Thanks Dan, here's the 4 logs...and is it ok if, during the MalewareBytes' run that...after it finished by brother went ahead and cleared all the infected files without my permission then scanned again, then i couldn't find the original log...i hope this isn't too much of a bother...
Here's the ComboFix:ComboFix 08-03-05.3 - Adalcinda 2008-03-06 10:47:04.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1541 [GMT -6:00]
Running from: C:\Documents and Settings\Adalcinda\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Adalcinda\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!FILE ::
C:\DOCUME~1\ADALCI~1\LOCALS~1\Temp\efipsk.sys
C:\Program Files\readme.txt
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\readme.txt
C:\Program Files\Save
C:\Program Files\Save\ffext.mod
C:\Program Files\Save\save.db
C:\Program Files\Save\save.htm
C:\Program Files\Save\store.db
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_EFIPSK
-------\efipsk
((((((((((((((((((((((((( Files Created from 2008-02-06 to 2008-03-06 )))))))))))))))))))))))))))))))
.
2008-03-06 10:44 . 2004-08-04 06:00 388,608 --a------ C:\CF20222.exe
2008-02-28 19:58 . 2003-09-22 23:42 303,104 --a------ C:\WINDOWS\system32\LEXBCES.EXE
2008-02-28 19:58 . 2003-09-22 23:55 286,720 --a------ C:\WINDOWS\system32\lxbfcomm.dll
2008-02-28 19:58 . 2003-09-22 23:36 201,216 --a------ C:\WINDOWS\system32\LEXP2P32.DLL
2008-02-28 19:58 . 2003-09-22 23:45 196,096 --a------ C:\WINDOWS\system32\LEX2KUSB.DLL
2008-02-28 19:58 . 2003-09-22 23:37 192,512 --a------ C:\WINDOWS\system32\lexlmpm.dll
2008-02-28 19:58 . 2008-01-09 10:27 174,592 --a------ C:\WINDOWS\system32\LEXPPS.EXE
2008-02-28 19:58 . 2003-09-22 23:39 147,456 --a------ C:\WINDOWS\system32\LEXBCE.DLL
2008-02-28 19:58 . 2003-09-22 23:36 73,728 --a------ C:\WINDOWS\system32\lxbfpwr.dll
2008-02-28 19:58 . 2002-11-13 13:40 40,960 --a------ C:\WINDOWS\system32\lxbfvs.dll
2008-02-28 19:57 . 2008-03-06 10:46 <DIR> d-------- C:\Program Files\Lexmark X6100 Series
2008-02-20 23:34 . 2008-02-20 23:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\nView_Profiles
2008-02-20 22:35 . 2008-02-20 22:35 0 --a------ C:\config.ini
2008-02-16 22:38 . 2008-03-06 10:52 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-02-16 22:38 . 2008-02-26 10:13 1,409 --a------ C:\WINDOWS\QTFont.for
2008-02-14 18:48 . 2008-02-14 18:48 <DIR> d-------- C:\Program Files\GlobalStar Software
2008-02-07 17:59 . 2008-02-07 17:59 <DIR> d-------- C:\PROGRAM1
2008-02-07 16:48 . 2008-02-07 18:10 <DIR> d-------- C:\DUKE3D
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-06 16:47 --------- d--h--r C:\Program Files\rnamfler
2008-03-06 16:47 --------- d-----w C:\Program Files\QuickTime
2008-03-06 16:46 --------- d-----w C:\Program Files\iTunes
2008-03-06 16:46 --------- d-----w C:\Program Files\AIM6
2008-03-06 16:28 --------- d-----w C:\Program Files\Viewpoint
2008-03-06 16:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-03-06 00:44 --------- d-----w C:\Program Files\Warcraft III
2008-03-05 13:43 --------- d-----w C:\Program Files\McAfee
2008-03-02 05:48 --------- d-----w C:\Documents and Settings\Adalcinda\Application Data\SiteAdvisor
2008-02-25 20:10 --------- d-----w C:\Program Files\Real
2008-02-25 20:10 --------- d-----w C:\Program Files\Common Files\Real
2008-02-23 19:01 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-19 22:15 --------- d-----w C:\Program Files\Call of Duty Game of the Year Edition
2008-02-16 15:43 --------- d-----w C:\Program Files\Legacy Interactive
2008-02-15 03:18 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-14 22:27 --------- d-----w C:\Program Files\IMVU
2008-02-14 22:27 --------- d-----w C:\Documents and Settings\Adalcinda\Application Data\IMVU
2008-02-11 06:14 --------- d-----w C:\Program Files\Common Files\Adobe
2008-01-31 01:41 --------- d-----w C:\Program Files\DivX
2008-01-25 01:31 --------- d-----w C:\Program Files\There
2008-01-12 01:08 --------- d-----w C:\Program Files\Google
2008-01-11 01:08 --------- d-----w C:\Documents and Settings\Adalcinda\Application Data\Skype
2008-01-07 19:40 --------- d-----w C:\Program Files\iPod
2008-01-07 19:26 --------- d-----w C:\Program Files\Apple Software Update
2008-01-07 19:23 --------- d-----w C:\Program Files\Common Files\Apple
2008-01-07 19:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2007-11-24 05:00 9 ----a-w C:\Program Files\BF1942.pid
2007-11-01 15:55 20,944 ----a-w C:\Documents and Settings\Adalcinda\Application Data\GDIPFONTCACHEV1.DAT
2006-12-05 23:42 774,144 ----a-w C:\Program Files\RngInterstitial.dll
2004-10-19 19:07 3,399,680 ----a-w C:\Program Files\BF1942_w32ded.exe
2004-10-19 19:04 5,648,384 ----a-w C:\Program Files\BF1942.exe
2004-01-22 16:36 368,640 ----a-w C:\Program Files\DedicatedServer.exe
2003-11-25 18:47 16,674 ----a-w C:\Program Files\lexiconDS.dat
2003-09-26 18:14 6,144 ----a-w C:\Program Files\BlackScreen.exe
2003-09-01 16:02 466,944 ----a-w C:\Program Files\bfcprt.dll
2002-11-13 10:51 201,728 ----a-w C:\Program Files\bf1942changer.exe
2002-08-14 22:54 358,963 ----a-w C:\Program Files\binkw32.dll
2002-03-28 04:21 128 ----a-w C:\Program Files\bfdist.vlu
2002-02-18 19:26 224,768 ----a-w C:\Program Files\fpupdate.exe
2002-01-05 18:48 974,848 ----a-w C:\Program Files\mfc70.dll
2002-01-05 17:37 344,064 ----a-w C:\Program Files\msvcr70.dll
.
((((((((((((((((((((((((((((( snapshot@2008-03-05_22.56.18.30 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-03-06 02:57:50 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-03-06 16:28:30 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-03-06 02:57:50 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-03-06 16:28:30 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-03-06 16:28:31 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DW4"="C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe" [2008-01-08 10:18 728176]
"WhenUSave"="C:\Program Files\Save\Save.exe" [ ]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-01-08 10:17 68856]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2008-01-13 10:46 8720384]
"Aim6"="" []
"Cdoo"="C:\PROGRA~1\COMMON~1\APPATC~1\wuaclt.exe" [ ]
"197678b58bfded03caecf89371042a00"="C:\DOCUME~1\ALLUSE~1\DOCUME~1\MYPICT~1\RYAN'S~1\PRISON~1.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" [2005-03-07 13:33 53248 C:\WINDOWS\system32\VTTimer.exe]
"VTTrayp"="VTtrayp.exe" [2005-10-31 14:15 163840 C:\WINDOWS\system32\VTTrayp.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2008-01-08 10:17 132496]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-01-08 10:17 1836544]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2008-01-08 10:17 57344]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2006-08-11 22:43 7630848]
"nwiz"="nwiz.exe" [2006-08-11 22:43 1519616 C:\WINDOWS\system32\nwiz.exe]
"SoundMan"="SOUNDMAN.EXE" [2005-11-11 00:07 90112 C:\WINDOWS\SOUNDMAN.EXE]
"NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [2006-08-11 22:43 86016]
"NNServ"="C:\Program Files\NewDotNet\nnrun.exe" [ ]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2008-03-04 09:05 582992]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6253\SiteAdv.exe" [2008-01-08 10:17 36640]
"McENUI"="C:\PROGRA~1\McAfee\MHN\McENUI.exe" [2008-03-04 09:05 1160480]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-11 12:02 282624]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-05 07:55 267048]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-08 10:17 39792]
"Lexmark X6100 Series"="C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe" [2008-02-29 08:28 57344]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2008-01-13 10:46 8720384]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-12 23:01:04 83360]
Picture Package Menu.lnk - C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe [2007-10-14 13:56:53 151552]
Picture Package VCD Maker.lnk - C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe [2007-10-14 13:56:45 106496]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Firefly Studios\\Stronghold 2\\Stronghold2.exe"=
"C:\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Sierra\\Empire Earth - The Art of Conquest\\EE-AOC.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\WINDOWS\\system32\\LEXPPS.EXE"=
"C:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe"=
"C:\\Sierra\\Empire Earth\\Empire Earth.exe"=
"C:\\Program Files\\Sierra Entertainment\\Empire Earth III\\EE3.exe"=
"C:\\Program Files\\Paradox Interactive\\Europa Universalis III\\eu3game.exe"=
"C:\\Program Files\\Firefly Studios\\Stronghold\\Stronghold.exe"=
"C:\\WINDOWS\\system32\\dplaysvr.exe"=
"C:\\Program Files\\BF1942.exe"=
"C:\\Program Files\\GSC Game World\\Cossacks II\\Cossacks2.exe"=
"C:\\Program Files\\Strategy First\\Europa Universalis 2\\EU2.exe"=
"C:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 15:38]
S2 0303081204724587mcinstcleanup;McAfee Application Installer Cleanup (0303081204724587);C:\WINDOWS\TEMP\
030308~1.EXE C:\PROGRA~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini []
S4 Boonty Games;Boonty Games;"C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe" [2006-11-01 16:51]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a228bdcc-a86f-11dc-97f9-0016174d056f}]
\Shell\Auto\command - F:\UFO.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL UFO.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-02-29 00:15:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-10-12 13:44:27 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2007-12-31 05:36:53 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe'
"2008-01-01 07:03:51 C:\WINDOWS\Tasks\McQcTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-03-06 10:51:48
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\SiteAdvisor\6253\SAService.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Lexmark X6100 Series\lxbfbmon.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Java\jre1.6.0_03\bin\jucheck.exe
.
**************************************************************************
.
Completion time: 2008-03-06 11:02:33 - machine was rebooted [Adalcinda]
ComboFix-quarantined-files.txt 2008-03-06 17:02:26
ComboFix2.txt 2008-03-06 04:56:41
.
2008-03-06 16:25:06 --- E O F ---
Here's the MalewareBytes' one:Malwarebytes' Anti-Malware 1.07
Database version: 461
Scan type: Full Scan (A:\|C:\|)
Objects scanned: 285308
Time elapsed: 1 hour(s), 25 minute(s), 28 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Here's the Kapersky Friday, March 07, 2008 7:55:20 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 7/03/2008
Kaspersky Anti-Virus database records: 607941
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
A:\
C:\
D:\
E:\
Scan Statistics
Total number of scanned objects 234569
Number of viruses found 13
Number of infected objects 199
Number of suspicious objects 0
Duration of the scan process 03:01:12
Infected Object Name Virus Name Last Action
C:\Documents and Settings\Adalcinda\Application Data\Mozilla\Firefox\Profiles\d9tg2bf5.default\cert8.db Object is locked skipped
C:\Documents and Settings\Adalcinda\Application Data\Mozilla\Firefox\Profiles\d9tg2bf5.default\formhistory.dat Object is locked skipped
C:\Documents and Settings\Adalcinda\Application Data\Mozilla\Firefox\Profiles\d9tg2bf5.default\history.dat Object is locked skipped
C:\Documents and Settings\Adalcinda\Application Data\Mozilla\Firefox\Profiles\d9tg2bf5.default\key3.db Object is locked skipped
C:\Documents and Settings\Adalcinda\Application Data\Mozilla\Firefox\Profiles\d9tg2bf5.default\parent.lock Object is locked skipped
C:\Documents and Settings\Adalcinda\Application Data\Mozilla\Firefox\Profiles\d9tg2bf5.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Adalcinda\Application Data\Mozilla\Firefox\Profiles\d9tg2bf5.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Adalcinda\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Adalcinda\Local Settings\Application Data\Google\Google Desktop Search\dbc2e.ht1 Object is locked skipped
C:\Documents and Settings\Adalcinda\Local Settings\Application Data\Google\Google Desktop Search\dbdam Object is locked skipped
C:\Documents and Settings\Adalcinda\Local Settings\Application Data\Google\Google Desktop Search\dbdao Object is locked skipped
C:\Documents and Settings\Adalcinda\Local Settings\Application Data\Google\Google Desktop Search\dbeam Object is locked skipped
C:\Documents and Settings\Adalcinda\Local Settings\Application Data\Google\Google Desktop Search\dbeao Object is locked skipped
C:\Documents and Settings\Adalcinda\Local Settings\Application Data\Google\Google Desktop Search\dbm Object is locked skipped
C:\Documents and Settings\Adalcinda\Local Settings\Application Data\Google\Google Desktop Search\dbu2d.ht1 Object is locked skipped
C:\Documents and Settings\Adalcinda\Local Settings\Application Data\Google\Google Desktop Search\dbvm.cf1 Object is locked skipped
C:\Documents and Settings\Adalcinda\Local Settings\Application Data\Google\Google Desktop Search\dbvmh.ht1 Object is locked skipped
C:\Documents and Settings\Adalcinda\Local Settings\Application Data\Google\Google Desktop Search\fii.cf1 Object is locked skipped
C:\Documents and Settings\Adalcinda\Local Settings\Application Data\Google\Google Desktop Search\fiih.ht1 Object is locked skipped
C:\Documents and Settings\Adalcinda\Local Settings\Application Data\Google\Google Desktop Search\fim1i.cf1 Object is locked skipped
C:\Documents and Settings\Adalcinda\Local Settings\Application Data\Google\Google Desktop Search\fim1ih.ht1 Object is locked skipped
C:\Documents and Settings\Adalcinda\Local Settings\Application Data\Google\Google Desktop Search\fim2i.cf1 Object is locked skipped
C:\Documents and Settings\Adalcinda\Local Settings\Application Data\Google\Google Desktop Search\fim2ih.ht1 Object is locked skipped
C:\Documents and Settings\Adalcinda\Local Settings\Application Data\Google\Google Desktop Search\hp Object is locked skipped
C:\Documents and Settings\Adalcinda\Local Settings\Application Data\Google\Google Desktop Search\hpt2i.ht1 Object is locked skipped
C:\Documents and Settings\Adalcinda\Local Settings\Application Data\Google\Google Desktop Search\rpm.cf1 Object is locked skipped
C:\Documents and Settings\Adalcinda\Local Settings\Application Data\Google\Google Desktop Search\rpm1n.cf1 Object is locked skipped
C:\Documents and Settings\Adalcinda\Local Settings\Application Data\Google\Google Desktop Search\rpm1n1m.cf1 Object is locked skipped
C:\Documents and Settings\Adalcinda\Local Settings\Application Data\Google\Google Desktop Search\rpm1n1mh.ht1 Object is locked skipped
C:\Documents and Settings\Adalcinda\Local Settings\Application Data\Google\Google Desktop Search\rpm1nh.ht1 Object is locked skipped
C:\Documents and Settings\Adalcinda\Local Settings\Application Data\Google\Google Desktop Search\rpmh.ht1 Object is locked skipped
C:\Documents and Settings\Adalcinda\Local Settings\Application Data\Google\Google Desktop Search\safeweb\goog-black-enchashm.cf1 Object is locked skipped
C:\Documents and Settings\Adalcinda\Local Settings\Application Data\Google\Google Desktop Search\safeweb\goog-black-enchashmh.ht1 Object is locked skipped
C:\Documents and Settings\Adalcinda\Local Settings\Application Data\Google\Google Desktop Search\safeweb\goog-black-urlm.cf1 Object is locked skipped
C:\Documents and Settings\Adalcinda\Local Settings\Application Data\Google\Google Desktop Search\safeweb\goog-black-urlmh.ht1 Object is locked skipped
C:\Documents and Settings\Adalcinda\Local Settings\Application Data\Google\Google Desktop Search\safeweb\goog-malware-domainm.cf1 Object is locked skipped
C:\Documents and Settings\Adalcinda\Local Settings\Application Data\Google\Google Desktop Search\safeweb\goog-malware-domainmh.ht1 Object is locked skipped
C:\Documents and Settings\Adalcinda\Local Settings\Application Data\Google\Google Desktop Search\safeweb\goog-white-domainm.cf1 Object is locked skipped
C:\Documents and Settings\Adalcinda\Local Settings\Application Data\Google\Google Desktop Search\safeweb\goog-white-domainmh.ht1 Object is locked skipped
C:\Documents and Settings\Adalcinda\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Adalcinda\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Adalcinda\Local Settings\Application Data\Mozilla\Firefox\Profiles\d9tg2bf5.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Adalcinda\Local Settings\Application Data\Mozilla\Firefox\Profiles\d9tg2bf5.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Adalcinda\Local Settings\Application Data\Mozilla\Firefox\Profiles\d9tg2bf5.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Adalcinda\Local Settings\Application Data\Mozilla\Firefox\Profiles\d9tg2bf5.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Adalcinda\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Adalcinda\Local Settings\Temp\sqlite_aHRZ5m3sdRyt0xM Object is locked skipped
C:\Documents and Settings\Adalcinda\Local Settings\Temp\~DF6CA2.tmp Object is locked skipped
C:\Documents and Settings\Adalcinda\Local Settings\Temp\~DFC998.tmp Object is locked skipped
C:\Documents and Settings\Adalcinda\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Adalcinda\ntuser.dat Object is locked skipped
C:\Documents and Settings\Adalcinda\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\EasyNet\MHNData Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MNA\NAData Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MPF\data\log.edb Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\Events.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\{D914D06B-421D-4C75-8597-21F44FABB137}.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\{DE2C585B-B583-46E3-B6D1-48115462C10B}.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\McUsers.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSK\MSKWMDB.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSK\settingsdb.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Data\TFR3.tmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Logs\OAS.Log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Documents\My Pictures\Ryan's Pictures\W3XNameSpooferPro11800.exe Infected: Trojan.Win32.Agent.fmr skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\HTML TOOLS\4216A5B.dll Infected: not-a-virus:AdWare.Win32.IeSearchBar.a skipped
C:\Program Files\Mozilla Firefox\CakeManiaSetup-dm.exe Infected: not-a-virus:AdWare.Win32.Trymedia.b skipped
C:\Program Files\Mozilla Firefox\plugins\NPMyWebS.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.i skipped
C:\QooBox\Quarantine\C\Program Files\AIM6\aim6.exe.vir Infected: Virus.Win32.Trats.d skipped
C:\QooBox\Quarantine\C\Program Files\iTunes\iTunesHelper.exe.vir Infected: Virus.Win32.Trats.d skipped
C:\QooBox\Quarantine\C\Program Files\rnamfler\naomf.exe.vir Infected: Virus.Win32.Trats.d skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\akoylifl.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\apksquof.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\birdfgyt.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\bxydlkpg.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\dllowahg.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\eeqatrsm.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\emswcbcw.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\encwtwjl.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\fcyhufsk.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\gdjdmpfg.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\gfksakmp.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\grxpggkb.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\jarbsfqn.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\jwpqlvbr.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\ntrcvrxi.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.ixf skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\rwqmlula.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\sftgcodp.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\sjcsumio.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\wmakcbdc.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\xqvbkaoh.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\xwvxmsnl.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\catchme2008-03-05_225150.42.zip/ddcyw.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\catchme2008-03-05_225150.42.zip ZIP: infected - 1 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP115\A0010203.dll Infected: not-a-virus:AdWare.Win32.OneStep.e skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP115\A0010204.exe Infected: not-a-virus:AdWare.Win32.OneStep.c skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP154\A0016463.exe Infected: not-a-virus:AdWare.Win32.OneStep.c skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP155\A0016473.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP155\A0016482.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP155\A0016485.exe Infected: not-a-virus:AdWare.Win32.OneStep.c skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP155\A0016498.dll Infected: not-a-virus:AdWare.Win32.NewDotNet.l skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP155\A0016502.exe Infected: Trojan-Downloader.Win32.Osel.bx skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP155\A0016515.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP155\A0016530.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP155\A0016534.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP156\A0016562.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP156\A0016576.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP156\A0016744.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP156\A0016771.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP156\A0017730.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP156\A0017740.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP157\A0017780.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP157\A0017792.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP157\A0017854.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP157\A0017866.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP157\A0017870.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP158\A0017998.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP158\A0018005.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP158\A0018010.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP159\A0018100.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP159\A0018107.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP161\A0018197.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP161\A0018204.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP163\A0018258.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP163\A0018265.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP163\A0019258.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP163\A0019268.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP164\A0019348.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP164\A0019356.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP166\A0019405.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP166\A0019417.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP168\A0019472.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP168\A0019478.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP170\A0019554.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP170\A0019565.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP172\A0019640.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP172\A0019646.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP173\A0019882.rbf Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP174\A0020021.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP174\A0020058.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP175\A0020219.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP176\A0020274.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP178\A0020367.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP179\A0021376.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP180\A0021466.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP182\A0021526.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP182\A0021573.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP183\A0021652.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP184\A0021717.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP185\A0021790.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP186\A0022853.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP187\A0023879.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP188\A0023929.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP189\A0023966.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP191\A0024038.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP193\A0024153.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP193\A0025146.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP194\A0025166.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP196\A0025230.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP197\A0025288.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP198\A0025348.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP198\A0025374.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP199\A0025441.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP200\A0025504.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP200\A0025538.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP202\A0025602.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP203\A0025671.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP205\A0025736.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP206\A0025799.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP207\A0025890.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP208\A0026024.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP210\A0026091.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP211\A0026202.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP212\A0026302.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP212\A0026383.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP213\A0026418.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP214\A0026471.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP214\A0026539.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP215\A0026630.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP215\A0026652.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP216\A0026730.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP217\A0026733.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP217\A0026752.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP218\A0026803.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP219\A0026832.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP221\A0026884.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP221\A0026885.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP221\A0026906.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP221\A0027905.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP222\A0027969.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP222\A0027987.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP225\A0028099.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP225\A0028118.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP226\A0028173.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP226\A0028174.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP226\A0028193.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP228\A0028208.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP229\A0028267.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP229\A0028292.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP231\A0028448.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP232\A0028528.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP232\A0028596.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP232\A0028671.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP233\A0028688.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP234\A0028703.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP235\A0028777.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP236\A0028833.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP236\A0028895.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP236\A0029002.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP239\A0029517.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP244\A0029862.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP244\A0029932.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP245\A0032919.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP246\A0032928.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP247\A0032987.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP250\A0033753.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP250\A0033754.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP254\A0033956.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ixe skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP257\A0034051.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.bce skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP258\A0034565.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP261\A0034672.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP261\A0034686.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP262\A0034752.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP262\A0034772.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP263\A0035028.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP263\A0035073.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP264\A0035107.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP265\A0035131.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP265\A0035205.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP265\A0035221.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP267\A0035260.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP267\A0035279.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP268\A0035324.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP268\A0035342.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP269\A0035391.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP269\A0035405.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP270\A0035430.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP270\A0035450.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP271\A0035524.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP271\A0035525.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP271\A0035526.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP271\A0035527.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP271\A0035528.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP271\A0035529.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP271\A0035530.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP271\A0035531.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP271\A0035532.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP271\A0035533.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP271\A0035534.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP271\A0035535.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP271\A0035536.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP271\A0035537.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP271\A0035538.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ixf skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP271\A0035539.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP271\A0035540.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP271\A0035541.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP271\A0035542.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP271\A0035543.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP271\A0035544.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP271\A0035590.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP271\A0035591.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP271\A0035592.exe Infected: Virus.Win32.Trats.d skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP273\change.log Object is locked skipped
C:\System Volume Information\_restore{8427ABF2-F19D-4D6D-996A-F8D98CBD7981}\RP53\A0004719.exe Infected: not-a-virus:AdWare.Win32.OneStep.c skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\mcafee_ftnIymZuxro7t2i Object is locked skipped
C:\WINDOWS\Temp\mcmsc_2T20m5fEDfrcgh1 Object is locked skipped
C:\WINDOWS\Temp\mcmsc_eMw0nu9Wvswpjs0 Object is locked skipped
C:\WINDOWS\Temp\mcmsc_uOB1gDH6yn8N7Am Object is locked skipped
C:\WINDOWS\Temp\mcmsc_UOLrkjJxlG8IhWO Object is locked skipped
C:\WINDOWS\Temp\mcmsc_x78djCEwiFXG3ER Object is locked skipped
C:\WINDOWS\Temp\sqlite_5kVcioCnINVGsye Object is locked skipped
C:\WINDOWS\Temp\sqlite_e7iyb8TNvL6oaPw Object is locked skipped
C:\WINDOWS\Temp\sqlite_eSKd3bYdHbzYR9Z Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
And here's the HiJackThis log:Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:56:11 AM, on 3/7/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\SiteAdvisor\6253\SAService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\system32\VTTimer.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe
C:\Program Files\Lexmark X6100 Series\lxbfbmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe
C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\explorer.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Java\jre1.6.0_03\bin\jucheck.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Adalcinda\Desktop\HJT\HiJackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.com/customize/ie/def ... earch.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - C:\Program Files\McAfee\MSK\mcapbho.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NNServ] "C:\Program Files\NewDotNet\nnrun.exe" "C:\Program Files\NewDotNet\nncore.dll" ServiceStart
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Lexmark X6100 Series] "C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe"
O4 - HKCU\..\Run: [WhenUSave] "C:\Program Files\Save\Save.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Cdoo] "C:\PROGRA~1\COMMON~1\APPATC~1\wuaclt.exe" -vt yazb
O4 - HKCU\..\Run: [197678b58bfded03caecf89371042a00] C:\DOCUME~1\ALLUSE~1\DOCUME~1\MYPICT~1\RYAN'S~1\PRISON~1.EXE /r
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Picture Package Menu.lnk = C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe
O4 - Global Startup: Picture Package VCD Maker.lnk = C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe
O8 - Extra context menu item: &Search -
http://edits.mywebsearch.com/toolbaredi ... p=ZJfox000O8 - Extra context menu item: &Windows Live Search -
res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspxO8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab -
res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?f2fa2c59c5e54cae9c0cfedaacbfb727
O8 - Extra context menu item: Open in new foreground tab -
res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?f2fa2c59c5e54cae9c0cfedaacbfb727
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Adalcinda\Start Menu\Programs\IMVU\Run IMVU.lnk
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky.com/kos/eng/partne ... nicode.cabO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupda ... 6556929326O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: McAfee Application Installer Cleanup (0303081204724587) (0303081204724587mcinstcleanup) - Unknown owner - C:\WINDOWS\TEMP\030308~1.EXE (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6253\SAService.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 11791 bytes