-1-5-21-2914288250-963918322-4271176276-1006\Software\Classes\AutoSearch.AutoSearchObj\CLSID -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
HKU\S-1-5-21-2914288250-963918322-4271176276-1006\Software\Classes\AutoSearch.AutoSearchObj\CurVer -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP649\A0358276.dll -> Adware.EZula : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP651\A0360456.dll -> Adware.EZula : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP654\A0361617.dll -> Adware.EZula : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP667\A0366067.dll -> Adware.EZula : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP667\A0366068.dll -> Adware.EZula : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP668\A0366114.dll -> Adware.EZula : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP669\A0367052.dll -> Adware.EZula : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP669\A0367053.dll -> Adware.EZula : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP669\A0367054.dll -> Adware.EZula : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP673\A0368133.dll -> Adware.EZula : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Avenue Media\Internet Optimizer -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Avenue Media\Internet Optimizer\Browser Helper -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Avenue Media\Internet Optimizer\Browser Helper\cf1 -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Kapabout -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\AMeOpt -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Policies\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKU\S-1-5-21-2914288250-963918322-4271176276-1006\Software\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKU\S-1-5-21-2914288250-963918322-4271176276-1006\Software\Microsoft\Windows\CurrentVersion\Policies\AMeOpt -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKU\S-1-5-21-2914288250-963918322-4271176276-1006\Software\Policies\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0357115.DLL -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0357117.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0357171.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP654\A0361622.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP645\A0356979.ocx -> Adware.MediaMotor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP645\A0356980.ocx -> Adware.MediaMotor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0357022.ocx -> Adware.MediaMotor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0358223.exe -> Adware.MediaMotor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\snapshot\MFEX-1.DAT -> Adware.MediaMotor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\snapshot\MFEX-2.DAT -> Adware.MediaMotor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP662\A0365909.exe -> Adware.MediaMotor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP673\A0368135.ocx -> Adware.MediaMotor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP673\A0368136.ocx -> Adware.MediaMotor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0357024.exe -> Adware.MediaTickets : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP649\A0358301.dll -> Adware.Mirar : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP662\A0365996.dll -> Adware.Mirar : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP673\A0368131.dll -> Adware.Mirar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\DyFuCA_BH.BHObj -> Adware.MoneyTree : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\DyFuCA_BH.BHObj.1 -> Adware.MoneyTree : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\DyFuCA_BH.BHObj\CLSID -> Adware.MoneyTree : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\DyFuCA_BH.BHObj\CurVer -> Adware.MoneyTree : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DyFuCA -> Adware.MoneyTree : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0357147.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0357148.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP647\A0358247.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP654\A0361618.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP654\A0361625.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP667\A0366049.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0358227.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP649\A0358294.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP649\A0358401.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP651\A0360424.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP662\A0366013.dll -> Adware.Searchcolours : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP649\A0358406.dll -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0357116.dll -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP649\A0358283.dll -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP662\A0365912.exe -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP662\A0365928.dll -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0357086.exe -> Adware.Systemdoctor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP651\A0360457.dll -> Adware.TrafficSol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP651\A0360458.dll -> Adware.TrafficSol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP662\A0365908.dll -> Adware.TrafficSol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP667\A0366053.dll -> Adware.TrafficSol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP667\A0366050.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\ins -> Adware.WebRebates : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0358204.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP649\A0358295.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP649\A0358327.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP649\A0358328.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP649\A0358336.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0358216.0XE -> Downloader.Adload.fg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP662\A0365916.exe -> Downloader.Adload.gf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0358171.0LL -> Downloader.Agent.agw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP654\A0361624.0XE -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP655\A0361667.rbf -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP655\A0361750.0XE -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP656\A0361837.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP656\A0361838.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP656\A0361839.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP656\A0361840.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP662\A0365927.dll -> Downloader.Bomka.r : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP667\A0366106.dll -> Downloader.Dyfuca : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0358221.0XE -> Downloader.Dyfuca.ey : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0358222.0XE -> Downloader.Dyfuca.ey : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP662\A0365910.exe -> Downloader.Dyfuca.ey : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP662\A0366018.exe -> Downloader.Dyfuca.ey : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP649\A0358325.exe -> Downloader.PurityScan.bl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP654\A0361623.0XE -> Downloader.PurityScan.cx : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP662\A0365994.exe -> Downloader.PurityScan.cx : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP656\A0361790.exe -> Downloader.PurityScan.dc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP662\A0366012.exe -> Downloader.PurityScan.dc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0357021.0XE -> Downloader.Qoologic.at : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP662\A0365921.exe -> Downloader.Small.buy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP656\A0361815.0XE -> Downloader.Small.dul : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0358202.0XE -> Downloader.VB.alg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0358217.0XE -> Downloader.VB.amb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP656\A0361828.0XE -> Hijacker.StartPage.hw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP662\A0365952.exe -> Not-A-Virus.Monitor.Win32.NetMon.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Puraj\Cookies\puraj@cnn.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Puraj\Cookies\puraj@advertising[1].txt -> TrackingCookie.Advertising : Cleaned.
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP667\A0366051.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0358172.0XE -> Trojan.Qoologic : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0358224.0XE -> Trojan.Qoologic : Cleaned with backup (quarantined).


::Report end

KASPERSKY LOG

KASPERSKY ONLINE SCANNER REPORT
Wednesday, October 18, 2006 2:49:29 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 1 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 18/10/2006
Kaspersky Anti-Virus database records: 232843


Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true

Scan Target My Computer
A:\
C:\
D:\

Scan Statistics
Total number of scanned objects 59341
Number of viruses found 22
Number of infected objects 98 / 0
Number of suspicious objects 0
Duration of the scan process 01:13:44

Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\00940000.VBN/page.htm Infected: not-a-virus:AdWare.Win32.MediaMotor.p skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\00940000.VBN/SystemDoctor2006FreeInstall.cab/USDR6_0001_D08M0404NetInstaller.exe Infected: not-a-virus:Downloader.Win32.WinFixer.l skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\00940000.VBN/SystemDoctor2006FreeInstall.cab Infected: not-a-virus:Downloader.Win32.WinFixer.l skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\00940000.VBN CHM: infected - 3 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\00940000.VBN CryptZ: infected - 3 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\00940001.VBN Infected: Trojan-Downloader.Win32.VB.wz skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\00980000.VBN/page.htm Infected: not-a-virus:AdWare.Win32.MediaMotor.p skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\00980000.VBN/SystemDoctor2006FreeInstall.cab/USDR6_0001_D08M0404NetInstaller.exe Infected: not-a-virus:Downloader.Win32.WinFixer.l skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\00980000.VBN/SystemDoctor2006FreeInstall.cab Infected: not-a-virus:Downloader.Win32.WinFixer.l skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\00980000.VBN CHM: infected - 3 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\00980000.VBN CryptZ: infected - 3 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\00980001.VBN Infected: Trojan-Downloader.Win32.VB.wz skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\00980002.VBN Infected: Trojan-Downloader.Win32.Small.cyh skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\009C0000.VBN Infected: Trojan-Downloader.Win32.Small.cyh skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\009C0002.VBN/page.htm Infected: not-a-virus:AdWare.Win32.MediaMotor.p skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\009C0002.VBN/SystemDoctor2006FreeInstall.cab/USDR6_0001_D08M0404NetInstaller.exe Infected: not-a-virus:Downloader.Win32.WinFixer.l skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\009C0002.VBN/SystemDoctor2006FreeInstall.cab Infected: not-a-virus:Downloader.Win32.WinFixer.l skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\009C0002.VBN CHM: infected - 3 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\009C0002.VBN CryptZ: infected - 3 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\009C0003.VBN Infected: Trojan-Downloader.Win32.VB.wz skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\009C0004.VBN/data0002 Infected: Trojan.Win32.VB.tg skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\009C0004.VBN/data0005 Infected: Trojan.Win32.VB.tg skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\009C0004.VBN/data0006 Infected: Trojan.Win32.VB.tg skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\009C0004.VBN NSIS: infected - 3 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\009C0004.VBN CryptZ: infected - 3 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0BE80000.VBN/data0002 Infected: Trojan.Win32.VB.tg skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0BE80000.VBN/data0005 Infected: Trojan.Win32.VB.tg skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0BE80000.VBN/data0006 Infected: Trojan.Win32.VB.tg skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0BE80000.VBN NSIS: infected - 3 skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\0BE80000.VBN CryptZ: infected - 3 skipped

C:\Documents and Settings\LocalService\Cookies\INDEX.DAT Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT Object is locked skipped

C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\Puraj\Cookies\INDEX.DAT Object is locked skipped

C:\Documents and Settings\Puraj\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\Puraj\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\Puraj\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped

C:\Documents and Settings\Puraj\Local Settings\History\History.IE5\MSHist012006101820061019\index.dat Object is locked skipped

C:\Documents and Settings\Puraj\Local Settings\Temp\Perflib_Perfdata_570.dat Object is locked skipped

C:\Documents and Settings\Puraj\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Puraj\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\Puraj\ntuser.dat.LOG Object is locked skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP636\A0353790.exe/stream Infected: Trojan-Downloader.Win32.IstBar.no skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP636\A0353790.exe NSIS: infected - 1 skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP636\A0353790.exe UPX: infected - 1 skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0357113.exe/InpB/SskBho.dll Infected: not-a-virus:AdWare.Win32.SurfSide.ay skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0357113.exe/InpB/SskCore.dll Infected: not-a-virus:AdWare.Win32.SurfSide.ay skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0357113.exe/InpB/Ssk.exe Infected: not-a-virus:AdWare.Win32.SurfSide.av skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0357113.exe/InpB/Ssk3RepairInstall.exe Infected: not-a-virus:AdWare.Win32.SurfSide.az skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0357113.exe/InpB Infected: not-a-virus:AdWare.Win32.SurfSide.az skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0357113.exe CAB: infected - 5 skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0358197.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Softomate.r skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0358197.exe/stream Infected: not-a-virus:AdWare.Win32.Softomate.r skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0358197.exe NSIS: infected - 2 skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0358219.exe/stream/data0002 Infected: not-a-virus:AdWare.Win32.EZula.cc skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0358219.exe/stream Infected: not-a-virus:AdWare.Win32.EZula.cc skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0358219.exe NSIS: infected - 2 skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0358225.exe/stream/data0002 Infected: not-a-virus:AdWare.Win32.EZula.cc skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0358225.exe/stream Infected: not-a-virus:AdWare.Win32.EZula.cc skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP646\A0358225.exe NSIS: infected - 2 skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP649\A0358293.exe/stream/data0003 Infected: not-a-virus:AdWare.Win32.Agent.y skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP649\A0358293.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Softomate.q skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP649\A0358293.exe/stream/data0006 Infected: not-a-virus:AdWare.Win32.Softomate.u skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP649\A0358293.exe/stream Infected: not-a-virus:AdWare.Win32.Softomate.u skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP649\A0358293.exe NSIS: infected - 4 skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP649\A0358296.exe/stream/data0002 Infected: not-a-virus:AdWare.Win32.EZula.cc skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP649\A0358296.exe/stream Infected: not-a-virus:AdWare.Win32.EZula.cc skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP649\A0358296.exe NSIS: infected - 2 skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP649\A0358340.exe/msnmsgrs.exe Infected: Backdoor.Win32.Rbot.azl skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP649\A0358340.exe/wuauclts.exe Infected: P2P-Worm.Win32.SpyBot.gw skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP649\A0358340.exe CreateInstall: infected - 2 skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP655\A0361769.exe Infected: Backdoor.Win32.Delf.avh skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP655\A0361770.exe Infected: Backdoor.Win32.Delf.avh skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP655\A0361773.exe Infected: Backdoor.Win32.Delf.avh skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP656\A0361788.dll Infected: Packed.Win32.Klone.k skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP656\A0361812.exe Infected: Backdoor.Win32.Delf.avh skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP656\A0361816.exe Infected: Backdoor.Win32.Delf.avh skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP656\A0361829.0XE Infected: Trojan-PSW.Win32.Sinowal.ay skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP657\A0362836.exe Infected: Backdoor.Win32.Delf.avh skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP657\A0362837.exe Infected: Backdoor.Win32.Delf.avh skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP657\A0362838.exe Infected: Backdoor.Win32.Delf.avh skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP662\A0365913.exe/data.rar/whCC-GIANT2.exe/data.rar/webhdll.dll Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP662\A0365913.exe/data.rar/whCC-GIANT2.exe/data.rar Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP662\A0365913.exe/data.rar/whCC-GIANT2.exe Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP662\A0365913.exe/data.rar Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP662\A0365913.exe RarSFX: infected - 4 skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP662\A0365914.exe/data.rar/whCC-GIANT3.exe/data.rar/webhdll.dll Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP662\A0365914.exe/data.rar/whCC-GIANT3.exe/data.rar Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP662\A0365914.exe/data.rar/whCC-GIANT3.exe Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP662\A0365914.exe/data.rar Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP662\A0365914.exe RarSFX: infected - 4 skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP662\A0365915.exe/data0003/stream/data0001 Infected: not-a-virus:AdWare.Win32.TrafficSol.c skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP662\A0365915.exe/data0003/stream Infected: not-a-virus:AdWare.Win32.TrafficSol.c skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP662\A0365915.exe/data0003 Infected: not-a-virus:AdWare.Win32.TrafficSol.c skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP662\A0365915.exe NSIS: infected - 3 skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP662\A0365919.exe/InpB/DxcBho.dll Infected: not-a-virus:AdWare.Win32.SurfSide.ay skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP662\A0365919.exe/InpB/DxcCore.dll Infected: not-a-virus:AdWare.Win32.SurfSide.ay skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP662\A0365919.exe/InpB/Dxc.exe Infected: not-a-virus:AdWare.Win32.SurfSide.bb skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP662\A0365919.exe/InpB/DxcRepairInstall.exe Infected: not-a-virus:AdWare.Win32.SurfSide.bb skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP662\A0365919.exe/InpB Infected: not-a-virus:AdWare.Win32.SurfSide.bb skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP662\A0365919.exe CAB: infected - 5 skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP662\A0365924.exe/stream/data0001 Infected: not-a-virus:AdWare.Win32.TrafficSol.c skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP662\A0365924.exe/stream Infected: not-a-virus:AdWare.Win32.TrafficSol.c skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP662\A0365924.exe NSIS: infected - 2 skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP662\A0365991.exe/data.rar/webhdll.dll Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP662\A0365991.exe/data.rar Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP662\A0365991.exe RarSFX: infected - 2 skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP662\A0365993.exe/data.rar/webhdll.dll Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP662\A0365993.exe/data.rar Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP662\A0365993.exe RarSFX: infected - 2 skipped

C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP673\change.log Object is locked skipped

C:\WINDOWS\Debug\oakley.log Object is locked skipped

C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

C:\WINDOWS\SchedLgU.Txt Object is locked skipped

C:\WINDOWS\SoftwareDistribution\EventCache\{195FA17B-285E-4E0F-947E-25A52666DED8}.bin Object is locked skipped

C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped

C:\WINDOWS\Sti_Trace.log Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\AppEvent.Evt Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SAM Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SecEvent.Evt Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SECURITY Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SysEvent.Evt Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG Object is locked skipped

C:\WINDOWS\SYSTEM32\H323LOG.TXT Object is locked skipped

C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.BTR Object is locked skipped

C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.DATA Object is locked skipped

C:\WINDOWS\WIADEBUG.LOG Object is locked skipped

C:\WINDOWS\WIASERVC.LOG Object is locked skipped

C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.
wyrdrune is offline