Thanks for the reply
The logs are at the bottom
*A few notes though:
-Since the first HJT log i posted a few things changed
-dmpus.exe was replaced by dmval.exe (so i just treated it like dmpus and continued with the instructions)
-one of the O17's at the time of cleaning wasnt there, in specific this one:
O17 - HKLM\System\CCS\Services\Tcpip\..\{9EF3BC42-EF3F-4D97-976D-9392EECCB8E3}: NameServer = 85.255.116.104 85.255.112.229
-!!! BUT it's back now as i saw in the new HJT log
-My DNS thing was already set to automatic but i clicked ok anyway.
My computer seems normal, whats funny is that norton only noticed the dmval.exe virus when i opened AVG and couldn't delete it anyways (said it was a restricted file) but i tihnk it's gone now.
Logs:
Logfile of HijackThis v1.99.1
Scan saved at 6:43:11 PM, on 2/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Messenger Plus! 3\MsgPlus.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2P1.EXE
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Philips\Philips Device Transfer Pop-up\PDeviceConn.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\Sierra\Planner\PLNRnote.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\VIA\RAID\raid_tool.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\HJT\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.c...rch/search.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://us.rd.yahoo.c...//www.yahoo.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.c...rch/search.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://us.rd.yahoo.c...//www.yahoo.comR3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll (file missing)
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [EPSON PictureMate] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2P1.EXE /P17 "EPSON PictureMate" /O6 "USB001" /M "PictureMate"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [LaunchPDeviceConn] "C:\Program Files\Philips\Philips Device Transfer Pop-up\PDeviceConn.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Scheduler.lnk = C:\Program Files\SpyCatcher\Scheduler daemon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Event Planner Reminders Tray Icon.lnk = C:\Sierra\Planner\PLNRnote.exe
O4 - Global Startup: Forget Me Not.lnk = C:\Program Files\Broderbund\AG CreataCard\AGRemind.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: VIA RAID TOOL.lnk = C:\Program Files\VIA\RAID\raid_tool.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Search -
http://edits.mywebse...arch.jhtml?p=ZJO8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC Class) -
http://www.pcpitstop...cpConnCheck.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoft...free/asinst.cabO16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) -
http://gamedownload....GPlugin9USA.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{9EF3BC42-EF3F-4D97-976D-9392EECCB8E3}: NameServer = 85.255.116.104 85.255.112.229
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\Nortel Networks\Extranet_serv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 6:35:58 PM 2/13/2007
+ Scan result:
C:\Program Files\HQvideo -> Adware.HQvideo : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP287\A0025314.exe -> Downloader.Zlob.bjg : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP287\A0025315.exe -> Downloader.Zlob.bjg : Cleaned.
:mozilla.11:C:\Documents and Settings\J\Application Data\Mozilla\Firefox\Profiles\sgdpa1i7.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.29:C:\Documents and Settings\J\Application Data\Mozilla\Firefox\Profiles\sgdpa1i7.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.46:C:\Documents and Settings\J\Application Data\Mozilla\Firefox\Profiles\sgdpa1i7.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.47:C:\Documents and Settings\J\Application Data\Mozilla\Firefox\Profiles\sgdpa1i7.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.48:C:\Documents and Settings\J\Application Data\Mozilla\Firefox\Profiles\sgdpa1i7.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.49:C:\Documents and Settings\J\Application Data\Mozilla\Firefox\Profiles\sgdpa1i7.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.31:C:\Documents and Settings\J\Application Data\Mozilla\Firefox\Profiles\sgdpa1i7.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.15:C:\Documents and Settings\J\Application Data\Mozilla\Firefox\Profiles\sgdpa1i7.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.28:C:\Documents and Settings\J\Application Data\Mozilla\Firefox\Profiles\sgdpa1i7.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.30:C:\Documents and Settings\J\Application Data\Mozilla\Firefox\Profiles\sgdpa1i7.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.19:C:\Documents and Settings\J\Application Data\Mozilla\Firefox\Profiles\sgdpa1i7.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.40:C:\Documents and Settings\J\Application Data\Mozilla\Firefox\Profiles\sgdpa1i7.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.17:C:\Documents and Settings\J\Application Data\Mozilla\Firefox\Profiles\sgdpa1i7.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.41:C:\Documents and Settings\J\Application Data\Mozilla\Firefox\Profiles\sgdpa1i7.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.42:C:\Documents and Settings\J\Application Data\Mozilla\Firefox\Profiles\sgdpa1i7.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP279\A0024063.exe -> Trojan.DNSChanger.hk : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP279\A0024064.exe -> Trojan.DNSChanger.hk : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP279\A0024061.exe -> Trojan.DNSChanger.hm : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP279\A0024062.exe -> Trojan.DNSChanger.hm : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP279\A0024065.exe -> Trojan.DNSChanger.hm : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP250\A0018910.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP250\A0018942.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP251\A0019950.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP251\A0019964.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP252\A0019976.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP252\A0019987.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP253\A0020003.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP253\A0020023.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP254\A0020043.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP254\A0022045.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP255\A0022056.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP255\A0022093.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP256\A0022107.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP256\A0022125.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP256\A0022134.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP257\A0022160.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP257\A0022170.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP257\A0022179.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP258\A0022192.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP258\A0022210.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP258\A0022219.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP259\A0022232.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP259\A0022247.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP259\A0022256.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP260\A0022269.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP261\A0022285.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP261\A0022314.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP262\A0022323.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP264\A0022412.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP264\A0022421.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP264\A0022428.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP265\A0022454.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP266\A0022464.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP267\A0022477.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP268\A0022495.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP268\A0022517.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP268\A0022526.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP269\A0022537.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP269\A0022545.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP270\A0022628.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP271\A0022671.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP271\A0022682.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP272\A0022698.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP273\A0022713.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP274\A0022778.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP274\A0022792.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP275\A0022805.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP275\A0022814.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP276\A0022829.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP276\A0023830.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP276\A0023835.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP276\A0023844.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP277\A0024009.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP277\A0024018.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP278\A0024038.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP278\A0024045.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP280\A0024077.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP281\A0024099.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP281\A0024107.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP281\A0024121.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP282\A0024129.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP282\A0025129.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP282\A0025154.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP282\A0025164.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP282\A0025172.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP283\A0025180.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP285\A0025288.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP286\A0025308.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP287\A0025324.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP288\A0025338.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP289\A0025358.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP289\A0025365.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP289\A0025371.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP290\A0025387.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP290\A0025397.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP291\A0025404.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP291\A0025411.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP291\A0025425.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP291\A0025432.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP292\A0025444.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP293\A0025453.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP293\A0025469.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP293\A0025476.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP294\A0025503.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP294\A0025512.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP295\A0025528.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP295\A0025535.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP295\A0025555.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP297\A0025585.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP298\A0025602.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP298\A0025609.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP298\A0025620.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP298\A0025626.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP299\A0025641.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP299\A0025648.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP300\A0025671.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP300\A0025684.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP302\A0025698.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP304\A0025719.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP304\A0025737.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP305\A0025742.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP305\A0025761.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP305\A0025769.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP305\A0025775.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP306\A0025785.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP306\A0025790.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP307\A0025807.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP307\A0025827.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP307\A0026827.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP308\A0026835.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP308\A0026844.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP309\A0027845.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP309\A0027854.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP310\A0027866.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP310\A0027884.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP310\A0027893.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP311\A0027902.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP311\A0027908.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP312\A0027915.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP312\A0027923.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP312\A0027929.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP312\A0027937.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP313\A0027943.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP313\A0027951.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP313\A0027959.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP314\A0027972.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP314\A0027978.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP315\A0027989.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP315\A0027995.exe -> Trojan.Small.fb : Cleaned.
C:\System Volume Information\_restore{8FF9F956-2653-4BF1-85C6-9AAAF011EBEA}\RP315\A0028015.exe -> Trojan.Small.fb : Cleaned.
C:\WINDOWS\system32\dmval.exe -> Trojan.Small.fb : Cleaned.
::Report end
UNINSTAL LIST:
µTorrent
010 Editor 1.3
AC3Filter (remove only)
Ad-Aware SE Personal
Adobe Acrobat 5.0
Adobe Flash Player 9 ActiveX
Adobe Photoshop 7.0
American Greetings CreataCard Select 6
Apophysis 2.0
ATI - Software Uninstall Utility
ATI Catalyst Control Center
ATI Display Driver
Auction Client
AVG Anti-Spyware 7.5
Barbie Fashion Show CD-ROM
BitTorrent 4.0.2
BroadJump Client Foundation
Counter-Strike: Condition Zero
DAEMON Tools
Diablo II
DivX
Dungeon Siege
Emperor: Battle For Dune
EPSON CardMonitor
EPSON PhotoStarter3.0
EPSON PictureMate User's Guide
EPSON Printer Software
Event Planner
ewido anti-malware
FEAR
Film Factory
GoGear Digital Audio Player SA250/255/260 Device Manager
Guild Wars
Hallmark Card Studio 3 Deluxe
Hero Editor V0.80
HighMAT Extension to Microsoft Windows XP CD Writing Wizard
HijackThis 1.99.1
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Icy Tower v1.2 (11kHz)
ijji - Gunz
InterVideo WinDVD 4
iPod for Windows 2005-09-23
iTunes
J2SE Development Kit 5.0 Update 7
J2SE Runtime Environment 5.0 Update 10
J2SE Runtime Environment 5.0 Update 5
J2SE Runtime Environment 5.0 Update 6
J2SE Runtime Environment 5.0 Update 9
Java 2 Runtime Environment, SE v1.4.2_06
JCreator LE 3.50
Kittens 2 Screen Saver
KKND Krossfire
Kohan
Kohan Ahriman's Gift
LiveReg (Symantec Corporation)
LiveUpdate 3.0 (Symantec Corporation)
Macromedia Extension Manager
Macromedia Flash 8
Macromedia Flash 8 Video Encoder
Macromedia Flash MX
MemoriesOnTV 2.2.0
Messenger Plus! 3
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB886903)
Microsoft .NET Framework 2.0
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office FrontPage 2003
Microsoft Office Professional Edition 2003
Microsoft Web Publishing Wizard 1.52
Mozilla Firefox (1.5.0.9)
MP3 Rocket
MP3Rocket
MSN Messenger 7.5
MSXML 4.0 SP2 (KB927978)
Napster
Napster Burn Engine
Nero OEM
Nortel Networks Contivity VPN Client
Norton AntiVirus 2003
Norton WMI Update
Nox
NoxTools
NoxTools
Panda ActiveScan
Philips Device Transfer Pop-up
Puppy Luv (remove only)
Puzzle Pirates
Quake II
Quake II MP: Ground Zero
QuickTime
Rakion International
Red Alert Windows 95
Scrapbook Factory Deluxe
Security Update for Microsoft .NET Framework 2.0 (KB917283)
Security Update for Microsoft .NET Framework 2.0 (KB922770)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB926255)
Softnyx Launcher
SoulSeekkor's TQ Defiler (C:\Program Files\TQDefiler\)
SoulSeekkor's TQ Defiler (C:\Program Files\TQDefiler\) #3
SoulSeekkor's TQ Defiler (C:\Program Files\TQDefiler\) #4
SoundMAX
Spy Sweeper
Spybot - Search & Destroy 1.4
Starcraft
Steam
TeamSpeak 2 RC2
Titan Quest
Uninstall MPEG2 Plugin
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
USB CASIO Digital Camera Device Driver
Westwood Shared Internet Components
Windows Genuine Advantage v1.3.0254.0
Windows Installer 3.1 (KB893803)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Format Runtime
Windows Media Player 10
Windows XP Hotfix - KB834707
Windows XP Hotfix - KB867282
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB887797
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
Windows XP Service Pack 2
WinRAR archiver
WinZip
Yahoo! Browser Services
Yahoo! Mail
Yahoo! Mail Quick Select Tool (PhotoMail)
Yahoo! Messenger
Fixwareout Last edited 2/11/2007
Post this report in the forums please
...
»»»»»Prerun check
HKLM\SOFTWARE\~\Winlogon\ "System"="csvwb.exe"
»»»»» System restarted
»»»»» Postrun check
HKLM\SOFTWARE\~\Winlogon\ "system"=""
....
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}854338A6C716-8B9B-DA54-2683-D4EDED71{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "lavmd" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "1trap" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "2trap" Deleted
....
»»»»» Misc files.
....
»»»»» Checking for older varients.
....
Search five digit cs, dm, kd, jb, other, files.
The following files NEED TO BE SUBMITTED to one of the following URL'S for further inspection.
C:\WINDOWS\system32\dmval.exe 61012 08/04/2004
Click browse, find the file then click submit.
http://www.virustota...h/index_en.htmlOr
http://virusscan.jotti.org/»»»»» Other
»»»»» Current runs
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BJCFD"="C:\\Program Files\\BroadJump\\Client Foundation\\CFD.exe"
"MessengerPlus3"="\"C:\\Program Files\\Messenger Plus! 3\\MsgPlus.exe\""
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_10\\bin\\jusched.exe\""
"ccApp"="C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe"
"ccRegVfy"="C:\\Program Files\\Common Files\\Symantec Shared\\ccRegVfy.exe"
"Symantec NetDriver Monitor"="C:\\PROGRA~1\\SYMNET~1\\SNDMon.exe /Consumer"
"EPSON PictureMate"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_S4I2P1.EXE /P17 \"EPSON PictureMate\" /O6 \"USB001\" /M \"PictureMate\""
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"DAEMON Tools-1033"="\"C:\\Program Files\\D-Tools\\daemon.exe\" -lang 1033"
"LaunchPDeviceConn"="\"C:\\Program Files\\Philips\\Philips Device Transfer Pop-up\\PDeviceConn.exe\""
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"ATICCC"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\CLIStart.exe\""
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"MessengerPlus3"="\"C:\\Program Files\\Messenger Plus! 3\\MsgPlus.exe\" /WinStart"
"Steam"=""
"Yahoo! Pager"="\"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe\" -quiet"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
....
Hosts file was reset, If you use a custom hosts file please replace it
»»»»» End report »»»»»
Thanks for the time.