BitDefender Online Scanner
Scan report generated at: Mon, Jun 05, 2006 - 01:12:59
Scan path: A:\;C:\;D:\;E:\;F:\;G:\;H:\;
Statistics
Time
05:40:02
Files
403548
Folders
7787
Boot Sectors
4
Archives
5790
Packed Files
15165
Results
Identified Viruses
7
Infected Files
11
Suspect Files
0
Warnings
0
Disinfected
0
Deleted Files
11
Engines Info
Virus Definitions
386449
Engine build
AVCORE v1.0 (build 2310) (i386) (Apr 17 2006 16:24:38)
Scan plugins
13
Archive plugins
40
Unpack plugins
4
E-mail plugins
6
System plugins
1
Scan Settings
First Action
Disinfect
Second Action
Delete
Heuristics
Yes
Enable Warnings
Yes
Scanned Extensions
*;
Exclude Extensions
Scan Emails
Yes
Scan Archives
Yes
Scan Packed
Yes
Scan Files
Yes
Scan Boot
Yes
Scanned File
Status
C:\Documents and Settings\Gill\Angel's Documents\Downloads\MsgPlus-301.exe
Infected with: Trojan.Swizzor.DP
C:\Documents and Settings\Gill\Angel's Documents\Downloads\MsgPlus-301.exe
Disinfection failed
C:\Documents and Settings\Gill\Angel's Documents\Downloads\MsgPlus-301.exe
Deleted
C:\Documents and Settings\Gill\Angel's Documents\Downloads\68907.exe=>wise0018
Infected with: Trojan.Dloader.HK
C:\Documents and Settings\Gill\Angel's Documents\Downloads\68907.exe=>wise0018
Disinfection failed
C:\Documents and Settings\Gill\Angel's Documents\Downloads\68907.exe=>wise0018
Deleted
C:\Documents and Settings\Gill\Angel's Documents\Downloads\68907.exe
Update failed
C:\Documents and Settings\Gill\Angel's Documents\Downloads\68907.exe=>wise0019
Infected with: Dropped:Application.Adware.NewDotNet.A
C:\Documents and Settings\Gill\Angel's Documents\Downloads\68907.exe=>wise0019
Disinfection failed
C:\Documents and Settings\Gill\Angel's Documents\Downloads\68907.exe=>wise0019
Deleted
C:\Documents and Settings\Gill\Angel's Documents\Downloads\68907.exe
Update failed
C:\Documents and Settings\Gill\Angel's Documents\Downloads\66429.exe=>wise0019
Infected with: Trojan.Dloader.HK
C:\Documents and Settings\Gill\Angel's Documents\Downloads\66429.exe=>wise0019
Disinfection failed
C:\Documents and Settings\Gill\Angel's Documents\Downloads\66429.exe=>wise0019
Deleted
C:\Documents and Settings\Gill\Angel's Documents\Downloads\66429.exe
Update failed
C:\Documents and Settings\Gill\Angel's Documents\Downloads\66429.exe=>wise0020
Infected with: Dropped:Application.Adware.NewDotNet.A
C:\Documents and Settings\Gill\Angel's Documents\Downloads\66429.exe=>wise0020
Disinfection failed
C:\Documents and Settings\Gill\Angel's Documents\Downloads\66429.exe=>wise0020
Deleted
C:\Documents and Settings\Gill\Angel's Documents\Downloads\66429.exe
Update failed
C:\Documents and Settings\Gill\Angel's Documents\Downloads\66429.exe=>wise0021
Infected with: Dropped:Application.ProcKill.Jk
C:\Documents and Settings\Gill\Angel's Documents\Downloads\66429.exe=>wise0021
Disinfection failed
C:\Documents and Settings\Gill\Angel's Documents\Downloads\66429.exe=>wise0021
Deleted
C:\Documents and Settings\Gill\Angel's Documents\Downloads\66429.exe
Update failed
C:\Documents and Settings\Gill\Angel's Documents\Downloads\75712.exe=>wise0018
Infected with: Trojan.Dloader.HK
C:\Documents and Settings\Gill\Angel's Documents\Downloads\75712.exe=>wise0018
Disinfection failed
C:\Documents and Settings\Gill\Angel's Documents\Downloads\75712.exe=>wise0018
Deleted
C:\Documents and Settings\Gill\Angel's Documents\Downloads\75712.exe
Update failed
C:\Documents and Settings\Gill\Angel's Documents\Downloads\75712.exe=>wise0019
Infected with: Dropped:Application.Adware.NewDotNet.A
C:\Documents and Settings\Gill\Angel's Documents\Downloads\75712.exe=>wise0019
Disinfection failed
C:\Documents and Settings\Gill\Angel's Documents\Downloads\75712.exe=>wise0019
Deleted
C:\Documents and Settings\Gill\Angel's Documents\Downloads\75712.exe
Update failed
D:\Documents and Settings\Angel\My Documents\Downloads\ScreenSavers\dolphinfree.exe=> wise0059
Detected with: Application.Adware.NewDotNet.Dropper
D:\Documents and Settings\Angel\My Documents\Downloads\ScreenSavers\dolphinfree.exe=> wise0059
Deleted
D:\Documents and Settings\Angel\My Documents\Downloads\ScreenSavers\dolphinfree.exe
Update failed
D:\Documents and Settings\Angel\My Documents\Downloads\ScreenSavers\dolphinfree.exe=> wise0060
Detected with: Application.Adware.NewDotNet.B.Dropper
D:\Documents and Settings\Angel\My Documents\Downloads\ScreenSavers\dolphinfree.exe=> wise0060
Deleted
D:\Documents and Settings\Angel\My Documents\Downloads\ScreenSavers\dolphinfree.exe
Update failed
D:\WINDOWS\system32\gdiw2k.sys
Infected with: Trojan.Spy.Goldun.DJ
D:\WINDOWS\system32\gdiw2k.sys
Disinfection failed
D:\WINDOWS\system32\gdiw2k.sys
Deleted
when the scan had finished it said my pc is still infected,bitdefender is great to find all of them after programmes i tried didn't..
new hjt log:
Logfile of HijackThis v1.99.1
Scan saved at 01:33:51, on 05/06/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
D:\WINDOWS\system32\LEXBCES.EXE
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\system32\LEXPPS.EXE
D:\WINDOWS\Explorer.EXE
d:\progra~1\mcafee\mcafee antispyware\massrv.exe
d:\program files\mcafee.com\agent\mcdetect.exe
d:\PROGRA~1\mcafee.com\agent\mctskshd.exe
D:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
D:\WINDOWS\System32\oodag.exe
d:\progra~1\mcafee.com\vso\mcvsescn.exe
D:\WINDOWS\system32\pctspk.exe
d:\program files\mcafee.com\agent\mcagent.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
D:\Program Files\QuickTime\qttask.exe
D:\Program Files\MessengerPlus! 3\MsgPlus1.exe
D:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
D:\progra~1\mcafee\MCAFEE~1\masalert.exe
D:\Program Files\PromptCast\PromptCast.exe
D:\Program Files\McAfee\McAfee QuickClean\Plguni.exe
D:\Program Files\MRU-Blaster\scheduler.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\PROGRA~1\McAfee.com\PERSON~1\Mp***ent.exe
D:\Program Files\ewido anti-malware\ewidoctrl.exe
d:\progra~1\mcafee.com\vso\mcvsftsn.exe
D:\Program Files\Messenger\msmsgs.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\wuauclt.exe
D:\Program Files\Outlook Express\msimn.exe
d:\PROGRA~1\mcafee.com\vso\mcshield.exe
d:\PROGRA~1\mcafee.com\vso\OasClnt.exe
D:\Documents and Settings\Angel\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.wanadoo.co.uk/iesearch/default.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.orange.co.uk/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.orange.co.uk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Wanadoo
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyServer = http=http://www-cache.wanadoo.co.uk:8080;ftp=http://www-cache.wanadoo.co.uk:8080
R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - D:\Program Files\ICQToolbar\toolbaru.dll
O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - D:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O2 - BHO: Big Fish Games Toolbar - {4E7BD74F-2B8D-469E-86BD-FD60BB9AAE3A} - D:\PROGRA~1\BFGTOO~1\BFGTOO~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar2.dll
O2 - BHO: CoTGT_BHO Class - {C333CF63-767F-4831-94AC-E683D962C63C} - D:\Program Files\TGTSoft\StyleXP\TGT_BHO.dll
O3 - Toolbar: Big Fish Games Toolbar - {4E7BD74F-2B8D-469E-86BD-FD60BB9AAE3A} - D:\PROGRA~1\BFGTOO~1\BFGTOO~1.DLL
O3 - Toolbar: Wanadoo - {8B68564D-53FD-4293-B80C-993A9F3988EE} - C:\PROGRA~1\Wanadoo\WSBar\WSBar.dll
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - D:\Program Files\ICQToolbar\toolbaru.dll
O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - D:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar2.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - d:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] D:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [InCD] D:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [NeroFilterCheck] D:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Lexmark X1100 Series] "D:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [Fellowes Proxy] D:\WINDOWS\System32\r3proxy.exe
O4 - HKLM\..\Run: [MessengerPlus3] "D:\Program Files\MessengerPlus! 3\MsgPlus1.exe"
O4 - HKLM\..\Run: [MPFExe] D:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [MCAgentExe] d:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] d:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [VSOCheckTask] "D:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] D:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] D:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [_AntiSpyware] d:\progra~1\mcafee\MCAFEE~1\masalert.exe
O4 - HKLM\..\RunOnce: [MRUBlaster] D:\Program Files\MRU-Blaster\indexcleaner.exe -CC
O4 - HKCU\..\Run: [STYLEXP] D:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [PromptCast] D:\Program Files\PromptCast\PromptCast.exe
O4 - HKCU\..\Run: [McAfee QuickClean Imonitor] D:\Program Files\McAfee\McAfee QuickClean\Plguni.exe /START
O4 - Startup: MRU-Blaster Scheduler.lnk = D:\Program Files\MRU-Blaster\scheduler.exe
O4 - Startup: MRU-Blaster Silent Clean.lnk = D:\Program Files\MRU-Blaster\mrublaster.exe
O8 - Extra context menu item: &eBay Search - res://D:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: &Google Search - res://d:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &ICQ Toolbar Search - res://D:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O8 - Extra context menu item: &Translate English Word - res://d:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: &Windows Live Search - res://D:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Backward Links - res://d:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://d:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Download all by Free Download Manager - file://D:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download by Free Download Manager - file://D:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: Download selected by Free Download Manager - file://D:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download web site by Free Download Manager - file://D:\Program Files\Free Download Manager\dlpage.htm
O8 - Extra context menu item: Open in new background tab - res://D:\Program Files\Windows Live Toolbar\Components\en-gb\msntabres.dll.mui/229?ea0ef7f7ca9d4fc18a76d30ae86cba25
O8 - Extra context menu item: Open in new foreground tab - res://D:\Program Files\Windows Live Toolbar\Components\en-gb\msntabres.dll.mui/230?ea0ef7f7ca9d4fc18a76d30ae86cba25
O8 - Extra context menu item: Search with Wanadoo - res://C:\PROGRA~1\Wanadoo\WSBar\WSBar.dll/VSearch.htm
O8 - Extra context menu item: Similar Pages - res://d:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://d:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - D:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - D:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - D:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - D:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - D:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} -
http://aolcc.aolsvc.aol.co.uk/comput...up/qdiagcc.cab
O16 - DPF: {5554A026-7282-4C11-A8F1-652D0599CD02} (NMInstall Control) -
http://a14.g.akamai.net/f/14/7141/1d...OPE_SILENT.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -
http://download.bitdefender.com/reso...an8/oscan8.cab
O16 - DPF: {77DD44BF-551D-4E3C-82CD-D637D5018D3C} -
http://www.surveys.com/promptcast/In...ST%20SETUP.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) -
http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {A9FD89D6-C839-11D3-B0FE-0050044B8FE9} (OBInstallRunner Control) -
http://www.opinionbar.com/download/r...allCabinet.CAB
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn.com/download/Ms...Downloader.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) -
http://ax.emsisoft.com/asquared.cab
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) -
https://spinpalace.microgaming.com/freeplay/FlashAX.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) -
http://www.popcap.com/games/popcaploader_v6.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) -
http://chat.msn.com/controls/msnchat45.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - "D:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: MsgPlusLoader.dll
O20 - Winlogon Notify: gdiwxp - gdiwxp.dll (file missing)
O20 - Winlogon Notify: intel3 - intel3.dll (file missing)
O23 - Service: ewido security suite control - ewido networks - D:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - D:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee AntiSpyware Service - McAfee, Inc. - d:\progra~1\mcafee\mcafee antispyware\massrv.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - d:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - d:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - d:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - D:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - D:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: O&O Defrag - O&O Software GmbH - D:\WINDOWS\System32\oodag.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - D:\WINDOWS\system32\pctspk.exe
O23 - Service: StyleXPService - Unknown owner - D:\Program Files\TGTSoft\StyleXP\StyleXPService.exe