-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Wednesday, May 28, 2008 4:35:35 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 28/05/2008
Kaspersky Anti-Virus database records: 809537
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\
I:\
Scan Statistics:
Total number of scanned objects: 139778
Number of viruses found: 6
Number of infected objects: 13
Number of suspicious objects: 0
Duration of the scan process: 01:25:06
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Nero\Nero8\Nero BackItUp\Cache\NeroBackItUpScheduler3.log Object is locked skipped
C:\Documents and Settings\FEDERAL\Application Data\Webroot\Spy Sweeper\Logs\080528145146.ses Object is locked skipped
C:\Documents and Settings\FEDERAL\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\FEDERAL\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\FEDERAL\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\FEDERAL\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\FEDERAL\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\FEDERAL\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\FEDERAL\My Documents\Azureus Downloads\software\Nero 8 Ultra Edition 8.3.0 Multilanguage FULL Retail\Nero 8.3.0.iso/Nero PhotoShow Express/nero_photoshow_express_5_setup.exe/data0017 Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\Documents and Settings\FEDERAL\My Documents\Azureus Downloads\software\Nero 8 Ultra Edition 8.3.0 Multilanguage FULL Retail\Nero 8.3.0.iso/Nero PhotoShow Express/nero_photoshow_express_5_setup.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\Documents and Settings\FEDERAL\My Documents\Azureus Downloads\software\Nero 8 Ultra Edition 8.3.0 Multilanguage FULL Retail\Nero 8.3.0.iso/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\Documents and Settings\FEDERAL\My Documents\Azureus Downloads\software\Nero 8 Ultra Edition 8.3.0 Multilanguage FULL Retail\Nero 8.3.0.iso ISOimage: infected - 3 skipped
C:\Documents and Settings\FEDERAL\My Documents\Rars\System Mechanic Professional.7.keygen.zip/SM.7.1.8/SM7_activator.exe/lsass.exe Infected: Backdoor.Win32.MoSucker.ee skipped
C:\Documents and Settings\FEDERAL\My Documents\Rars\System Mechanic Professional.7.keygen.zip/SM.7.1.8/SM7_activator.exe Infected: Backdoor.Win32.MoSucker.ee skipped
C:\Documents and Settings\FEDERAL\My Documents\Rars\System Mechanic Professional.7.keygen.zip ZIP: infected - 2 skipped
C:\Documents and Settings\FEDERAL\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\FEDERAL\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Data\settings.dat Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS01866C4B-6FE0-41DD-81D6-CF9ED5E9CB2D.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS0267D2D4-49C0-4FBA-A801-BB1836C57D5B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS02DED4DE-63B2-4930-A28C-528040224937.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS0748621D-F8F2-4B72-B61C-85C61D4C1B7D.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS07FB3654-D89F-49B6-9261-937327549F46.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS0852F277-3660-44BE-9C87-E20DEE0F6583.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS0897328F-8839-4FDF-8F5D-AD06D23DB196.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS0C2F348B-9F4D-4B28-B27D-0FD8C5B589CF.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS10E87ED3-D99A-4761-AE3F-DEC130EC9C38.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS11825BEA-4DC7-417B-A627-8EE6EFD0DA16.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS11DCF53B-5106-455D-850F-0277D8F17D87.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS12143206-5513-45ED-B0F6-47651CD9A380.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS1A0151DB-654F-40C6-A3E8-CC0B3ED78048.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS1B5E4610-11F2-41CC-AC38-FE37C9C16C8F.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS262DF378-C9A6-4B51-BC62-3A230E9BEC68.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS29CDF6A8-C29A-4F1C-84C3-F9D941EA0793.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2D5C1C58-D8ED-4D36-8F70-05A8909CDE26.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2D7FA2F9-76EB-42E7-9251-171095F67275.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2FFF0C9A-B97E-4E60-87A0-DE3A15A959F8.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS34F2139A-FF32-41A8-9788-2CB4F69A9154.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS3609496B-4B6B-4896-A101-0CCD2F952A1D.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS36E5D1E6-CDCF-4AAE-B495-AA26390A4537.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS428FB964-4896-49E6-9E75-69F25A136783.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS430DABD1-04AD-40F1-9157-9871011C9FA2.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS43A70434-BDFE-421D-8951-DD7BE67A385F.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS45A42172-3642-43DF-A6BA-C3523C44923D.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS4902488A-281F-4E07-80BA-190D021012D8.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS4EF35B54-7E6A-4731-8414-1357B6146DA5.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5008F04F-C566-4C61-8721-55E4812FD735.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS529D5AC7-CBC3-4B21-9EE4-409BE7E10B07.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS54EA31A3-CB8B-4B70-A1D9-F8EF0372DF8D.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS55EBFA92-A1D3-4147-BAEC-8FEB065A3B40.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS56C863DE-61F0-4902-931E-D34609F7FEC4.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5C5A7A56-E60C-4E15-817C-375AD705B697.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS62CB4B9F-8376-4CDA-B0C5-B426A0C5A818.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS648C6415-9711-4B01-8B96-78409D5F1EB5.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS66D19BB0-7203-4AF4-A733-8DBBE3FCA61F.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS67D3A07B-DA95-476B-A96C-D9990BB0CED7.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6DE756DE-63AF-4A31-9E89-6F3E0E094168.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS73D18A59-A141-4389-90C8-F5149A0FC073.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS73FA1452-7759-4481-BF7B-8ECED8FE3223.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS751D986B-3CC6-4DDF-8E47-038A5CDD82DC.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS7D32E206-462A-45D2-A1BA-94C00344371C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS7E5D2268-C174-4782-87FA-F84E13EA89B4.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS8026A15D-959E-4A0B-B4C9-E8E9DAE39C4E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS8A22EC05-31B4-4A05-A211-D845DE126176.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS8C107B0A-AD08-4D4B-9BB5-F1EE0688E5A9.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS8E94ED50-F10B-480B-B135-6A1D4DA59038.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS916737DA-C2F9-4F3D-80F9-93FDAA93A498.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS91EF34F4-5622-47A5-A284-2D46A6B2A185.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9264AFD6-2793-4EA0-A199-1C91CD3DE9BC.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS997205EB-A01D-4386-B1A4-0F3B91B33DA1.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9DA8B869-CA66-445D-822E-A93342CBF605.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9FD737CD-18B1-4B8F-90D7-2D6B0B554395.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA14E7B5F-99FD-4E5F-9414-0CCF96FE6AE6.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA6603A35-9CEE-4318-B6C1-DF060D6C90D9.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA69F8BBC-8B9B-400D-8850-9FF07187F677.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSAAD13BF7-68EE-4E21-B758-1828AFA67A3D.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSAEB4F8FD-2188-4401-BDD1-520AC22A3DFE.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB82F4D48-8C8D-4263-BCB1-4D26B6D5A37C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB92F73C1-135F-453B-81A1-C52EFD8CD495.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSBAB1D41D-A86C-422E-99C3-13B71DD0EC33.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSBB1D86B2-5614-43A9-8562-8A34CDBD263E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSBC3460EC-DB88-4FFF-9999-9D8B2EFEF90F.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSBE2A31CF-CBCC-4C57-973C-907ABC8435B6.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSBEF34F24-89B5-462C-BBD9-2003015CF408.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSBFFD3E09-7A46-4873-81FE-9E6DB1B45A66.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC21132B0-86C3-44D7-97B7-AABDD5305152.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC3DDC0E3-8C68-487A-84B7-0AAEF5AE47A2.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC79495F2-D538-4D73-A0C7-2A6DC41CE15E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSCDCEA4E4-8A05-4761-881A-F055B1E7046C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD076541E-9BF1-4ACE-8C6A-DFE0FE4C9389.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD37CBBE7-E72A-4CA2-B8A4-B18C1A93F8BF.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD3EB7B28-97D3-4131-B35C-9C5FFA2CFD2B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD808A4FE-28E2-40C8-8CA8-41B99D85E53E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD9024E3C-0BA2-4036-B53C-9299F0B3C339.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD956B5D8-E1A9-4ABF-9C20-3BA0E372751D.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSDF15B920-F216-4691-B15C-B6A4A4669846.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE2E0CC09-5C83-4B9D-BA78-4E9DF1C3DB2F.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE7A14E29-05CE-4205-B460-DB9E24492E52.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSEAB4DFB3-8FC6-4589-9F0E-5354FDEF168E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSEC6BD3A6-176D-4070-9B0B-BD4ECA41EC34.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSECF2CF66-5AE6-4DF6-BD0A-0E85D5D902F1.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF3220CAE-A4D5-4548-8A6C-22CEC081F0ED.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF4F60207-3211-4474-A265-4E4A4D82A1EA.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF6139FB4-3F39-46C3-BF61-D9F08813B559.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF938D60D-A367-4E23-9711-97F3962B62B6.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSFAF29850-0AA8-4814-980F-70F3AD74E300.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSFE81377C-F28E-408E-9E8F-D8E632F9E72E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\integ\avast.int Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\selfdef.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\report\Resident protection.txt Object is locked skipped
C:\Program Files\Nero\Nero8\Nero BackItUp\BIU1.txt Object is locked skipped
C:\Program Files\PeerGuardian2\history.db Object is locked skipped
C:\Program Files\Webroot\Spy Sweeper\Masters\masters.bak Object is locked skipped
C:\Program Files\Webroot\Spy Sweeper\Masters\Masters.const Object is locked skipped
C:\Program Files\Webroot\Spy Sweeper\Masters\masters.mst Object is locked skipped
C:\Program Files\Webroot\Spy Sweeper\Masters.base Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{423842DC-4966-4FD8-B284-A7AAE7DA7129}\RP138\A0020115.exe/data0000.cab/WinDll32.exe Infected: Backdoor.Win32.Small.dlv skipped
C:\System Volume Information\_restore{423842DC-4966-4FD8-B284-A7AAE7DA7129}\RP138\A0020115.exe/data0000.cab Infected: Backdoor.Win32.Small.dlv skipped
C:\System Volume Information\_restore{423842DC-4966-4FD8-B284-A7AAE7DA7129}\RP138\A0020115.exe Rsrc-Package: infected - 2 skipped
C:\System Volume Information\_restore{423842DC-4966-4FD8-B284-A7AAE7DA7129}\RP165\A0034993.exe Infected: not-a-virus:AdWare.Win32.Shopper.r skipped
C:\System Volume Information\_restore{423842DC-4966-4FD8-B284-A7AAE7DA7129}\RP173\A0036574.exe Infected: Trojan.Win32.Agent.qoh skipped
C:\System Volume Information\_restore{423842DC-4966-4FD8-B284-A7AAE7DA7129}\RP174\A0036622.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.tss skipped
C:\System Volume Information\_restore{423842DC-4966-4FD8-B284-A7AAE7DA7129}\RP174\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{0E5BEF9C-1442-4295-971F-E0466EF4CD5C}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_6b0.dat Object is locked skipped
C:\WINDOWS\Temp\_avast4_\Webshlock.txt Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
E:\System Volume Information\_restore{423842DC-4966-4FD8-B284-A7AAE7DA7129}\RP174\change.log Object is locked skipped
Scan process completed.
--------------------------------------------------------------------------------------------------------------------------------------------------------------
--------------------------------------------------------------------------------------------------------------------------------------------------------------
--------------------------------------------------------------------------------------------------------------------------------------------------------------
Deckard's System Scanner v20071014.68
Run by FEDERAL on 2008-05-28 16:39:32
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
-- Last 5 Restore Point(s) --
175: 2008-05-28 23:36:31 UTC - RP175 - Deckard's System Scanner Restore Point
174: 2008-05-28 17:12:52 UTC - RP174 - Software Distribution Service 3.0
173: 2008-05-27 15:13:07 UTC - RP173 - Installed Age of Empires III - The Asian Dynasties
172: 2008-05-27 15:09:27 UTC - RP172 - Eliminado Age of Empires III - The Asian Dynasties
171: 2008-05-27 13:24:38 UTC - RP171 - Instalado Age of Empires III - The Asian Dynasties
-- First Restore Point --
1: 2008-04-25 18:12:18 UTC - RP1 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
System Drive C: has 16.58 GiB (less than 15%) free.-- HijackThis (run as FEDERAL.exe) ---------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:40:07 PM, on 5/28/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\PeerGuardian2\pg2.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\MagicDisc\MagicDisc.exe
C:\Program Files\WallMaster\wallmast.exe
C:\WINDOWS\System32\PnkBstrA.exe
C:\WINDOWS\system32\Wacom_Tablet.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\WTablet\Wacom_TabletUser.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\Wacom_Tablet.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Documents and Settings\FEDERAL\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\FEDERAL.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {54018E98-10E3-46C6-9673-2999253F9C65} - C:\WINDOWS\system32\gebbCUKA.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SoundMAXPnP] "C:\Program Files\Analog Devices\Core\smax4pnp.exe"
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [CPU Power Monitor] "C:\Program Files\ASUS\AI Suite\AiGear3\CpuPowerMonitor.exe"
O4 - HKLM\..\Run: [Cpu Level Up help] "C:\Program Files\ASUS\AI Suite\CpuLevelUpHelp.exe"
O4 - HKLM\..\Run: [Ai Nap] "C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] "C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe"
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PeerGuardian] "C:\Program Files\PeerGuardian2\pg2.exe"
O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
O4 - Startup: WallMaster.lnk = C:\Program Files\WallMaster\wallmast.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) -
http://go.microsoft....k/?linkid=58813O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky...can_unicode.cabO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....k/?linkid=39204O16 - DPF: {1E3F1348-4370-4BBE-A67A-CC7ED824CA85} (Microsoft Genuine Advantage Self Support Tool) -
http://go.microsoft....k/?LinkId=82580O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.mi...b?1209156139453O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.mi...b?1209199948500O20 - Winlogon Notify: gebbCUKA - gebbCUKA.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\System32\PnkBstrA.exe
O23 - Service: TabletServiceWacom - Wacom Technology, Corp. - C:\WINDOWS\system32\Wacom_Tablet.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
--
End of file - 8386 bytes
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R1 SCDEmu - c:\windows\system32\drivers\scdemu.sys <Not Verified; PowerISO Computing, Inc.; scdemu>
R2 Haspnt - c:\windows\system32\drivers\haspnt.sys <Not Verified; Aladdin Knowledge Systems; Windows NT HASP Kernel Device Driver>
R3 mcdbus (Driver for MagicISO SCSI Host Controller) - c:\windows\system32\drivers\mcdbus.sys <Not Verified; MagicISO, Inc.; MagicISO SCSI Host Controller>
R3 pgfilter - c:\program files\peerguardian2\pgfilter.sys
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
R2 Bonjour Service (##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##) - "c:\program files\bonjour\mdnsresponder.exe" <Not Verified; Apple Computer, Inc.; Bonjour>
R2 Nero BackItUp Scheduler 3 - c:\program files\nero\nero8\nero backitup\nbservice.exe
R2 Viewpoint Manager Service - "c:\program files\viewpoint\common\viewpointservice.exe" <Not Verified; Viewpoint Corporation; Viewpoint Manager>
S3 FLEXnet Licensing Service - "c:\program files\common files\macrovision shared\flexnet publisher\fnplicensingservice.exe" <Not Verified; Macrovision Europe Ltd.; FLEXnet Publisher (32 bit)>
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: RTL8187_Wireless
Device ID: USB\VID_0BDA&PID_8187\0015AF19E03E
Manufacturer:
Name: RTL8187_Wireless
PNP Device ID: USB\VID_0BDA&PID_8187\0015AF19E03E
Service:
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: 1394 Net Adapter
Device ID: V1394\NIC1394\14F570311D800
Manufacturer: Microsoft
Name: 1394 Net Adapter
PNP Device ID: V1394\NIC1394\14F570311D800
Service: NIC1394
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Realtek RTL8169/8110 Family Gigabit Ethernet NIC
Device ID: PCI\VEN_10EC&DEV_8167&SUBSYS_820D1043&REV_10\4&19ABE7DE&0&20F0
Manufacturer: Realtek Semiconductor Corp.
Name: Realtek RTL8169/8110 Family Gigabit Ethernet NIC
PNP Device ID: PCI\VEN_10EC&DEV_8167&SUBSYS_820D1043&REV_10\4&19ABE7DE&0&20F0
Service: RTL8023xp
-- Scheduled Tasks -------------------------------------------------------------
2008-05-22 18:27:03 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
-- Files created between 2008-04-28 and 2008-05-28 -----------------------------
2008-05-28 14:56:52 0 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-28 14:56:51 0 d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-05-28 14:56:49 0 d-------- C:\WINDOWS\LastGood
2008-05-28 12:09:22 0 d-------- C:\Program Files\Trend Micro
2008-05-27 22:50:39 0 d-------- C:\VundoFix Backups
2008-05-27 11:11:13 0 d-------- C:\Documents and Settings\LocalService\Application Data\Webroot
2008-05-27 11:11:05 0 d-------- C:\Program Files\Webroot
2008-05-27 11:11:05 0 d-------- C:\Documents and Settings\FEDERAL\Application Data\Webroot
2008-05-27 11:11:05 0 d-------- C:\Documents and Settings\All Users\Application Data\Webroot
2008-05-27 08:21:57 164 --a------ C:\install.dat
2008-05-27 06:41:45 0 d-------- C:\Documents and Settings\All Users\Application Data\Age of Empires 3
2008-05-27 06:12:35 0 d-------- C:\Program Files\Microsoft Games
2008-05-26 11:38:37 0 d-------- C:\Documents and Settings\FEDERAL\scenes
2008-05-22 19:59:18 0 d-------- C:\Program Files\Lemonade Tycoon 2
2008-05-22 19:59:09 0 d-------- C:\Program Files\ReflexiveArcade
2008-05-22 19:46:03 0 d-------- C:\Program Files\TryMedia
2008-05-21 10:24:42 96256 --a------ C:\WINDOWS\system32\drivers\mcdbus.sys <Not Verified; MagicISO, Inc.; MagicISO SCSI Host Controller>
2008-05-21 10:24:42 0 d-------- C:\Program Files\MagicDisc
2008-05-21 10:07:09 0 d-------- C:\Program Files\DAEMON Tools Lite
2008-05-20 09:51:10 717296 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2008-05-20 09:51:05 0 d-------- C:\Documents and Settings\FEDERAL\Application Data\DAEMON Tools
2008-05-19 20:46:21 0 d-------- C:\Documents and Settings\LocalService\Application Data\WTablet
2008-05-18 22:13:15 0 d-------- C:\Documents and Settings\FEDERAL\Application Data\acccore
2008-05-18 22:12:57 0 d-------- C:\Program Files\Viewpoint
2008-05-18 22:12:57 0 d-------- C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-05-18 22:12:49 0 d-------- C:\Documents and Settings\All Users\Application Data\AOL
2008-05-18 22:12:49 0 d-------- C:\Documents and Settings\All Users\Application Data\AOL OCP
2008-05-18 22:12:34 0 d-------- C:\Program Files\Common Files\AOL
2008-05-18 22:12:21 0 d-------- C:\Program Files\AIM6
2008-05-18 21:57:45 0 d-------- C:\Program Files\MSXML 4.0
2008-05-11 22:38:49 0 d-------- C:\Documents and Settings\FEDERAL\Application Data\Nero
2008-05-11 22:35:58 0 d-------- C:\Program Files\Nero
2008-05-11 22:35:58 0 d-------- C:\Program Files\Common Files\Nero
2008-05-11 22:35:58 0 d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-05-11 22:34:26 0 d-------- C:\Program Files\[bleep] NFO Viewer
2008-05-05 11:15:07 0 d-------- C:\Documents and Settings\FEDERAL\Application Data\WTablet
2008-05-05 11:14:40 0 d-------- C:\WINDOWS\system32\WTablet
2008-05-05 11:14:34 0 d-------- C:\Program Files\Tablet
2008-05-05 10:09:34 0 d-------- C:\WINDOWS\SHELLNEW
2008-05-05 10:09:32 0 d-------- C:\Program Files\Microsoft ActiveSync
2008-05-05 09:37:17 0 d-------- C:\Program Files\PeerGuardian2
2008-04-30 17:27:27 0 d-------- C:\Program Files\Common Files\Idu
2008-04-30 17:27:03 0 d-------- C:\Program Files\WarZone
2008-04-30 17:26:27 0 d-------- C:\Program Files\Microprose
2008-04-30 11:04:16 0 d-------- C:\Program Files\iPod
2008-04-30 11:04:11 0 d-------- C:\Program Files\iTunes
2008-04-30 11:03:45 0 d-------- C:\Program Files\Common Files\Apple
2008-04-30 11:02:20 0 d-------- C:\Program Files\Apple Software Update
2008-04-30 11:02:20 0 d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-04-29 21:07:00 0 d-------- C:\WINDOWS\pss
2008-04-29 17:12:31 0 d--hs---- C:\found.000
2008-04-28 16:45:19 0 d-------- C:\Documents and Settings\FEDERAL\Application Data\Songbird1
2008-04-28 16:44:55 0 d-------- C:\Documents and Settings\All Users\Application Data\SongbirdVLC
2008-04-28 11:38:05 0 d-------- C:\Documents and Settings\All Users\Application Data\LogiShrd
2008-04-28 11:37:44 0 d-------- C:\Documents and Settings\FEDERAL\Application Data\Logitech
2008-04-28 11:36:41 0 d-------- C:\Documents and Settings\All Users\Application Data\Logitech
2008-04-28 11:36:39 0 d-------- C:\Program Files\Common Files\Logishrd
2008-04-28 11:36:37 0 d-------- C:\Program Files\Logitech
2008-04-28 09:22:25 0 d-------- C:\Program Files\Lavasoft
2008-04-28 09:22:25 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-04-28 09:22:07 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-28 09:20:26 0 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
-- Find3M Report ---------------------------------------------------------------
2008-05-28 11:36:38 0 d-------- C:\Documents and Settings\FEDERAL\Application Data\Azureus
2008-05-27 22:54:33 0 d-------- C:\Program Files\Poweriso
2008-05-27 06:30:04 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-05-24 14:55:48 0 d-------- C:\Documents and Settings\FEDERAL\Application Data\Adobe
2008-05-19 15:45:39 0 d-------- C:\Program Files\WallMaster
2008-05-18 22:12:34 0 d-------- C:\Program Files\Common Files
2008-05-08 11:51:19 0 d-------- C:\Program Files\Winamp
2008-04-30 12:15:27 0 d-------- C:\Program Files\Azureus
2008-04-30 11:04:31 0 d-------- C:\Documents and Settings\FEDERAL\Application Data\Apple Computer
2008-04-28 16:45:21 0 d-------- C:\Documents and Settings\FEDERAL\Application Data\Mozilla
2008-04-28 09:18:04 0 d-------- C:\Program Files\MagicISO
2008-04-27 13:33:19 0 d-------- C:\Program Files\Next Limit
2008-04-27 13:26:28 6656 --a------ C:\WINDOWS\system32\haspvdd.dll <Not Verified; Aladdin Knowledge Systems.; Windows NT HASP Virtual Device Driver>
2008-04-27 13:26:28 383 --a------ C:\WINDOWS\system32\haspdos.sys
2008-04-27 13:26:25 0 d-------- C:\Program Files\Aladdin
2008-04-27 13:24:28 0 d-------- C:\Program Files\2d3
2008-04-27 12:56:47 0 d-------- C:\Program Files\Common Files\Adobe
2008-04-27 12:56:21 0 d-------- C:\Program Files\Bonjour
2008-04-27 12:49:29 0 d-------- C:\Program Files\Common Files\Macrovision Shared
2008-04-27 10:38:00 0 d-------- C:\Program Files\Messenger
2008-04-26 20:30:02 0 d-------- C:\Documents and Settings\FEDERAL\Application Data\vlc
2008-04-26 19:53:33 0 d-------- C:\Program Files\VideoLAN
2008-04-26 18:49:38 0 d-------- C:\Documents and Settings\FEDERAL\Application Data\WinRAR
2008-04-26 18:09:48 0 d-------- C:\Program Files\K-Lite Codec Pack
2008-04-26 15:14:45 0 d-------- C:\Program Files\QuickTime
2008-04-26 15:10:01 0 d-------- C:\Documents and Settings\FEDERAL\Application Data\Help
2008-04-26 15:07:28 0 d-------- C:\Program Files\Alwil Software
2008-04-26 14:42:23 0 d-------- C:\Program Files\Movie Maker
2008-04-26 14:41:22 0 d-------- C:\Program Files\Windows NT
2008-04-26 13:58:55 0 d-------- C:\Documents and Settings\FEDERAL\Application Data\Winamp
2008-04-26 01:14:05 1160 --a------ C:\WINDOWS\mozver.dat
2008-04-25 14:07:49 0 d-------- C:\Program Files\AveIconifier2
2008-04-25 14:06:24 0 d-------- C:\Program Files\Cogito Research
2008-04-25 13:55:41 0 d-------- C:\Program Files\Devious Codeworks
2008-04-25 13:31:33 0 d-------- C:\Program Files\Activision
2008-04-25 13:27:11 0 d-------- C:\Documents and Settings\FEDERAL\Application Data\Macromedia
2008-04-25 13:13:38 0 d-------- C:\Program Files\support.com
2008-04-25 13:13:08 0 d-------- C:\Program Files\Common Files\SupportSoft
2008-04-25 13:07:27 0 d--h----- C:\Program Files\WindowsUpdate
2008-04-25 12:47:06 0 --a------ C:\WINDOWS\ativpsrm.bin
2008-04-25 12:45:35 0 d-------- C:\Program Files\Analog Devices
2008-04-25 12:43:49 0 d-------- C:\Program Files\ASUS
2008-04-25 12:41:52 0 d-------- C:\Program Files\Realtek
2008-04-25 12:41:48 0 d-------- C:\Documents and Settings\FEDERAL\Application Data\InstallShield
2008-04-25 12:41:35 0 d-------- C:\Program Files\Marvell
2008-04-25 12:39:29 0 d-------- C:\Program Files\Common Files\InstallShield
2008-04-25 12:07:15 0 d-------- C:\Program Files\Intel
2008-04-25 12:05:20 0 d-------- C:\Program Files\ATI Technologies
2008-04-25 11:12:13 0 d-------- C:\Documents and Settings\FEDERAL\Application Data\Identities
2008-04-25 11:09:19 0 d-------- C:\Program Files\microsoft frontpage
2008-04-25 11:09:12 0 -rahs---- C:\MSDOS.SYS
2008-04-25 11:09:12 0 -rahs---- C:\IO.SYS
2008-04-25 11:09:12 0 --a------ C:\CONFIG.SYS
2008-04-25 11:09:12 0 --a------ C:\AUTOEXEC.BAT
2008-04-25 11:07:22 0 d-------- C:\Program Files\Common Files\MSSoap
2008-04-25 11:06:56 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2008-04-25 11:06:45 0 d-------- C:\Program Files\Online Services
2008-04-25 11:06:36 0 d-------- C:\Program Files\MSN Gaming Zone
2008-04-24 13:16:26 0 --a------ C:\WINDOWS\nsreg.dat
2008-04-21 12:58:31 0 d-------- C:\Documents and Settings\FEDERAL\Application Data\Sun
2008-04-18 17:22:19 0 d-------- C:\Program Files\Java
2008-04-18 17:21:46 0 d-------- C:\Program Files\Common Files\Java
2008-04-18 07:44:27 0 d-------- C:\Program Files\MAXON
2008-04-18 07:21:40 0 d-------- C:\Program Files\KellySoftware
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{54018E98-10E3-46C6-9673-2999253F9C65}]
C:\WINDOWS\system32\gebbCUKA.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [05/15/2008 04:19 PM]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [12/18/2006 09:34 PM]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [07/13/2006 07:12 AM]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [03/28/2008 11:37 PM]
"CPU Power Monitor"="C:\Program Files\ASUS\AI Suite\AiGear3\CpuPowerMonitor.exe" [10/16/2007 11:35 AM]
"Cpu Level Up help"="C:\Program Files\ASUS\AI Suite\CpuLevelUpHelp.exe" [11/30/2007 08:03 PM]
"Ai Nap"="C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe" [12/10/2007 09:49 PM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [03/30/2008 10:36 AM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [02/22/2008 04:25 AM]
"NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [03/01/2007 03:57 PM]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [08/08/2007 09:25 AM]
"SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [07/19/2007 10:54 PM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 12:56 AM]
"PeerGuardian"="C:\Program Files\PeerGuardian2\pg2.exe" [09/18/2005 06:40 PM]
"Aim6"="" []
C:\Documents and Settings\FEDERAL\Start Menu\Programs\Startup\
MagicDisc.lnk - C:\Program Files\MagicDisc\MagicDisc.exe [5/21/2008 10:24:42 AM]
WallMaster.lnk - C:\Program Files\WallMaster\wallmast.exe [5/19/2008 3:45:36 PM]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [4/28/2008 11:36:54 AM]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{54018E98-10E3-46C6-9673-2999253F9C65}"= C:\WINDOWS\system32\gebbCUKA.dll [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gebbCUKA]
gebbCUKA.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll 01/09/2008 12:30 PM 72208 c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
AutoRun\command- H:\autorun.exe
setup\command- H:\instalar.exe
*Newly Created Service* - PGFILTER
-- Hosts -----------------------------------------------------------------------
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
8385 more entries in hosts file.
-- End of Deckard's System Scanner: finished at 2008-05-28 16:41:01 ------------
Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------
-- System Information ----------------------------------------------------------
Microsoft Windows XP Home Edition (build 2600) SP 2.0
Architecture: X86; Language: English
CPU 0: Intel® Core2 Quad CPU Q6600 @ 2.40GHz
CPU 1: Intel® Core2 Quad CPU Q6600 @ 2.40GHz
CPU 2: Intel® Core2 Quad CPU Q6600 @ 2.40GHz
CPU 3: Intel® Core2 Quad CPU Q6600 @ 2.40GHz
Percentage of Memory in Use: 20%
Physical Memory (total/avail): 3327.04 MiB / 2636.88 MiB
Pagefile Memory (total/avail): 6491.66 MiB / 5951.79 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1929.5 MiB
A: is Removable (No Media)
C: is Fixed (NTFS) - 153.38 GiB total, 16.58 GiB free.
D: is CDROM (No Media)
E: is Fixed (NTFS) - 232.88 GiB total, 208.23 GiB free.
F: is CDROM (No Media)
G: is CDROM (No Media)
H: is CDROM (No Media)
I: is Removable (FAT32)
\\.\PHYSICALDRIVE0 - WDC WD1600YS-01SHB1 - 153.38 GiB - 1 partition
\PARTITION0 (bootable) - Installable File System - 153.38 GiB - C:
\\.\PHYSICALDRIVE1 - WDC WD2500KS-00MJB0 - 232.88 GiB - 1 partition
\PARTITION0 (bootable) - Installable File System - 232.88 GiB - E:
\\.\PHYSICALDRIVE2 - Apple iPod USB Device - 972.69 MiB - 1 partition
\PARTITION0 - Unknown - 894.24 MiB - I:
-- Security Center ---