I ran adaware and spyware doctor. I then ran trojan hunter and ewido scans. I double checked my windows updates and they are fine. I also ran kasperspy last night, though i did this prior to running the trojan and ewido. Finally, here I am with the logs for ewido, trojan hunter, and HJT. I also turned the system restore off, rebooted, turned it back on, rebooted, and also cleaned out the temp files/cookies.
One other problem, hopefully it will reveal itself here, is that when I go to shutdown I get two error messages stating the SLRACLUI.EXE DLL initialization failed and DMOEDLIN.EXE initialization failed.
Here's the logs...
EWIDO...
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 9:17:55 AM, 11/16/2005
+ Report-Checksum: FADCAB8E
+ Scan result:
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\ins -> Spyware.WebRebates : Cleaned with backup
HKU\S-1-5-21-3567388149-3575068407-513705992-1005\Software\Classes\CLSID\\ -> Spyware.AproposMedia : Cleaned with backup
HKU\S-1-5-21-3567388149-3575068407-513705992-1005_Classes\CLSID\\ -> Spyware.AproposMedia : Error during cleaning
:mozilla.10:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.11:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.12:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.13:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.14:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.15:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.16:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.19:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.20:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.21:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.22:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.23:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.24:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.25:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.26:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.27:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.28:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.29:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.30:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.31:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.35:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.71:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.72:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.73:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.74:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.75:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.76:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.77:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.79:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
:mozilla.80:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
:mozilla.81:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
:mozilla.82:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.83:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.100:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.103:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.104:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.105:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.106:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.107:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.109:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.110:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.111:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.112:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.113:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.114:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.115:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.122:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.124:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.126:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.129:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.135:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.141:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.142:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.146:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.147:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.148:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.149:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.150:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.154:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.157:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.159:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.169:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.173:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.521:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.561:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
:mozilla.578:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.580:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.605:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.626:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Specificpop : Cleaned with backup
:mozilla.629:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.638:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.645:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.649:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.651:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.652:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.653:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.654:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.655:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.669:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.682:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.689:C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\gsze5yp0.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\user\Cookies\user@2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\user\Cookies\[email protected][2].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\user\Cookies\[email protected][2].txt -> Spyware.Cookie.Pointroll : Cleaned with backup
C:\Documents and Settings\user\Cookies\user@advertising[2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\user\Cookies\user@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\user\Cookies\user@centrport[1].txt -> Spyware.Cookie.Centrport : Cleaned with backup
C:\Documents and Settings\user\Cookies\[email protected][1].txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
C:\Documents and Settings\user\Cookies\[email protected][1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\user\Cookies\user@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\user\Cookies\user@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\user\Cookies\[email protected][1].txt -> Spyware.Cookie.Ru4 : Cleaned with backup
C:\Documents and Settings\user\Cookies\[email protected][2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\user\Cookies\[email protected][1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\user\Cookies\[email protected][2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\user\Cookies\user@hitbox[1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\user\Cookies\user@mediaplex[2].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Documents and Settings\user\Cookies\[email protected][1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\user\Cookies\user@questionmarket[1].txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\user\Cookies\[email protected][1].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\user\Cookies\user@serving-sys[1].txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
C:\Documents and Settings\user\Cookies\user@statcounter[1].txt -> Spyware.Cookie.Statcounter : Cleaned with backup
C:\Documents and Settings\user\Cookies\user@tradedoubler[2].txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
C:\Documents and Settings\user\Cookies\user@trafficmp[1].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\user\Cookies\user@tribalfusion[2].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\user\Cookies\[email protected][1].txt -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Documents and Settings\user\Local Settings\Application Data\Wildtangent\Cdacache\00\00\0F.dat/files\wtvh.dll -> Spyware.WildTangent : Cleaned with backup
C:\Documents and Settings\user\Local Settings\Temp\Cookies\[email protected][1].txt -> Spyware.Cookie.Pointroll : Cleaned with backup
C:\Documents and Settings\user\Local Settings\Temp\Cookies\user@advertising[2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\user\Local Settings\Temp\Cookies\user@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\user\Local Settings\Temp\Cookies\[email protected][1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\user\Local Settings\Temp\Cookies\[email protected][1].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Documents and Settings\user\Local Settings\Temp\Cookies\[email protected][1].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Documents and Settings\user\Local Settings\Temp\Cookies\[email protected][1].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Documents and Settings\user\Local Settings\Temp\Cookies\[email protected][1].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Documents and Settings\user\Local Settings\Temp\Cookies\[email protected][2].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Documents and Settings\user\Local Settings\Temp\Cookies\[email protected][1].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Documents and Settings\user\Local Settings\Temp\Cookies\[email protected][2].txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
C:\Documents and Settings\user\Local Settings\Temp\Cookies\user@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\user\Local Settings\Temp\Cookies\[email protected][1].txt -> Spyware.Cookie.Valueclick : Cleaned with backup
C:\Documents and Settings\user\Local Settings\Temp\Cookies\user@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Documents and Settings\user\Local Settings\Temp\Cookies\user@questionmarket[1].txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\user\Local Settings\Temp\Cookies\[email protected][1].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\user\Local Settings\Temp\Cookies\user@sextracker[1].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Documents and Settings\user\Local Settings\Temp\Cookies\user@valueclick[1].txt -> Spyware.Cookie.Valueclick : Cleaned with backup
::Report End
Trojan Hunter
Registry scan
No suspicious entries found
Inifile scan
No suspicious entries found
Port scan
No suspicious open ports found
Memory scan
No trojans found in memory
File scan
Found trojan file: C:\Program Files\AT&T\WnClient\Programs\WnCSMServer.exe (Dialer)
1 trojan files found
Kasperspy (last night prior to the above)
-------------------------------------------------------------------------------
KASPERSKY ON-LINE SCANNER REPORT
Tuesday, November 15, 2005 20:26:00
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 16/11/2005
Kaspersky Anti-Virus database records: 150302
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
Scan Statistics:
Total number of scanned objects: 88360
Number of viruses found: 18
Number of infected objects: 146
Number of suspicious objects: 15
Duration of the scan process: 6767 sec
Infected Object Name - Virus Name
C:\Program Files\Norton AntiVirus\Quarantine\0268597F Infected: Net-Worm.Win32.Mytob.be
C:\Program Files\Norton AntiVirus\Quarantine\04350B90/document.txt .exe Infected: Email-Worm.Win32.NetSky.q
C:\Program Files\Norton AntiVirus\Quarantine\04350B90 Infected: Email-Worm.Win32.NetSky.q
C:\Program Files\Norton AntiVirus\Quarantine\0B1D2C85/[From Mail Delivery System <[email protected]>][Date Wed, 26 Jan 2005 08:49:21 -0800]/UNNAMED/[From [email protected]][Date Wed, 26 Jan 2005 11:49:17 -0500]/UNNAMED/UNNAMED/html Suspicious: Exploit.HTML.Iframe.FileDownload
C:\Program Files\Norton AntiVirus\Quarantine\0B1D2C85/[From Mail Delivery System <[email protected]>][Date Wed, 26 Jan 2005 08:49:21 -0800]/UNNAMED/[From [email protected]][Date Wed, 26 Jan 2005 11:49:17 -0500]/UNNAMED/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload
C:\Program Files\Norton AntiVirus\Quarantine\0B1D2C85/[From Mail Delivery System <[email protected]>][Date Wed, 26 Jan 2005 08:49:21 -0800]/UNNAMED/[From [email protected]][Date Wed, 26 Jan 2005 11:49:17 -0500]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload
C:\Program Files\Norton AntiVirus\Quarantine\0B1D2C85/[From Mail Delivery System <[email protected]>][Date Wed, 26 Jan 2005 08:49:21 -0800]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload
C:\Program Files\Norton AntiVirus\Quarantine\0B1D2C85 Suspicious: Exploit.HTML.Iframe.FileDownload
C:\Program Files\Norton AntiVirus\Quarantine\0BD863AA/details.txt .pif Infected: Email-Worm.Win32.NetSky.q
C:\Program Files\Norton AntiVirus\Quarantine\0BD863AA Infected: Email-Worm.Win32.NetSky.q
C:\Program Files\Norton AntiVirus\Quarantine\0CBF2AB9/document.txt .exe Infected: Email-Worm.Win32.NetSky.q
C:\Program Files\Norton AntiVirus\Quarantine\0CBF2AB9 Infected: Email-Worm.Win32.NetSky.q
C:\Program Files\Norton AntiVirus\Quarantine\0D701E42 Infected: Exploit.HTML.Mht
C:\Program Files\Norton AntiVirus\Quarantine\0D701E42.htm Infected: Exploit.HTML.Mht
C:\Program Files\Norton AntiVirus\Quarantine\0E186F38/[From [email protected]][Date Fri, 06 May 2005 11:53:17 UTC]/error-mail_info.zip Infected: Email-Worm.Win32.Sober.p
C:\Program Files\Norton AntiVirus\Quarantine\0E186F38 Infected: Email-Worm.Win32.Sober.p
C:\Program Files\Norton AntiVirus\Quarantine\0E8E1E2C.htm Suspicious: Exploit.HTML.Mht
C:\Program Files\Norton AntiVirus\Quarantine\0E9B461E.class Infected: Trojan.Java.ClassLoader.c
C:\Program Files\Norton AntiVirus\Quarantine\0EB26C05.htm Suspicious: Exploit.HTML.Mht
C:\Program Files\Norton AntiVirus\Quarantine\0EEA35C7.htm Suspicious: Exploit.HTML.Mht
C:\Program Files\Norton AntiVirus\Quarantine\0F072FA7.htm Suspicious: Exploit.HTML.Mht
C:\Program Files\Norton AntiVirus\Quarantine\0F285383.htm Suspicious: Exploit.HTML.Mht
C:\Program Files\Norton AntiVirus\Quarantine\0F382571.htm Suspicious: Exploit.HTML.Mht
C:\Program Files\Norton AntiVirus\Quarantine\0FE92FF2.htm Infected: Exploit.HTML.Mht
C:\Program Files\Norton AntiVirus\Quarantine\10EA7593.htm Suspicious: Exploit.HTML.Mht
C:\Program Files\Norton AntiVirus\Quarantine\10F71D85.htm Suspicious: Exploit.HTML.Mht
C:\Program Files\Norton AntiVirus\Quarantine\15490DC5 Infected: Trojan.Java.ClassLoader.Dummy.a
C:\Program Files\Norton AntiVirus\Quarantine\159C5069.htm Suspicious: Exploit.HTML.Mht
C:\Program Files\Norton AntiVirus\Quarantine\16180BE0.htm Suspicious: Exploit.HTML.Mht
C:\Program Files\Norton AntiVirus\Quarantine\164C5362 Infected: Exploit.Java.Bytverify
C:\Program Files\Norton AntiVirus\Quarantine\173F3D5E/mail.zip/mail.txt .scr Infected: Email-Worm.Win32.Mydoom.m
C:\Program Files\Norton AntiVirus\Quarantine\173F3D5E/mail.zip Infected: Email-Worm.Win32.Mydoom.m
C:\Program Files\Norton AntiVirus\Quarantine\173F3D5E Infected: Email-Worm.Win32.Mydoom.m
C:\Program Files\Norton AntiVirus\Quarantine\17684DD7 Infected: Trojan-Downloader.Java.OpenConnection.v
C:\Program Files\Norton AntiVirus\Quarantine\177B3D6A/file.zip/file.htm .scr Infected: Email-Worm.Win32.Mydoom.m
C:\Program Files\Norton AntiVirus\Quarantine\177B3D6A/file.zip Infected: Email-Worm.Win32.Mydoom.m
C:\Program Files\Norton AntiVirus\Quarantine\177B3D6A Infected: Email-Worm.Win32.Mydoom.m
C:\Program Files\Norton AntiVirus\Quarantine\18B176D9 Infected: Trojan.Java.ClassLoader.c
C:\Program Files\Norton AntiVirus\Quarantine\19BA34CA/details.txt .pif Infected: Email-Worm.Win32.NetSky.q
C:\Program Files\Norton AntiVirus\Quarantine\19BA34CA Infected: Email-Worm.Win32.NetSky.q
C:\Program Files\Norton AntiVirus\Quarantine\1C4C70E4 Infected: Trojan.Java.ClassLoader.Dummy.d
C:\Program Files\Norton AntiVirus\Quarantine\1FF772D9 Infected: Trojan.Java.ClassLoader.c
C:\Program Files\Norton AntiVirus\Quarantine\25B06F93.htm Infected: Exploit.HTML.Mht
C:\Program Files\Norton AntiVirus\Quarantine\28D93126.htm Infected: Exploit.VBS.Phel.a
C:\Program Files\Norton AntiVirus\Quarantine\29610269.class Infected: Trojan.Java.ClassLoader.Dummy.d
C:\Program Files\Norton AntiVirus\Quarantine\2CC30EA7/details.txt .pif Infected: Email-Worm.Win32.NetSky.q
C:\Program Files\Norton AntiVirus\Quarantine\2CC30EA7 Infected: Email-Worm.Win32.NetSky.q
C:\Program Files\Norton AntiVirus\Quarantine\2D7A4405/data.rtf .scr Infected: Email-Worm.Win32.NetSky.q
C:\Program Files\Norton AntiVirus\Quarantine\2D7A4405 Infected: Email-Worm.Win32.NetSky.q
C:\Program Files\Norton AntiVirus\Quarantine\30E7324F Infected: Exploit.Java.Bytverify
C:\Program Files\Norton AntiVirus\Quarantine\411F7CE3 Infected: Trojan.Java.ClassLoader.c
C:\Program Files\Norton AntiVirus\Quarantine\418460B9/details.txt .pif Infected: Email-Worm.Win32.NetSky.q
C:\Program Files\Norton AntiVirus\Quarantine\418460B9 Infected: Email-Worm.Win32.NetSky.q
C:\Program Files\Norton AntiVirus\Quarantine\42E044E0.htm Infected: Exploit.HTML.Mht
C:\Program Files\Norton AntiVirus\Quarantine\42F6505A/khzke.zip/khzke.pif Infected: Email-Worm.Win32.Mydoom.m
C:\Program Files\Norton AntiVirus\Quarantine\42F6505A/khzke.zip Infected: Email-Worm.Win32.Mydoom.m
C:\Program Files\Norton AntiVirus\Quarantine\42F6505A Infected: Email-Worm.Win32.Mydoom.m
C:\Program Files\Norton AntiVirus\Quarantine\49823B08 Infected: Net-Worm.Win32.Mytob.au
C:\Program Files\Norton AntiVirus\Quarantine\4E4C075C.class Infected: Exploit.Java.Bytverify
C:\Program Files\Norton AntiVirus\Quarantine\513567D6 Infected: Exploit.Java.Bytverify
C:\Program Files\Norton AntiVirus\Quarantine\51CE751A Infected: Trojan-Downloader.Java.OpenConnection.v
C:\Program Files\Norton AntiVirus\Quarantine\5A120BFA.htm Infected: Exploit.VBS.Phel.a
C:\Program Files\Norton AntiVirus\Quarantine\5ACA42BD Infected: Trojan-Downloader.Java.OpenConnection.v
C:\Program Files\Norton AntiVirus\Quarantine\5B8F3CAC.htm Infected: Exploit.VBS.Phel.a
C:\Program Files\Norton AntiVirus\Quarantine\5B9F0E9A.htm Infected: Exploit.VBS.Phel.a
C:\Program Files\Norton AntiVirus\Quarantine\633C53E0 Infected: Trojan.Java.ClassLoader.c
C:\Program Files\Norton AntiVirus\Quarantine\63DF7F58 Infected: Trojan-Downloader.Java.OpenStream.d
C:\Program Files\Norton AntiVirus\Quarantine\664149C8 Infected: Trojan.Java.ClassLoader.Dummy.a
C:\Program Files\Norton AntiVirus\Quarantine\692644C1 Infected: Email-Worm.Win32.NetSky.q
C:\Program Files\Norton AntiVirus\Quarantine\6C381511.htm Infected: Exploit.VBS.Phel.a
C:\Program Files\Norton AntiVirus\Quarantine\6D567E42 Infected: Exploit.Java.Bytverify
C:\Program Files\Norton AntiVirus\Quarantine\71DE0020 Infected: Trojan.Java.ClassLoader.Dummy.a
C:\Program Files\Norton AntiVirus\Quarantine\790B4BE7.htm Infected: Exploit.VBS.Phel.a
C:\Program Files\Norton AntiVirus\Quarantine\7D344781/data.rtf .scr Infected: Email-Worm.Win32.NetSky.q
C:\Program Files\Norton AntiVirus\Quarantine\7D344781 Infected: Email-Worm.Win32.NetSky.q
C:\Program Files\Norton AntiVirus\Quarantine\7FE35617/document.txt .exe Infected: Email-Worm.Win32.NetSky.q
C:\Program Files\Norton AntiVirus\Quarantine\7FE35617 Infected: Email-Worm.Win32.NetSky.q
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP647\A0021094.exe Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP647\A0021095.exe Infected: Trojan-Downloader.Win32.Agent.ro
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP650\A0021137.exe Infected: Trojan-Downloader.Win32.Apropo.g
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP651\A0021158.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP651\A0021159.dll Infected: Trojan-Downloader.Win32.Apropo.ag
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP651\A0021160.exe Infected: Trojan-Downloader.Win32.Apropo.ag
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP651\A0021161.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP651\A0021162.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP651\A0021163.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP651\A0021164.exe Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP676\A0021499.exe Infected: Trojan-Downloader.Win32.Apropo.g
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP677\A0021520.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP677\A0021521.dll Infected: Trojan-Downloader.Win32.Apropo.ag
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP677\A0021522.exe Infected: Trojan-Downloader.Win32.Apropo.ag
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP677\A0021523.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP677\A0021524.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP677\A0021525.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP677\A0021526.exe Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP680\A0021550.exe Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP680\A0021551.exe Infected: Trojan-Downloader.Win32.Agent.ro
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP680\A0021553.exe Infected: Trojan-Downloader.Win32.Apropo.g
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP680\A0021555.exe Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP680\A0021556.exe Infected: Trojan-Downloader.Win32.Agent.ro
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP681\A0021592.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP681\A0021593.dll Infected: Trojan-Downloader.Win32.Apropo.ag
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP681\A0021594.exe Infected: Trojan-Downloader.Win32.Apropo.ag
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP681\A0021595.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP681\A0021596.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP681\A0021597.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP681\A0021598.exe Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP684\A0021629.exe Infected: Trojan-Downloader.Win32.Apropo.g
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP684\A0021633.exe Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP684\A0021634.exe Infected: Trojan-Downloader.Win32.Agent.ro
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP685\A0021686.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP685\A0021687.dll Infected: Trojan-Downloader.Win32.Apropo.ag
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP685\A0021688.exe Infected: Trojan-Downloader.Win32.Apropo.ag
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP685\A0021689.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP685\A0021690.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP685\A0021691.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP685\A0021692.exe Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP689\A0021734.exe Infected: Trojan-Downloader.Win32.Apropo.g
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP690\A0021745.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP690\A0021746.dll Infected: Trojan-Downloader.Win32.Apropo.ag
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP690\A0021747.exe Infected: Trojan-Downloader.Win32.Apropo.ag
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP690\A0021748.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP690\A0021749.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP690\A0021750.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP690\A0021751.exe Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP693\A0021773.exe Infected: Trojan-Downloader.Win32.Apropo.g
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP693\A0021871.exe Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP693\A0021872.exe Infected: Trojan-Downloader.Win32.Agent.ro
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP693\A0021873.exe Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP693\A0021874.exe Infected: Trojan-Downloader.Win32.Agent.ro
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP693\A0021891.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP693\A0021892.dll Infected: Trojan-Downloader.Win32.Apropo.ag
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP693\A0021893.exe Infected: Trojan-Downloader.Win32.Apropo.ag
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP693\A0021894.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP693\A0021895.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP693\A0021896.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP693\A0021897.exe Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP695\A0021916.exe Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP695\A0021917.exe Infected: Trojan-Downloader.Win32.Agent.ro
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP698\A0022030.exe Infected: Trojan-Downloader.Win32.Apropo.g
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP699\A0022066.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP699\A0022067.dll Infected: Trojan-Downloader.Win32.Apropo.ag
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP699\A0022068.exe Infected: Trojan-Downloader.Win32.Apropo.ag
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP699\A0022069.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP699\A0022070.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP699\A0022071.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP699\A0022072.exe Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP704\A0022103.exe Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP704\A0022104.exe Infected: Trojan-Downloader.Win32.Agent.ro
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP704\A0022129.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP704\A0022131.dll Infected: Trojan-Downloader.Win32.Apropo.ag
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP704\A0022132.exe Infected: Trojan-Downloader.Win32.Apropo.ag
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP704\A0022133.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP704\A0022134.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP704\A0022135.exe Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP704\A0022136.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP704\A0022145.exe Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP704\A0022146.exe Infected: Trojan-Downloader.Win32.Agent.ro
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP704\A0022183.exe Infected: Trojan-Downloader.Win32.Apropo.g
C:\System Volume Information\_restore{18AC2EAA-6A66-4C32-A00E-B8C5E98B1B03}\RP726\A0022810.dll Infected: Trojan.Win32.Crypt.t
C:\WINDOWS\system32\ddecoins.dll Infected: Trojan.Win32.Crypt.t
Scan process completed.
HJT just now...
Logfile of HijackThis v1.99.1
Scan saved at 9:34:20 AM, on 11/16/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Google\ggviewer67-33.exe
C:\WINDOWS\System32\00THotkey.exe
C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\system32\TFNF5.exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\WINDOWS\system32\TPWRTRAY.EXE
C:\WINDOWS\System32\EZSP_PX.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\toshiba\ivp\ism\pinger.exe
C:\Program Files\DIGStream\digstream.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Symantec\LiveUpdate\ALUNOTIFY.EXE
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft Money\System\mnyexpr.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\OpenOffice.org1.1.5\program\soffice.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\Documents and Settings\user\Desktop\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshiba.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [PmProxy] C:\Program Files\Analog Devices\SoundMAX\PmProxy.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe /Type 28
O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [Tpwrtray] TPWRTRAY.EXE
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\EZSP_PX.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNOTIFY.EXE
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - Startup: OpenOffice.org 1.1.5.lnk = C:\Program Files\OpenOffice.org1.1.5\program\quickstart.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\GameClient.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O15 - Trusted Zone: *.fnismls.com
O16 - DPF: {0854D220-A90A-466D-BC02-6683183802B7} (PrintPreview Class) - http://crmls.fnismls...rintControl.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg...ol_v1-0-3-9.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1130289785357
O16 - DPF: {8CE3BAE6-AB66-40B6-9019-41E5282FF1E2} (QuickBooks Online Edition Utilities Class v8) - https://accounting.q....096/qboax8.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/...ro.cab34246.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/...fault/shapo.cab
O16 - DPF: {ECDEDB7F-BFD2-4010-9502-D300C3DDCD54} (SystemChecker.CheckerCtrl) - http://crmls.fnismls...stemChecker.cab
O16 - DPF: {FA9740A2-5802-42E2-B509-81186EEB3C42} (WABControl Class) - https://www.linkedin...cab/wabctrl.cab
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\