Here are the logs:
ComboFix 08-03-10.1 - Steve Kulcsar 2008-03-14 17:00:48.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.134 [GMT -5:00]
Running from: C:\Documents and Settings\Steve Kulcsar\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Steve Kulcsar\Desktop\CFScript-2.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!FILE ::
C:\WINDOWS\uccspecb.sys
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\uccspecb.sys
.
((((((((((((((((((((((((( Files Created from 2008-02-14 to 2008-03-14 )))))))))))))))))))))))))))))))
.
2008-03-13 23:44 . 2008-03-13 23:44 <DIR> d-------- C:\WINDOWS\ERUNT
2008-03-13 23:43 . 2008-03-13 23:43 <DIR> d-------- C:\SDFIX
2008-03-11 06:07 . 2007-06-05 11:56 44,928 --a------ C:\WINDOWS\system32\drivers\SDTHOOK.SYS
2008-03-05 20:20 . 2008-03-05 20:20 <DIR> d-------- C:\WINDOWS\system32\Quarantine
2008-03-03 13:40 . 2008-03-03 13:40 <DIR> d-------- C:\House
2008-03-03 13:38 . 2008-03-03 13:41 265,042 --a------ C:\WINDOWS\house.jpg
2008-02-27 19:46 . 2008-02-27 19:46 <DIR> d-------- C:\Program Files\vso
2008-02-27 19:46 . 2008-02-27 19:46 68,608 --a------ C:\WINDOWS\system32\drivers\Pcatip.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-14 21:55 77,824 ----a-w C:\WINDOWS\system32\kdfapi.dll
2008-03-14 21:55 726,568 ----a-w C:\WINDOWS\system32\kdfmgr.exe
2008-03-14 21:55 53,248 ----a-w C:\WINDOWS\system32\Kdfhok.dll
2008-03-14 21:55 192,512 ----a-w C:\WINDOWS\system32\kdfvmgr.exe
2008-03-14 04:40 --------- d-----w C:\Program Files\Lx_cats
2008-03-11 11:27 --------- d-----w C:\Program Files\Lexmark 5200 Series
2008-03-11 11:25 --------- d-----w C:\Program Files\Google
2008-03-11 11:22 --------- d-----w C:\Program Files\Common Files\Autodesk Shared
2008-02-28 00:46 34,528 ----a-w C:\WINDOWS\system32\drivers\Pcouffin.sys
2008-02-25 22:07 --------- d-----w C:\Program Files\GhostSurf 2005
2008-01-25 01:27 5,773 ----a-w C:\WINDOWS\system32\nqorypcx.dll
2008-01-24 01:25 5,773 ----a-w C:\WINDOWS\system32\cmxukhjp.dll
2008-01-23 01:21 5,773 ----a-w C:\WINDOWS\system32\pcqudhjc.dll
2008-01-22 01:26 5,773 ----a-w C:\WINDOWS\system32\esgisdsf.dll
2008-01-21 01:26 5,773 ----a-w C:\WINDOWS\system32\hgcftels.dll
2008-01-19 13:24 5,773 ----a-w C:\WINDOWS\system32\ekcoemhd.dll
2008-01-18 13:19 5,773 ----a-w C:\WINDOWS\system32\enkpkqph.dll
2008-01-18 13:15 5,735 ----a-w C:\WINDOWS\system32\lfbyqdoq.dll
2008-01-17 13:24 5,773 ----a-w C:\WINDOWS\system32\gloxspmx.dll
2008-01-17 13:21 5,735 ----a-w C:\WINDOWS\system32\eyraigyp.dll
2008-01-16 13:25 5,773 ----a-w C:\WINDOWS\system32\ajccykos.dll
2008-01-16 13:16 5,735 ----a-w C:\WINDOWS\system32\wteioiyb.dll
2008-01-14 13:24 5,773 ----a-w C:\WINDOWS\system32\vxfivyeb.dll
2008-01-14 13:18 5,735 ----a-w C:\WINDOWS\system32\pldtbidv.dll
2008-01-13 01:25 5,773 ----a-w C:\WINDOWS\system32\lubturan.dll
2008-01-13 01:16 5,735 ----a-w C:\WINDOWS\system32\cjpphwmf.dll
2008-01-11 13:25 5,773 ----a-w C:\WINDOWS\system32\pqnyfjee.dll
2008-01-11 13:22 5,735 ----a-w C:\WINDOWS\system32\xjwdtssl.dll
2008-01-11 00:48 5,773 ----a-w C:\WINDOWS\system32\sbofkcow.dll
2008-01-11 00:45 5,735 ----a-w C:\WINDOWS\system32\obdmiasb.dll
2008-01-08 06:58 5,773 ----a-w C:\WINDOWS\system32\rodtfkjl.dll
2007-12-25 15:11 5,773 ----a-w C:\WINDOWS\system32\cgqvmgtq.dll
2007-12-23 07:27 5,773 ----a-w C:\WINDOWS\system32\mdeumfaf.dll
2007-12-22 01:15 6,691 ----a-w C:\WINDOWS\system32\bmbqdlqt.dll
2007-12-21 01:15 6,691 ----a-w C:\WINDOWS\system32\uiagjadh.dll
2007-12-19 16:42 6,691 ----a-w C:\WINDOWS\system32\qepcfwec.dll
2007-12-14 20:31 6,691 ----a-w C:\WINDOWS\system32\wffnuaqb.dll
.
((((((((((((((((((((((((((((( snapshot@2008-03-12_20.13.46.06 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-03-12 07:35:36 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2008-03-14 04:44:42 7,434,240 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\
00000001\ntuser.dat
+ 2008-03-14 04:44:42 225,280 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\
00000002\UsrClass.dat
+ 2008-03-12 07:35:36 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2008-03-14 04:44:29 7,434,240 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\
00000001\ntuser.dat
+ 2008-03-14 04:44:29 225,280 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\
00000002\UsrClass.dat
- 2008-03-12 22:46:28 52,764 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-03-14 12:52:09 52,764 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-03-12 22:46:28 380,350 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-03-14 12:52:09 380,350 ----a-w C:\WINDOWS\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{E7620C98-FCCC-40E5-92EC-C7685D2E1E40}"= "C:\Program Files\Trend Micro\TrendSecure\TransactionProtector\TSToolbar.dll" [2007-09-16 09:21 103760]
[HKEY_CLASSES_ROOT\clsid\{e7620c98-fccc-40e5-92ec-c7685d2e1e40}]
[HKEY_CLASSES_ROOT\TSToolbar.TSProtectorBar.1]
[HKEY_CLASSES_ROOT\TypeLib\{EC525605-2266-4775-8F78-A68A6446465C}]
[HKEY_CLASSES_ROOT\TSToolbar.TSProtectorBar]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [ ]
"SureCleanProfessional"="C:\PROGRA~1\PANICW~1\SURECL~1\SRClean.exe" [ ]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [ ]
"SUPERAntiSpyware"="D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-03-12 17:47 1481968]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [ ]
"ezShieldProtector for Px"="C:\WINDOWS\System32\ezSP_Px.exe" [ ]
"ZTgServerSwitch"="c:\program files\support.com\client\bin\tgcmd.exe" [ ]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [ ]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [ ]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2003-08-18 20:56 4841472]
"AGRSMMSG"="AGRSMMSG.exe" []
"VAIO Recovery"="C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe" [ ]
"LXBTCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBTtime.dll" [2004-02-23 08:47 61440]
"GhostSurfDelSatellite"="C:\Program Files\GhostSurf 2005\DeleteSatellite.exe" [ ]
C:\Documents and Settings\Steve Kulcsar\Start Menu\Programs\Startup\
Scheduler.lnk - C:\Program Files\GhostSurf 2005\Scheduler daemon.exe [2004-03-09 16:47:16 86133]
C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 01:05:26 29696]
AutoCAD Startup Accelerator.lnk - C:\Program Files\Common Files\Autodesk Shared\acstart16.exe [2004-02-25 02:35:22 10872]
Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2003-06-25 06:25:38 614531]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2000-01-21 03:15:54 65588]
WinZip Quick Pick.lnk - C:\WinZip\WZQKPICK.EXE [2005-01-10 21:35:02 106560]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= D:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
D:\Program Files\SUPERAntiSpyware\SASWINLO.DLL 2008-03-12 17:47 294912 D:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\GhostSurf 2005\\Proxy.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\WINDOWS\\explorer.exe"=
"C:\\Program Files\\Java\\j2re1.4.2_01\\launch4j-tmp\\yahtzee.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Real\\RealOne Player\\realplay.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R3 odysseyIM3;Odyssey Network Services Miniport;C:\WINDOWS\system32\DRIVERS\odysseyIM3.sys [2003-05-14 17:01]
S3 CBTNDIS5;CBTNDIS5 NDIS Protocol Driver;C:\WINDOWS\System32\CBTNDIS5.SYS [2003-07-16 23:28]
S3 IPN2120;Wireless-B PCI Adapter Driver;C:\WINDOWS\system32\DRIVERS\LSIPNDS.sys []
S3 Partizan;Partizan;C:\WINDOWS\system32\drivers\Partizan.sys [2007-12-04 06:56]
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-03-14 17:04:34
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-03-14 17:05:22
ComboFix-quarantined-files.txt 2008-03-14 22:05:19
ComboFix2.txt 2008-03-14 12:44:06
ComboFix3.txt 2008-03-13 01:14:18
.
2008-03-12 14:02:53 --- E O F ---
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Friday, March 14, 2008 9:05:35 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 14/03/2008
Kaspersky Anti-Virus database records: 630343
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
Scan Statistics:
Total number of scanned objects: 90729
Number of viruses found: 10
Number of infected objects: 239
Number of suspicious objects: 0
Duration of the scan process: 01:31:54
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Sony Corporation\SonicStage\Packages\MtData.ldb Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Sony Corporation\SonicStage\Packages\MtData.mdb Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2008-03-14_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped
C:\Documents and Settings\All Users\Documents\{499663EE-202C-4468-874C-198A9E0BC058} Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Steve Kulcsar\Application Data\Sun\Java\Deployment\cache\6.0\36\5c192a24-77e884ac/vlocal.class Infected: Trojan-Downloader.Java.Agent.f skipped
C:\Documents and Settings\Steve Kulcsar\Application Data\Sun\Java\Deployment\cache\6.0\36\5c192a24-77e884ac ZIP: infected - 1 skipped
C:\Documents and Settings\Steve Kulcsar\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\AppLogs\SUPERANTISPYWARE-3-14-2008( 17-8-56 ).LOG Object is locked skipped
C:\Documents and Settings\Steve Kulcsar\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Steve Kulcsar\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Steve Kulcsar\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Steve Kulcsar\Local Settings\Application Data\Trend Micro\TrendSecure\Log\TS-COMSVR-20071210-082611-468.log Object is locked skipped
C:\Documents and Settings\Steve Kulcsar\Local Settings\Application Data\Trend Micro\TrendSecure\Log\TS-TGP-20080314-103622-609.log Object is locked skipped
C:\Documents and Settings\Steve Kulcsar\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Steve Kulcsar\Local Settings\Temp\me_H4ggRplEBVtd2nk Object is locked skipped
C:\Documents and Settings\Steve Kulcsar\Local Settings\Temp\me_HfyY9jy17CCTsB7 Object is locked skipped
C:\Documents and Settings\Steve Kulcsar\Local Settings\Temp\me_qIgbnlgGMsjdavD Object is locked skipped
C:\Documents and Settings\Steve Kulcsar\Local Settings\Temp\me_th7QTB1ud7aQ1CD Object is locked skipped
C:\Documents and Settings\Steve Kulcsar\ntuser.dat Object is locked skipped
C:\Documents and Settings\Steve Kulcsar\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsys.dll Object is locked skipped
C:\Program Files\Internet Explorer\iexplore.exe.tmp Infected: Virus.Win32.Trats.b skipped
C:\Program Files\Kodak\Kodak EasyShare software\Catalog\EasyShare.me Object is locked skipped
C:\Program Files\Kodak\Kodak EasyShare software\Catalog\EasyShare.mm Object is locked skipped
C:\Program Files\QuickTime\qttask.exe Infected: Virus.Win32.Trats.b skipped
C:\Program Files\Sony\VAIO Media Integrated Server\Photo\DB\vpdb.ldb Object is locked skipped
C:\Program Files\Sony\VAIO Media Integrated Server\Photo\DB\vpdb.mdb Object is locked skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\1A8.tmp Infected: Virus.Win32.Trats.b skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\28.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\31.tmp Infected: Virus.Win32.Trats.b skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\32.tmp Infected: Virus.Win32.Trats.b skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\33.tmp Infected: Virus.Win32.Trats.b skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\34.tmp Infected: Virus.Win32.Trats.b skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\35.tmp Infected: Virus.Win32.Trats.b skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\36.tmp Infected: Virus.Win32.Trats.b skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\37.tmp Infected: Virus.Win32.Trats.b skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\38.tmp Infected: Virus.Win32.Trats.b skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\39.tmp Infected: Virus.Win32.Trats.b skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\3A.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\3B.tmp Infected: Virus.Win32.Trats.b skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\3C.tmp Infected: Virus.Win32.Trats.b skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\3CF.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\3D.tmp Infected: Virus.Win32.Trats.b skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\3D2.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\3E.tmp Infected: Virus.Win32.Trats.b skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\3EF.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\3F.tmp Infected: Virus.Win32.Trats.b skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\40.tmp Infected: Virus.Win32.Trats.b skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\41.tmp Infected: Virus.Win32.Trats.b skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\42.tmp Infected: Virus.Win32.Trats.b skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\43.tmp Infected: Virus.Win32.Trats.b skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\44.tmp Infected: Virus.Win32.Trats.b skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\45.tmp Infected: Virus.Win32.Trats.b skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\46.tmp Infected: Virus.Win32.Trats.b skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\47.tmp Infected: Virus.Win32.Trats.b skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\48.tmp Infected: Virus.Win32.Trats.b skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\49.tmp Infected: Virus.Win32.Trats.b skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\4A.tmp Infected: Virus.Win32.Trats.b skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\4B.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\4C.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\4D.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\4E.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\4F.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\50.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\51.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\52.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\53.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\54.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\55.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\56.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\57.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\58.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\59.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\5A.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\5B.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\5C.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\5D.tmp Infected: Virus.Win32.Trats.b skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\5E.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\5F.tmp Infected: Virus.Win32.Trats.b skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\60.tmp Infected: Virus.Win32.Trats.b skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\94.tmp Infected: Virus.Win32.Trats.b skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\95.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\96.tmp Infected: Virus.Win32.Trats.b skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\CDTFEARI.DLL Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\HCTP[1]_804.VIR Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\iddqd[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\iddqd[1]_294.VIR Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\iddqd[1]_854.VIR Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\ptch[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\ptch[1]_14c.VIR Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\ptch[1]_824.VIR Infected: not-a-virus:AdWare.Win32.SuperJuan.in skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\ptch[1]_880.VIR Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\ptch[1]_88c.VIR Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\Trend Micro\Internet Security\Quarantine\ptch[1]_eb8.VIR Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\Program Files\Trend Micro\Internet Security\Trusted.dat Object is locked skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\ctfmon.exe.tmp.vir Infected: Virus.Win32.Trats.b skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\RCX10.tmp.vir Infected: Virus.Win32.Trats.b skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\RCX12.tmp.vir Infected: Virus.Win32.Trats.b skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\RCXD.tmp.vir Infected: Virus.Win32.Trats.b skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\RCXE.tmp.vir Infected: Virus.Win32.Trats.b skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\vtsqo.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\vtsqo.exe.vir Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP801\A0112455.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP801\A0113464.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP801\A0113465.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP801\A0113466.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP801\A0113467.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP802\A0113562.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP802\A0113563.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP802\A0113564.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP802\A0113565.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP804\A0113684.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP804\A0113685.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP804\A0113686.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP804\A0113687.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP805\A0113761.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP805\A0113762.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP805\A0113763.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP805\A0113764.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP806\A0113803.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP806\A0113804.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP806\A0113805.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP806\A0113806.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP807\A0114753.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP807\A0114754.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP807\A0114755.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP807\A0114756.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP807\A0114759.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP807\A0114761.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP807\A0114795.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP807\A0114796.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP807\A0114797.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP807\A0114798.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP807\A0115792.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP807\A0115793.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP807\A0115794.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP807\A0115795.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP807\A0115798.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP807\A0115799.EXE Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP808\A0115838.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP808\A0115839.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP808\A0115840.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP808\A0115841.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP809\A0115882.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP809\A0115883.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP809\A0115884.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP809\A0115885.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP809\A0116879.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP809\A0116880.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP809\A0116881.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP809\A0116882.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP809\A0116885.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP809\A0116886.EXE Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP810\A0116927.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP810\A0116928.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP810\A0116929.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP810\A0116987.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP810\A0116988.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP810\A0116989.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP810\A0116990.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP810\A0117013.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP810\A0117023.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP810\A0117024.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP810\A0117025.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP810\A0117026.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP810\A0117031.EXE Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP811\A0117080.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP811\A0117081.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP811\A0117082.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP811\A0117083.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP811\A0117111.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP811\A0117112.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP811\A0117113.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP811\A0117114.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP811\A0117115.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP811\A0117116.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP811\A0117117.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP811\A0117118.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP811\A0117119.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP811\A0117120.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP811\A0117121.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP811\A0117122.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP811\A0117123.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP811\A0117124.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP811\A0117125.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP811\A0117141.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP811\A0117142.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP811\A0117143.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP811\A0117144.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP813\A0117230.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP813\A0117231.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP813\A0117232.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP813\A0117233.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP813\A0117246.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP813\A0118246.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP813\A0119258.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP813\A0119259.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP813\A0119260.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP813\A0119261.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP814\A0119298.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP814\A0119299.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP814\A0119300.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP814\A0119301.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP814\A0119303.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP814\A0119315.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP814\A0119316.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP814\A0119317.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP814\A0119318.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP814\A0119319.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP814\A0119320.EXE Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP814\A0119321.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP814\A0119344.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP814\A0119355.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP814\A0119357.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP814\A0119358.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP814\A0119359.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP814\A0119361.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP814\A0119395.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP814\A0119396.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP814\A0119397.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP814\A0119398.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP814\A0119400.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP814\A0119428.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP814\A0119429.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP814\A0119430.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP814\A0119431.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP814\A0119434.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP815\A0119460.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP815\A0119461.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP815\A0119462.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP815\A0119463.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP815\A0119465.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP817\A0120537.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP826\A0121965.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP826\A0121966.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP826\A0121999.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP826\A0122002.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP826\A0123002.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP826\A0123010.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP826\A0123011.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP828\A0123196.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP830\A0123234.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP831\A0123275.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP831\A0123281.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP831\A0123283.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP831\A0123287.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP831\A0123305.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP831\A0125345.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP833\A0125359.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP834\A0125436.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP834\A0125439.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP836\A0125636.exe Infected: Virus.Win32.Trats.b skipped
C:\System Volume Information\_restore{45892D38-A0BF-43F9-8C9F-96715222A8FE}\RP837\change.log Object is locked skipped
C:\WINDOWS\$NtUninstallKB824141$\user32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB824141$\win32k.sys Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\accwiz.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\crypt32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\cryptsvc.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\hh.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\hhctrl.ocx Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\hhsetup.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\html32.cnv Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\itircl.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\itss.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\locator.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\magnify.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\migwiz.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\mrxsmb.sys Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\msconv97.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\narrator.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\newdev.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\ntdll.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\ntkrnlpa.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\ntoskrnl.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\ole32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\pchshell.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\raspptp.sys Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\rpcrt4.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\rpcss.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\shell32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\shmedia.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\srrstr.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\srv.sys Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\user32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\winsrv.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828035$\msgsvc.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828035$\wkssvc.dll Object is locked skipped
C:\WINDOWS\$NtUninstallQ828026$\msdxm.ocx Object is locked skipped
C:\WINDOWS\$NtUninstallQ828026$\wmpcore.dll Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{4021A8C3-883F-45CA-947C-796305CA9FB8}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\GHU7CV8X\js[1].html Infected: Exploit.HTML.CodeBaseExec skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\MRT.exe Infected: Virus.Win32.Trats.b skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\JET7F9F.tmp Object is locked skipped
C:\WINDOWS\Temp\JET8FAD.tmp Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\Bday\New Folder\Quarantine\478F16BC Infected: not-a-virus:RiskTool.Win32.HideRun skipped
D:\Bday\New Folder\Quarantine\4F037FA3.exe Infected: Trojan-Proxy.Win32.Bobax.c skipped
D:\Bday\New Folder\Quarantine\4F0629A0.exe Infected: Trojan-Proxy.Win32.Bobax.c skipped
D:\Bday\New Folder\Quarantine\51311B3D Infected: Trojan-Spy.Win32.Briss.c skipped
D:\Bday\New Folder\Quarantine\51354539 Infected: Trojan-Spy.Win32.Briss.h skipped
D:\Bday\New Folder\Quarantine\51386F35 Infected: Trojan-Spy.Win32.Briss.h skipped
D:\Program Files\Internet Explorer Temporary Files\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
D:\Program Files\Internet Explorer Temporary Files\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
D:\Program Files\Outlook Express\Email Files\Folders.dbx Object is locked skipped
D:\Program Files\Outlook Express\Email Files\Inbox.dbx Object is locked skipped
D:\Program Files\Outlook Express\Email Files\Offline.dbx Object is locked skipped
D:\Program Files\Outlook Express\Email Files\Passwords.dbx/[From MidAmerica Bank <
[email protected]>][Date Wed, 05 Jul 2006 09:32:06 -0400]/UNNAMED/html Infected: Trojan-Spy.HTML.Bankfraud.pd skipped
D:\Program Files\Outlook Express\Email Files\Passwords.dbx/[From MidAmerica Bank <
[email protected]>][Date Wed, 05 Jul 2006 09:32:06 -0400]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.pd skipped
D:\Program Files\Outlook Express\Email Files\Passwords.dbx Mail MS Outlook 5: infected - 2 skipped
D:\Program Files\Outlook Express\Email Files\Pop3uidl.dbx Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
Scan process completed.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:06:35 PM, on 03/14/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
d:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
C:\WINDOWS\System32\svchost.exe
C:\Program