Things I have tried:
- I have tryed following the steps on Here, I got stuck on the part after when running Kapersky AV ( Which I did a complete scan on), I could not locate "jkhhi.dll" in my directory, even after showing hidden files.
- I have tryed multiple programs that state they remove Vundo, but none seems to come up clean.
- Ran VundoFix in Safemode.
- Ran Anti-Virus / Spyboy S&D / Ad-Aware in Safemode.
Hijackthis log:
Logfile of HijackThis v1.99.1 Scan saved at 1:49:31 PM, on 1/6/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16574) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\WINDOWS\System32\HPZipm12.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\Craig's\Desktop\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 F3 - REG:win.ini: load=C:\WINDOWS\system32\ddcca.exe O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKLM\..\Run: [Zboard] C:\Program Files\Ideazon\ZEngine\Zboard.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [d8967f50] rundll32.exe "C:\WINDOWS\system32\uhqxfbme.dll",b O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\System32\igfxtray.exe O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\System32\hkcmd.exe O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\System32\igfxpers.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [BitZip - Powered by Miro] C:\Program Files\Participatory Culture Foundation\Miro\Miro.exe --theme "BitZip" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O11 - Options group: [INTERNATIONAL] International* O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-CA/a-UNO1/GAME_UNO1.cab O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab O16 - DPF: {68BCE50A-DC9B-4519-A118-6FDA19DB450D} (Info Class) - http://www.blizzard.com/support/includes/cabs/si.cab O16 - DPF: {82FFA573-38AA-482A-99AD-91F697B91631} (Installer.InstallControl) - http://static.35mb.com/applet/applet_o.cab O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - AppInit_DLLs: O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
VundoFix Log:
VundoFix V6.7.7 Checking Java version... Java version is 1.5.0.6 Old versions of java are exploitable and should be removed. Java version is 1.5.0.8 Old versions of java are exploitable and should be removed. Scan started at 10:55:11 AM 1/6/2008 Listing files found while scanning.... C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\igfxpers.exe C:\WINDOWS\system32\igfxtray.exe Beginning removal... Attempting to delete C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\hkcmd.exe Has been deleted! Attempting to delete C:\WINDOWS\system32\igfxpers.exe C:\WINDOWS\system32\igfxpers.exe Has been deleted! Attempting to delete C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\igfxtray.exe Has been deleted! Performing Repairs to the registry. Done!
Kapersky AV Log:
[code=auto:0]-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Sunday, January 06, 2008 1:50:49 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 6/01/2008
Kaspersky Anti-Virus database records: 503089
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\
Scan Statistics:
Total number of scanned objects: 98045
Number of viruses found: 11
Number of infected objects: 185
Number of suspicious objects: 0
Duration of the scan process: 01:06:06
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\Craig's\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\eRT.jar-59afe7f7-4cdbcc71.zip/HiPointInstallShieldRT.class Infected: Trojan-Downloader.Java.OpenConnection.ap skipped
C:\Documents and Settings\Craig's\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\eRT.jar-59afe7f7-4cdbcc71.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Craig's\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\nRT.jar-5e7eb989-4f650f42.zip/HiPointInstallShieldRT.class Infected: Trojan-Downloader.Java.OpenConnection.ap skipped
C:\Documents and Settings\Craig's\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\nRT.jar-5e7eb989-4f650f42.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Craig's\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Craig's\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Craig's\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Craig's\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Craig's\Local Settings\Temp\eZROMs.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Mostofate.u skipped
C:\Documents and Settings\Craig's\Local Settings\Temp\eZROMs.exe/stream/data0005 Infected: not-a-virus:AdWare.Win32.Mostofate.u skipped
C:\Documents and Settings\Craig's\Local Settings\Temp\eZROMs.exe/stream/data0006 Infected: not-a-virus:AdWare.Win32.Mostofate.u skipped
C:\Documents and Settings\Craig's\Local Settings\Temp\eZROMs.exe/stream Infected: not-a-virus:AdWare.Win32.Mostofate.u skipped
C:\Documents and Settings\Craig's\Local Settings\Temp\eZROMs.exe NSIS: infected - 4 skipped
C:\Documents and Settings\Craig's\Local Settings\Temp\RCX15F.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\Craig's\Local Settings\Temp\RCX165.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\Craig's\Local Settings\Temp\RCX16B.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\Craig's\Local Settings\Temp\RCX171.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\Craig's\Local Settings\Temp\RCX31.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\Craig's\Local Settings\Temp\RCX32.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\Craig's\Local Settings\Temp\RCX36.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\Craig's\Local Settings\Temp\RCX37.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\Craig's\Local Settings\Temp\RCX3C.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\Craig's\Local Settings\Temp\RCX3E.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\Craig's\Local Settings\Temp\RCX40.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\Craig's\Local Settings\Temp\RCX42.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\Craig's\Local Settings\Temp\RCX47.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\Craig's\Local Settings\Temp\RCX48.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\Craig's\Local Settings\Temp\RCX49.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\Craig's\Local Settings\Temp\RCX4D.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\Craig's\Local Settings\Temp\RCX4F.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\Craig's\Local Settings\Temp\RCX50.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\Craig's\Local Settings\Temp\RCX53.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\Craig's\Local Settings\Temp\RCX56.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\Craig's\Local Settings\Temp\TMP3A.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\Craig's\Local Settings\Temp\TMP3B.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\Craig's\Local Settings\Temp\_avast4_\unp137539845.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\Craig's\Local Settings\Temp\_avast4_\unp195895763.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\Craig's\Local Settings\Temp\_avast4_\unp213856196.tmp Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Documents and Settings\Craig's\Local Settings\Temp\~DFE195.tmp Object is locked skipped
C:\Documents and Settings\Craig's\Local Settings\Temp\~DFE1A1.tmp Object is locked skipped
C:\Documents and Settings\Craig's\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Craig's\Local Settings\Temporary Internet Files\Content.IE5\6BOC9KMJ\hctp[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.din skipped
C:\Documents and Settings\Craig's\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Craig's\Local Settings\Temporary Internet Files\Content.IE5\LCO7T9KT\smart-keystroke-recorder-pro-setup[1].exe/file05 Infected: not-a-virus:Monitor.Win32.SKRecorder.a skipped
C:\Documents and Settings\Craig's\Local Settings\Temporary Internet Files\Content.IE5\LCO7T9KT\smart-keystroke-recorder-pro-setup[1].exe/file10 Infected: not-a-virus:Monitor.Win32.SKRecorder.a skipped
C:\Documents and Settings\Craig's\Local Settings\Temporary Internet Files\Content.IE5\LCO7T9KT\smart-keystroke-recorder-pro-setup[1].exe Inno: infected - 2 skipped
C:\Documents and Settings\Craig's\Local Settings\Temporary Internet Files\Content.IE5\N7T3354W\smart-keystroke-recorder-setup[1].exe/file04 Infected: not-a-virus:Monitor.Win32.SKRecorder.a skipped
C:\Documents and Settings\Craig's\Local Settings\Temporary Internet Files\Content.IE5\N7T3354W\smart-keystroke-recorder-setup[1].exe/file09 Infected: not-a-virus:Monitor.Win32.SKRecorder.a skipped
C:\Documents and Settings\Craig's\Local Settings\Temporary Internet Files\Content.IE5\N7T3354W\smart-keystroke-recorder-setup[1].exe Inno: infected - 2 skipped
C:\Documents and Settings\Craig's\Local Settings\Temporary Internet Files\Content.IE5\N7T3354W\smart-keystroke-recorder-setup[2].exe/file04 Infected: not-a-virus:Monitor.Win32.SKRecorder.a skipped
C:\Documents and Settings\Craig's\Local Settings\Temporary Internet Files\Content.IE5\N7T3354W\smart-keystroke-recorder-setup[2].exe/file09 Infected: not-a-virus:Monitor.Win32.SKRecorder.a skipped
C:\Documents and Settings\Craig's\Local Settings\Temporary Internet Files\Content.IE5\N7T3354W\smart-keystroke-recorder-setup[2].exe Inno: infected - 2 skipped
C:\Documents and Settings\Craig's\Local Settings\Temporary Internet Files\Content.IE5\N7T3354W\smart-keystroke-recorder-setup[3].exe/file04 Infected: not-a-virus:Monitor.Win32.SKRecorder.a skipped
C:\Documents and Settings\Craig's\Local Settings\Temporary Internet Files\Content.IE5\N7T3354W\smart-keystroke-recorder-setup[3].exe/file09 Infected: not-a-virus:Monitor.Win32.SKRecorder.a skipped
C:\Documents and Settings\Craig's\Local Settings\Temporary Internet Files\Content.IE5\N7T3354W\smart-keystroke-recorder-setup[3].exe Inno: infected - 2 skipped
C:\Documents and Settings\Craig's\Local Settings\Temporary Internet Files\Content.IE5\N7T3354W\smart-keystroke-recorder-setup[4].exe/file04 Infected: not-a-virus:Monitor.Win32.SKRecorder.a skipped
C:\Documents and Settings\Craig's\Local Settings\Temporary Internet Files\Content.IE5\N7T3354W\smart-keystroke-recorder-setup[4].exe/file09 Infected: not-a-virus:Monitor.Win32.SKRecorder.a skipped
C:\Documents and Settings\Craig's\Local Settings\Temporary Internet Files\Content.IE5\N7T3354W\smart-keystroke-recorder-setup[4].exe Inno: infected - 2 skipped
C:\Documents and Settings\Craig's\Local Settings\Temporary Internet Files\Content.IE5\QITFGQCT\gamadril20071203[1] Infected: Backdoor.Win32.Agent.dbm skipped
C:\Documents and Settings\Craig's\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Craig's\NTUSER.DAT.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\report\Resident protection.txt Object is locked skipped
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Program Files\Ideazon\ZEngine\Zboard.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Program Files\iTunes\iTunesHelper.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Program Files\QuickTime\qttask .exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Program Files\QuickTime\qttask .exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Program Files\QuickTime\qttask .exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Program Files\QuickTime\qttask .exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Program Files\QuickTime\qttask .exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Program Files\QuickTime\qttask .exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Program Files\QuickTime\qttask .exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Program Files\QuickTime\qttask .exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Program Files\QuickTime\qttask .exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Program Files\QuickTime\qttask.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP504\A0114947.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP504\A0114948.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP504\A0114949.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP504\A0114950.exe Infected: Trojan-PSW.Win32.Magania.hh skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP504\A0114951.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP504\A0114952.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP504\A0114953.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP504\A0114973.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP504\A0114974.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP504\A0114975.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP504\A0114977.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP504\A0114978.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP504\A0114979.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP504\A0114987.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP504\A0114989.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP504\A0114990.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP504\A0114991.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP504\A0114992.exe Infected: Trojan-PSW.Win32.Magania.hh skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP504\A0114993.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP504\A0114995.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP505\A0115032.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP505\A0115034.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP505\A0115035.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP505\A0115036.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP505\A0115038.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP505\A0115039.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP505\A0115040.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP506\A0115069.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP506\A0115074.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP506\A0115076.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP506\A0115077.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP506\A0115078.exe Infected: Trojan-PSW.Win32.Magania.hh skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP506\A0115079.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP506\A0115081.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP506\A0115106.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP506\A0115113.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP506\A0115115.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP506\A0115116.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP506\A0115117.exe Infected: Trojan-PSW.Win32.Magania.hh skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP506\A0115118.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP506\A0115120.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP507\A0115179.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP507\A0115180.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP507\A0115181.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP507\A0115182.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP507\A0115183.exe Infected: Trojan-PSW.Win32.Magania.hh skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP507\A0115184.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP507\A0115186.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP507\A0115190.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP507\A0115204.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP507\A0115205.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP507\A0115206.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP507\A0115208.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP507\A0115209.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP507\A0115210.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP507\A0115211.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP507\A0115212.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP507\A0115213.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP507\A0115274.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP507\A0115279.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP507\A0115281.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP507\A0115282.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP507\A0115283.exe Infected: Trojan-PSW.Win32.Magania.hh skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP507\A0115284.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP507\A0115286.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP507\A0115287.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP507\A0115288.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP507\A0115289.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP508\A0115729.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP508\A0115821.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP508\A0115823.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP508\A0115825.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP508\A0115826.exe Infected: Trojan-PSW.Win32.Magania.hh skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP508\A0115827.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP508\A0115829.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP508\A0115830.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP508\A0115831.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP508\A0115832.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP509\A0115877.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP509\A0115882.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP509\A0115883.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP509\A0115886.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP509\A0115888.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP509\A0115889.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP509\A0115890.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP509\A0115891.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP509\A0115892.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP509\A0115893.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP509\A0115900.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP509\A0115925.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP509\A0115933.exe Infected: Trojan-PSW.Win32.Magania.hh skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP509\A0116937.exe Infected: Trojan-PSW.Win32.Magania.hh skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP511\A0116974.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP511\A0116975.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP511\A0116976.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP511\A0116978.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP511\A0117238.exe Infected: Trojan.Win32.Dialer.yz skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP511\A0117244.exe/data.rar/officekey.exe Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP511\A0117244.exe/data.rar Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP511\A0117244.exe RarSFX: infected - 2 skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP511\A0117248.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP511\A0117249.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP511\A0117252.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP511\A0117254.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP511\A0117255.exe Infected: Trojan-PSW.Win32.Magania.hh skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP512\A0117298.dll Infected: Trojan-Downloader.Win32.Small.hme skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP512\A0117299.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP512\A0117300.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP512\A0117301.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.din skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP512\A0117304.dll Infected: Trojan-Downloader.Win32.Small.hme skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP512\A0118306.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP512\A0118327.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.din skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP512\A0118328.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP512\A0118344.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP512\A0118345.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP512\A0118346.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\System Volume Information\_restore{6E504182-C0FB-4384-B5F4-5EA641F0F436}\RP513\change.log Object is locked skipped
C:\VundoFix Backups\hkcmd.exe.bad Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\VundoFix Backups\igfxpers.exe.bad Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\VundoFix Backups\igfxtray.exe.bad Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\Ir32_a.exe Infected: Trojan-PSW.Win32.Magania.hh skipped
C:\WINDOWS\system32\Ir32_b.exe Infected: Trojan-PSW.Win32.Maga
Edited by Joker2kill, 06 January 2008 - 01:25 PM.