Hi,
I have virus/trojans on my pc.
I have used Superantispyware, Ad-Aware SE and Avast to remove most of them.
I will post logs from the programs below.
I have seemed to get most of the infections off my computer.
I still have a virus sending internet mail thru my pc I can see it sending thru avast's On-access scanner.
Please Help Me.
Thanks
Ad-Aware SE Build 1.06r1
Logfile Created on:Wednesday, January 17, 2007 11:50:54 AM
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R145 17.01.2007
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Tracking Cookie(TAC index:3):1 total references
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Ad-Aware SE Settings
===========================
Set : Search for negligible risk entries
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan my Hosts file
Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : During removal, unload Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Include alternate data stream details in log file
Set : Play sound at scan completion if scan locates critical objects
1-17-2007 11:50:54 AM - Scan started. (Full System Scan)
Listing running processes
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ProcessID : 152
ThreadCreationTime : 1-17-2007 6:53:51 PM
BasePriority : Normal
#:2 [csrss.exe]
FilePath : \??\C:\WINNT\system32\
ProcessID : 176
ThreadCreationTime : 1-17-2007 6:54:02 PM
BasePriority : Normal
#:3 [winlogon.exe]
FilePath : \??\C:\WINNT\system32\
ProcessID : 196
ThreadCreationTime : 1-17-2007 6:54:04 PM
BasePriority : High
#:4 [services.exe]
FilePath : C:\WINNT\system32\
ProcessID : 224
ThreadCreationTime : 1-17-2007 6:54:05 PM
BasePriority : Normal
FileVersion : 5.00.2195.7035
ProductVersion : 5.00.2195.7035
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Services and Controller app
InternalName : services.exe
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : services.exe
#:5 [lsass.exe]
FilePath : C:\WINNT\system32\
ProcessID : 236
ThreadCreationTime : 1-17-2007 6:54:05 PM
BasePriority : Normal
FileVersion : 5.00.2195.7011
ProductVersion : 5.00.2195.7011
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : LSA Executable and Server DLL (Export Version)
InternalName : lsasrv.dll and lsass.exe
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : lsasrv.dll and lsass.exe
#:6 [svchost.exe]
FilePath : C:\WINNT\system32\
ProcessID : 396
ThreadCreationTime : 1-17-2007 6:54:08 PM
BasePriority : Normal
FileVersion : 5.00.2134.1
ProductVersion : 5.00.2134.1
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : svchost.exe
#:7 [svchost.exe]
FilePath : C:\WINNT\system32\
ProcessID : 468
ThreadCreationTime : 1-17-2007 6:54:38 PM
BasePriority : Normal
FileVersion : 5.00.2134.1
ProductVersion : 5.00.2134.1
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : svchost.exe
#:8 [spoolsv.exe]
FilePath : C:\WINNT\system32\
ProcessID : 476
ThreadCreationTime : 1-17-2007 6:54:38 PM
BasePriority : Normal
FileVersion : 5.00.2195.7059
ProductVersion : 5.00.2195.7059
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolss.exe
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : spoolss.exe
#:9 [aswupdsv.exe]
FilePath : C:\Program Files\Alwil Software\Avast4\
ProcessID : 592
ThreadCreationTime : 1-17-2007 6:54:46 PM
BasePriority : Normal
#:10 [ashserv.exe]
FilePath : C:\Program Files\Alwil Software\Avast4\
ProcessID : 608
ThreadCreationTime : 1-17-2007 6:54:46 PM
BasePriority : High
FileVersion : 4, 7, 936, 0
ProductVersion : 4, 7, 0, 0
ProductName : avast! Antivirus
FileDescription : avast! antivirus service
InternalName : aswServ
LegalCopyright : Copyright © 2007 ALWIL Software
OriginalFilename : aswServ.exe
#:11 [cvpnd.exe]
FilePath : C:\Program Files\Cisco Systems\VPN Client\
ProcessID : 628
ThreadCreationTime : 1-17-2007 6:54:48 PM
BasePriority : Normal
FileVersion : 3.6.1 (Rel)
ProductVersion : 3.6.1 (Rel)
ProductName : Cisco Systems VPN Client
CompanyName : Cisco Systems, Inc.
FileDescription : Cisco Systems VPN Client
InternalName : cvpnd
LegalCopyright : Copyright © 1998-2002 Cisco Systems, Inc.
OriginalFilename : CVPND.EXE
#:12 [svchost.exe]
FilePath : C:\WINNT\System32\
ProcessID : 652
ThreadCreationTime : 1-17-2007 6:54:57 PM
BasePriority : Normal
FileVersion : 5.00.2134.1
ProductVersion : 5.00.2134.1
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : svchost.exe
#:13 [ntrtscan.exe]
FilePath : C:\Program Files\Trend Micro\OfficeScan Client\
ProcessID : 692
ThreadCreationTime : 1-17-2007 6:54:58 PM
BasePriority : Normal
FileVersion : 5.58.0.1063
ProductVersion : 5.58
ProductName : Trend Micro OfficeScan
CompanyName : Trend Micro Inc.
LegalCopyright : Copyright © 1999-2004 Trend Micro Incorporated. All rights reserved.
LegalTrademarks : Copyright © Trend Micro, Inc.
#:14 [regsvc.exe]
FilePath : C:\WINNT\system32\
ProcessID : 748
ThreadCreationTime : 1-17-2007 6:54:59 PM
BasePriority : Normal
FileVersion : 5.00.2195.6701
ProductVersion : 5.00.2195.6701
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Remote Registry Service
InternalName : regsvc
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : REGSVC.EXE
#:15 [mstask.exe]
FilePath : C:\WINNT\system32\
ProcessID : 808
ThreadCreationTime : 1-17-2007 6:54:59 PM
BasePriority : Normal
FileVersion : 4.71.2195.6972
ProductVersion : 4.71.2195.6972
ProductName : Microsoft® Windows® Task Scheduler
CompanyName : Microsoft Corporation
FileDescription : Task Scheduler Engine
InternalName : TaskScheduler
LegalCopyright : Copyright © Microsoft Corp. 1997
OriginalFilename : mstask.exe
#:16 [tmlisten.exe]
FilePath : C:\Program Files\Trend Micro\OfficeScan Client\
ProcessID : 856
ThreadCreationTime : 1-17-2007 6:55:00 PM
BasePriority : Normal
#:17 [winmgmt.exe]
FilePath : C:\WINNT\System32\WBEM\
ProcessID : 940
ThreadCreationTime : 1-17-2007 6:55:02 PM
BasePriority : Normal
FileVersion : 1.50.1085.0100
ProductVersion : 1.50.1085.0100
ProductName : Windows Management Instrumentation
CompanyName : Microsoft Corporation
FileDescription : Windows Management Instrumentation
InternalName : WINMGMT
LegalCopyright : Copyright © Microsoft Corp. 1995-1999
#:18 [winvnc4.exe]
FilePath : C:\Program Files\RealVNC\VNC4\
ProcessID : 948
ThreadCreationTime : 1-17-2007 6:55:09 PM
BasePriority : Normal
FileVersion : 4.0
ProductVersion : 4.0
ProductName : VNC Server 4.0
CompanyName : RealVNC Ltd.
FileDescription : VNC Server for Win32
InternalName : WinVNC 4.0
LegalCopyright : Copyright © RealVNC Ltd. 2002-2004
LegalTrademarks : RealVNC
OriginalFilename : winvnc4.exe
#:19 [svchost.exe]
FilePath : C:\WINNT\system32\
ProcessID : 1064
ThreadCreationTime : 1-17-2007 6:55:12 PM
BasePriority : Normal
FileVersion : 5.00.2134.1
ProductVersion : 5.00.2134.1
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : svchost.exe
#:20 [ofcdog.exe]
FilePath : C:\Program Files\Trend Micro\OfficeScan Client\
ProcessID : 1228
ThreadCreationTime : 1-17-2007 6:55:36 PM
BasePriority : Normal
#:21 [ashmaisv.exe]
FilePath : C:\Program Files\Alwil Software\Avast4\
ProcessID : 1232
ThreadCreationTime : 1-17-2007 6:55:36 PM
BasePriority : Normal
#:22 [ashwebsv.exe]
FilePath : C:\Program Files\Alwil Software\Avast4\
ProcessID : 1252
ThreadCreationTime : 1-17-2007 6:55:43 PM
BasePriority : Normal
#:23 [explorer.exe]
FilePath : C:\WINNT\
ProcessID : 1260
ThreadCreationTime : 1-17-2007 6:55:43 PM
BasePriority : Normal
FileVersion : 5.00.3700.6690
ProductVersion : 5.00.3700.6690
ProductName : Microsoft® Windows ® 2000 Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
LegalCopyright : Copyright © Microsoft Corp. 1981-1999
OriginalFilename : EXPLORER.EXE
#:24 [igfxtray.exe]
FilePath : C:\WINNT\System32\
ProcessID : 1152
ThreadCreationTime : 1-17-2007 6:55:59 PM
BasePriority : Normal
FileVersion : 3,0,0,1918
ProductVersion : 7,0,0,1918
ProductName : Intel® Common User Interface
CompanyName : Intel Corporation
FileDescription : igfxTray Module
InternalName : IGFXTRAY
LegalCopyright : Copyright 1999-2002, Intel Corporation
OriginalFilename : IGFXTRAY.EXE
#:25 [hkcmd.exe]
FilePath : C:\WINNT\System32\
ProcessID : 1136
ThreadCreationTime : 1-17-2007 6:55:59 PM
BasePriority : Normal
FileVersion : 3,0,0,1918
ProductVersion : 7,0,0,1918
ProductName : Intel® Common User Interface
CompanyName : Intel Corporation
FileDescription : hkcmd Module
InternalName : HKCMD
LegalCopyright : Copyright 1999-2002, Intel Corporation
OriginalFilename : HKCMD.EXE
#:26 [pccntmon.exe]
FilePath : C:\Program Files\Trend Micro\OfficeScan Client\
ProcessID : 1516
ThreadCreationTime : 1-17-2007 6:55:59 PM
BasePriority : Normal
FileVersion : 5.58.0.1063
ProductVersion : 5.58
ProductName : Trend Micro OfficeScan
CompanyName : Trend Micro Inc.
FileDescription : I/O Monitor
InternalName : PCCNTMON
LegalCopyright : Copyright © 1999-2004 Trend Micro Incorporated. All rights reserved.
LegalTrademarks : Copyright © Trend Micro, Inc.
OriginalFilename : PCCNTMON.EXE
#:27 [qttask.exe]
FilePath : C:\Program Files\QuickTime\
ProcessID : 1524
ThreadCreationTime : 1-17-2007 6:55:59 PM
BasePriority : Normal
FileVersion : 7.1.3
ProductVersion : QuickTime 7.1.3
ProductName : QuickTime
CompanyName : Apple Computer, Inc.
FileDescription : QuickTime Task
InternalName : QuickTime Task
LegalCopyright : Copyright Apple Computer, Inc. 1989-2006
OriginalFilename : QTTask.exe
#:28 [ituneshelper.exe]
FilePath : C:\Program Files\iTunes\
ProcessID : 1556
ThreadCreationTime : 1-17-2007 6:56:01 PM
BasePriority : Normal
FileVersion : 7.0.2.16
ProductVersion : 7.0.2.16
ProductName : iTunes
CompanyName : Apple Computer, Inc.
FileDescription : iTunesHelper Module
InternalName : iTunesHelper
LegalCopyright : © 2003-2006 Apple Computer, Inc. All Rights Reserved.
OriginalFilename : iTunesHelper.exe
#:29 [ashdisp.exe]
FilePath : C:\PROGRA~1\ALWILS~1\Avast4\
ProcessID : 1564
ThreadCreationTime : 1-17-2007 6:56:01 PM
BasePriority : Normal
FileVersion : 4, 7, 936, 0
ProductVersion : 4, 7, 0, 0
ProductName : avast! Antivirus
FileDescription : avast! service GUI component
InternalName : aswDisp
LegalCopyright : Copyright © 2007 ALWIL Software
OriginalFilename : aswDisp.exe
#:30 [upnp.exe]
FilePath : C:\winnt\system32\
ProcessID : 1572
ThreadCreationTime : 1-17-2007 6:56:01 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180
ProductVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductName : upnp manager Microcoft® Windows®
CompanyName : Microcoft Corporation
FileDescription : upnp manager
InternalName : unker
LegalCopyright : © Microcoft Corporation. All rights reserved
LegalTrademarks : Microsoft ®
OriginalFilename : unker.EXE
#:31 [ipodservice.exe]
FilePath : C:\Program Files\iPod\bin\
ProcessID : 1648
ThreadCreationTime : 1-17-2007 6:56:08 PM
BasePriority : Normal
FileVersion : 7.0.2.16
ProductVersion : 7.0.2.16
ProductName : iTunes
CompanyName : Apple Computer, Inc.
FileDescription : iPodService Module
InternalName : iPodService
LegalCopyright : © 2003-2006 Apple Computer, Inc. All Rights Reserved.
OriginalFilename : iPodService.exe
#:32 [wf_scheduler.exe]
FilePath : C:\Program Files\AceBIT\WISE-FTP\
ProcessID : 1692
ThreadCreationTime : 1-17-2007 6:56:09 PM
BasePriority : Normal
FileVersion : 3.0.0.7
ProductVersion : 3.0.0.7
CompanyName : AceBIT GmbH
LegalCopyright : © 1998-2003 by AceBIT GmbH
#:33 [superantispyware.exe]
FilePath : C:\Program Files\SUPERAntiSpyware\
ProcessID : 1668
ThreadCreationTime : 1-17-2007 6:56:13 PM
BasePriority : Normal
FileVersion : 3, 5, 0, 1016
ProductVersion : 3, 5, 0, 1016
ProductName : SUPERAntiSpyware
CompanyName : SUPERAntiSpyware.com
FileDescription : SUPERAntiSpyware
InternalName : SUPERAntiSpyware
LegalCopyright : Copyright © 2005-2007 by SUPERAntiSpyware.com and SUPERAdBlocker.com
OriginalFilename : SUPERAntiSpyware.exe
#:34 [wzqkpick.exe]
FilePath : C:\Program Files\WinZip\
ProcessID : 1272
ThreadCreationTime : 1-17-2007 6:56:30 PM
BasePriority : Normal
FileVersion : 1.0 (32-bit)
ProductVersion : 8.1 (4319)
ProductName : WinZip
CompanyName : WinZip Computing, Inc.
FileDescription : WinZip Executable
InternalName : WZQKPICK.EXE
LegalCopyright : Copyright © WinZip Computing, Inc. 1991-2001 - All Rights Reserved
LegalTrademarks : WinZip is a registered trademark of WinZip Computing, Inc
OriginalFilename : WZQKPICK.EXE
Comments : StringFileInfo: U.S. English
#:35 [googletoolbarnotifier.exe]
FilePath : C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\
ProcessID : 1144
ThreadCreationTime : 1-17-2007 7:09:00 PM
BasePriority : Normal
FileVersion : 1, 2, 908, 5008
ProductVersion : 1, 2, 908, 5008
ProductName : GoogleToolbarNotifier
CompanyName : Google Inc.
FileDescription : GoogleToolbarNotifier
LegalCopyright : Copyright © 2005-2006
OriginalFilename : GoogleToolbarNotifier.exe
#:36 [iexplore.exe]
FilePath : C:\Program Files\Internet Explorer\
ProcessID : 992
ThreadCreationTime : 1-17-2007 7:30:15 PM
BasePriority : Normal
FileVersion : 6.00.2800.1106
ProductVersion : 6.00.2800.1106
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Internet Explorer
InternalName : iexplore
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : IEXPLORE.EXE
#:37 [ad-aware.exe]
FilePath : C:\PROGRA~1\Lavasoft\AD-AWA~1\
ProcessID : 2688
ThreadCreationTime : 1-17-2007 7:50:00 PM
BasePriority : Normal
FileVersion : 6.2.0.236
ProductVersion : SE 106
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright © Lavasoft AB Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved
Memory scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0
Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Registry Scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0
Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0
Started Tracking Cookie scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : kylem@revsci[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:2
Value : Cookie:kylem@revsci.net/
Expires : 1-12-2027 11:31:10 AM
LastSync : Hits:2
UseCount : 0
Hits : 2
Tracking cookie scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 1
Objects found so far: 1
Deep scanning and examining files (C:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Disk Scan Result for C:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 1
Scanning Hosts file......
Hosts file location:"C:\WINNT\system32\drivers\etc\hosts".
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Hosts file scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
1 entries scanned.
New critical objects:0
Objects found so far: 1
Performing conditional scans...
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Conditional scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 1
11:55:58 AM Scan Complete
Summary Of This Scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Total scanning time:00:05:04.547
Objects scanned:88376
Objects identified:1
Objects ignored:0
New critical objects:1
*** Next ***
SUPERAntiSpyware Scan Log
Generated 01/17/2007 at 10:50 AM
Application Version : 3.5.1016
Core Rules Database Version : 3165
Trace Rules Database Version: 1176
Scan type : Complete Scan
Total Scan Time : 00:44:17
Memory items scanned : 347
Memory threats detected : 4
Registry items scanned : 3749
Registry threats detected : 24
File items scanned : 36213
File threats detected : 181
Trojan.Downloader-Gen/Win
C:\WINNT\SYSTEM32\KERNELS88.EXE
C:\WINNT\SYSTEM32\KERNELS88.EXE
[System] C:\WINNT\SYSTEM32\KERNELS88.EXE
Trojan.VXGame-Gen
C:\WINNT\SYSTEM32\DLH9JKD1Q2.EXE
C:\WINNT\SYSTEM32\DLH9JKD1Q2.EXE
C:\WINNT\SYSTEM32\DLH9JKD1Q6.EXE
C:\WINNT\SYSTEM32\DLH9JKD1Q6.EXE
C:\WINNT\SYSTEM32\DLH9JKD1Q7.EXE
C:\WINNT\SYSTEM32\DLH9JKD1Q7.EXE
C:\DOCUMENTS AND SETTINGS\TFRENCH\LOCAL SETTINGS\TEMP\2.DLLB
C:\DOCUMENTS AND SETTINGS\TFRENCH\LOCAL SETTINGS\TEMP\6.DLLB
C:\WINNT\SYSTEM32\VXG6AME4.EXE
C:\WINNT\SYSTEM32\VXGA1ME4T1.EXE
C:\WINNT\SYSTEM32\VXGA4ME1.EXE
Trojan.Downloader-Gen/MultiBot
[WinUpgrade] C:\DOCUME~1\TFRENCH\LOCALS~1\TEMP\130406.EXE
C:\DOCUME~1\TFRENCH\LOCALS~1\TEMP\130406.EXE
[WinUpdate] C:\DOCUME~1\TFRENCH\LOCALS~1\TEMP\131546.EXE
C:\DOCUME~1\TFRENCH\LOCALS~1\TEMP\131546.EXE
C:\DOCUMENTS AND SETTINGS\TFRENCH\LOCAL SETTINGS\TEMP\12038593.EXE
C:\DOCUMENTS AND SETTINGS\TFRENCH\LOCAL SETTINGS\TEMP\12038734.EXE
C:\DOCUMENTS AND SETTINGS\TFRENCH\LOCAL SETTINGS\TEMP\129296.EXE
C:\DOCUMENTS AND SETTINGS\TFRENCH\LOCAL SETTINGS\TEMP\130406.EXE
C:\DOCUMENTS AND SETTINGS\TFRENCH\LOCAL SETTINGS\TEMP\131546.EXE
C:\DOCUMENTS AND SETTINGS\TFRENCH\LOCAL SETTINGS\TEMP\152125.EXE
C:\DOCUMENTS AND SETTINGS\TFRENCH\LOCAL SETTINGS\TEMP\152343.EXE
C:\DOCUMENTS AND SETTINGS\TFRENCH\LOCAL SETTINGS\TEMP\152531.EXE
Trojan.Downloader-WS2F
Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\winsys2freg
C:\DOCUMENTS AND SETTINGS\ALL USERS\DOCUMENTS\SETTINGS\WINSYS2F.DLL
HKLM\Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\winsys2freg
HKLM\Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\winsys2freg#DllName
HKLM\Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\winsys2freg#Startup
HKLM\Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\winsys2freg#Impersonate
HKLM\Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\winsys2freg#Asynchronous
Adware.Tracking Cookie
C:\Documents and Settings\Tfrench\Cookies\kylem@25513229[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@bluestreak[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@ads.cnn[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@sales.liveperson[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@ehg-chartercommunications.hitbox[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@adopt.euroclick[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@t4.trackalyzer[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@onlinerewardcenter[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@adserver.pollstar[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@mediaplex[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@tacoda[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@adbrite[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@adknowledge[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@azoogleads[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@overture[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@77090012[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@buycom.122.2o7[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@perf.overture[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@statse.webtrendslive[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@anad.tacoda[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@tripod[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@adrevolver[3].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@serving-sys[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@ehg-dig.hitbox[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@cgi-bin[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@adrevolver[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@fastclick[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@atdmt[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@edge.ru4[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@casalemedia[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@2o7[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@advertising[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@ad[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@as-us.falkag[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@1069551092[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@44153975[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@ehg-accuweather.hitbox[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@1072696478[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@azjmp[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@adlegend[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@ehg-esignal.hitbox[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@www.upspiral[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@stats1.reliablestats[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@ads.belointeractive[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@revenue[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@tribalfusion[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@adinterax[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@86845467[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@a.websponsors[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@phg.hitbox[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@gmgmacfs.112.2o7[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@dowjones.122.2o7[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@interclick[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@ehg-bizjournals.hitbox[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@vhost.oddcast[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@ehg.hitbox[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@ehg-tigerdirect2.hitbox[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@cbs.112.2o7[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@host.oddcast[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@tracking.foxnews[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@ehg-aig.hitbox[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@rrpartners.122.2o7[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@1072707690[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@www.serials[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@ehg-inforspaceinc.hitbox[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@nasdaq.122.2o7[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@mb[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@riskwaters[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@realmedia[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@c.goclick[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@statcounter[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@e-2dj6wjnyogazcdp.stats.esomniture[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@rambler[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@msnportal.112.2o7[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@dealtime[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@doubleclick[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@login.tracking101[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@stats4u.traffic4u[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@ads.pointroll[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@ehg-verizon.hitbox[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@hitbox[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@atwola[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@www.windowsmedia[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@ad.yieldmanager[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@oddcast[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@zedo[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@e-2dj6wjlyclcjiap.stats.esomniture[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@nextag[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@adopt.specificclick[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@wrigley.122.2o7[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@maxserving[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@offers.intermediainteractive[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@stat.dealtime[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@belnk[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@ads.monster[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@pt.crossmediaservices[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@ehg-traderpublishing.hitbox[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@ads.addynamix[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@ford.112.2o7[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@kanoodle[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@revsci[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@server.iad.liveperson[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@anheuserbusch.122.2o7[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@qnsr[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@cnn.122.2o7[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@questionmarket[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@e-2dj6wjkyknajahp.stats.esomniture[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@trafficmp[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@counter.surfcounters[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@e-2dj6wjl4knajgco.stats.esomniture[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@gostats[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@ehg-salomon.hitbox[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@e-2dj6wjlooodjehp.stats.esomniture[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@e-2dj6wjkochc5ago.stats.esomniture[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@yadro[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@c2.zedo[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@1070041844[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@clickauditor[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@toplist[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@anat.tacoda[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@76226072[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@ehg-verizonwireless.hitbox[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@p[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@risk[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@usenext[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@counter.hitslink[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@www.dealtime[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@z1.adserver[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@ehg-newegg.hitbox[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@tradedoubler[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@paypal.112.2o7[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@e-2dj6wfkygkczglp.stats.esomniture[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@adtech[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@stat.onestat[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@58154541[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@1072704879[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@e-2dj6wjkoaidjsgp.stats.esomniture[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@roiservice[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@40715998[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@coolsavings[1].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@mb[2].txt
C:\Documents and Settings\Tfrench\Cookies\kylem@partner2profit[1].txt
C:\Documents and Settings\Administrator.WENATCHEE\Cookies\administrator@atdmt[1].txt
C:\Documents and Settings\Tfrench\Local Settings\Temp\Cookies\kylem@2o7[1].txt
C:\Documents and Settings\Tfrench\Local Settings\Temp\Cookies\kylem@ads.pointroll[2].txt
C:\Documents and Settings\Tfrench\Local Settings\Temp\Cookies\kylem@advertising[1].txt
C:\Documents and Settings\Tfrench\Local Settings\Temp\Cookies\kylem@atdmt[2].txt
C:\Documents and Settings\Tfrench\Local Settings\Temp\Cookies\kylem@atwola[1].txt
C:\Documents and Settings\Tfrench\Local Settings\Temp\Cookies\kylem@doubleclick[1].txt
C:\Documents and Settings\Tfrench\Local Settings\Temp\Cookies\kylem@kanoodle[2].txt
C:\Documents and Settings\Tfrench\Local Settings\Temp\Cookies\kylem@mediaplex[1].txt
C:\Documents and Settings\Tfrench\Local Settings\Temp\Cookies\kylem@msnportal.112.2o7[1].txt
C:\Documents and Settings\Tfrench\Local Settings\Temp\Cookies\kylem@perf.overture[1].txt
C:\Documents and Settings\Tfrench\Local Settings\Temp\Cookies\kylem@questionmarket[1].txt
C:\Documents and Settings\Tfrench\Local Settings\Temp\Cookies\kylem@zedo[2].txt
Adware.SideStep Toolbar
HKCR\CLSID\{D714A94F-123A-45CC-8F03-040BCAF82AD6}
HKCR\CLSID\{D714A94F-123A-45CC-8F03-040BCAF82AD6}\InprocServer32
HKCR\CLSID\{D714A94F-123A-45CC-8F03-040BCAF82AD6}\InprocServer32#ThreadingModel
HKCR\CLSID\{83B28A74-640D-48F4-9F51-E80EED7CC7E0}
HKCR\CLSID\{83B28A74-640D-48F4-9F51-E80EED7CC7E0}\Implemented Categories
HKCR\CLSID\{83B28A74-640D-48F4-9F51-E80EED7CC7E0}\Implemented Categories\{00021493-0000-0000-C000-000000000046}
HKCR\CLSID\{83B28A74-640D-48F4-9F51-E80EED7CC7E0}\InprocServer32
HKCR\CLSID\{83B28A74-640D-48F4-9F51-E80EED7CC7E0}\InprocServer32#ThreadingModel
Trojan.BraveSentry
C:\Program Files\BraveSentry\BraveSentry.exe
C:\Program Files\BraveSentry\BraveSentry.lic
C:\Program Files\BraveSentry\Uninstall.exe
C:\Program Files\BraveSentry
Trojan.Haxdoor-P79
HKLM\Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\pasksa
HKLM\Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\pasksa#DllName
HKLM\Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\pasksa#Startup
HKLM\Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\pasksa#Impersonate
HKLM\Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\pasksa#Asynchronous
HKLM\Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\pasksa#MaxWait
HKLM\Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\pasksa#2sksid
Trojan.Downloader/SmitF
C:\WINNT\DESKTOP.HTML
Trojan.Unknown Origin
C:\WINNT\SYSTEM32\VX.TLL