Help - Search - Members
Full Version: hijackthis log analysis needed
Piriform Community Forums > Computer Help and Discussion > Spyware Hell
SpaXx
hello.. could anyone help me to analysis my log.. i had scanned with my superantispyware and it founds alot of trojan and i denied the change of registry by using spybot but it's still kept pop-out the denied caution.. meanwhile the trojan is still exist in my system.. below here is my hijackthis's log :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:20:37 AM, on 7/20/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\system32\explorer.exe
C:\WINDOWS\system32\sstray.exe
C:\WINDOWS\VM_STI.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\GridService\peer.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\comremok.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\lpim15.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,svchost.xy3
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {74381DEC-D78B-43E4-BA5D-5244F669EBE4} - [SASInprocServer32] (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [nForce Tray Options] "sstray.exe" /r
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] "C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /SYNC
O4 - HKLM\..\Run: [PHIME2002A] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /IMEName
O4 - HKLM\..\Run: [BigDogPath] "C:\WINDOWS\VM_STI.EXE" USB PC Camera 301P
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [NSLauncher] C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe /startup
O4 - HKLM\..\Run: [Grid Service] "C:\Program Files\GridService\peer.exe" -n Grid
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe" -H
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: &Winamp Toolbar Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Send picture by MMS - C:\Program Files\Tencent\QQ\0\SendMMS.htm
O9 - Extra button: Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: VisualRoute Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {072039AB-2117-4ED5-A85F-9B9EB903E021} (NowStarter Control) - http://www.clubbox.co.kr/neo.fld/NowStarter.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m...01/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flas...ent/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{69FBD647-05B0-46D2-9605-28ECE1212E4A}: NameServer = 202.188.0.133 202.188.1.5
O20 - AppInit_DLLs: wcomipe.dll longasus.dll sctzxy.dll mssddyn.dll comremo.dll welycz.dll googleons.dll joliom.dll follwel.dll pcibexl.dll ceshleo.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 12409 bytes
SpaXx
below here is my avira scanning report ( i scanned in safemode ) :



Avira AntiVir Personal
Report file date: Sunday, July 20, 2008 01:32

Scanning for 1475814 virus strains and unwanted programs.

Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 3) [5.1.2600]
Boot mode: Save mode
Username: userr
Computer name: USERR-5115FB8DA

Version information:
BUILD.DAT : 8.1.0.326 16933 Bytes 7/11/2008 12:57:00
AVSCAN.EXE : 8.1.4.7 315649 Bytes 7/18/2008 00:18:10
AVSCAN.DLL : 8.1.4.0 40705 Bytes 7/18/2008 00:18:10
LUKE.DLL : 8.1.4.5 164097 Bytes 7/18/2008 00:18:10
LUKERES.DLL : 8.1.4.0 12033 Bytes 7/18/2008 00:18:10
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 7/18/2007 04:33:34
ANTIVIR1.VDF : 7.0.5.1 8182784 Bytes 6/24/2008 13:37:57
ANTIVIR2.VDF : 7.0.5.119 1264128 Bytes 7/15/2008 00:17:50
ANTIVIR3.VDF : 7.0.5.138 321536 Bytes 7/18/2008 00:16:30
Engineversion : 8.1.1.11
AEVDF.DLL : 8.1.0.5 102772 Bytes 2/25/2008 03:58:21
AESCRIPT.DLL : 8.1.0.59 307579 Bytes 7/19/2008 00:16:46
AESCN.DLL : 8.1.0.23 119156 Bytes 7/17/2008 00:18:00
AERDL.DLL : 8.1.0.20 418165 Bytes 7/3/2008 13:39:09
AEPACK.DLL : 8.1.2.1 364917 Bytes 7/17/2008 00:17:59
AEOFFICE.DLL : 8.1.0.21 192891 Bytes 7/19/2008 00:16:44
AEHEUR.DLL : 8.1.0.43 1339767 Bytes 7/19/2008 00:16:42
AEHELP.DLL : 8.1.0.15 115063 Bytes 7/3/2008 13:38:34
AEGEN.DLL : 8.1.0.29 307573 Bytes 7/3/2008 13:38:31
AEEMU.DLL : 8.1.0.6 430451 Bytes 7/3/2008 13:38:22
AECORE.DLL : 8.1.1.6 172405 Bytes 7/18/2008 00:18:10
AEBB.DLL : 8.1.0.1 53617 Bytes 7/18/2008 00:18:10
AVWINLL.DLL : 1.0.0.12 15105 Bytes 7/18/2008 00:18:10
AVPREF.DLL : 8.0.2.0 38657 Bytes 7/18/2008 00:18:10
AVREP.DLL : 7.0.0.1 155688 Bytes 4/16/2007 07:26:47
AVREG.DLL : 8.0.0.1 33537 Bytes 7/18/2008 00:18:10
AVARKT.DLL : 1.0.0.23 307457 Bytes 2/12/2008 02:29:23
AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 7/18/2008 00:18:10
SQLITE3.DLL : 3.3.17.1 339968 Bytes 1/22/2008 11:28:02
SMTPLIB.DLL : 1.2.0.23 28929 Bytes 7/18/2008 00:18:10
NETNT.DLL : 8.0.0.1 7937 Bytes 1/25/2008 06:05:10
RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 7/18/2008 00:18:07
RCTEXT.DLL : 8.0.52.0 86273 Bytes 7/18/2008 00:18:07

Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: on
Scan boot sector.................: on
Boot sectors.....................: C:, D:,
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium

Start of the scan: Sunday, July 20, 2008 01:32

The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'fkwc.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'MsMpEng.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
13 processes with 13 modules were scanned

Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!

Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Boot sector 'D:\'
[INFO] No virus was found!

Starting to scan the registry.
The registry was scanned ( '73' files ).


Starting the file scan:

Begin scan in 'C:\'
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\Documents and Settings\userr\Local Settings\Temporary Internet Files\Content.IE5\2W1FPZSW\jss06[1].exe
[DETECTION] Is the TR/Dropper.Gen Trojan
[NOTE] The file was moved to '48f5263e.qua'!
C:\Documents and Settings\userr\Local Settings\Temporary Internet Files\Content.IE5\2W1FPZSW\jss10[1].exe
[DETECTION] Is the TR/Dropper.Gen Trojan
[NOTE] The file was moved to '48f52643.qua'!
C:\Documents and Settings\userr\Local Settings\Temporary Internet Files\Content.IE5\2W1FPZSW\jss23[1].exe
[DETECTION] Is the TR/Dropper.Gen Trojan
[NOTE] The file was moved to '48f52646.qua'!
C:\Documents and Settings\userr\Local Settings\Temporary Internet Files\Content.IE5\2W1FPZSW\jss34[1].exe
[DETECTION] Is the TR/Dropper.Gen Trojan
[NOTE] The file was moved to '48f52649.qua'!
C:\Documents and Settings\userr\Local Settings\Temporary Internet Files\Content.IE5\3OD83JQN\jss24[1].exe
[DETECTION] Is the TR/Dropper.Gen Trojan
[NOTE] A backup was created as '48f52669.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\userr\Local Settings\Temporary Internet Files\Content.IE5\3OD83JQN\jss35[1].exe
[DETECTION] Is the TR/Dropper.Gen Trojan
[NOTE] A backup was created as '48f5266d.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\userr\Local Settings\Temporary Internet Files\Content.IE5\3OD83JQN\WIN%209,0,115,0ie[1].swf
[0] Archive type: SWC
--> Object
[DETECTION] Contains recognition pattern of the EXP/Flash.Gen exploit
[NOTE] A backup was created as '48d0264b.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\userr\Local Settings\Temporary Internet Files\Content.IE5\ARM16Q8E\jss04[1].exe
[DETECTION] Is the TR/Dropper.Gen Trojan
[NOTE] A backup was created as '48f52680.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\userr\Local Settings\Temporary Internet Files\Content.IE5\ARM16Q8E\jss14[1].exe
[DETECTION] Is the TR/Dropper.Gen Trojan
[NOTE] A backup was created as '48f52684.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\userr\Local Settings\Temporary Internet Files\Content.IE5\ARM16Q8E\jss19[1].exe
[DETECTION] Is the TR/Dropper.Gen Trojan
[NOTE] A backup was created as '48f52688.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\userr\Local Settings\Temporary Internet Files\Content.IE5\ARM16Q8E\jss25[1].exe
[DETECTION] Is the TR/Dropper.Gen Trojan
[NOTE] A backup was created as '48f5268b.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\userr\Local Settings\Temporary Internet Files\Content.IE5\ARM16Q8E\jss28[1].exe
[DETECTION] Is the TR/Dropper.Gen Trojan
[NOTE] A backup was created as '48f5268e.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\userr\Local Settings\Temporary Internet Files\Content.IE5\ARM16Q8E\jss32[1].exe
[DETECTION] Is the TR/Dropper.Gen Trojan
[NOTE] A backup was created as '48f5268f.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\userr\Local Settings\Temporary Internet Files\Content.IE5\HGZJP89P\jss09[1].exe
[DETECTION] Is the TR/Dropper.Gen Trojan
[NOTE] A backup was created as '48f5269a.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\userr\Local Settings\Temporary Internet Files\Content.IE5\HGZJP89P\jss15[1].exe
[DETECTION] Is the TR/Dropper.Gen Trojan
[NOTE] A backup was created as '48f5269b.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\userr\Local Settings\Temporary Internet Files\Content.IE5\HGZJP89P\jss27[1].exe
[DETECTION] Is the TR/Dropper.Gen Trojan
[NOTE] A backup was created as '4945876c.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\userr\Local Settings\Temporary Internet Files\Content.IE5\HGZJP89P\user[1].exe
[DETECTION] Contains HEUR/Crypted suspicious code
[NOTE] The detection was classified as suspicious.
[NOTE] A backup was created as '48e7269e.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\userr\My Documents\My Received Files\Cafe Crack.rar
[0] Archive type: RAR
--> ᅪ￸ᄚ￉ᅥᅥᄑ¬2008.exe
[DETECTION] Is the TR/FlyStudio.AI.5 Trojan
[NOTE] A backup was created as '48e826f6.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\userr\My Documents\Software\mircv6.21keygendevotion.zip
[0] Archive type: ZIP
--> MIRC.v6.21.Incl.KeyMaker-DVT/DVT/KeyMaker.exe
[DETECTION] Is the TR/Agent.201493 Trojan
[NOTE] A backup was created as '48f42716.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\WINDOWS\Downloaded Program Files\FP_AX_CAB_INSTALLER.exe
[DETECTION] Contains a recognition pattern of the (harmful) BDS/Ceckno.buo back-door program
[NOTE] A backup was created as '48e12a22.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\WINDOWS\SoftwareDistribution\Download\9fc2ed40080cc6e02a8117ac264424a2\BIT3E.tmp
[0] Archive type: CAB (Microsoft)
--> B_53901\ati3duag.dll
[WARNING] No further files can be extracted from this archive. The archive will be closed
C:\WINDOWS\system32\ceshleo.dll
[DETECTION] Is the TR/PSW.OnL.BJ.24576 Trojan
[NOTE] A backup was created as '48f52b9f.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\WINDOWS\system32\welycz.dll
[DETECTION] Is the TR/PSW.OnL.BJ.24576 Trojan
[NOTE] A backup was created as '48ee2bce.qua' ( QUARANTINE )
[NOTE] The file was deleted!
Begin scan in 'D:\'


End of the scan: Sunday, July 20, 2008 02:01
Used time: 29:23 Minute(s)

The scan has been done completely.

4585 Scanning directories
206220 Files were scanned
21 viruses and/or unwanted programs were found
1 Files were classified as suspicious:
18 files were deleted
0 files were repaired
22 files were moved to quarantine
0 files were renamed
1 Files cannot be scanned
206197 Files not concerned
1547 Archives were scanned
2 Warnings
22 Notes

DennisD
Hi SpaXx, sorry for the inconvenience, but until further notice, could you refer to the link below to get the assistance you need.

Thanks.

http://forum.piriform.com/index.php?showtopic=16943
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2010 Invision Power Services, Inc.