This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Malware Removal Forums

Cleaning my computer

7 min read

This thread's last reply is from November 19, 2006, 10:18 PM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

I have recently detected several malware and dodgy things happening on my computer, here is a log from KASPERSKY ONLINE:

Can someone take a look at that and guide me in the right direction, please?

----------------------------------
KASPERSKY ONLINE SCANNER REPORT
Sunday, November 19, 2006 9:56:02 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 19/11/2006
Kaspersky Anti-Virus database records: 242928


Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true

Scan Target My Computer
C:\
D:\
E:\

Scan Statistics
Total number of scanned objects 47868
Number of viruses found 16
Number of infected objects 90 / 0
Number of suspicious objects 0
Duration of the scan process 00:54:09

Infected Object Name Virus Name Last Action
C:\deskbar_e55.exe/deskbar.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Softomate.r skipped

C:\deskbar_e55.exe/deskbar.exe/stream Infected: not-a-virus:AdWare.Win32.Softomate.r skipped

C:\deskbar_e55.exe/deskbar.exe Infected: not-a-virus:AdWare.Win32.Softomate.r skipped

C:\deskbar_e55.exe ZIP: infected - 3 skipped

C:\deskbar_e58.exe/deskbar.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Softomate.r skipped

C:\deskbar_e58.exe/deskbar.exe/stream Infected: not-a-virus:AdWare.Win32.Softomate.r skipped

C:\deskbar_e58.exe/deskbar.exe Infected: not-a-virus:AdWare.Win32.Softomate.r skipped

C:\deskbar_e58.exe ZIP: infected - 3 skipped

C:\deskbar_e59.exe/deskbar.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Softomate.r skipped

C:\deskbar_e59.exe/deskbar.exe/stream Infected: not-a-virus:AdWare.Win32.Softomate.r skipped

C:\deskbar_e59.exe/deskbar.exe Infected: not-a-virus:AdWare.Win32.Softomate.r skipped

C:\deskbar_e59.exe ZIP: infected - 3 skipped

C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP244\A0081676.exe Object is locked skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP244\A0081678.exe Object is locked skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP244\A0081683.exe Object is locked skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP245\A0081917.exe Infected: not-a-virus:Downloader.Win32.WinFixer.t skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP248\A0084676.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Softomate.r skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP248\A0084676.exe/stream Infected: not-a-virus:AdWare.Win32.Softomate.r skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP248\A0084676.exe NSIS: infected - 2 skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP248\A0084677.dll Infected: not-a-virus:AdWare.Win32.Softomate.r skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP248\A0084680.exe Object is locked skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP248\A0085700.exe Infected: not-a-virus:AdWare.Win32.NewDotNet.e skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP248\A0085701.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Softomate.r skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP248\A0085701.exe/stream Infected: not-a-virus:AdWare.Win32.Softomate.r skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP248\A0085701.exe NSIS: infected - 2 skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP248\A0086692.dll Infected: not-a-virus:AdWare.Win32.NewDotNet.i skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP248\A0088700.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Softomate.r skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP248\A0088700.exe/stream Infected: not-a-virus:AdWare.Win32.Softomate.r skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP248\A0088700.exe NSIS: infected - 2 skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP249\A0088751.dll Object is locked skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP250\A0089949.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Softomate.r skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP250\A0089949.exe/stream Infected: not-a-virus:AdWare.Win32.Softomate.r skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP250\A0089949.exe NSIS: infected - 2 skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP250\A0089952.exe Infected: not-a-virus:AdWare.Win32.NewDotNet.e skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP250\A0089953.exe Infected: not-a-virus:AdWare.Win32.NewDotNet.e skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP250\A0089954.dll Infected: not-a-virus:AdWare.Win32.NewDotNet.a skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP250\A0089955.exe/deskbar.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Softomate.r skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP250\A0089955.exe/deskbar.exe/stream Infected: not-a-virus:AdWare.Win32.Softomate.r skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP250\A0089955.exe/deskbar.exe Infected: not-a-virus:AdWare.Win32.Softomate.r skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP250\A0089955.exe ZIP: infected - 3 skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP250\A0089956.exe Object is locked skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP250\A0089957.exe Object is locked skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP250\A0089966.dll Infected: not-a-virus:AdWare.Win32.Softomate.r skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP250\A0089967.exe/deskbar.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Softomate.r skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP250\A0089967.exe/deskbar.exe/stream Infected: not-a-virus:AdWare.Win32.Softomate.r skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP250\A0089967.exe/deskbar.exe Infected: not-a-virus:AdWare.Win32.Softomate.r skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP250\A0089967.exe ZIP: infected - 3 skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP250\A0089969.exe Object is locked skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP250\A0089971.exe Object is locked skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP250\A0089972.exe Object is locked skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP251\A0090219.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Softomate.r skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP251\A0090219.exe/stream Infected: not-a-virus:AdWare.Win32.Softomate.r skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP251\A0090219.exe NSIS: infected - 2 skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP251\A0090222.exe Infected: not-a-virus:AdWare.Win32.NewDotNet.e skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP251\A0090223.exe Infected: not-a-virus:AdWare.Win32.NewDotNet.e skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP251\A0090224.dll Infected: not-a-virus:AdWare.Win32.NewDotNet.a skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP251\A0090225.exe/deskbar.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Softomate.r skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP251\A0090225.exe/deskbar.exe/stream Infected: not-a-virus:AdWare.Win32.Softomate.r skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP251\A0090225.exe/deskbar.exe Infected: not-a-virus:AdWare.Win32.Softomate.r skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP251\A0090225.exe ZIP: infected - 3 skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP251\A0090227.exe Object is locked skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP251\A0090236.dll Infected: not-a-virus:AdWare.Win32.Softomate.r skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP251\A0090237.exe/deskbar.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Softomate.r skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP251\A0090237.exe/deskbar.exe/stream Infected: not-a-virus:AdWare.Win32.Softomate.r skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP251\A0090237.exe/deskbar.exe Infected: not-a-virus:AdWare.Win32.Softomate.r skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP251\A0090237.exe ZIP: infected - 3 skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP251\A0090239.exe Object is locked skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP251\A0090241.exe Object is locked skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP251\A0090242.exe Object is locked skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP251\A0090279.dll Infected: not-a-virus:AdWare.Win32.SurfSide.ay skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP251\A0090280.dll Infected: not-a-virus:AdWare.Win32.SurfSide.ap skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP251\A0090352.dll Infected: not-a-virus:AdWare.Win32.Softomate.r skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP252\A0090510.exe Infected: not-a-virus:AdWare.Win32.NewDotNet skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP252\A0090511.exe Infected: not-a-virus:AdWare.Win32.NewDotNet.e skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP252\A0090683.dll Infected: not-a-virus:AdWare.Win32.NewDotNet.a skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP252\A0090698.exe Infected: not-a-virus:AdWare.Win32.SurfSide.bb skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP252\A0090699.exe Infected: not-a-virus:AdWare.Win32.PurityScan.ew skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP252\A0090709.dll Object is locked skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP252\A0090710.exe Object is locked skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP252\A0090711.exe Object is locked skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP252\A0090712.dll Infected: not-a-virus:AdWare.Win32.CommAd.a skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP252\A0090713.exe Infected: not-a-virus:AdWare.Win32.CommAd.a skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP252\A0090714.exe Object is locked skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP252\A0090715.exe Object is locked skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP252\A0090716.exe Object is locked skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP252\A0090717.exe Object is locked skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP252\A0090718.exe Infected: not-a-virus:AdWare.Win32.SurfSide.ax skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP252\A0090719.exe Object is locked skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP252\A0090720.exe Object is locked skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP252\A0090721.exe Object is locked skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP252\A0090722.exe Object is locked skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP252\A0090724.exe Object is locked skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP252\A0090725.exe Infected: not-a-virus:AdWare.Win32.NewDotNet skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP252\A0090727.dll Infected: not-a-virus:AdWare.Win32.SurfSide.ay skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP252\A0090734.exe Object is locked skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP252\A0090750.exe Object is locked skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP252\A0090753.exe/data0002 Infected: not-a-virus:AdWare.Win32.PurityScan.ew skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP252\A0090753.exe NSIS: infected - 1 skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP252\A0090754.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Softomate.r skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP252\A0090754.exe/stream Infected: not-a-virus:AdWare.Win32.Softomate.r skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP252\A0090754.exe NSIS: infected - 2 skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP252\A0090756.exe Infected: not-a-virus:AdWare.Win32.NewDotNet skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP252\A0090763.exe Infected: not-a-virus:AdWare.Win32.NewDotNet.e skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP252\A0090769.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP252\A0090770.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped

C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP252\change.log Object is locked skipped

C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

C:\WINDOWS\NDNuninstall7_44.exe Infected: not-a-virus:AdWare.Win32.NewDotNet.e skipped

C:\WINDOWS\SchedLgU.Txt Object is locked skipped

C:\WINDOWS\SoftwareDistribution\EventCache\{29D0A7DA-ADEB-456E-AF97-29AA782F656A}.bin Object is locked skipped

C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped

C:\WINDOWS\system32\aaa00000.dll Object is locked skipped

C:\WINDOWS\system32\bkd.exe/InpB/DxcBho.dll Infected: not-a-virus:AdWare.Win32.SurfSide.ay skipped

C:\WINDOWS\system32\bkd.exe/InpB/DxcCore.dll Infected: not-a-virus:AdWare.Win32.SurfSide.ay skipped

C:\WINDOWS\system32\bkd.exe/InpB/Dxc.exe Infected: not-a-virus:AdWare.Win32.SurfSide.bb skipped

C:\WINDOWS\system32\bkd.exe/InpB/DxcRepairInstall.exe Infected: not-a-virus:AdWare.Win32.SurfSide.bb skipped

C:\WINDOWS\system32\bkd.exe/InpB Infected: not-a-virus:AdWare.Win32.SurfSide.bb skipped

C:\WINDOWS\system32\bkd.exe CAB: infected - 5 skipped

C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped

C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped

C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\DEFAULT Object is locked skipped

C:\WINDOWS\system32\config\default.LOG Object is locked skipped

C:\WINDOWS\system32\config\SAM Object is locked skipped

C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped

C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\SECURITY Object is locked skipped

C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped

C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped

C:\WINDOWS\system32\config\software.LOG Object is locked skipped

C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\SYSTEM Object is locked skipped

C:\WINDOWS\system32\config\system.LOG Object is locked skipped

C:\WINDOWS\system32\h323log.txt Object is locked skipped

C:\WINDOWS\system32\lggf6ac7.dll Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

C:\WINDOWS\WindowsUpdate.log Object is locked skipped

D:\Documents and Settings\All Users\Application Data\AutoSearch.dll Infected: not-a-virus:AdWare.Win32.AutoSearch.b skipped

D:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped

D:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped

D:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped

D:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped

D:\Documents and Settings\All Users\Application Data\WinSoftware\WinAntiVirus 2006\Quarantine\winantiviruspro2006freeinstall[1].cabggbwkfnq/UWA6P_0001_N91M1807NetInstaller.exe Infected: not-a-virus:Downloader.Win32.WinFixer.o skipped

D:\Documents and Settings\All Users\Application Data\WinSoftware\WinAntiVirus 2006\Quarantine\winantiviruspro2006freeinstall[1].cabggbwkfnq CAB: infected - 1 skipped

D:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

D:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

D:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped

D:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped

D:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

D:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped

D:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

D:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped

D:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

D:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

D:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped

D:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

D:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

D:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

D:\Documents and Settings\Sally\Cookies\index.dat Object is locked skipped

D:\Documents and Settings\Sally\DoctorWeb\Quarantine\dxc.exe Infected: not-a-virus:AdWare.Win32.SurfSide.bb skipped

D:\Documents and Settings\Sally\DoctorWeb\Quarantine\psdream.exe Infected: not-a-virus:AdWare.Win32.PurityScan.ew skipped

D:\Documents and Settings\Sally\DoctorWeb\Quarantine\xumyku.htmljoivvgob Infected: Trojan-Clicker.Win32.Small.jf skipped

D:\Documents and Settings\Sally\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

D:\Documents and Settings\Sally\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

D:\Documents and Settings\Sally\Local Settings\History\History.IE5\index.dat Object is locked skipped

D:\Documents and Settings\Sally\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

D:\Documents and Settings\Sally\NTUSER.DAT Object is locked skipped

D:\Documents and Settings\Sally\ntuser.dat.LOG Object is locked skipped

D:\Documents and Settings\Sally\Shared\Free Game.exe Object is locked skipped

D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

D:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP252\change.log Object is locked skipped

Scan process completed.
Here is a hijack this log:

Logfile of HijackThis v1.99.1
Scan saved at 22:17:28, on 19/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\DOCUME~1\Sally\LOCALS~1\Temp\Temporary Directory 2 for hijackthis.zip\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\uk.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
R3 - URLSearchHook: (no name) - _{A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - (no file)
R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - C:\Program Files\DeluxeCommunications\DxcBho.dll (file missing)
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,difbnfq.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {21E37170-41CE-43DD-AF80-560A1D71B40E} - C:\Program Files\MSN\vifywahi.dll (file missing)
O2 - BHO: (no name) - {40A2988E-C954-4DDE-BD08-453191805BB9} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Domain Helper - {B8A5DE1C-BC13-4DD2-BF00-7BE3C603F9F2} - C:\WINDOWS\system32\DomainHelper.dll
O4 - HKLM\..\Run: [LXBSCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBStime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\RunServices: [p2p networking] p2pnetworking.exe
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\uk.htm
O15 - Trusted Zone: http://*.billingnow.com
O15 - Trusted Zone: http://*.reliablestats.com
O15 - Trusted Zone: http://*.winantispyware.com
O15 - Trusted Zone: http://*.winantivirus.com
O15 - Trusted Zone: http://*.winantiviruspro.com
O15 - Trusted Zone: http://*.winfixer.com
O15 - Trusted Zone: http://*.winnanny.com
O15 - Trusted Zone: http://*.winsoftware.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/ka ... nicode.cab
O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://www.drivecleaner.com/.freeware/installdrivecleanerstart.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: dxclib303562752.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: lxbs_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxbscoms.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe