aeroredbaron
9 Feb 2008, 4:02am
One computer on our network (laptop) was hit really hard with a virus. It broke AVG and has prevented me from being able to reinstall. I can't get into safe mode either. Right now I'm trying to clean up the other computer (desktop) on the next work before tackling the laptop if it is even saveable. On the desktop, I ran through all the steps and adaware, spybot and AVG have gotten most of it, but I'm still getting hits in Kaspery and Panda as shown below. Thank you so much for your help!
Panda:
Incident Status Location
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\InnerChange VZ\Application Data\Mozilla\Firefox\Profiles\n8lp9xos.default\cookies.txt[.adultfriendfinder.com/]
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\InnerChange VZ\Application Data\Mozilla\Firefox\Profiles\n8lp9xos.default\cookies.txt[.xiti.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\InnerChange VZ\Application Data\Mozilla\Firefox\Profiles\n8lp9xos.default\cookies.txt[.com.com/]
Spyware:Cookie/Azjmp Not disinfected C:\Documents and Settings\InnerChange VZ\Application Data\Mozilla\Firefox\Profiles\n8lp9xos.default\cookies.txt[.azjmp.com/]
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\InnerChange VZ\Application Data\Mozilla\Firefox\Profiles\n8lp9xos.default\cookies.txt[.go.com/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\InnerChange VZ\Application Data\Mozilla\Firefox\Profiles\n8lp9xos.default\cookies.txt[.atwola.com/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Shorack Family\Application Data\Mozilla\Firefox\Profiles\rd6hwkq1.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Shorack Family\Application Data\Mozilla\Firefox\Profiles\rd6hwkq1.default\cookies.txt[.advertising.com/]
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Shorack Family\Application Data\Mozilla\Firefox\Profiles\rd6hwkq1.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Shorack Family\Application Data\Mozilla\Firefox\Profiles\rd6hwkq1.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Shorack Family\Application Data\Mozilla\Firefox\Profiles\rd6hwkq1.default\cookies.txt[server.iad.liveperson.net/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Shorack Family\Application Data\Mozilla\Firefox\Profiles\rd6hwkq1.default\cookies.txt[server.iad.liveperson.net/hc/62124831]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Shorack Family\Application Data\Mozilla\Firefox\Profiles\rd6hwkq1.default\cookies.txt[server.iad.liveperson.net/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Shorack Family\Application Data\Mozilla\Firefox\Profiles\rd6hwkq1.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Shorack Family\Application Data\Mozilla\Firefox\Profiles\rd6hwkq1.default\cookies.txt[.apmebf.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Shorack Family\Application Data\Mozilla\Firefox\Profiles\rd6hwkq1.default\cookies.txt[.perf.overture.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Shorack Family\Application Data\Mozilla\Firefox\Profiles\rd6hwkq1.default\cookies.txt[.overture.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Shorack Family\Application Data\Mozilla\Firefox\Profiles\rd6hwkq1.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Shorack Family\Application Data\Mozilla\Firefox\Profiles\rd6hwkq1.default\cookies.txt[.trafficmp.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Shorack Family\Application Data\Mozilla\Firefox\Profiles\rd6hwkq1.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Shorack Family\Application Data\Mozilla\Firefox\Profiles\rd6hwkq1.default\cookies.txt[.bs.serving-sys.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Shorack Family\Application Data\Mozilla\Firefox\Profiles\rd6hwkq1.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/Target Not disinfected C:\Documents and Settings\Shorack Family\Application Data\Mozilla\Firefox\Profiles\rd6hwkq1.default\cookies.txt[.target.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Shorack Family\Application Data\Mozilla\Firefox\Profiles\rd6hwkq1.default\cookies.txt[.uol.com.br/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Shorack Family\Application Data\Mozilla\Firefox\Profiles\rd6hwkq1.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Shorack Family\Application Data\Mozilla\Firefox\Profiles\rd6hwkq1.default\cookies.txt[.atwola.com/]
Spyware:Cookie/FortuneCity Not disinfected C:\Documents and Settings\Shorack Family\Application Data\Mozilla\Firefox\Profiles\rd6hwkq1.default\cookies.txt[.fortunecity.com/]
Spyware:Cookie/Bridgetrack Not disinfected C:\Documents and Settings\Shorack Family\Application Data\Mozilla\Firefox\Profiles\rd6hwkq1.default\cookies.txt[citi.bridgetrack.com/]
Spyware:Cookie/Humanclick Not disinfected C:\Documents and Settings\Shorack Family\Application Data\Mozilla\Firefox\Profiles\rd6hwkq1.default\cookies.txt[hc2.humanclick.com/]
Spyware:Cookie/Humanclick Not disinfected C:\Documents and Settings\Shorack Family\Application Data\Mozilla\Firefox\Profiles\rd6hwkq1.default\cookies.txt[hc2.humanclick.com/hc/74139060]
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\USUARIO\Configuración local\Temp\Cookies\usuario@belnk[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\USUARIO\Configuración local\Temp\Cookies\usuario@dist.belnk[2].txt
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.yadro.ru/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.zedo.com/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.fastclick.net/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.advertising.com/]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/Bridgetrack Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[citi.bridgetrack.com/]
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/fe.lea.lycos Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[fe.lea.lycos.es/]
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.adrevolver.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.perf.overture.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.overture.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.com.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[statse.webtrendslive.com/]
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.statse.webtrendslive.com/]
Spyware:Cookie/Tradedoubler Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.tradedoubler.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.bs.serving-sys.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.247realmedia.com/]
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.adultfriendfinder.com/]
Spyware:Cookie/PayCounter Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.paycounter.com/]
Spyware:Cookie/SexList Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.sexlist.com/]
Spyware:Cookie/cs.sexcounter Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.cs.sexcounter.com/]
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.xiti.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.terra.com.br/]
Potentially unwanted tool:Application/PRScheduler Not disinfected C:\Documents and Settings\USUARIO\Menú Inicio\Programas\Inicio\PowerReg Scheduler.exe
Kaspersky
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Datos de programa\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\All Users\Datos de programa\Symantec\SRTSP\SrtETmp\53173A68.TMP Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\InnerChange VZ\Application Data\Mozilla\Firefox\Profiles\n8lp9xos.default\cert8.db Object is locked skipped
C:\Documents and Settings\InnerChange VZ\Application Data\Mozilla\Firefox\Profiles\n8lp9xos.default\formhistory.dat Object is locked skipped
C:\Documents and Settings\InnerChange VZ\Application Data\Mozilla\Firefox\Profiles\n8lp9xos.default\history.dat Object is locked skipped
C:\Documents and Settings\InnerChange VZ\Application Data\Mozilla\Firefox\Profiles\n8lp9xos.default\key3.db Object is locked skipped
C:\Documents and Settings\InnerChange VZ\Application Data\Mozilla\Firefox\Profiles\n8lp9xos.default\parent.lock Object is locked skipped
C:\Documents and Settings\InnerChange VZ\Application Data\Mozilla\Firefox\Profiles\n8lp9xos.default\search.sqlite Object is locked skipped
C:\Documents and Settings\InnerChange VZ\Application Data\Mozilla\Firefox\Profiles\n8lp9xos.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\InnerChange VZ\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\InnerChange VZ\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\InnerChange VZ\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\InnerChange VZ\Local Settings\Application Data\Mozilla\Firefox\Profiles\n8lp9xos.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\InnerChange VZ\Local Settings\Application Data\Mozilla\Firefox\Profiles\n8lp9xos.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\InnerChange VZ\Local Settings\Application Data\Mozilla\Firefox\Profiles\n8lp9xos.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\InnerChange VZ\Local Settings\Application Data\Mozilla\Firefox\Profiles\n8lp9xos.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\InnerChange VZ\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\InnerChange VZ\Local Settings\Temp\fla10D7.tmp Object is locked skipped
C:\Documents and Settings\InnerChange VZ\Local Settings\Temp\jar_cache20144.tmp Object is locked skipped
C:\Documents and Settings\InnerChange VZ\Local Settings\Temp\~DF6836.tmp Object is locked skipped
C:\Documents and Settings\InnerChange VZ\Local Settings\Temp\~DFDEB3.tmp Object is locked skipped
C:\Documents and Settings\InnerChange VZ\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\InnerChange VZ\My Documents\Marna\WebfettiSetup2.2.60.11-2.ZKfox000.exe/mwsSetup.CommonCodebase.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\Documents and Settings\InnerChange VZ\My Documents\Marna\WebfettiSetup2.2.60.11-2.ZKfox000.exe CAB: infected - 1 skipped
C:\Documents and Settings\InnerChange VZ\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\InnerChange VZ\NTUSER.DAT.LOG Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\ntuser.dat.LOG Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Internet Logs\DESKTOP.ldb Object is locked skipped
C:\WINDOWS\Internet Logs\fwdbglog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped
C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox.dat Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox.idx Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_638.dat Object is locked skipped
C:\WINDOWS\Temp\ZLT0447d.TMP Object is locked skipped
C:\WINDOWS\Temp\ZLT0448a.TMP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
and finally Hijack this:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:19:23 PM, on 2/8/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\LTMSG.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\program files\Messenger\msmsgs.exe
C:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\program files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\program files\Trend Micro\HijackThis\HijackThis.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ZoneAlarm Spy Blocker BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [StatusClient] C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe /auto
O4 - HKLM\..\Run: [TomcatStartup] C:\Program Files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\RunOnce: [WDM_DMUSIC1] rundll32.exe streamci.dll,StreamingDeviceSetup {8C07DD50-7A8D-11d2-8F8C-00C04FBF8FEF},dmusic,{DFF220F3-F70F-11D0-B917-00A0C9223196},C:\WINDOWS\INF\WDMAUDIO.inf,WDM_DMUSIC.Interface.Install
O4 - HKLM\..\RunOnce: [WDM_DMUSIC2] rundll32.exe streamci.dll,StreamingDeviceSetup {8C07DD50-7A8D-11d2-8F8C-00C04FBF8FEF},dmusic,{6994AD04-93EF-11D0-A3CC-00A0C9223196},C:\WINDOWS\INF\WDMAUDIO.inf,WDM_DMUSIC.Interface.Install
O4 - HKLM\..\RunOnce: [WDM_WDMAUD] rundll32.exe streamci.dll,StreamingDeviceSetup {CD171DE3-69E5-11D2-B56D-0000F8754380},{9B365890-165F-11D0-A195-0020AFD156E4},{3E227E76-690D-11D2-8161-0000F8775BF1},C:\WINDOWS\INF\WDMAUDIO.inf,WDM_WDMAUD.Interface.Install
O4 - HKLM\..\RunOnce: [WDM_SPLITTER0] rundll32.exe streamci.dll,StreamingDeviceSetup {2F412AB5-ED3A-4590-AB24-B0CE2AA77D3C},{9B365890-165F-11D0-A195-0020AFD156E4},{9EA331FA-B91B-45F8-9285-BD2BC77AFCDE},C:\WINDOWS\INF\WDMAUDIO.inf,WDM_SPLITTER.Interface.Install
O4 - HKLM\..\RunOnce: [WDM_SPLITTER1] rundll32.exe streamci.dll,StreamingDeviceSetup {2F412AB5-ED3A-4590-AB24-B0CE2AA77D3C},{9B365890-165F-11D0-A195-0020AFD156E4},{6994AD04-93EF-11D0-A3CC-00A0C9223196},C:\WINDOWS\INF\WDMAUDIO.inf,WDM_SPLITTER.Interface.Install
O4 - HKCU\..\Run: [MSMSGS] "C:\program files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O8 - Extra context menu item: &Search - ?p=ZKfox000
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1184706092406
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://arturoyaco2000.spaces.live.com/PhotoUpload/MsnPUpld.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
--
End of file - 9281 bytes
Panda:
Incident Status Location
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\InnerChange VZ\Application Data\Mozilla\Firefox\Profiles\n8lp9xos.default\cookies.txt[.adultfriendfinder.com/]
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\InnerChange VZ\Application Data\Mozilla\Firefox\Profiles\n8lp9xos.default\cookies.txt[.xiti.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\InnerChange VZ\Application Data\Mozilla\Firefox\Profiles\n8lp9xos.default\cookies.txt[.com.com/]
Spyware:Cookie/Azjmp Not disinfected C:\Documents and Settings\InnerChange VZ\Application Data\Mozilla\Firefox\Profiles\n8lp9xos.default\cookies.txt[.azjmp.com/]
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\InnerChange VZ\Application Data\Mozilla\Firefox\Profiles\n8lp9xos.default\cookies.txt[.go.com/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\InnerChange VZ\Application Data\Mozilla\Firefox\Profiles\n8lp9xos.default\cookies.txt[.atwola.com/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Shorack Family\Application Data\Mozilla\Firefox\Profiles\rd6hwkq1.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Shorack Family\Application Data\Mozilla\Firefox\Profiles\rd6hwkq1.default\cookies.txt[.advertising.com/]
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Shorack Family\Application Data\Mozilla\Firefox\Profiles\rd6hwkq1.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Shorack Family\Application Data\Mozilla\Firefox\Profiles\rd6hwkq1.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Shorack Family\Application Data\Mozilla\Firefox\Profiles\rd6hwkq1.default\cookies.txt[server.iad.liveperson.net/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Shorack Family\Application Data\Mozilla\Firefox\Profiles\rd6hwkq1.default\cookies.txt[server.iad.liveperson.net/hc/62124831]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Shorack Family\Application Data\Mozilla\Firefox\Profiles\rd6hwkq1.default\cookies.txt[server.iad.liveperson.net/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Shorack Family\Application Data\Mozilla\Firefox\Profiles\rd6hwkq1.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Shorack Family\Application Data\Mozilla\Firefox\Profiles\rd6hwkq1.default\cookies.txt[.apmebf.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Shorack Family\Application Data\Mozilla\Firefox\Profiles\rd6hwkq1.default\cookies.txt[.perf.overture.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Shorack Family\Application Data\Mozilla\Firefox\Profiles\rd6hwkq1.default\cookies.txt[.overture.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Shorack Family\Application Data\Mozilla\Firefox\Profiles\rd6hwkq1.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Shorack Family\Application Data\Mozilla\Firefox\Profiles\rd6hwkq1.default\cookies.txt[.trafficmp.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Shorack Family\Application Data\Mozilla\Firefox\Profiles\rd6hwkq1.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Shorack Family\Application Data\Mozilla\Firefox\Profiles\rd6hwkq1.default\cookies.txt[.bs.serving-sys.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Shorack Family\Application Data\Mozilla\Firefox\Profiles\rd6hwkq1.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/Target Not disinfected C:\Documents and Settings\Shorack Family\Application Data\Mozilla\Firefox\Profiles\rd6hwkq1.default\cookies.txt[.target.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Shorack Family\Application Data\Mozilla\Firefox\Profiles\rd6hwkq1.default\cookies.txt[.uol.com.br/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Shorack Family\Application Data\Mozilla\Firefox\Profiles\rd6hwkq1.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Shorack Family\Application Data\Mozilla\Firefox\Profiles\rd6hwkq1.default\cookies.txt[.atwola.com/]
Spyware:Cookie/FortuneCity Not disinfected C:\Documents and Settings\Shorack Family\Application Data\Mozilla\Firefox\Profiles\rd6hwkq1.default\cookies.txt[.fortunecity.com/]
Spyware:Cookie/Bridgetrack Not disinfected C:\Documents and Settings\Shorack Family\Application Data\Mozilla\Firefox\Profiles\rd6hwkq1.default\cookies.txt[citi.bridgetrack.com/]
Spyware:Cookie/Humanclick Not disinfected C:\Documents and Settings\Shorack Family\Application Data\Mozilla\Firefox\Profiles\rd6hwkq1.default\cookies.txt[hc2.humanclick.com/]
Spyware:Cookie/Humanclick Not disinfected C:\Documents and Settings\Shorack Family\Application Data\Mozilla\Firefox\Profiles\rd6hwkq1.default\cookies.txt[hc2.humanclick.com/hc/74139060]
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\USUARIO\Configuración local\Temp\Cookies\usuario@belnk[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\USUARIO\Configuración local\Temp\Cookies\usuario@dist.belnk[2].txt
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.yadro.ru/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.zedo.com/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.fastclick.net/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.advertising.com/]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/Bridgetrack Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[citi.bridgetrack.com/]
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/fe.lea.lycos Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[fe.lea.lycos.es/]
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.adrevolver.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.perf.overture.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.overture.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.com.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[statse.webtrendslive.com/]
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.statse.webtrendslive.com/]
Spyware:Cookie/Tradedoubler Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.tradedoubler.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.bs.serving-sys.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.247realmedia.com/]
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.adultfriendfinder.com/]
Spyware:Cookie/PayCounter Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.paycounter.com/]
Spyware:Cookie/SexList Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.sexlist.com/]
Spyware:Cookie/cs.sexcounter Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.cs.sexcounter.com/]
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.xiti.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\USUARIO\Datos de programa\Mozilla\Firefox\Profiles\srnjsgaf.default\cookies.txt[.terra.com.br/]
Potentially unwanted tool:Application/PRScheduler Not disinfected C:\Documents and Settings\USUARIO\Menú Inicio\Programas\Inicio\PowerReg Scheduler.exe
Kaspersky
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Datos de programa\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\All Users\Datos de programa\Symantec\SRTSP\SrtETmp\53173A68.TMP Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\InnerChange VZ\Application Data\Mozilla\Firefox\Profiles\n8lp9xos.default\cert8.db Object is locked skipped
C:\Documents and Settings\InnerChange VZ\Application Data\Mozilla\Firefox\Profiles\n8lp9xos.default\formhistory.dat Object is locked skipped
C:\Documents and Settings\InnerChange VZ\Application Data\Mozilla\Firefox\Profiles\n8lp9xos.default\history.dat Object is locked skipped
C:\Documents and Settings\InnerChange VZ\Application Data\Mozilla\Firefox\Profiles\n8lp9xos.default\key3.db Object is locked skipped
C:\Documents and Settings\InnerChange VZ\Application Data\Mozilla\Firefox\Profiles\n8lp9xos.default\parent.lock Object is locked skipped
C:\Documents and Settings\InnerChange VZ\Application Data\Mozilla\Firefox\Profiles\n8lp9xos.default\search.sqlite Object is locked skipped
C:\Documents and Settings\InnerChange VZ\Application Data\Mozilla\Firefox\Profiles\n8lp9xos.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\InnerChange VZ\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\InnerChange VZ\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\InnerChange VZ\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\InnerChange VZ\Local Settings\Application Data\Mozilla\Firefox\Profiles\n8lp9xos.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\InnerChange VZ\Local Settings\Application Data\Mozilla\Firefox\Profiles\n8lp9xos.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\InnerChange VZ\Local Settings\Application Data\Mozilla\Firefox\Profiles\n8lp9xos.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\InnerChange VZ\Local Settings\Application Data\Mozilla\Firefox\Profiles\n8lp9xos.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\InnerChange VZ\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\InnerChange VZ\Local Settings\Temp\fla10D7.tmp Object is locked skipped
C:\Documents and Settings\InnerChange VZ\Local Settings\Temp\jar_cache20144.tmp Object is locked skipped
C:\Documents and Settings\InnerChange VZ\Local Settings\Temp\~DF6836.tmp Object is locked skipped
C:\Documents and Settings\InnerChange VZ\Local Settings\Temp\~DFDEB3.tmp Object is locked skipped
C:\Documents and Settings\InnerChange VZ\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\InnerChange VZ\My Documents\Marna\WebfettiSetup2.2.60.11-2.ZKfox000.exe/mwsSetup.CommonCodebase.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\Documents and Settings\InnerChange VZ\My Documents\Marna\WebfettiSetup2.2.60.11-2.ZKfox000.exe CAB: infected - 1 skipped
C:\Documents and Settings\InnerChange VZ\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\InnerChange VZ\NTUSER.DAT.LOG Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\ntuser.dat.LOG Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Internet Logs\DESKTOP.ldb Object is locked skipped
C:\WINDOWS\Internet Logs\fwdbglog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped
C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox.dat Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox.idx Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_638.dat Object is locked skipped
C:\WINDOWS\Temp\ZLT0447d.TMP Object is locked skipped
C:\WINDOWS\Temp\ZLT0448a.TMP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
and finally Hijack this:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:19:23 PM, on 2/8/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\LTMSG.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\program files\Messenger\msmsgs.exe
C:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\program files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\program files\Trend Micro\HijackThis\HijackThis.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ZoneAlarm Spy Blocker BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [StatusClient] C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe /auto
O4 - HKLM\..\Run: [TomcatStartup] C:\Program Files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\RunOnce: [WDM_DMUSIC1] rundll32.exe streamci.dll,StreamingDeviceSetup {8C07DD50-7A8D-11d2-8F8C-00C04FBF8FEF},dmusic,{DFF220F3-F70F-11D0-B917-00A0C9223196},C:\WINDOWS\INF\WDMAUDIO.inf,WDM_DMUSIC.Interface.Install
O4 - HKLM\..\RunOnce: [WDM_DMUSIC2] rundll32.exe streamci.dll,StreamingDeviceSetup {8C07DD50-7A8D-11d2-8F8C-00C04FBF8FEF},dmusic,{6994AD04-93EF-11D0-A3CC-00A0C9223196},C:\WINDOWS\INF\WDMAUDIO.inf,WDM_DMUSIC.Interface.Install
O4 - HKLM\..\RunOnce: [WDM_WDMAUD] rundll32.exe streamci.dll,StreamingDeviceSetup {CD171DE3-69E5-11D2-B56D-0000F8754380},{9B365890-165F-11D0-A195-0020AFD156E4},{3E227E76-690D-11D2-8161-0000F8775BF1},C:\WINDOWS\INF\WDMAUDIO.inf,WDM_WDMAUD.Interface.Install
O4 - HKLM\..\RunOnce: [WDM_SPLITTER0] rundll32.exe streamci.dll,StreamingDeviceSetup {2F412AB5-ED3A-4590-AB24-B0CE2AA77D3C},{9B365890-165F-11D0-A195-0020AFD156E4},{9EA331FA-B91B-45F8-9285-BD2BC77AFCDE},C:\WINDOWS\INF\WDMAUDIO.inf,WDM_SPLITTER.Interface.Install
O4 - HKLM\..\RunOnce: [WDM_SPLITTER1] rundll32.exe streamci.dll,StreamingDeviceSetup {2F412AB5-ED3A-4590-AB24-B0CE2AA77D3C},{9B365890-165F-11D0-A195-0020AFD156E4},{6994AD04-93EF-11D0-A3CC-00A0C9223196},C:\WINDOWS\INF\WDMAUDIO.inf,WDM_SPLITTER.Interface.Install
O4 - HKCU\..\Run: [MSMSGS] "C:\program files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O8 - Extra context menu item: &Search - ?p=ZKfox000
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1184706092406
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://arturoyaco2000.spaces.live.com/PhotoUpload/MsnPUpld.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
--
End of file - 9281 bytes