Thank you so much for your help! I used to use AVG but when I got new hardware I may have forgotten to reinstall it
Avira Log:
Avira AntiVir Personal
Report file date: Thursday, May 15, 2008 18:20
Scanning for 1266589 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 3, v.3311) [5.1.2600]
Boot mode: Normally booted
Username: SYSTEM
Computer name: GHETTOBOX
Version information:
BUILD.DAT : 8.1.00.295 16479 Bytes 4/9/2008 16:24:00
AVSCAN.EXE : 8.1.2.12 311553 Bytes 3/18/2008 18:02:56
AVSCAN.DLL : 8.1.1.0 53505 Bytes 2/7/2008 17:43:37
LUKE.DLL : 8.1.2.9 151809 Bytes 2/28/2008 17:41:23
LUKERES.DLL : 8.1.2.1 12033 Bytes 2/21/2008 17:28:40
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 7/18/2007 19:33:34
ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 3/7/2008 22:08:58
ANTIVIR2.VDF : 7.0.4.0 1554432 Bytes 5/5/2008 01:18:44
ANTIVIR3.VDF : 7.0.4.39 197120 Bytes 5/14/2008 01:18:46
Engineversion : 8.1.0.42
AEVDF.DLL : 8.1.0.5 102772 Bytes 2/25/2008 18:58:21
AESCRIPT.DLL : 8.1.0.31 262522 Bytes 5/16/2008 01:19:01
AESCN.DLL : 8.1.0.16 119156 Bytes 5/16/2008 01:19:00
AERDL.DLL : 8.1.0.20 418165 Bytes 5/16/2008 01:18:59
AEPACK.DLL : 8.1.1.4 364918 Bytes 5/16/2008 01:18:58
AEOFFICE.DLL : 8.1.0.18 192890 Bytes 5/16/2008 01:18:56
AEHEUR.DLL : 8.1.0.26 1237366 Bytes 5/16/2008 01:18:55
AEHELP.DLL : 8.1.0.14 115063 Bytes 5/16/2008 01:18:51
AEGEN.DLL : 8.1.0.20 299380 Bytes 5/16/2008 01:18:50
AEEMU.DLL : 8.1.0.6 430451 Bytes 5/16/2008 01:18:48
AECORE.DLL : 8.1.0.28 168310 Bytes 5/16/2008 01:18:47
AVWINLL.DLL : 1.0.0.7 14593 Bytes 1/24/2008 02:07:53
AVPREF.DLL : 8.0.0.1 25857 Bytes 2/18/2008 19:37:50
AVREP.DLL : 7.0.0.1 155688 Bytes 4/16/2007 22:26:47
AVREG.DLL : 8.0.0.0 30977 Bytes 1/24/2008 02:07:49
AVARKT.DLL : 1.0.0.23 307457 Bytes 2/12/2008 17:29:23
AVEVTLOG.DLL : 8.0.0.11 114945 Bytes 2/28/2008 17:31:31
SQLITE3.DLL : 3.3.17.1 339968 Bytes 1/23/2008 02:28:02
SMTPLIB.DLL : 1.2.0.19 28929 Bytes 1/24/2008 02:08:39
NETNT.DLL : 8.0.0.1 7937 Bytes 1/25/2008 21:05:10
RCIMAGE.DLL : 8.0.0.35 2371841 Bytes 3/10/2008 23:37:25
RCTEXT.DLL : 8.0.32.0 86273 Bytes 3/6/2008 21:02:11
Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: on
Scan boot sector.................: on
Boot sectors.....................: C:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Start of the scan: Thursday, May 15, 2008 18:20
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'Ymsgr_tray.exe' - '1' Module(s) have been scanned
Scan process 'devldr32.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
Scan process 'jusched.exe' - '1' Module(s) have been scanned
Scan process 'rundll32.exe' - '1' Module(s) have been scanned
Scan process 'firefox.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'iexplore.exe' - '1' Module(s) have been scanned
Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'aawservice.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
28 processes with 28 modules were scanned
Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Starting to scan the registry.
The registry was scanned ( '25' files ).
Starting the file scan:
Begin scan in 'C:\'
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\Documents and Settings\Akyouser\Local Settings\Temp\awaxfuvm.dll
[DETECTION] Is the Trojan horse TR/Monder.105472
[NOTE] The file was moved to '488de204.qua'!
C:\Documents and Settings\Akyouser\Local Settings\Temp\bbreplgx.dll
[DETECTION] Is the Trojan horse TR/PCK.Monder.104448.1
[NOTE] The file was moved to '489ee1fe.qua'!
C:\Documents and Settings\Akyouser\Local Settings\Temp\bnkvnsmo.dll
[DETECTION] Is the Trojan horse TR/PCK.Monder.96256.2
[NOTE] The file was moved to '4897e20d.qua'!
C:\Documents and Settings\Akyouser\Local Settings\Temp\ccuybrab.dll
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[WARNING] An error has occurred and the file was not deleted. ErrorID: 26003
[WARNING]
C:\Documents and Settings\Akyouser\Local Settings\Temp\cpixkesj.dll
[DETECTION] Is the Trojan horse TR/PCK.Monder.104512.1
[NOTE] The file was moved to '4895e220.qua'!
C:\Documents and Settings\Akyouser\Local Settings\Temp\djlqovwy.dll
[DETECTION] Is the Trojan horse TR/PCK.Monder.96256.1
[NOTE] The file was moved to '4898e21d.qua'!
C:\Documents and Settings\Akyouser\Local Settings\Temp\fkimerpm.dll
[DETECTION] Is the Trojan horse TR/PCK.Monder.104448
[NOTE] The file was moved to '4895e223.qua'!
C:\Documents and Settings\Akyouser\Local Settings\Temp\fxnshgxm.dll
[DETECTION] Is the Trojan horse TR/PCK.Monder.96256
[NOTE] The file was moved to '489ae231.qua'!
C:\Documents and Settings\Akyouser\Local Settings\Temp\iptdcnxv.dll
[DETECTION] Is the Trojan horse TR/Monder.107008
[NOTE] The file was moved to '48a0e22b.qua'!
C:\Documents and Settings\Akyouser\Local Settings\Temp\lhflxbce.dll
[DETECTION] Is the Trojan horse TR/PCK.Monder.107008
[NOTE] The file was moved to '4892e223.qua'!
C:\Documents and Settings\Akyouser\Local Settings\Temp\mhiguqfv.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '49e4c9ac.qua'!
C:\Documents and Settings\Akyouser\Local Settings\Temp\pscdonwf.dll
[DETECTION] Is the Trojan horse TR/Monder.96320
[NOTE] The file was moved to '488fe22f.qua'!
C:\Documents and Settings\Akyouser\Local Settings\Temp\qbvgoxxo.dll
[DETECTION] Is the Trojan horse TR/PCK.Monder.97792
[NOTE] The file was moved to '48a2e21e.qua'!
C:\Documents and Settings\Akyouser\Local Settings\Temp\qvgdxdyc.dll
[DETECTION] Is the Trojan horse TR/Monder.105536
[NOTE] The file was moved to '4893e233.qua'!
C:\Documents and Settings\Akyouser\Local Settings\Temp\rerxavvp.dll
[DETECTION] Is the Trojan horse TR/Agent.3648.1
[WARNING] An error has occurred and the file was not deleted. ErrorID: 26003
[WARNING]
C:\Documents and Settings\Akyouser\Local Settings\Temp\tcsxyefq.exe
[DETECTION] Is the Trojan horse TR/PrivacySet.A
[WARNING] An error has occurred and the file was not deleted. ErrorID: 26003
[WARNING]
C:\Documents and Settings\Akyouser\Local Settings\Temp\tpalbygf.dll
[DETECTION] Is the Trojan horse TR/PCK.Monder.107072.1
[NOTE] The file was moved to '488de236.qua'!
C:\Documents and Settings\Akyouser\Local Settings\Temp\vdlvgelb.dll
[DETECTION] Is the Trojan horse TR/PCK.Monder.105472
[NOTE] The file was moved to '4898e22a.qua'!
C:\Documents and Settings\Akyouser\Local Settings\Temporary Internet Files\Content.IE5\M5A9YZA9\glas[2]
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488de23a.qua'!
C:\Documents and Settings\Akyouser\Local Settings\Temporary Internet Files\Content.IE5\M5A9YZA9\glas[3]
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '49fed8f3.qua'!
C:\Documents and Settings\Akyouser\Local Settings\Temporary Internet Files\Content.IE5\M5A9YZA9\idkfa[1]
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '4897e233.qua'!
C:\Documents and Settings\Akyouser\Local Settings\Temporary Internet Files\Content.IE5\S3S1QDQB\0419bsz[1].exe
[DETECTION] Is the Trojan horse TR/Inject.GE.23
[NOTE] The file was moved to '485de20a.qua'!
C:\Documents and Settings\Akyouser\Local Settings\Temporary Internet Files\Content.IE5\S3S1QDQB\glas[2]
[DETECTION] Is the Trojan horse TR/PCK.Monder.104448.1
[NOTE] The file was moved to '488de248.qua'!
C:\Documents and Settings\Akyouser\Local Settings\Temporary Internet Files\Content.IE5\S3S1QDQB\yaypalassamosvala[1]
[DETECTION] Is the Trojan horse TR/PrivacySet.A
[NOTE] The file was moved to '48a5e243.qua'!
C:\Documents and Settings\Akyouser\Local Settings\Temporary Internet Files\Content.IE5\UFYD81Q1\CAQZ6N2H
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '487de226.qua'!
C:\Documents and Settings\Akyouser\Local Settings\Temporary Internet Files\Content.IE5\UFYD81Q1\CAZQIHBB
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '4886e227.qua'!
C:\Documents and Settings\Akyouser\Local Settings\Temporary Internet Files\Content.IE5\UFYD81Q1\kriv[1]
[DETECTION] Is the Trojan horse TR/Monder.96320
[NOTE] The file was moved to '4895e25b.qua'!
C:\Documents and Settings\Akyouser\Local Settings\Temporary Internet Files\Content.IE5\WD69UB4H\moorate[1]
[DETECTION] Is the Trojan horse TR/Agent.3648.1
[NOTE] The file was moved to '489be264.qua'!
C:\Old40G\My Documents\files\College.Wild.Parties.11.English.XXX.DVDRip.XVID.exe
[0] Archive type: RAR SFX (self extracting)
--> 1.exe
[DETECTION] Is the Trojan horse TR/Crypt.CFI.Gen
[NOTE] The file was moved to '4898e3bf.qua'!
C:\Program Files\Common Files\Microsoft Shared\MSInfo\isasse.exe
[DETECTION] Is the Trojan horse TR/Crypt.CFI.Gen
[WARNING] An error has occurred and the file was not deleted. ErrorID: 26003
[WARNING]
C:\Program Files\Internet Explorer\Down(1).exe
[DETECTION] Is the Trojan horse TR/Inject.GE.23
[NOTE] The file was moved to '48a3e4e7.qua'!
C:\Program Files\Internet Explorer\Down(2).exe
[DETECTION] Is the Trojan horse TR/Inject.GE.23
[NOTE] The file was moved to '49dceb98.qua'!
C:\RECYCLER\S-1-5-21-1229272821-790525478-839522115-500\Dc1.dll
[DETECTION] Is the Trojan horse TR/Monder.DI
[NOTE] The file was moved to '485de5f8.qua'!
C:\System Volume Information\_restore{DFF21018-14DE-4B2A-969C-8A56F82DFB32}\RP41\A0024035.exe
[DETECTION] Is the Trojan horse TR/Crypt.CFI.Gen
[NOTE] The file was moved to '485ce67c.qua'!
C:\System Volume Information\_restore{DFF21018-14DE-4B2A-969C-8A56F82DFB32}\RP43\A0024103.exe
[DETECTION] Is the Trojan horse TR/Crypt.CFI.Gen
[NOTE] The file was moved to '485ce67f.qua'!
C:\System Volume Information\_restore{DFF21018-14DE-4B2A-969C-8A56F82DFB32}\RP44\A0025164.dll
[DETECTION] Is the Trojan horse TR/PCK.Monder.87104.1
[NOTE] The file was moved to '485ce681.qua'!
C:\System Volume Information\_restore{DFF21018-14DE-4B2A-969C-8A56F82DFB32}\RP44\A0025165.dll
[DETECTION] Is the Trojan horse TR/PCK.Monder.97856
[NOTE] The file was moved to '49dcf192.qua'!
C:\System Volume Information\_restore{DFF21018-14DE-4B2A-969C-8A56F82DFB32}\RP45\A0025185.dll
[DETECTION] Is the Trojan horse TR/PCK.Monder.106048
[NOTE] The file was moved to '485ce682.qua'!
C:\System Volume Information\_restore{DFF21018-14DE-4B2A-969C-8A56F82DFB32}\RP54\A0027699.dll
[DETECTION] Is the Trojan horse TR/PCK.Monder.95232
[NOTE] The file was moved to '485ce6ac.qua'!
C:\System Volume Information\_restore{DFF21018-14DE-4B2A-969C-8A56F82DFB32}\RP54\A0027711.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '49dcf1bd.qua'!
C:\System Volume Information\_restore{DFF21018-14DE-4B2A-969C-8A56F82DFB32}\RP54\A0027712.dll
[DETECTION] Is the Trojan horse TR/PCK.Monder.107072
[NOTE] The file was moved to '485ce6ae.qua'!
C:\System Volume Information\_restore{DFF21018-14DE-4B2A-969C-8A56F82DFB32}\RP54\A0027713.dll
[DETECTION] Is the Trojan horse TR/PCK.Monder.108544
[NOTE] The file was moved to '485ce6ad.qua'!
C:\System Volume Information\_restore{DFF21018-14DE-4B2A-969C-8A56F82DFB32}\RP54\A0027714.dll
[DETECTION] Is the Trojan horse TR/PCK.Monder.96320
[NOTE] The file was moved to '49dcf1be.qua'!
C:\System Volume Information\_restore{DFF21018-14DE-4B2A-969C-8A56F82DFB32}\RP54\A0027715.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '485ce6af.qua'!
C:\System Volume Information\_restore{DFF21018-14DE-4B2A-969C-8A56F82DFB32}\RP54\A0027716.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '49dcf1a0.qua'!
C:\System Volume Information\_restore{DFF21018-14DE-4B2A-969C-8A56F82DFB32}\RP54\A0027719.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '49dcf1bf.qua'!
C:\System Volume Information\_restore{DFF21018-14DE-4B2A-969C-8A56F82DFB32}\RP54\A0027720.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '485ce6d0.qua'!
C:\System Volume Information\_restore{DFF21018-14DE-4B2A-969C-8A56F82DFB32}\RP60\A0027838.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '485ce710.qua'!
C:\System Volume Information\_restore{DFF21018-14DE-4B2A-969C-8A56F82DFB32}\RP60\A0027840.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '49dcf001.qua'!
C:\System Volume Information\_restore{DFF21018-14DE-4B2A-969C-8A56F82DFB32}\RP60\A0027841.dll
[DETECTION] Is the Trojan horse TR/PCK.Monder.104448.1
[NOTE] The file was moved to '485ce712.qua'!
C:\System Volume Information\_restore{DFF21018-14DE-4B2A-969C-8A56F82DFB32}\RP63\A0028843.dll
[DETECTION] Is the Trojan horse TR/Monder.96320
[NOTE] The file was moved to '485ce713.qua'!
C:\System Volume Information\_restore{DFF21018-14DE-4B2A-969C-8A56F82DFB32}\RP63\A0028844.dll
[DETECTION] Is the Trojan horse TR/Monder.95296
[NOTE] The file was moved to '49dcf004.qua'!
C:\System Volume Information\_restore{DFF21018-14DE-4B2A-969C-8A56F82DFB32}\RP63\A0028845.dll
[DETECTION] Is the Trojan horse TR/Monder.DB
[NOTE] The file was moved to '485ce715.qua'!
C:\System Volume Information\_restore{DFF21018-14DE-4B2A-969C-8A56F82DFB32}\RP63\A0028846.dll
[DETECTION] Is the Trojan horse TR/Monder.96768
[NOTE] The file was moved to '485ce714.qua'!
C:\System Volume Information\_restore{DFF21018-14DE-4B2A-969C-8A56F82DFB32}\RP63\A0028847.dll
[DETECTION] Is the Trojan horse TR/Monder.96832
[NOTE] The file was moved to '49dcf005.qua'!
C:\System Volume Information\_restore{DFF21018-14DE-4B2A-969C-8A56F82DFB32}\RP64\A0028883.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '485ce716.qua'!
C:\System Volume Information\_restore{DFF21018-14DE-4B2A-969C-8A56F82DFB32}\RP64\A0028902.dll
[DETECTION] Is the Trojan horse TR/Monder.105024
[NOTE] The file was moved to '49dcf007.qua'!
C:\System Volume Information\_restore{DFF21018-14DE-4B2A-969C-8A56F82DFB32}\RP64\A0028904.dll
[DETECTION] Is the Trojan horse TR/Monder.104512
[NOTE] The file was moved to '485ce718.qua'!
C:\System Volume Information\_restore{DFF21018-14DE-4B2A-969C-8A56F82DFB32}\RP64\A0028905.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '485ce717.qua'!
C:\System Volume Information\_restore{DFF21018-14DE-4B2A-969C-8A56F82DFB32}\RP64\A0028906.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '49dcf008.qua'!
C:\System Volume Information\_restore{DFF21018-14DE-4B2A-969C-8A56F82DFB32}\RP64\A0028907.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '485ce719.qua'!
C:\System Volume Information\_restore{DFF21018-14DE-4B2A-969C-8A56F82DFB32}\RP64\A0028908.dll
[DETECTION] Is the Trojan horse TR/Monder.107584
[NOTE] The file was moved to '49dcf00a.qua'!
C:\System Volume Information\_restore{DFF21018-14DE-4B2A-969C-8A56F82DFB32}\RP64\A0028909.dll
[DETECTION] Is the Trojan horse TR/Monder.106560
[NOTE] The file was moved to '49dcf009.qua'!
C:\System Volume Information\_restore{DFF21018-14DE-4B2A-969C-8A56F82DFB32}\RP64\A0028910.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '485ce71a.qua'!
C:\System Volume Information\_restore{DFF21018-14DE-4B2A-969C-8A56F82DFB32}\RP64\A0028911.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '49dcf00b.qua'!
C:\System Volume Information\_restore{DFF21018-14DE-4B2A-969C-8A56F82DFB32}\RP64\A0028912.dll
[DETECTION] Is the Trojan horse TR/Monder.108544
[NOTE] The file was moved to '485ce71c.qua'!
C:\System Volume Information\_restore{DFF21018-14DE-4B2A-969C-8A56F82DFB32}\RP64\A0028913.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '485ce71b.qua'!
C:\System Volume Information\_restore{DFF21018-14DE-4B2A-969C-8A56F82DFB32}\RP66\A0029907.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '49dcf00c.qua'!
C:\System Volume Information\_restore{DFF21018-14DE-4B2A-969C-8A56F82DFB32}\RP66\A0029909.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '485ce71d.qua'!
C:\System Volume Information\_restore{DFF21018-14DE-4B2A-969C-8A56F82DFB32}\RP66\A0029917.dll
[DETECTION] Is the Trojan horse TR/Monder.DF
[NOTE] The file was moved to '49dcf00d.qua'!
C:\System Volume Information\_restore{DFF21018-14DE-4B2A-969C-8A56F82DFB32}\RP66\A0029918.dll
[DETECTION] Is the Trojan horse TR/Monder.DE
[NOTE] The file was moved to '485ce71e.qua'!
C:\System Volume Information\_restore{DFF21018-14DE-4B2A-969C-8A56F82DFB32}\RP66\A0029919.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '49dcf00f.qua'!
C:\System Volume Information\_restore{DFF21018-14DE-4B2A-969C-8A56F82DFB32}\RP67\A0029937.dll
[DETECTION] Is the Trojan horse TR/Monder.DJ
[NOTE] The file was moved to '49dcf00e.qua'!
C:\System Volume Information\_restore{DFF21018-14DE-4B2A-969C-8A56F82DFB32}\RP67\A0029939.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '485ce700.qua'!
C:\System Volume Information\_restore{DFF21018-14DE-4B2A-969C-8A56F82DFB32}\RP67\A0029958.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '49dcf011.qua'!
C:\System Volume Information\_restore{DFF21018-14DE-4B2A-969C-8A56F82DFB32}\RP69\A0029978.exe
[0] Archive type: RAR SFX (self extracting)
--> 1.exe
[DETECTION] Is the Trojan horse TR/Crypt.CFI.Gen
[NOTE] The file was moved to '485ce723.qua'!
C:\System Volume Information\_restore{DFF21018-14DE-4B2A-969C-8A56F82DFB32}\RP69\A0029979.exe
[DETECTION] Is the Trojan horse TR/Inject.GE.23
[NOTE] The file was moved to '49dcf034.qua'!
C:\System Volume Information\_restore{DFF21018-14DE-4B2A-969C-8A56F82DFB32}\RP69\A0029980.exe
[DETECTION] Is the Trojan horse TR/Inject.GE.23
[NOTE] The file was moved to '485ce724.qua'!
C:\System Volume Information\_restore{DFF21018-14DE-4B2A-969C-8A56F82DFB32}\RP69\A0029981.dll
[DETECTION] Is the Trojan horse TR/Monder.DI
[NOTE] The file was moved to '485ce725.qua'!
C:\WINDOWS\system32\ciwffxik.exe
[DETECTION] Is the Trojan horse TR/PrivacySet.A
[NOTE] The file was moved to '48a3e8f3.qua'!
C:\WINDOWS\system32\cleshpdb.exe
[DETECTION] Is the Trojan horse TR/PrivacySet.A
[NOTE] The file was moved to '4891e8f6.qua'!
C:\WINDOWS\system32\fhtglhon.exe
[DETECTION] Is the Trojan horse TR/PrivacySet.A
[NOTE] The file was moved to '48a0e8f9.qua'!
C:\WINDOWS\system32\gghrwvcg.dll
[DETECTION] Is the Trojan horse TR/Agent.3648.1
[NOTE] The file was moved to '4894e8f8.qua'!
C:\WINDOWS\system32\igujbmcd.exe
[DETECTION] Is the Trojan horse TR/PrivacySet.A
[NOTE] The file was moved to '48a1e8fa.qua'!
C:\WINDOWS\system32\issaue.exe
[DETECTION] Is the Trojan horse TR/Inject.GE.23
[NOTE] The file was moved to '489fe908.qua'!
C:\WINDOWS\system32\psdsiixq.exe
[DETECTION] Is the Trojan horse TR/PrivacySet.A
[NOTE] The file was moved to '4890e91a.qua'!
C:\WINDOWS\system32\syeapuvi.exe
[DETECTION] Is the Trojan horse TR/PrivacySet.A
[NOTE] The file was moved to '4891e926.qua'!
C:\WINDOWS\system32\tuvULdcD.dll_old
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[WARNING] An error has occurred and the file was not deleted. ErrorID: 26003
[WARNING]
C:\WINDOWS\system32\drivers\sptd.sys
[WARNING] The file could not be opened!
End of the scan: Thursday, May 15, 2008 18:52
Used time: 31:49 min
The scan has been done completely.
5381 Scanning directories
311654 Files were scanned
88 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
0 files were deleted
0 files were repaired
83 files were moved to quarantine
0 files were renamed
2 Files cannot be scanned
311566 Files not concerned
2061 Archives were scanned
7 Warnings
83 Notes
HiJack This! Log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:58:13 PM, on 5/15/2008
Platform: Windows XP SP3, v.3311 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.3311)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Old40G\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\program files\internet explorer\IEXPLORE.EXE
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
O2 - BHO: {c0880f51-c276-cb5a-05f4-a8103f357f60} - {06f753f3-018a-4f50-a5bc-672c15f0880c} - C:\WINDOWS\system32\fysqtrxe.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {A64160E5-66F4-47A0-AD2D-E829A5B313A0} - C:\WINDOWS\system32\pmnlKBTJ.dll (file missing)
O2 - BHO: (no name) - {A6C54318-5AC7-477D-B0A7-49AF5189300C} - C:\WINDOWS\system32\ljJYRLFY.dll
O2 - BHO: (no name) - {FD6A66CF-34AD-48E8-9776-19AD262817C4} - C:\WINDOWS\system32\tuvULdcD.dll (file missing)
O2 - BHO: (no name) - {FE14858E-1888-497E-A80A-EDFF86F48E35} - C:\WINDOWS\system32\geBTLbcD.dll (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [msnmsgr] "C:\Old40G\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "C:\Program Files\DAEMON Tools Pro\DTProAgent.exe"
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.mi...b?1209447015796O20 - Winlogon Notify: ljJYRLFY - C:\WINDOWS\SYSTEM32\ljJYRLFY.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Avira AntiVir Personal Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Windows Display Driver Managerment - Unknown owner - C:\Program Files\Common Files\Microsoft Shared\MSINFO\isasse.exe (file missing)
--
End of file - 4456 bytes