Mon Mar 21 21:50:33 2005 => Total Number of Files Scanned: 26879
Mon Mar 21 21:50:33 2005 => Total Number of Virus(es) Found: 14
Mon Mar 21 21:50:33 2005 => Total Number of Disinfected Files: 0
Mon Mar 21 21:50:33 2005 => Total Number of Files Renamed: 6
Mon Mar 21 21:50:33 2005 => Total Number of Deleted Files: 0
Mon Mar 21 21:50:33 2005 => Total Number of Errors: 0
Mon Mar 21 21:50:33 2005 => Time Elapsed: 00:17:20
Mon Mar 21 21:50:33 2005 => ***** Scanning complete. *****
Mon Mar 21 21:50:33 2005 => Virus Database Date: 2005/02/17
Mon Mar 21 21:50:33 2005 => Virus Database Count: 118536
Mon Mar 21 21:50:33 2005 => Scan Completed.
File C:\WINDOWS\System32\geec.exe infected by "Backdoor.Win32.PoeBot.b" Virus. Action Taken: File Renamed.
File C:\RECYCLER\S-1-5-21-861567501-2052111302-725345543-1003\Dc1.exe infected by "Backdoor.Win32.PoeBot.b" Virus. Action Taken: File Renamed.
File C:\RECYCLER\S-1-5-21-861567501-2052111302-725345543-1003\Dc2.exe infected by "Backdoor.Win32.Rbot.gen" Virus. Action Taken: File Renamed.
File C:\System Volume Information\_restore{8EB0299E-4B72-4842-93FB-4FB18661FE6A}\RP4\A0002574.exe infected by "Backdoor.Win32.PoeBot.b" Virus. Action Taken: File Renamed.
File C:\System Volume Information\_restore{8EB0299E-4B72-4842-93FB-4FB18661FE6A}\RP4\A0002575.exe infected by "Backdoor.Win32.PoeBot.b" Virus. Action Taken: File Renamed.
File C:\System Volume Information\_restore{8EB0299E-4B72-4842-93FB-4FB18661FE6A}\RP4\A0002576.exe infected by "Backdoor.Win32.Rbot.gen" Virus. Action Taken: File Renamed.
File D:\SETUPprogrammer\0011\CuteFTP v3.5.6\cute3532t.exe tagged as not-a-virus:AdWare.Aureate. No Action Taken.
File D:\SETUPprogrammer\BearShare INSTALL.exe tagged as not-a-virus:AdWare.SaveNow.z. No Action Taken.
File D:\SETUPprogrammer\fjernsupport program\vnc-3.3.7-x86_win32.exe tagged as not-a-virus:RiskWare.RemoteAdmin.WinVNC-based.c. No Action Taken.
File D:\System Volume Information\_restore{04E98B94-560D-4F04-BBF5-30CFF1436E1E}\RP33\A0004531.exe tagged as not-a-virus:RiskWare.mIRC.6.03. No Action Taken.
File D:\System Volume Information\_restore{5B485029-6D56-4B32-9104-ADBFF362CFE9}\RP127\A0029830.exe tagged as not-a-virus:AdWare.SaveNow.z. No Action Taken.
File D:\System Volume Information\_restore{5B485029-6D56-4B32-9104-ADBFF362CFE9}\RP140\A0037247.exe tagged as not-a-virus:AdWare.Beginto.a. No Action Taken.
File D:\System Volume Information\_restore{8EB0299E-4B72-4842-93FB-4FB18661FE6A}\RP1\A0000138.exe tagged as not-a-virus:AdWare.SaveNow.z. No Action Taken.
File D:\System Volume Information\_restore{8EB0299E-4B72-4842-93FB-4FB18661FE6A}\RP1\A0000614.exe tagged as not-a-virus:RiskWare.mIRC.6.03. No Action Taken.
Logfile of HijackThis v1.99.1
Scan saved at 21:52:40, on 21-03-2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programmer\MSN Apps\Updater\01.02.3000.1001\da\msnappau.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Programmer\Meaya\Popup Ad Filter\PopFilter.exe
D:\Programmer\Zone Labs\ZoneAlarm\zonealarm.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Programmer\Internet Explorer\iexplore.exe
D:\SETUPprogrammer\hijackthis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.dr.dk/R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Programmer\MSN Apps\ST\01.02.3000.1001\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmer\MSN Apps\MSN Toolbar\01.02.3000.1001\da\msntb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmer\MSN Apps\MSN Toolbar\01.02.3000.1001\da\msntb.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [msnappau] "C:\Programmer\MSN Apps\Updater\01.02.3000.1001\da\msnappau.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Skype] "D:\Programmer\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Popup Ad Filter] C:\Programmer\Meaya\Popup Ad Filter\PopFilter.exe
O4 - Global Startup: ZoneAlarm.lnk = D:\Programmer\Zone Labs\ZoneAlarm\zonealarm.exe
O8 - Extra context menu item: Allow Popups - C:\Programmer\Meaya\Popup Ad Filter\WhiteGetUrl.js
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe