DrWeb.CSV
================================================== =
cqniccmd.VIR;C:\WINDOWS\system32;Win32.Virut.5;Inc urable.Moved.;
dns.VIR;C:\WINDOWS\system32;Win32.Virut.5;Incurabl e.Moved.;
evntwin.VIR;C:\WINDOWS\system32;Win32.Virut.5;Incu rable.Moved.;
expand.VIR;C:\WINDOWS\system32;Win32.Virut.5;Incur able.Moved.;
flattemp.VIR;C:\WINDOWS\system32;Win32.Virut.5;Inc urable.Moved.;
label.VIR;C:\WINDOWS\system32;Win32.Virut.5;Incura ble.Moved.;
rdshost.VIR;C:\WINDOWS\system32;Win32.Virut.5;Incu rable.Moved.;
relog.VIR;C:\WINDOWS\system32;Win32.Virut.5;Incura ble.Moved.;
savedump.VIR;C:\WINDOWS\system32;Win32.Virut.5;Inc urable.Moved.;
vdsldr.VIR;C:\WINDOWS\system32;Win32.Virut.5;Incur able.Moved.;
winmsd.VIR;C:\WINDOWS\system32;Win32.Virut.5;Incur able.Moved.;
wlbs.VIR;C:\WINDOWS\system32;Win32.Virut.5;Incurab le.Moved.;
wpabaln.VIR;C:\WINDOWS\system32;Win32.Virut.5;Incu rable.Moved.;
Welcome.html;C:\Program Files\Trend Micro\ISVW\UI\j2re1.4.2;Trojan.Starman.100;Cured.;
ftsbody.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
ftsdhtml.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
ftsform.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
H-admin-lic-active_text0.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
H-ftp-config_text0.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
H-ftp-config_text1.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
H-http-config_text0.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
H-http-config_text1.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
H-pop3-config_text0.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
H-pop3-config_text1.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
H-pop3-config_text2.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
H-pop3-config_text3.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
H-pop3-content-targ_text0.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
H-pop3-content-targ_text1.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
H-pop3-spam-targ_text0.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
H-server-config-alerts_text0.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
H-smtp-config-incoming_text0.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
H-smtp-config-relay_text0.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
H-smtp-config-server_text0.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
H-smtp-config-server_text1.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
H-smtp-config-server_text2.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
H-smtp-config-server_text3.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
H-smtp-config-server_text4.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
H-smtp-content-incoming-targ_text0.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
H-smtp-content-incoming-targ_text1.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
H-smtp-content-incoming-targ_text2.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
H-smtp-content-outgoing-targ_text0.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
H-smtp-content-outgoing-targ_text1.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
H-smtp-content-outgoing-targ_text2.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
H-smtp-quarantine-search_text0.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
H-smtp-spam-targ_text0.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
H-update-proxy_text0.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
H-update-proxy_text1.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
H-update-proxy_text2.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
How_Viruses_Spread_text0.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
idxbody.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
idxdhtml.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
idxform.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
idxlist.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
ISVW.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
ISVW_csh.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
Methods_of_Virus_Detection_text0.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
Methods_of_Virus_Detection_text1.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
Methods_of_Virus_Detection_text2.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
Methods_of_Virus_Detection_text3.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
Methods_of_Virus_Detection_text4.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
Methods_of_Virus_Detection_text5.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
navframe.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
navpane1.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
navpane2.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
tabframe.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
tocdhtml.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
toclist.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
Types_of_Antivirus_Programs_text0.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
Types_of_Antivirus_Programs_text1.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
Types_of_Viruses_text0.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
Types_of_Viruses_text1.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
_blank.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\ROOT\L10N\en\help;Trojan.Starman.100;C ured.;
interruptMsg.htm;C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\webapps\user\html;Trojan.Starman.100;Cured.;
CasPol.exe;C:\sysclean\backup;Win32.Virut.5;Incura ble.Moved.;
dfscmd.exe;C:\sysclean\backup;Win32.Virut.5;Incura ble.Moved.;
DotNetInstaller.exe;C:\sysclean\backup;Win32.Virut .5;Incurable.Moved.;
evcreate.exe;C:\sysclean\backup;Win32.Virut.5;Incu rable.Moved.;
eventcreate.exe;C:\sysclean\backup;Win32.Virut.5;I ncurable.Moved.;
eventtriggers.exe;C:\sysclean\backup;Win32.Virut.5 ;Incurable.Moved.;
evtrig.exe;C:\sysclean\backup;Win32.Virut.5;Incura ble.Moved.;
hscupd.exe;C:\sysclean\backup;Win32.Virut.5;Incura ble.Moved.;
hscupd.VIR;C:\sysclean\backup;Win32.Virut.5;Incura ble.Moved.;
IEExec.exe;C:\sysclean\backup;Win32.Virut.5;Incura ble.Moved.;
imjpdadm.exe;C:\sysclean\backup;Win32.Virut.5;Incu rable.Moved.;
InstallUtil.exe;C:\sysclean\backup;Win32.Virut.5;I ncurable.Moved.;
jsc.exe;C:\sysclean\backup;Win32.Virut.5;Incurable .Moved.;
ldifde.exe;C:\sysclean\backup;Win32.Virut.5;Incura ble.Moved.;
ldifde.VIR;C:\sysclean\backup;Win32.Virut.5;Incura ble.Moved.;
MigPol.exe;C:\sysclean\backup;Win32.Virut.5;Incura ble.Moved.;
migpol.VI0;C:\sysclean\backup;Win32.Virut.5;Incura ble.Moved.;
migpol.VIR;C:\sysclean\backup;Win32.Virut.5;Incura ble.Moved.;
MigPolWin.exe;C:\sysclean\backup;Win32.Virut.5;Inc urable.Moved.;
migpolwin.VI0;C:\sysclean\backup;Win32.Virut.5;Inc urable.Moved.;
migpolwin.VIR;C:\sysclean\backup;Win32.Virut.5;Inc urable.Moved.;
mnmsrvc.exe;C:\sysclean\backup;Win32.Virut.5;Incur able.Moved.;
mofcomp.exe;C:\sysclean\backup;Win32.Virut.5;Incur able.Moved.;
mofcomp.VIR;C:\sysclean\backup;Win32.Virut.5;Incur able.Moved.;
msdtc.exe;C:\sysclean\backup;Win32.Virut.5;Incurab le.Moved.;
msg.exe;C:\sysclean\backup;Win32.Virut.5;Incurable .Moved.;
RegAsm.exe;C:\sysclean\backup;Win32.Virut.5;Incura ble.Moved.;
RegSvcs.exe;C:\sysclean\backup;Win32.Virut.5;Incur able.Moved.;
regsvcs.VI0;C:\sysclean\backup;Win32.Virut.5;Incur able.Moved.;
regsvcs.VIR;C:\sysclean\backup;Win32.Virut.5;Incur able.Moved.;
rsdiag.exe;C:\sysclean\backup;Win32.Virut.5;Incura ble.Moved.;
sc.exe;C:\sysclean\backup;Win32.Virut.5;Incurable. Moved.;
sfmpsexe.exe;C:\sysclean\backup;Win32.Virut.5;Incu rable.Moved.;
tapicfg.exe;C:\sysclean\backup;Win32.Virut.5;Incur able.Moved.;
tasklist.exe;C:\sysclean\backup;Win32.Virut.5;Incu rable.Moved.;
tsecimp.exe;C:\sysclean\backup;Win32.Virut.5;Incur able.Moved.;
tsprof.exe;C:\sysclean\backup;Win32.Virut.5;Incura ble.Moved.;
dns.VIR;C:\WINDOWS\$NtServicePackUninstall$;Win32. Virut.5;Incurable.Moved.;
find.VIR;C:\WINDOWS\$NtServicePackUninstall$;Win32 .Virut.5;Incurable.Moved.;
ftp.VIR;C:\WINDOWS\$NtServicePackUninstall$;Win32. Virut.5;Incurable.Moved.;
fxssend.VIR;C:\WINDOWS\$NtServicePackUninstall$;Wi n32.Virut.5;Incurable.Moved.;
gprslt.VIR;C:\WINDOWS\$NtServicePackUninstall$;Win 32.Virut.5;Incurable.Moved.;
osk.exe;C:\WINDOWS\$NtServicePackUninstall$;Win32. Virut.5;Cured.;
sc.VIR;C:\WINDOWS\$NtServicePackUninstall$;Win32.V irut.5;Incurable.Moved.;
utilman.VIR;C:\WINDOWS\$NtServicePackUninstall$;Wi n32.Virut.5;Incurable.Moved.;
ciadmin.htm;C:\WINDOWS\Help;Trojan.Starman.100;Cur ed.;
SmartNav.htm;C:\WINDOWS\Microsoft.NET\Framework\v1 .1.4322\ASP.NETClientFiles;Trojan.Starman.100;Cure d.;
AboutCompat.htm;C:\WINDOWS\PCHEALTH\HELPCTR\System \CompatCtr;Trojan.Starman.100;Cured.;
CompatOffline.htm;C:\WINDOWS\PCHEALTH\HELPCTR\Syst em\CompatCtr;Trojan.Starman.100;Cured.;
LearnCompat.htm;C:\WINDOWS\PCHEALTH\HELPCTR\System \CompatCtr;Trojan.Starman.100;Cured.;
privacy.htm;C:\WINDOWS\PCHEALTH\HELPCTR\System\DFS ;Trojan.Starman.100;Cured.;
uplddrvinfo.htm;C:\WINDOWS\PCHEALTH\HELPCTR\System \DFS;Trojan.Starman.100;Cured.;
xmldialog.htm;C:\WINDOWS\PCHEALTH\HELPCTR\System\D FS;Trojan.Starman.100;Cured.;
dvdupgrd.htm;C:\WINDOWS\PCHEALTH\HELPCTR\System\DV DUpgrd;Trojan.Starman.100;Cured.;
ErrorMessagesOffline.htm;C:\WINDOWS\PCHEALTH\HELPC TR\System\ErrMsg;Trojan.Starman.100;Cured.;
dglogshelp.htm;C:\WINDOWS\PCHEALTH\HELPCTR\System\ NetDiag;Trojan.Starman.100;Cured.;
blank.htm;C:\WINDOWS\PCHEALTH\HELPCTR\System\panel s;Trojan.Starman.100;Cured.;
rcRequest.htm;C:\WINDOWS\PCHEALTH\HELPCTR\System\r c;Trojan.Starman.100;Cured.;
helpeeaccept.htm;C:\WINDOWS\PCHEALTH\HELPCTR\Syste m\Remote Assistance;Trojan.Starman.100;Cured.;
RAStartPage.htm;C:\WINDOWS\PCHEALTH\HELPCTR\System \Remote Assistance;Trojan.Starman.100;Cured.;
ConnIssue.htm;C:\WINDOWS\PCHEALTH\HELPCTR\System\R emote Assistance\Common;Trojan.Starman.100;Cured.;
LearnInternet.htm;C:\WINDOWS\PCHEALTH\HELPCTR\Syst em\Remote Assistance\Common;Trojan.Starman.100;Cured.;
RCMoreInfo.htm;C:\WINDOWS\PCHEALTH\HELPCTR\System\ Remote Assistance\Common;Trojan.Starman.100;Cured.;
DividerBar.htm;C:\WINDOWS\PCHEALTH\HELPCTR\System\ Remote Assistance\Interaction\Client;Trojan.Starman.100;C ured.;
RAChatClient.htm;C:\WINDOWS\PCHEALTH\HELPCTR\Syste m\Remote Assistance\Interaction\Client;Trojan.Starman.100;C ured.;
RAClient.htm;C:\WINDOWS\PCHEALTH\HELPCTR\System\Re mote Assistance\Interaction\Client;Trojan.Starman.100;C ured.;
RAStatusBar.htm;C:\WINDOWS\PCHEALTH\HELPCTR\System \Remote Assistance\Interaction\Client;Trojan.Starman.100;C ured.;
rcscreen6_head.htm;C:\WINDOWS\PCHEALTH\HELPCTR\Sys tem\Remote Assistance\Interaction\Client;Trojan.Starman.100;C ured.;
setting.htm;C:\WINDOWS\PCHEALTH\HELPCTR\System\Rem ote Assistance\Interaction\Client;Trojan.Starman.100;C ured.;
ErrorMsgs.htm;C:\WINDOWS\PCHEALTH\HELPCTR\System\R emote Assistance\Interaction\Common;Trojan.Starman.100;C ured.;
RCFileXfer.htm;C:\WINDOWS\PCHEALTH\HELPCTR\System\ Remote Assistance\Interaction\Common;Trojan.Starman.100;C ured.;
voicefirewallmsg.htm;C:\WINDOWS\PCHEALTH\HELPCTR\S ystem\Remote Assistance\Interaction\Common;Trojan.Starman.100;C ured.;
VOIPMsgs.htm;C:\WINDOWS\PCHEALTH\HELPCTR\System\Re mote Assistance\Interaction\Common;Trojan.Starman.100;C ured.;
DividerBar1.htm;C:\WINDOWS\PCHEALTH\HELPCTR\System \Remote Assistance\Interaction\Server;Trojan.Starman.100;C ured.;
RAChatServer.htm;C:\WINDOWS\PCHEALTH\HELPCTR\Syste m\Remote Assistance\Interaction\Server;Trojan.Starman.100;C ured.;
SettingServer.htm;C:\WINDOWS\PCHEALTH\HELPCTR\Syst em\Remote Assistance\Interaction\Server;Trojan.Starman.100;C ured.;
TakeControlMsgs.htm;C:\WINDOWS\PCHEALTH\HELPCTR\Sy stem\Remote Assistance\Interaction\Server;Trojan.Starman.100;C ured.;
msinfo.htm;C:\WINDOWS\PCHEALTH\HELPCTR\System\sysi nfo;Trojan.Starman.100;Cured.;
sysComponentInfo.htm;C:\WINDOWS\PCHEALTH\HELPCTR\S ystem\sysinfo;Trojan.Starman.100;Cured.;
sysEvtLogInfo.htm;C:\WINDOWS\PCHEALTH\HELPCTR\Syst em\sysinfo;Trojan.Starman.100;Cured.;
sysHealthInfo.htm;C:\WINDOWS\PCHEALTH\HELPCTR\Syst em\sysinfo;Trojan.Starman.100;Cured.;
sysinfosum.htm;C:\WINDOWS\PCHEALTH\HELPCTR\System\ sysinfo;Trojan.Starman.100;Cured.;
sysRemoteInfo.htm;C:\WINDOWS\PCHEALTH\HELPCTR\Syst em\sysinfo;Trojan.Starman.100;Cured.;
sysServicesInfo.htm;C:\WINDOWS\PCHEALTH\HELPCTR\Sy stem\sysinfo;Trojan.Starman.100;Cured.;
sysSoftwareInfo.htm;C:\WINDOWS\PCHEALTH\HELPCTR\Sy stem\sysinfo;Trojan.Starman.100;Cured.;
AboutWU.htm;C:\WINDOWS\PCHEALTH\HELPCTR\System\Upd ateCtr;Trojan.Starman.100;Cured.;
Learn.htm;C:\WINDOWS\PCHEALTH\HELPCTR\System\Updat eCtr;Trojan.Starman.100;Cured.;
LearnInternet.htm;C:\WINDOWS\PCHEALTH\HELPCTR\Syst em\UpdateCtr;Trojan.Starman.100;Cured.;
learnWU.htm;C:\WINDOWS\PCHEALTH\HELPCTR\System\Upd ateCtr;Trojan.Starman.100;Cured.;
updatecenter.htm;C:\WINDOWS\PCHEALTH\HELPCTR\Syste m\UpdateCtr;Trojan.Starman.100;Cured.;
Connection.htm;C:\WINDOWS\PCHEALTH\HELPCTR\Vendors \CN=Microsoft Corporation,L=Redmond,S=Washington,C=US;Trojan.Sta rman.100;Cured.;
OfflineDC.htm;C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\ CN=Microsoft Corporation,L=Redmond,S=Washington,C=US;Trojan.Sta rman.100;Cured.;
OfflineOptions.htm;C:\WINDOWS\PCHEALTH\HELPCTR\Ven dors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US;Trojan.Sta rman.100;Cured.;
rcstatus.htm;C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\C N=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance;Trojan.Starman.100;Cured.;
ConnIssue-pro.htm;C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Mic rosoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Common;Trojan.Starman.100;Cured.;
ConnIssue.htm;C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\ CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Common;Trojan.Starman.100;Cured.;
LearnInternet.htm;C:\WINDOWS\PCHEALTH\HELPCTR\Vend ors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Common;Trojan.Starman.100;Cured.;
RCMoreInfo.htm;C:\WINDOWS\PCHEALTH\HELPCTR\Vendors \CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Common;Trojan.Starman.100;Cured.;
rcscreen1.htm;C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\ CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common;Trojan.Starman.100;Cu red.;
rcscreen2.htm;C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\ CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common;Trojan.Starman.100;Cu red.;
rcscreen3.htm;C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\ CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Common;Trojan.Starman.100;Cu red.;
escalationhelp-pro.htm;C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Mic rosoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email;Trojan.Starman.100;Cur ed.;
escalationhelp.htm;C:\WINDOWS\PCHEALTH\HELPCTR\Ven dors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email;Trojan.Starman.100;Cur ed.;
rcscreen5.htm;C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\ CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email;Trojan.Starman.100;Cur ed.;
rcscreen6.htm;C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\ CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email;Trojan.Starman.100;Cur ed.;
rcscreen6_head.htm;C:\WINDOWS\PCHEALTH\HELPCTR\Ven dors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email;Trojan.Starman.100;Cur ed.;
rcscreen8.htm;C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\ CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email;Trojan.Starman.100;Cur ed.;
rcscreen9.htm;C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\ CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email;Trojan.Starman.100;Cur ed.;
reminder.htm;C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\C N=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\Escalation\Email;Trojan.Starman.100;Cur ed.;
fpagloss.htm;C:\WINDOWS\ServicePackFiles\i386;Troj an.Starman.100;Cured.;
netmeet.htm;C:\WINDOWS\ServicePackFiles\i386;Troja n.Starman.100;Cured.;
tsweb1.htm;C:\WINDOWS\ServicePackFiles\i386;Trojan .Starman.100;Cured.;
wsgcgens.htm;C:\WINDOWS\ServicePackFiles\i386;Troj an.Starman.100;Cured.;
wsggloss.htm;C:\WINDOWS\ServicePackFiles\i386;Troj an.Starman.100;Cured.;
wsgindex.htm;C:\WINDOWS\ServicePackFiles\i386;Troj an.Starman.100;Cured.;
wsgpauth.htm;C:\WINDOWS\ServicePackFiles\i386;Troj an.Starman.100;Cured.;
wsgpcnfg.htm;C:\WINDOWS\ServicePackFiles\i386;Troj an.Starman.100;Cured.;
wsgpperf.htm;C:\WINDOWS\ServicePackFiles\i386;Troj an.Starman.100;Cured.;
wsgpscrp.htm;C:\WINDOWS\ServicePackFiles\i386;Troj an.Starman.100;Cured.;
wsgpsec.htm;C:\WINDOWS\ServicePackFiles\i386;Troja n.Starman.100;Cured.;
wsgpset.htm;C:\WINDOWS\ServicePackFiles\i386;Troja n.Starman.100;Cured.;
wsgpsmtp.htm;C:\WINDOWS\ServicePackFiles\i386;Troj an.Starman.100;Cured.;
default.htm;C:\WINDOWS\SoftwareDistribution\Downlo ad\7c205249e4e58548a01567c8dc12d1b5;Trojan.Starman .100;Cured.;
empty.htm;C:\WINDOWS\SoftwareDistribution\Download \7c205249e4e58548a01567c8dc12d1b5;Trojan.Starman.1 00;Cured.;
fpagloss.htm;C:\WINDOWS\SoftwareDistribution\Downl oad\7c205249e4e58548a01567c8dc12d1b5;Trojan.Starma n.100;Cured.;
navtree.htm;C:\WINDOWS\SoftwareDistribution\Downlo ad\7c205249e4e58548a01567c8dc12d1b5;Trojan.Starman .100;Cured.;
netmeet.htm;C:\WINDOWS\SoftwareDistribution\Downlo ad\7c205249e4e58548a01567c8dc12d1b5;Trojan.Starman .100;Cured.;
tree.htm;C:\WINDOWS\SoftwareDistribution\Download\ 7c205249e4e58548a01567c8dc12d1b5;Trojan.Starman.10 0;Cured.;
tsweb1.htm;C:\WINDOWS\SoftwareDistribution\Downloa d\7c205249e4e58548a01567c8dc12d1b5;Trojan.Starman. 100;Cured.;
wsgcgens.htm;C:\WINDOWS\SoftwareDistribution\Downl oad\7c205249e4e58548a01567c8dc12d1b5;Trojan.Starma n.100;Cured.;
wsggloss.htm;C:\WINDOWS\SoftwareDistribution\Downl oad\7c205249e4e58548a01567c8dc12d1b5;Trojan.Starma n.100;Cured.;
wsgindex.htm;C:\WINDOWS\SoftwareDistribution\Downl oad\7c205249e4e58548a01567c8dc12d1b5;Trojan.Starma n.100;Cured.;
wsgpauth.htm;C:\WINDOWS\SoftwareDistribution\Downl oad\7c205249e4e58548a01567c8dc12d1b5;Trojan.Starma n.100;Cured.;
wsgpcnfg.htm;C:\WINDOWS\SoftwareDistribution\Downl oad\7c205249e4e58548a01567c8dc12d1b5;Trojan.Starma n.100;Cured.;
wsgpperf.htm;C:\WINDOWS\SoftwareDistribution\Downl oad\7c205249e4e58548a01567c8dc12d1b5;Trojan.Starma n.100;Cured.;
wsgpscrp.htm;C:\WINDOWS\SoftwareDistribution\Downl oad\7c205249e4e58548a01567c8dc12d1b5;Trojan.Starma n.100;Cured.;
wsgpsec.htm;C:\WINDOWS\SoftwareDistribution\Downlo ad\7c205249e4e58548a01567c8dc12d1b5;Trojan.Starman .100;Cured.;
wsgpset.htm;C:\WINDOWS\SoftwareDistribution\Downlo ad\7c205249e4e58548a01567c8dc12d1b5;Trojan.Starman .100;Cured.;
wsgpsmtp.htm;C:\WINDOWS\SoftwareDistribution\Downl oad\7c205249e4e58548a01567c8dc12d1b5;Trojan.Starma n.100;Cured.;
eraseme_51737.exe;C:\WINNT\system32;BackDoor.IRC.S dbot.4974;Deleted.;
xsys.dll;C:\WINNT\system32;Tool.Moo;;
================================================== =
hijackthis.log
================================================== =
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:25:33 AM, on 10/16/2009
Platform: Windows 2003 SP2 (WinNT 5.02.3790)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\hp\hpsmh\data\cgi-bin\vcagent\vcagent.exe
C:\WINDOWS\System32\dns.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\bin\tomcat.exe
C:\Program Files\Trend Micro\ISVW\Web\FTP\isftpd.exe
C:\Program Files\Trend Micro\ISVW\Mail\ISNTSmtp\ISNTSysMonitor.exe
C:\Program Files\Trend Micro\ISVW\Mail\ISNTSmtp\IsntSmtp.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Trend Micro\Client Server Security Agent\ntrtscan.exe
C:\WINDOWS\system32\wmiprvse.exe
C:\Program Files\Trend Micro\ISVW\Mail\ISNTSmtp\scheduler.exe
C:\WINDOWS\System32\snmp.exe
C:\hp\hpsmh\bin\smhstart.exe
C:\WINDOWS\system32\CPQNiMgt\cpqnimgt.exe
C:\WINDOWS\system32\CpqRcmc.exe
C:\WINDOWS\system32\CPQMgmt\CqMgServ\cqmgserv.exe
C:\WINDOWS\system32\CPQMgmt\CqMgStor\cqmgstor.exe
C:\WINDOWS\system32\sysdown.exe
C:\Program Files\Trend Micro\Client Server Security Agent\tmlisten.exe
C:\WINDOWS\system32\CPQMgmt\CqMgHost\cqmghost.exe
C:\WINDOWS\System32\dmadmin.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\Client Server Security Agent\TmPfw.exe
C:\Program Files\Trend Micro\Client Server Security Agent\CNTAoSMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\cpqteam.exe
C:\Program Files\Trend Micro\Client Server Security Agent\pccntmon.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Trend Micro\OfficeScan Client\Apache2\bin\ApacheMonitor.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\dwwin.exe
C:\Program Files\Trend Micro\ISVW\Web\HTTP\IWSSHTTPMain.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\rdpclip.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\cpqteam.exe
C:\Program Files\Trend Micro\Client Server Security Agent\pccntmon.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\dumprep.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Trend Micro\OfficeScan Client\Apache2\bin\ApacheMonitor.exe
C:\WINDOWS\system32\dwwin.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://shdoclc.dll/softAdmin.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://shdoclc.dll/softAdmin.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
Hotmail, News, Sport, Music, Movies, Money, Cars, Shopping, Windows Live from MSN UK
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
Bing
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
Bing
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
Hotmail, News, Sport, Music, Movies, Money, Cars, Shopping, Windows Live from MSN UK
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyServer = *.*.*.*
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [CPQTEAM] cpqteam.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\Client Server Security Agent\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Monitor Apache Servers.lnk = C:\Program Files\Trend Micro\OfficeScan Client\Apache2\bin\ApacheMonitor.exe
O15 - ESC Trusted Zone:
http://runonce.msn.com
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) -
http://upload.facebook.com/controls/...oUploader5.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) -
http://housecall65.trendmicro.com/ho...vex/hcImpl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsu...?1229579345093
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) -
http://upload.facebook.com/controls/...Uploader55.cab
O18 - Protocol: hpapp - {24F45006-5BD9-41B7-9BD9-5F8921C8EBD1} - C:\Program Files\Compaq\Cpqacuxe\Bin\hpapp.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Apache2 - Unknown owner - c:\Program Files\Trend Micro\OfficeScan Client\Apache2\bin\Apache.exe (file missing)
O23 - Service: HP Insight NIC Agent (CpqNicMgmt) - Hewlett-Packard Company - C:\WINDOWS\system32\CPQNiMgt\cpqnimgt.exe
O23 - Service: HP ProLiant Remote Monitor Service (CpqRcmc) - Hewlett-Packard Company - C:\WINDOWS\system32\CpqRcmc.exe
O23 - Service: HP Version Control Agent (cpqvcagent) - Hewlett-Packard Company - C:\hp\hpsmh\data\cgi-bin\vcagent\vcagent.exe
O23 - Service: HP Insight Foundation Agents (CqMgHost) - Hewlett-Packard Company - C:\WINDOWS\system32\CPQMgmt\CqMgHost\cqmghost.exe
O23 - Service: HP Insight Server Agents (CqMgServ) - Hewlett-Packard Company - C:\WINDOWS\system32\CPQMgmt\CqMgServ\cqmgserv.exe
O23 - Service: HP Insight Storage Agents (CqMgStor) - Hewlett-Packard Company - C:\WINDOWS\system32\CPQMgmt\CqMgStor\cqmgstor.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InterScan VirusWall Management Console - Alexandria Software Consulting - C:\Program Files\Trend Micro\ISVW\UI\Tomcat 4.1\bin\tomcat.exe
O23 - Service: InterScan VirusWall for FTP (ISFTPD) - Trend Micro, Inc. - C:\Program Files\Trend Micro\ISVW\Web\FTP\isftpd.exe
O23 - Service: InterScan VirusWall System Monitor (ISNTSysMonitor) - Trend Micro Inc. - C:\Program Files\Trend Micro\ISVW\Mail\ISNTSmtp\ISNTSysMonitor.exe
O23 - Service: InterScan VirusWall for HTTP (ISVWHTTP) - Trend Micro Inc. - C:\Program Files\Trend Micro\ISVW\Web\HTTP\IWSSHTTPMain.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Trend Micro Client/Server Security Agent RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\Client Server Security Agent\ntrtscan.exe
O23 - Service: Protected Storage Manager (rspp) - Unknown owner - cmd /c start C:\WINDOWS\system32\wmiprvse.exe (file missing)
O23 - Service: Smart Card (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe (file missing)
O23 - Service: HP ProLiant System Shutdown Service (sysdown) - Compaq Computer Corporation - C:\WINDOWS\system32\sysdown.exe
O23 - Service: HP System Management Homepage (SysMgmtHP) - Hewlett-Packard Company - C:\hp\hpsmh/bin/smhstart.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\Client Server Security Agent\..\BM\TMBMSRV.exe
O23 - Service: Trend Micro Client/Server Security Agent Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\Client Server Security Agent\tmlisten.exe
O23 - Service: Trend Micro Client/Server Security Agent Personal Firewall (TmPfw) - Trend Micro Inc. - C:\Program Files\Trend Micro\Client Server Security Agent\TmPfw.exe
--
End of file - 9381 bytes
================================================== =