PDA

View Full Version : Can't get rid of popups



rjlittin
2007-12-14, 21:51
Hi,

Please help. I've been getting popups for the last few days and I can't seem to get rid of them. I have done virus scans and spybot scans that say that they have fixed the problem but they keep coming back.
Today I have tried a fresh spybot scan but it now stops by it's self after a few minutes saying that the user stopped it. Kaspersky has been running for the last 1 and a half hours and is 9% through it's scan so it will be a while. Here is a copy of my HJT log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:30:17, on 14/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\crypserv.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
c:\program files\common files\installshield\updateservice\isuspm.exe
C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
C:\Program Files\JGsoft\EditPadPro6\EditPadPro.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Trend Micro\HijackThis\scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.fluidmd.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Tiscali
N3 - Netscape 7: # Mozilla User Preferences

/* Do not edit this file.
*
* If you make changes to this file while the browser is running,
* the changes will be overwritten when the browser exits.
*
* To make a manual change to preferences, you can visit the URL about:config
* For more information, see http://www.mozilla.org/unix/customizing.html#prefs
*/

user_pref("browser.activation.checkedNNFlag", true);
user_pref("browser.bookmarks.added_static_root", true);
user_pref("browser.cache.disk.parent_directory", "C:\\DOCUMENTS AND SETTINGS\\ROGER LITTIN\\APPLICATION DATA\\Mozilla\\Profiles\\default\\7n1juq48.slt");
user_pref("browser.download.dir", "C:\\Documents and Settings\\Roger Littin\\My Documents");
user_pref("browser.search.defaultengine", "engine://C%3A%5CPROGRA%7E1%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src");
user_pref("browser.startup.homepage_override.mstone", "rv:1.7.2");
user_pref("browser.tabs.forceHide", true);
user_pref("browser.turbo.showDialog", false);
user_pref("dom.disabl
O1 - Hosts: ##.##.###.### roger ## router ip address
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {4261813A-FAF3-44B7-BCE4-38DA3D8A7309} - C:\WINDOWS\system32\awtqq.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7A03615A-4799-4B8E-B033-B105481CF1D4} - (no file)
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: IE DevToolbar BHO - {CC7E636D-39AA-49b6-B511-65413DA137A1} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O2 - BHO: (no name) - {FED51DF2-9644-4C58-9104-90244EDD6EEC} - C:\WINDOWS\system32\awtqpnm.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Developer Toolbar - {CC962137-2E78-4f94-975E-FC0C07DBD78F} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\RunServices: [SchedulingAgent] C:\WINDOWS\system32\mstask.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Program Files\VisualRoute\vrie.dll
O9 - Extra 'Tools' menuitem: VisualRoute Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Program Files\VisualRoute\vrie.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: IE Developer Toolbar - {48FFE35F-36D9-44bd-A6CC-1D34414EAC0D} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O9 - Extra button: Europa Casino - {4C826F10-D34B-4ba8-B609-1FB8C6482A05} - C:\Casino\Europa Casino\casino.exe (file missing)
O9 - Extra 'Tools' menuitem: Europa Casino - {4C826F10-D34B-4ba8-B609-1FB8C6482A05} - C:\Casino\Europa Casino\casino.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\flashget.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra 'Tools' menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .ocx: C:\Program Files\Opera\PLUGINS\NPFgc1.dll
O12 - Plugin for .ps: C:\Program Files\Opera\PLUGINS\NPFgc1.dll
O12 - Plugin for .tar: C:\Program Files\Opera\PLUGINS\NPFgc1.dll
O12 - Plugin for .zip: C:\Program Files\Opera\PLUGINS\NPFgc1.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.tiscali.co.uk/
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1108071541436
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
O16 - DPF: {E5ABEB00-B357-4884-9949-77B2C71A7EE3} (BoardCtl Class) - http://www.intel.com/design/motherbd/boardid/BoardID.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O18 - Filter hijack: text/html - (no CLSID) - (no file)
O20 - Winlogon Notify: awtqpnm - C:\WINDOWS\SYSTEM32\awtqpnm.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: Flash Media Server (FMS) (FMS) - Macromedia, Inc. - C:\Program Files\Macromedia\Flash Media Server 2\FMSMaster.exe
O23 - Service: Flash Media Administration Server (FMSAdmin) - Macromedia, Inc. - C:\Program Files\Macromedia\Flash Media Server 2\FMSAdmin.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: MySQL5 - Unknown owner - C:\Program.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Wowza Media Server Pro (WowzaMediaServerPro) - Unknown owner - C:\Program Files\Wowza Media Systems\Wowza Media Server Pro\bin\wrapper.exe

--
End of file - 12067 bytes

Shaba
2007-12-15, 11:11
Hi rjlittin and welcome to Safer Networking forums :)

1. Download combofix from any of these links and save it to Desktop:
Link 1 (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
Link 2 (http://www.forospyware.com/sUBs/ComboFix.exe)
Link 3 (http://subs.geekstogo.com/ComboFix.exe)

**Note: It is important that it is saved directly to your desktop**

2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you (C:\ComboFix.txt). Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.

Post:

- a fresh HijackThis log
- combofix report

rjlittin
2007-12-15, 13:58
Hi Shaba,

Iv got a bit of a problem at the moment:sad:. Was fiddling around last night and have broken something in the registry. I think I have got it back with a bartpe cd. Just managed to start up in safe mode and in the middle of a system restore to a few days ago. When I am up and running again I will let you know.

p.s. I won't fiddle any more:D:.

Roger.

Shaba
2007-12-15, 14:08
Hi

Ok, let me know after that and please keep just following instructions in the future, no soloing :)

rjlittin
2007-12-15, 15:02
Hi there,

I'm back up and running. combofix has been running for about an hour but it has stopped on Deleting Files/Folders:. There is no disk activity and it seems to have shut down explorer.exe as all the icons and the task bar have disappeared.

I will await further instructions.

Shaba
2007-12-15, 15:09
Hi

Try to run it in Safe Mode then.

rjlittin
2007-12-15, 15:11
Hi there,

I'm back up and running. combofix has been running for about an hour but it has stopped on Deleting Files/Folders:. There is no disk activity and it seems to have shut down explorer.exe as all the icons and the task bar have disappeared.

I will await further instructions.

Sorry, missed part of you first post. ended sed.cexe process and it started up again.

Shaba
2007-12-15, 15:15
Hi

Glad that it sorted out :)

rjlittin
2007-12-15, 15:33
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:31:12, on 15/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\crypserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\MySQL\MySQL Server 4.1\bin\mysqld-nt.exe
C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
C:\Program Files\Sawmill 7\SawmillService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sawmill 7\SawmillCL.exe
C:\Program Files\Sawmill 7\SawmillCL.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\V0230Mon.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.fluidmd.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
N3 - Netscape 7: # Mozilla User Preferences

/* Do not edit this file.
*
* If you make changes to this file while the browser is running,
* the changes will be overwritten when the browser exits.
*
* To make a manual change to preferences, you can visit the URL about:config
* For more information, see http://www.mozilla.org/unix/customizing.html#prefs
*/

user_pref("browser.activation.checkedNNFlag", true);
user_pref("browser.bookmarks.added_static_root", true);
user_pref("browser.cache.disk.parent_directory", "C:\\DOCUMENTS AND SETTINGS\\ROGER LITTIN\\APPLICATION DATA\\Mozilla\\Profiles\\default\\7n1juq48.slt");
user_pref("browser.download.dir", "C:\\Documents and Settings\\Roger Littin\\My Documents");
user_pref("browser.search.defaultengine", "engine://C%3A%5CPROGRA%7E1%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src");
user_pref("browser.startup.homepage_override.mstone", "rv:1.7.2");
user_pref("browser.tabs.forceHide", true);
user_pref("browser.turbo.showDialog", false);
user_pref("dom.disabl
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: IE DevToolbar BHO - {CC7E636D-39AA-49b6-B511-65413DA137A1} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Developer Toolbar - {CC962137-2E78-4f94-975E-FC0C07DBD78F} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [V0230Mon.exe] C:\WINDOWS\system32\V0230Mon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\RunServices: [SchedulingAgent] C:\WINDOWS\system32\mstask.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Program Files\VisualRoute\vrie.dll
O9 - Extra 'Tools' menuitem: VisualRoute Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Program Files\VisualRoute\vrie.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: IE Developer Toolbar - {48FFE35F-36D9-44bd-A6CC-1D34414EAC0D} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O9 - Extra button: Europa Casino - {4C826F10-D34B-4ba8-B609-1FB8C6482A05} - C:\Casino\Europa Casino\casino.exe (file missing)
O9 - Extra 'Tools' menuitem: Europa Casino - {4C826F10-D34B-4ba8-B609-1FB8C6482A05} - C:\Casino\Europa Casino\casino.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\flashget.exe
O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra 'Tools' menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .ocx: C:\Program Files\Opera\PLUGINS\NPFgc1.dll
O12 - Plugin for .ps: C:\Program Files\Opera\PLUGINS\NPFgc1.dll
O12 - Plugin for .tar: C:\Program Files\Opera\PLUGINS\NPFgc1.dll
O12 - Plugin for .zip: C:\Program Files\Opera\PLUGINS\NPFgc1.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.tiscali.co.uk/
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} -
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1108071541436
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
O16 - DPF: {E5ABEB00-B357-4884-9949-77B2C71A7EE3} (BoardCtl Class) - http://www.intel.com/design/motherbd/boardid/BoardID.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: Flash Media Server (FMS) (FMS) - Macromedia, Inc. - C:\Program Files\Macromedia\Flash Media Server 2\FMSMaster.exe
O23 - Service: Flash Media Administration Server (FMSAdmin) - Macromedia, Inc. - C:\Program Files\Macromedia\Flash Media Server 2\FMSAdmin.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: MySQL41 - Unknown owner - C:\Program.exe (file missing)
O23 - Service: MySQL5 - Unknown owner - C:\Program.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sawmill - Unknown owner - C:\Program Files\Sawmill 7\SawmillService.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Wowza Media Server Pro (WowzaMediaServerPro) - Unknown owner - C:\Program Files\Wowza Media Systems\Wowza Media Server Pro\bin\wrapper.exe

--
End of file - 11542 bytes

rjlittin
2007-12-15, 15:36
Should I have shut down tea timer before doing this. It started complaining big time about bho's getting deleted and trying to get renistated. Got a copy of resident.log if you need it.

ComboFix 07-12-15.1 - Roger Littin 2007-12-15 13:20:59.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.507 [GMT 0:00]
Running from: C:\Documents and Settings\Roger Littin\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Roger Littin\Application Data\MBSPicturePlugin4070.dll
C:\Documents and Settings\Roger Littin\Application Data\MBSQTImporterPlugin4175.dll
C:\Documents and Settings\Roger Littin\Application Data\MBSRectPlugin4070.dll
C:\Documents and Settings\Roger Littin\Application Data\MBSRegistrationPlugin4071.dll
C:\Documents and Settings\Roger Littin\Application Data\Rb3D350.dll
C:\Documents and Settings\Roger Littin\Application Data\rbap450.dll
C:\Documents and Settings\Roger Littin\Application Data\rbqt450.DLL
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\agjveouc.ini
C:\WINDOWS\system32\awtqpnm.dll
C:\WINDOWS\system32\awtqq.dll
C:\WINDOWS\system32\Cache
C:\WINDOWS\system32\cuoevjga.dll
C:\WINDOWS\system32\qqtwa.ini
C:\WINDOWS\system32\qqtwa.ini2

.
((((((((((((((((((((((((( Files Created from 2007-11-15 to 2007-12-15 )))))))))))))))))))))))))))))))
.

2007-12-15 13:07 . 2007-12-15 13:07 3,948 --a------ C:\WINDOWS\system32\PerfStringBackup.TMP
2007-12-15 12:41 . 2007-12-15 14:23 2,422 --a------ C:\WINDOWS\system32\wpa.dbl
2007-12-14 18:48 . 2007-12-14 18:48 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-12-14 18:48 . 2007-12-14 18:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-12-13 22:29 . 2007-12-13 23:03 <DIR> d-------- C:\VundoFix Backups
2007-12-13 22:09 . 2007-12-13 22:09 <DIR> d-------- C:\Program Files\Trend Micro
2007-12-08 10:55 . 2007-12-08 10:55 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2007-12-08 10:55 . 2007-12-08 10:55 1,409 --a------ C:\WINDOWS\QTFont.for
2007-11-25 19:33 . 2007-11-25 19:53 <DIR> d-------- C:\Program Files\SEPY ActionScript Editor
2007-11-21 00:00 . 2007-11-21 00:00 <DIR> d-------- C:\Documents and Settings\Roger Littin\Application Data\Subversion
2007-11-20 19:00 . 2007-11-20 19:00 <DIR> d-------- C:\Program Files\MTASC
2007-11-17 10:16 . 2007-12-15 14:21 4,171,808 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2007-11-17 10:16 . 2007-12-15 14:21 44,120 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2007-11-17 10:13 . 2007-11-17 10:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
2007-11-15 21:27 . 2007-11-15 21:27 <DIR> d-------- C:\Documents and Settings\Peta\Application Data\Corel

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-15 12:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-15 12:49 --------- d-----w C:\Documents and Settings\Roger Littin\Application Data\CoreFTP
2007-12-14 08:39 --------- d-----w C:\Program Files\WinTV
2007-12-07 19:35 --------- d-----w C:\Program Files\Opera
2007-11-23 18:40 --------- d-----w C:\Program Files\PremiumSoft Navicat
2007-11-19 18:26 --------- d-----w C:\Program Files\VisualRoute
2007-11-16 22:43 --------- d-----w C:\Program Files\FlashGet
2007-11-16 19:22 --------- d-----w C:\Program Files\Wowza Media Systems
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-04 22:12 --------- d-----w C:\Program Files\WebCamDV
2007-11-04 15:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-11-04 15:39 --------- d-----w C:\Program Files\BitTorrent
2007-11-04 15:32 --------- d-----w C:\Program Files\Java
2007-11-04 14:10 356,352 ----a-w C:\WINDOWS\eSellerateEngine.dll
2007-11-04 13:51 23,600 ----a-w C:\WINDOWS\system32\drivers\TVICHW32.SYS
2007-11-04 11:01 --------- d-----w C:\Documents and Settings\Roger Littin\Application Data\muvee Technologies
2007-07-03 18:05 4,660 ----a-w C:\Program Files\uninstal.log
2005-03-26 17:27 1,030 --sh--w C:\WINDOWS\system\nodemgr.sys
2007-05-26 10:39 56 --sh--r C:\WINDOWS\system32\430508F299.sys
2007-05-26 10:39 5,018 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4261813A-FAF3-44B7-BCE4-38DA3D8A7309}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7A03615A-4799-4B8E-B033-B105481CF1D4}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{883E49FC-7481-453C-B85E-6F1466DE8D47}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:56]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-01-31 21:10]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-07-27 22:03]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-04-17 12:41]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-04-13 06:07]
"V0230Mon.exe"="C:\WINDOWS\system32\V0230Mon.exe" [2006-07-19 17:00]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 03:00]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-09-06 16:14]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"SchedulingAgent"="C:\WINDOWS\system32\mstask.exe" []

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 07:56]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoCAD Startup Accelerator.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutoCAD Startup Accelerator.lnk
backup=C:\WINDOWS\pss\AutoCAD Startup Accelerator.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Phone Connection Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Phone Connection Monitor.lnk
backup=C:\WINDOWS\pss\Phone Connection Monitor.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Roger Littin^Start Menu^Programs^Startup^WinMySQLadmin.lnk]
path=C:\Documents and Settings\Roger Littin\Start Menu\Programs\Startup\WinMySQLadmin.lnk
backup=C:\WINDOWS\pss\WinMySQLadmin.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcctMgr]
C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe /startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\atwtusb]
atwtusb.exe beta

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GhostStartTrayApp]
2003-05-28 19:11 94208 --a------ C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMONTRAY]
2004-03-10 22:02 32768 --------- C:\Program Files\Intel\Intel(R) Active Monitor\imontray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Parallel Tasking]
C:\Program Files\Parallel Tasking\ptask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PinnacleDriverCheck]
C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
2003-10-23 09:37 962560 --a------ C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeedTouch USB Diagnostics]
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe /icon

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
C:\Program Files\Valve\Steam\Steam.exe -silent

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\STManager]
C:\Program Files\SpeedTouch\Dr SpeedTouch\drst.exe -b

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"GhostStartService"=2 (0x2)
"imonNT"=2 (0x2)
"NVSvc"=2 (0x2)
"MDM"=2 (0x2)

R1 HCW88AUD;Hauppauge WinTV 88x Audio Capture;C:\WINDOWS\system32\drivers\hcw88aud.sys
R2 MySQL41;MySQL41;"C:\Program Files\MySQL\MySQL Server 4.1\bin\mysqld-nt" --defaults-file="C:\Program Files\MySQL\MySQL Server 4.1\my.ini" MySQL41
R2 MySQL5;MySQL5;"C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt" --defaults-file="C:\Program Files\MySQL\MySQL Server 5.0\my.ini" MySQL5
R2 Sawmill;Sawmill;"C:\Program Files\Sawmill 7\SawmillService.exe"
R2 SIODRV;SIODRV;\??\C:\WINDOWS\System32\drivers\SIODRV.SYS
R2 WebCamDV;WebCamDV DV to Webcam Converter;C:\WINDOWS\system32\DRIVERS\WebCamDV.sys
R3 AIRPLUS;D-Link AirPlus Wireless Adapter;C:\WINDOWS\system32\DRIVERS\airplus.sys
R3 hcw88rc5;Hauppauge WinTV 88x IR Decoder;C:\WINDOWS\system32\Drivers\hcw88rc5.sys
R3 HCW88TSE;Hauppauge WinTV 88x MPEG/TS Capture;C:\WINDOWS\system32\drivers\hcw88tse.sys
R3 HCW88TUNE;Hauppauge WinTV 88x Tuner;C:\WINDOWS\system32\drivers\hcw88tun.sys
R3 hcw88vid;Hauppauge WinTV 88x Video;C:\WINDOWS\system32\drivers\hcw88vid.sys
R3 HCW88XBAR;Hauppauge WinTV 88x Crossbar;C:\WINDOWS\system32\drivers\HCW88BAR.sys
R3 Intels51;Sitecom 56K PCI modem DC-010v2;C:\WINDOWS\system32\DRIVERS\Intels51.sys
R3 smbusp;Intel(R) SMBus 2.0 Driver;C:\WINDOWS\system32\DRIVERS\smb.sys
R3 V0230Vfx;V0230Vfx;C:\WINDOWS\system32\DRIVERS\V0230Vfx.sys
R3 V0230VID;Live! Cam Video IM Pro;C:\WINDOWS\system32\DRIVERS\V0230VID.sys
R3 WCDV_Aud;WevCamDV WDM Virtual Audio Device;C:\WINDOWS\system32\drivers\wcdvaud.sys
S3 FMS;Flash Media Server (FMS);"C:\Program Files\Macromedia\Flash Media Server 2\FMSMaster.exe"
S3 FMSAdmin;Flash Media Administration Server;"C:\Program Files\Macromedia\Flash Media Server 2\FMSAdmin.exe"
S3 FTLUND;Lundinova Filter Driver;C:\WINDOWS\system32\drivers\ftlund.sys
S3 HCW88BDA;Hauppauge WinTV 88x DVB Tuner/Demod;C:\WINDOWS\system32\drivers\hcw88bda.sys
S3 idrmkl;idrmkl;\??\C:\WINDOWS\TEMP\idrmkl.sys
S3 rtl8029;Realtek RTL8029(AS)-based PCI Ethernet Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\RTL8029.SYS
S3 WowzaMediaServerPro;Wowza Media Server Pro;"C:\Program Files\Wowza Media Systems\Wowza Media Server Pro\bin\wrapper.exe" -s "C:\Program Files\Wowza Media Systems\Wowza Media Server Pro\bin\WowzaMediaServerPro-Service.conf"

.
Contents of the 'Scheduled Tasks' folder
"2007-12-15 14:00:00 C:\WINDOWS\Tasks\B36E0E949345B864.job"
- c:\docume~1\rogerl~1\applic~1\mfcdan~1\once dupe kind.exe
"2007-12-09 10:10:07 C:\WINDOWS\Tasks\Backups.job"
- C:\Program Files\PremiumSoft Navicat\navicat.exe
"2007-12-14 08:39:20 C:\WINDOWS\Tasks\Dragons_Den.job"
- C:\PROGRA~1\WinTV\WinTV2K.EXE9 -c10 -ntod -startr:Dragons_Den###.mpg -qvcd -limit:1800
"2005-05-17 21:46:13 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1100 series#1108593923.job"
- C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe4-I
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-15 14:23:45
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\MySql]
"ImagePath"="C:/mysql/bin/mysqld-max-nt.exe"
.
Completion time: 2007-12-15 14:25:39 - machine was rebooted
.
2007-11-28 21:17:44 --- E O F ---

Shaba
2007-12-15, 16:42
Hi

Please make sure that you can view all hidden files. Instructions on how to do this can be found here:

How to see hidden files in Windows (http://www.xtra.co.nz/help/0,,4155-1916458,00.html)

Please click this link-->Jotti (http://virusscan.jotti.org/)

When the jotti page has finished loading, click the Browse button and navigate to the following file and click Submit.

C:\WINDOWS\TEMP\idrmkl.sys

Please post back the results of the scan in your next post.

If Jotti is busy, try the same at Virustotal: http://www.virustotal.com/

rjlittin
2007-12-15, 17:09
C:\WINDOWS\TEMP\idrmkl.sys


This file seems to have dissappeared. I did empty out windows\temp a few days ago. Would the system restore I did eairlier today be causing combofix to be picking up old information?

Shaba
2007-12-15, 17:41
Hi

No that doesn't mean it.

Driver can exist though file doesn't.

Now, go to Start > Run, and copy/paste the following into the Open box:
sc delete idrmkl
Click: OK

Please do an online scan with Kaspersky Online Scanner (http://www.kaspersky.com/downloads/kws/kavwebscan.html). You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
The program will launch and then start to download the latest definition files.
Once the scanner is installed and the definitions downloaded, click Next.
Now click on Scan Settings
In the scan settings make sure that the following are selected:

o Scan using the following Anti-Virus database:

+ Extended (If available otherwise Standard)

o Scan Options:

+ Scan Archives
+ Scan Mail Bases

Click OK
Now under select a target to scan select My Computer
The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
Now click on the Save as Text button
Save the file to your desktop.
Copy and paste that information in your next post.

Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the license, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.

Post:

- a fresh HijackThis log
- kaspersky report

rjlittin
2007-12-16, 11:22
I don't use outlook express any more so that can be removed and also d:\recovered is files off of an old harddrive that crashed about 5 years ago. I can get rid of the outlook folders in there also. I don't use norton any more so how can i get rid of the nprotect folders?

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Sunday, December 16, 2007 10:08:27 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 15/12/2007
Kaspersky Anti-Virus database records: 483280
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\
K:\
L:\

Scan Statistics:
Total number of scanned objects: 291811
Number of viruses found: 13
Number of infected objects: 39
Number of suspicious objects: 4
Duration of the scan process: 06:15:04

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Roger Littin\Application Data\Mozilla\Firefox\Profiles\wvdp5n84.Default User\cert8.db Object is locked skipped
C:\Documents and Settings\Roger Littin\Application Data\Mozilla\Firefox\Profiles\wvdp5n84.Default User\flashgot.log Object is locked skipped
C:\Documents and Settings\Roger Littin\Application Data\Mozilla\Firefox\Profiles\wvdp5n84.Default User\formhistory.dat Object is locked skipped
C:\Documents and Settings\Roger Littin\Application Data\Mozilla\Firefox\Profiles\wvdp5n84.Default User\GoogleToolbarData\googlesafebrowsing.db Object is locked skipped
C:\Documents and Settings\Roger Littin\Application Data\Mozilla\Firefox\Profiles\wvdp5n84.Default User\history.dat Object is locked skipped
C:\Documents and Settings\Roger Littin\Application Data\Mozilla\Firefox\Profiles\wvdp5n84.Default User\key3.db Object is locked skipped
C:\Documents and Settings\Roger Littin\Application Data\Mozilla\Firefox\Profiles\wvdp5n84.Default User\parent.lock Object is locked skipped
C:\Documents and Settings\Roger Littin\Application Data\Mozilla\Firefox\Profiles\wvdp5n84.Default User\search.sqlite Object is locked skipped
C:\Documents and Settings\Roger Littin\Application Data\Mozilla\Firefox\Profiles\wvdp5n84.Default User\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Roger Littin\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Roger Littin\Local Settings\Application Data\Identities\{58ACB84F-D5EB-49F6-A67B-38C42072CC73}\Microsoft\Outlook Express\Deleted Items.dbx/[From "Halifax" <anti-fraud.ref.num13992956853499@halifax.co.uk>][Date Sat, 05 Feb 2005 07:21:44 -0100]/UNNAMED/html Infected: Trojan-Spy.HTML.Bankfraud.hs skipped
C:\Documents and Settings\Roger Littin\Local Settings\Application Data\Identities\{58ACB84F-D5EB-49F6-A67B-38C42072CC73}\Microsoft\Outlook Express\Deleted Items.dbx/[From "Halifax" <anti-fraud.ref.num13992956853499@halifax.co.uk>][Date Sat, 05 Feb 2005 07:21:44 -0100]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.hs skipped
C:\Documents and Settings\Roger Littin\Local Settings\Application Data\Identities\{58ACB84F-D5EB-49F6-A67B-38C42072CC73}\Microsoft\Outlook Express\Deleted Items.dbx/[From "Regions Bank Customer Service Center" <customer@regions.com>][Date Sun, 06 Feb 2005 08:25:51 +0600]/html Infected: Trojan-Spy.HTML.Bankfraud.cm skipped
C:\Documents and Settings\Roger Littin\Local Settings\Application Data\Identities\{58ACB84F-D5EB-49F6-A67B-38C42072CC73}\Microsoft\Outlook Express\Deleted Items.dbx Mail MS Outlook 5: infected - 3 skipped
C:\Documents and Settings\Roger Littin\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\Roger Littin\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Roger Littin\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Roger Littin\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Roger Littin\Local Settings\Temp\hsperfdata_Roger Littin\4032 Object is locked skipped
C:\Documents and Settings\Roger Littin\Local Settings\Temp\Temporary Directory 1 for kf151.zip\keyfinder.exe/data.rar/officekey.exe Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
C:\Documents and Settings\Roger Littin\Local Settings\Temp\Temporary Directory 1 for kf151.zip\keyfinder.exe/data.rar Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
C:\Documents and Settings\Roger Littin\Local Settings\Temp\Temporary Directory 1 for kf151.zip\keyfinder.exe RarSFX: infected - 2 skipped
C:\Documents and Settings\Roger Littin\Local Settings\Temp\~DF231F.tmp Object is locked skipped
C:\Documents and Settings\Roger Littin\Local Settings\Temp\~DFDC6E.tmp Object is locked skipped
C:\Documents and Settings\Roger Littin\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Roger Littin\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Roger Littin\My Documents\Eclipse\.metadata\.lock Object is locked skipped
C:\Documents and Settings\Roger Littin\My Documents\Eclipse\.metadata\.plugins\org.asdt.wizards\asdtWizards.log Object is locked skipped
C:\Documents and Settings\Roger Littin\My Documents\kf151.zip/keyfinder.exe/data.rar/officekey.exe Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
C:\Documents and Settings\Roger Littin\My Documents\kf151.zip/keyfinder.exe/data.rar Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
C:\Documents and Settings\Roger Littin\My Documents\kf151.zip/keyfinder.exe Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
C:\Documents and Settings\Roger Littin\My Documents\kf151.zip ZIP: infected - 3 skipped
C:\Documents and Settings\Roger Littin\My Documents\My Downloads\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Roger Littin\My Documents\My Downloads\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Roger Littin\My Documents\My Downloads\SmitfraudFix.exe RarSFX: infected - 2 skipped
C:\Documents and Settings\Roger Littin\ntuser.dat Object is locked skipped
C:\Documents and Settings\Roger Littin\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\report\Resident protection.txt Object is locked skipped
C:\Program Files\FlashGet\ads\cache434\B_434_0_1_549500.htm Infected: Exploit.HTML.IframeBof skipped
C:\Program Files\Mozilla Firefox\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Program Files\MySQL\MySQL Server 4.1\data\ibdata1 Object is locked skipped
C:\Program Files\MySQL\MySQL Server 4.1\data\ib_logfile0 Object is locked skipped
C:\Program Files\MySQL\MySQL Server 4.1\data\ib_logfile1 Object is locked skipped
C:\Program Files\MySQL\MySQL Server 4.1\data\roger.err Object is locked skipped
C:\Program Files\MySQL\MySQL Server 5.0\data\ibdata1 Object is locked skipped
C:\Program Files\MySQL\MySQL Server 5.0\data\ib_logfile0 Object is locked skipped
C:\Program Files\MySQL\MySQL Server 5.0\data\ib_logfile1 Object is locked skipped
C:\Program Files\MySQL\MySQL Server 5.0\data\roger.err Object is locked skipped
C:\Program Files\Sawmill 7\LogAnalysisInfo\IPC\MasterProcessLock.568 Object is locked skipped
C:\Program Files\Sawmill 7\ServiceOutput.txt Object is locked skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\cuoevjga.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\qoobox\Quarantine\catchme2007-12-15_142312.67.zip/awtqpnm.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bhw skipped
C:\qoobox\Quarantine\catchme2007-12-15_142312.67.zip ZIP: infected - 1 skipped
C:\RECYCLER\NPROTECT\00150012.box Object is locked skipped
C:\RECYCLER\NPROTECT\00150013.HTM Object is locked skipped
C:\RECYCLER\NPROTECT\00150016.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150017.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150018.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150019.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150020.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150021.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150022.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150024.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150025.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150027.box Object is locked skipped
C:\RECYCLER\NPROTECT\00150029.box Object is locked skipped
C:\RECYCLER\NPROTECT\00150030.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150032.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150033.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150035.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150036.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150037.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150039.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150040.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150041.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150043.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150044.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150045.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150047.box Object is locked skipped
C:\RECYCLER\NPROTECT\00150049.dat Object is locked skipped
C:\RECYCLER\NPROTECT\00150050.dat Object is locked skipped
C:\RECYCLER\NPROTECT\00150082.box Object is locked skipped
C:\RECYCLER\NPROTECT\00150085.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150086.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150087.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150089.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150090.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150091.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150092.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150093.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150094.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150095.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150098.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150100.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150101.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150103.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150104.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150105.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150106.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150108.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150109.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150111.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150112.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150114.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150115.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150116.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150117.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150118.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150119.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150121.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150122.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150124.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150125.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150127.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150128.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150129.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150131.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150132.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150134.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150135.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150136.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150137.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150138.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150139.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150140.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150141.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150142.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150144.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150145.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150146.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150147.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150149.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150150.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150151.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150153.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150154.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150155.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150157.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150158.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150159.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150160.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150162.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150164.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150165.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150166.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150168.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150169.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150170.box Object is locked skipped
C:\RECYCLER\NPROTECT\00150172.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150176.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150177.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150178.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150179.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150181.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150182.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150184.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150185.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150186.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150188.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150189.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150190.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150191.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150195.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150197.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150200.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150201.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150202.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150203.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150204.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150206.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150209.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150220.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150221.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150222.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150224.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150225.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150227.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150230.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150232.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150234.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150235.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150236.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150237.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150239.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150240.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150241.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150243.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150244.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150246.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150247.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150248.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150251.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150252.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150253.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150255.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150256.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150258.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150260.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150262.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150263.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150264.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150265.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150266.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150267.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150269.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150271.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150272.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150280.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150281.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150283.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150284.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150285.MOZ Object is locked skipped

rjlittin
2007-12-16, 11:23
C:\RECYCLER\NPROTECT\00150286.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150287.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150289.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150291.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150292.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150293.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150295.box Object is locked skipped
C:\RECYCLER\NPROTECT\00150296.box Object is locked skipped
C:\RECYCLER\NPROTECT\00150299.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150300.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150306.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150308.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150309.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150310.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150312.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150313.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150314.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150315.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150317.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150318.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150321.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150322.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150337.wpl Object is locked skipped
C:\RECYCLER\NPROTECT\00150338.XML Object is locked skipped
C:\RECYCLER\NPROTECT\00150341.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150343.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150344.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150346.box Object is locked skipped
C:\RECYCLER\NPROTECT\00150477.dat Object is locked skipped
C:\RECYCLER\NPROTECT\00150478.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150481.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150482.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150493.box Object is locked skipped
C:\RECYCLER\NPROTECT\00150498.HTM Object is locked skipped
C:\RECYCLER\NPROTECT\00150503.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150520.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150521.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150522.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150524.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150525.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150526.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150528.box Object is locked skipped
C:\RECYCLER\NPROTECT\00150529.box Object is locked skipped
C:\RECYCLER\NPROTECT\00150533.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150534.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150535.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150537.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150541.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150544.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150545.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150546.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150548.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150613.DIC Object is locked skipped
C:\RECYCLER\NPROTECT\00150617.LNK Object is locked skipped
C:\RECYCLER\NPROTECT\00150618.LNK Object is locked skipped
C:\RECYCLER\NPROTECT\00150626.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150627.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150629.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150630.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150632.box Object is locked skipped
C:\RECYCLER\NPROTECT\00150635.DIC Object is locked skipped
C:\RECYCLER\NPROTECT\00150639.LNK Object is locked skipped
C:\RECYCLER\NPROTECT\00150640.LNK Object is locked skipped
C:\RECYCLER\NPROTECT\00150643.PST Object is locked skipped
C:\RECYCLER\NPROTECT\00150644.PST Object is locked skipped
C:\RECYCLER\NPROTECT\00150672.box Object is locked skipped
C:\RECYCLER\NPROTECT\00150675.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150678.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150681.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150682.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150684.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150685.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150686.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150692.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150694.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150697.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150701.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150703.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150705.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150710.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150715.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150717.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150719.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150721.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150722.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150725.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150726.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150727.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150728.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150731.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150732.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150733.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150747.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150751.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150752.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150757.XML Object is locked skipped
C:\RECYCLER\NPROTECT\00150758.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150762.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150768.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150776.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150777.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150778.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150781.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150783.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150784.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150786.box Object is locked skipped
C:\RECYCLER\NPROTECT\00150809.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150815.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150816.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150817.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150818.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150819.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150820.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150821.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150822.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150823.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150824.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150825.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150826.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150829.box Object is locked skipped
C:\RECYCLER\NPROTECT\00150833.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150835.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150836.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150837.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150838.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150869.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150873.xml Object is locked skipped
C:\RECYCLER\NPROTECT\00150874.xml Object is locked skipped
C:\RECYCLER\NPROTECT\00150875.xml Object is locked skipped
C:\RECYCLER\NPROTECT\00150876.xml Object is locked skipped
C:\RECYCLER\NPROTECT\00150877.xml Object is locked skipped
C:\RECYCLER\NPROTECT\00150878.xml Object is locked skipped
C:\RECYCLER\NPROTECT\00150879.xml Object is locked skipped
C:\RECYCLER\NPROTECT\00150880.xml Object is locked skipped
C:\RECYCLER\NPROTECT\00150881.xml Object is locked skipped
C:\RECYCLER\NPROTECT\00150883.xml Object is locked skipped
C:\RECYCLER\NPROTECT\00150884.xml Object is locked skipped
C:\RECYCLER\NPROTECT\00150894.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150895.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150897.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150898.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150900.box Object is locked skipped
C:\RECYCLER\NPROTECT\00150902.xml Object is locked skipped
C:\RECYCLER\NPROTECT\00150931.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150932.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150933.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150934.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150935.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150936.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150937.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150938.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150940.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150941.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150942.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150943.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150944.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150945.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150946.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150947.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150948.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150949.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150950.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150974.xml Object is locked skipped
C:\RECYCLER\NPROTECT\00150976.xml Object is locked skipped
C:\RECYCLER\NPROTECT\00150977.xml Object is locked skipped
C:\RECYCLER\NPROTECT\00150978.xml Object is locked skipped
C:\RECYCLER\NPROTECT\00150980.xml Object is locked skipped
C:\RECYCLER\NPROTECT\00150982.box Object is locked skipped
C:\RECYCLER\NPROTECT\00150985.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150986.xml Object is locked skipped
C:\RECYCLER\NPROTECT\00151012.xml Object is locked skipped
C:\RECYCLER\NPROTECT\00151015.dat Object is locked skipped
C:\RECYCLER\NPROTECT\00151016.dat Object is locked skipped
C:\RECYCLER\NPROTECT\00151021.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151022.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151023.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151024.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151026.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151027.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151028.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151030.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151033.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151034.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151035.box Object is locked skipped
C:\RECYCLER\NPROTECT\00151037.xml Object is locked skipped
C:\RECYCLER\NPROTECT\00151053.dat Object is locked skipped
C:\RECYCLER\NPROTECT\00151054.box Object is locked skipped
C:\RECYCLER\NPROTECT\00151056.HTM Object is locked skipped
C:\RECYCLER\NPROTECT\00151065.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151066.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151067.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151068.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151070.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151071.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151073.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151074.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151075.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151076.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151078.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151079.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151080.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151081.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151082.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151084.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151085.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151087.box Object is locked skipped
C:\RECYCLER\NPROTECT\00151358.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151359.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151360.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151361.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151362.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151363.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151364.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151365.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151366.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151367.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151368.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151369.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151371.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151372.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151373.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151374.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151375.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151376.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151386.box Object is locked skipped
C:\RECYCLER\NPROTECT\00151395.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151396.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151401.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151402.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151408.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151412.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151414.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151415.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151417.box Object is locked skipped
C:\RECYCLER\NPROTECT\00151418.box Object is locked skipped
C:\RECYCLER\NPROTECT\00151421.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151422.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151424.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151427.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151428.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151429.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151430.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151431.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151432.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151433.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151434.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151436.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151437.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151438.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151439.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151440.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151441.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151443.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151444.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151445.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151446.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151447.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151448.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151450.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151451.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151452.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151453.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151454.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151457.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151459.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151461.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151462.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151463.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151464.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151466.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151467.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151470.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151472.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151473.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151475.box Object is locked skipped
C:\RECYCLER\NPROTECT\00151495.box Object is locked skipped
C:\RECYCLER\NPROTECT\00151500.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151501.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151517.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151518.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151521.wpl Object is locked skipped
C:\RECYCLER\NPROTECT\00151522.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151524.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151525.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151527.box Object is locked skipped
C:\RECYCLER\NPROTECT\00151548.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151549.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151550.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151551.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151552.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151553.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151554.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151555.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151556.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151557.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151558.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151559.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151560.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151561.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151562.TXT Object is locked skipped

rjlittin
2007-12-16, 11:25
C:\RECYCLER\NPROTECT\00151563.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151564.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151565.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151566.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151567.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151568.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151569.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151570.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151571.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151572.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151573.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151574.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151575.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151577.box Object is locked skipped
C:\RECYCLER\NPROTECT\00151580.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151582.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151583.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151587.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151589.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151591.XML Object is locked skipped
C:\RECYCLER\NPROTECT\00151594.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151595.XML Object is locked skipped
C:\RECYCLER\NPROTECT\00151598.XML Object is locked skipped
C:\RECYCLER\NPROTECT\00151601.XML Object is locked skipped
C:\RECYCLER\NPROTECT\00151604.XML Object is locked skipped
C:\RECYCLER\NPROTECT\00151608.XML Object is locked skipped
C:\RECYCLER\NPROTECT\00151611.XML Object is locked skipped
C:\RECYCLER\NPROTECT\00151614.XML Object is locked skipped
C:\RECYCLER\NPROTECT\00151617.XML Object is locked skipped
C:\RECYCLER\NPROTECT\00151620.XML Object is locked skipped
C:\RECYCLER\NPROTECT\00151622.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151623.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151625.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151626.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151627.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151628.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151630.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151631.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151632.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151633.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151634.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151636.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151638.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151639.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151642.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151644.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151645.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151646.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151648.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151649.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151650.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151652.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151653.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151654.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151656.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151657.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151659.box Object is locked skipped
C:\RECYCLER\NPROTECT\00151662.LNK Object is locked skipped
C:\RECYCLER\NPROTECT\00151663.LNK Object is locked skipped
C:\RECYCLER\NPROTECT\00151665.LNK Object is locked skipped
C:\RECYCLER\NPROTECT\00151666.LNK Object is locked skipped
C:\RECYCLER\NPROTECT\00151669.lnk Object is locked skipped
C:\RECYCLER\NPROTECT\00151671.LNK Object is locked skipped
C:\RECYCLER\NPROTECT\00151705.box Object is locked skipped
C:\RECYCLER\NPROTECT\00151710.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151725.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151727.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151728.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151730.box Object is locked skipped
C:\RECYCLER\NPROTECT\00151747.box Object is locked skipped
C:\RECYCLER\NPROTECT\00151764.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151766.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151767.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151768.box Object is locked skipped
C:\RECYCLER\NPROTECT\00151794.box Object is locked skipped
C:\RECYCLER\NPROTECT\00151821.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151823.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151825.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151827.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151828.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151829.box Object is locked skipped
C:\RECYCLER\NPROTECT\00151875.box Object is locked skipped
C:\RECYCLER\NPROTECT\00151885.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151919.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151921.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151922.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151923.box Object is locked skipped
C:\RECYCLER\NPROTECT\00151924.box Object is locked skipped
C:\RECYCLER\NPROTECT\00151930.dat Object is locked skipped
C:\RECYCLER\NPROTECT\00151931.dat Object is locked skipped
C:\RECYCLER\NPROTECT\00151933.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151935.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151936.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151937.box Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP978\A0214647.exe Infected: Trojan.Win32.Agent.cro skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP980\A0215803.exe Infected: not-a-virus:AdWare.Win32.RK.a skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP982\A0217774.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP982\A0218753.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP983\A0219847.exe Infected: not-a-virus:AdWare.Win32.RK.a skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP983\A0219851.dll Infected: not-a-virus:AdWare.Win32.RK.a skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP985\A0220034.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP985\A0220037.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP985\A0220038.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP985\A0220039.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP985\A0220041.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP985\A0220042.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP985\A0220044.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP986\A0220972.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP986\A0221091.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP987\A0221847.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP987\A0221862.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bhw skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP987\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Internet Logs\fwdbglog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped
C:\WINDOWS\Internet Logs\ROGER.ldb Object is locked skipped
C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edbtmp.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\atapi.sys Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox.dat Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox.idx Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\spool\notepad.exe/stream/data0002 Infected: Trojan-Clicker.Win32.Agent.iq skipped
C:\WINDOWS\system32\spool\notepad.exe/stream Infected: Trojan-Clicker.Win32.Agent.iq skipped
C:\WINDOWS\system32\spool\notepad.exe NSIS: infected - 2 skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\ib2 Object is locked skipped
C:\WINDOWS\Temp\ib3 Object is locked skipped
C:\WINDOWS\Temp\ib4 Object is locked skipped
C:\WINDOWS\Temp\ib5 Object is locked skipped
C:\WINDOWS\Temp\ib6 Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_70c.dat Object is locked skipped
C:\WINDOWS\Temp\ZLT05b92.TMP Object is locked skipped
C:\WINDOWS\Temp\ZLT06e8f.TMP Object is locked skipped
C:\WINDOWS\Temp\_avast4_\Webshlock.txt Object is locked skipped
C:\WINDOWS\TempFile Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\recovered\Documents\Outlook\outlook.pst/Personal Folders/Inbox/16 Oct 2002 17:48 from Belinda Edwards:Bulletin.html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
D:\recovered\Documents\Outlook\outlook.pst/Personal Folders/Inbox/20 Mar 2003 21:41 from Sue Hayden:Can't remember if I sent this?.html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
D:\recovered\Documents\Outlook\outlook.pst/Personal Folders/Inbox/03 Jun 2003 00:36 from David Mayers:Updated: Vantico Classificat.html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
D:\recovered\Documents\Outlook\outlook.pst Mail MS Mail: suspicious - 3 skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
F:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

Scan process completed.

rjlittin
2007-12-16, 11:27
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:24:37, on 16/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\crypserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\MySQL\MySQL Server 4.1\bin\mysqld-nt.exe
C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
C:\Program Files\Sawmill 7\SawmillService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sawmill 7\SawmillCL.exe
C:\Program Files\Sawmill 7\SawmillCL.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\V0230Mon.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\JGsoft\EditPadPro6\EditPadPro.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.fluidmd.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
N3 - Netscape 7: # Mozilla User Preferences

/* Do not edit this file.
*
* If you make changes to this file while the browser is running,
* the changes will be overwritten when the browser exits.
*
* To make a manual change to preferences, you can visit the URL about:config
* For more information, see http://www.mozilla.org/unix/customizing.html#prefs
*/

user_pref("browser.activation.checkedNNFlag", true);
user_pref("browser.bookmarks.added_static_root", true);
user_pref("browser.cache.disk.parent_directory", "C:\\DOCUMENTS AND SETTINGS\\ROGER LITTIN\\APPLICATION DATA\\Mozilla\\Profiles\\default\\7n1juq48.slt");
user_pref("browser.download.dir", "C:\\Documents and Settings\\Roger Littin\\My Documents");
user_pref("browser.search.defaultengine", "engine://C%3A%5CPROGRA%7E1%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src");
user_pref("browser.startup.homepage_override.mstone", "rv:1.7.2");
user_pref("browser.tabs.forceHide", true);
user_pref("browser.turbo.showDialog", false);
user_pref("dom.disabl
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: IE DevToolbar BHO - {CC7E636D-39AA-49b6-B511-65413DA137A1} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Developer Toolbar - {CC962137-2E78-4f94-975E-FC0C07DBD78F} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [V0230Mon.exe] C:\WINDOWS\system32\V0230Mon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\RunServices: [SchedulingAgent] C:\WINDOWS\system32\mstask.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Program Files\VisualRoute\vrie.dll
O9 - Extra 'Tools' menuitem: VisualRoute Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Program Files\VisualRoute\vrie.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: IE Developer Toolbar - {48FFE35F-36D9-44bd-A6CC-1D34414EAC0D} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O9 - Extra button: Europa Casino - {4C826F10-D34B-4ba8-B609-1FB8C6482A05} - C:\Casino\Europa Casino\casino.exe (file missing)
O9 - Extra 'Tools' menuitem: Europa Casino - {4C826F10-D34B-4ba8-B609-1FB8C6482A05} - C:\Casino\Europa Casino\casino.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\flashget.exe
O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra 'Tools' menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .ocx: C:\Program Files\Opera\PLUGINS\NPFgc1.dll
O12 - Plugin for .ps: C:\Program Files\Opera\PLUGINS\NPFgc1.dll
O12 - Plugin for .tar: C:\Program Files\Opera\PLUGINS\NPFgc1.dll
O12 - Plugin for .zip: C:\Program Files\Opera\PLUGINS\NPFgc1.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.tiscali.co.uk/
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1108071541436
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
O16 - DPF: {E5ABEB00-B357-4884-9949-77B2C71A7EE3} (BoardCtl Class) - http://www.intel.com/design/motherbd/boardid/BoardID.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: Flash Media Server (FMS) (FMS) - Macromedia, Inc. - C:\Program Files\Macromedia\Flash Media Server 2\FMSMaster.exe
O23 - Service: Flash Media Administration Server (FMSAdmin) - Macromedia, Inc. - C:\Program Files\Macromedia\Flash Media Server 2\FMSAdmin.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: MySQL41 - Unknown owner - C:\Program.exe (file missing)
O23 - Service: MySQL5 - Unknown owner - C:\Program.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sawmill - Unknown owner - C:\Program Files\Sawmill 7\SawmillService.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Wowza Media Server Pro (WowzaMediaServerPro) - Unknown owner - C:\Program Files\Wowza Media Systems\Wowza Media Server Pro\bin\wrapper.exe

--
End of file - 11690 bytes

Shaba
2007-12-16, 11:29
Hi

As for nprotect folders, see here (http://service1.symantec.com/SUPPORT/nsw.nsf/0/831aa5c6ef0d750685256c370048ad89?OpenDocument)

Empty deleted items in Outlook and delete this:

D:\recovered\Documents\Outlook\outlook.pst

Delete also these:

C:\Documents and Settings\Roger Littin\Local Settings\Temp\Temporary Directory 1 for kf151.zip
C:\Documents and Settings\Roger Littin\My Documents\kf151.zip
C:\WINDOWS\system32\spool\notepad.exe

And empty this folder:

C:\qoobox\Quarantine\

Empty Recycle Bin.

Re-scan with kaspersky.

Post:

- a fresh HijackThis log
- kaspersky report

rjlittin
2007-12-16, 11:32
Internet explorer seems to have forgotten what it is supposed to do with files that are not web pages. Instead of downloading them it tries to open them in a new window. I have to right click the link and save as but this sometimes doesn't work if the link goes to a download script.

Shaba
2007-12-16, 11:34
Hi

This (http://edutech.ch/vista/docs/HOWTOs/VIS033E_DownloadHelp.php)
might help.

rjlittin
2007-12-16, 12:21
Hi Shaba,

Can I safely do a kaspersky scan without including drives e & f. These contain 80 gig of work stuff between them and showed up clean in the last report.

Shaba
2007-12-16, 12:31
Hi

Yes :)

rjlittin
2007-12-16, 18:46
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Sunday, December 16, 2007 5:40:36 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 16/12/2007
Kaspersky Anti-Virus database records: 484048
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - Folders:
C:\
D:\

Scan Statistics:
Total number of scanned objects: 239417
Number of viruses found: 9
Number of infected objects: 25
Number of suspicious objects: 0
Duration of the scan process: 05:45:43

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Roger Littin\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Roger Littin\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\Roger Littin\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Roger Littin\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Roger Littin\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Roger Littin\Local Settings\History\History.IE5\MSHist012007121620071217\index.dat Object is locked skipped
C:\Documents and Settings\Roger Littin\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Roger Littin\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Roger Littin\My Documents\My Downloads\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Roger Littin\My Documents\My Downloads\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Roger Littin\My Documents\My Downloads\SmitfraudFix.exe RarSFX: infected - 2 skipped
C:\Documents and Settings\Roger Littin\ntuser.dat Object is locked skipped
C:\Documents and Settings\Roger Littin\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\report\Resident protection.txt Object is locked skipped
C:\Program Files\FlashGet\ads\cache434\B_434_0_1_549500.htm Infected: Exploit.HTML.IframeBof skipped
C:\Program Files\Mozilla Firefox\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Program Files\MySQL\MySQL Server 4.1\data\ibdata1 Object is locked skipped
C:\Program Files\MySQL\MySQL Server 4.1\data\ib_logfile0 Object is locked skipped
C:\Program Files\MySQL\MySQL Server 4.1\data\ib_logfile1 Object is locked skipped
C:\Program Files\MySQL\MySQL Server 4.1\data\roger.err Object is locked skipped
C:\Program Files\MySQL\MySQL Server 5.0\data\ibdata1 Object is locked skipped
C:\Program Files\MySQL\MySQL Server 5.0\data\ib_logfile0 Object is locked skipped
C:\Program Files\MySQL\MySQL Server 5.0\data\ib_logfile1 Object is locked skipped
C:\Program Files\MySQL\MySQL Server 5.0\data\roger.err Object is locked skipped
C:\Program Files\Sawmill 7\LogAnalysisInfo\IPC\MasterProcessLock.1524 Object is locked skipped
C:\Program Files\Sawmill 7\ServiceOutput.txt Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP978\A0214647.exe Infected: Trojan.Win32.Agent.cro skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP980\A0215803.exe Infected: not-a-virus:AdWare.Win32.RK.a skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP982\A0217774.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP982\A0218753.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP983\A0219847.exe Infected: not-a-virus:AdWare.Win32.RK.a skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP983\A0219851.dll Infected: not-a-virus:AdWare.Win32.RK.a skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP985\A0220034.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP985\A0220037.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP985\A0220038.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP985\A0220039.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP985\A0220041.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP985\A0220042.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP985\A0220044.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP986\A0220972.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP986\A0221091.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP987\A0221847.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP987\A0221862.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bhw skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP988\A0223579.exe/stream/data0002 Infected: Trojan-Clicker.Win32.Agent.iq skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP988\A0223579.exe/stream Infected: Trojan-Clicker.Win32.Agent.iq skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP988\A0223579.exe NSIS: infected - 2 skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP989\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Internet Logs\fwdbglog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped
C:\WINDOWS\Internet Logs\ROGER.ldb Object is locked skipped
C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{4E6A0B82-C821-4D55-B777-61C771DDDA27}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\atapi.sys Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox.dat Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox.idx Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\ib10 Object is locked skipped
C:\WINDOWS\Temp\ib2 Object is locked skipped
C:\WINDOWS\Temp\ib3 Object is locked skipped
C:\WINDOWS\Temp\ib4 Object is locked skipped
C:\WINDOWS\Temp\ib5 Object is locked skipped
C:\WINDOWS\Temp\ib6 Object is locked skipped
C:\WINDOWS\Temp\ib7 Object is locked skipped
C:\WINDOWS\Temp\ib8 Object is locked skipped
C:\WINDOWS\Temp\ib9 Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_6a8.dat Object is locked skipped
C:\WINDOWS\Temp\ZLT018f8.TMP Object is locked skipped
C:\WINDOWS\Temp\ZLT018fc.TMP Object is locked skipped
C:\WINDOWS\Temp\_avast4_\Webshlock.txt Object is locked skipped
C:\WINDOWS\TempFile Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.

rjlittin
2007-12-16, 18:49
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:46:33, on 16/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\crypserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\MySQL\MySQL Server 4.1\bin\mysqld-nt.exe
C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
C:\Program Files\Sawmill 7\SawmillService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sawmill 7\SawmillCL.exe
C:\Program Files\Sawmill 7\SawmillCL.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\V0230Mon.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\JGsoft\EditPadPro6\EditPadPro.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\eclipse\eclipse.exe
C:\Program Files\Trend Micro\HijackThis\scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.fluidmd.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
N3 - Netscape 7: # Mozilla User Preferences

/* Do not edit this file.
*
* If you make changes to this file while the browser is running,
* the changes will be overwritten when the browser exits.
*
* To make a manual change to preferences, you can visit the URL about:config
* For more information, see http://www.mozilla.org/unix/customizing.html#prefs
*/

user_pref("browser.activation.checkedNNFlag", true);
user_pref("browser.bookmarks.added_static_root", true);
user_pref("browser.cache.disk.parent_directory", "C:\\DOCUMENTS AND SETTINGS\\ROGER LITTIN\\APPLICATION DATA\\Mozilla\\Profiles\\default\\7n1juq48.slt");
user_pref("browser.download.dir", "C:\\Documents and Settings\\Roger Littin\\My Documents");
user_pref("browser.search.defaultengine", "engine://C%3A%5CPROGRA%7E1%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src");
user_pref("browser.startup.homepage_override.mstone", "rv:1.7.2");
user_pref("browser.tabs.forceHide", true);
user_pref("browser.turbo.showDialog", false);
user_pref("dom.disabl
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: IE DevToolbar BHO - {CC7E636D-39AA-49b6-B511-65413DA137A1} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Developer Toolbar - {CC962137-2E78-4f94-975E-FC0C07DBD78F} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [V0230Mon.exe] C:\WINDOWS\system32\V0230Mon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\RunServices: [SchedulingAgent] C:\WINDOWS\system32\mstask.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Program Files\VisualRoute\vrie.dll
O9 - Extra 'Tools' menuitem: VisualRoute Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Program Files\VisualRoute\vrie.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: IE Developer Toolbar - {48FFE35F-36D9-44bd-A6CC-1D34414EAC0D} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O9 - Extra button: Europa Casino - {4C826F10-D34B-4ba8-B609-1FB8C6482A05} - C:\Casino\Europa Casino\casino.exe (file missing)
O9 - Extra 'Tools' menuitem: Europa Casino - {4C826F10-D34B-4ba8-B609-1FB8C6482A05} - C:\Casino\Europa Casino\casino.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra 'Tools' menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.tiscali.co.uk/
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1108071541436
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
O16 - DPF: {E5ABEB00-B357-4884-9949-77B2C71A7EE3} (BoardCtl Class) - http://www.intel.com/design/motherbd/boardid/BoardID.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: Flash Media Server (FMS) (FMS) - Macromedia, Inc. - C:\Program Files\Macromedia\Flash Media Server 2\FMSMaster.exe
O23 - Service: Flash Media Administration Server (FMSAdmin) - Macromedia, Inc. - C:\Program Files\Macromedia\Flash Media Server 2\FMSAdmin.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: MySQL41 - Unknown owner - C:\Program.exe (file missing)
O23 - Service: MySQL5 - Unknown owner - C:\Program.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sawmill - Unknown owner - C:\Program Files\Sawmill 7\SawmillService.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Wowza Media Server Pro (WowzaMediaServerPro) - Unknown owner - C:\Program Files\Wowza Media Systems\Wowza Media Server Pro\bin\wrapper.exe

--
End of file - 11743 bytes

Shaba
2007-12-16, 19:07
Hi

Logs look good.

All viruses are in system restore and inactive.

I give you later instructions how to empty it.

Other than that, any problems left?

rjlittin
2007-12-16, 19:45
All seems to be going well at the moment. Thanks for your help so far.

Shaba
2007-12-16, 19:55
Hi

Then you're clean!

Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:

You can fix this, it's a leftover:

O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. A malicious site could render Java content under older, vulnerable versions of Sun's software if the user has not removed them. Please follow these steps to remove older version Java components and update: Download the latest version of Java Runtime Environment (JRE) 6 Update 3 (http://java.sun.com/javase/downloads/index.jsp) and save it to your desktop.
Scroll down to where it says "Java Runtime Environment (JRE) 6u3...allows end-users to run Java applications".
Click the "Download" button to the right.
Read the License Agreement and then check the box that says: "Accept License Agreement".
The page will refresh.
Click on the link to download Windows Offline Installation and save the file to your desktop.
Close any programs you may have running - especially your web browser.
Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
Click the Remove or Change/Remove button.
Repeat as many times as necessary to remove each Java versions.
Reboot your computer once all Java components are removed.
Then from your desktop double-click on jre-6u3-windows-i586-p.exe to install the newest version.

Update Adobe Reader
It looks like your version of Adobe Reader is out of date and you're vulnerable for infections.
Please download the newest version here:
http://www.adobe.com/products/acrobat/readstep2_servefile.html?option=full&order=1&type=&language=English&platform=WinXPSP2&esdcanbeused=0&esdcanhandle=0&hasjavascript=1&dlm=nos

Install it, then go to Add/Remove Programs and remove any older versions that may remain.

Next we remove all used tools.

Please download OTMoveIt (http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe) and save it to desktop.

Double-click OTMoveIt.exe.
Click the CleanUp! button.
Select Yes when the "Begin cleanup Process?" prompt appears.
If you are prompted to Reboot during the cleanup, select Yes.
The tool will delete itself once it finishes, if not delete it by yourself.


Note: If you receive a warning from your firewall or other security programs regarding OTMoveIt attempting to contact the internet, please allow it to do so.

Disable and Enable System Restore. - If you are using Windows XP then you should disable and re-enable system restore to make sure there are no infected files found in a restore point.

You can find instructions on how to enable and re-enable system restore here:

Windows XP System Restore Guide (http://www.bleepingcomputer.com/forums/tutorial56.html)

Re-enable system restore with instructions from tutorial above

Make your Internet Explorer more secure - This can be done by following these simple instructions:
From within Internet Explorer click on the Tools menu and then click on Options.
Click once on the Security tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt

Change the Download unsigned ActiveX controls to Disable

Change the Initialize and script ActiveX controls not marked as safe to Disable

Change the Installation of desktop items to Prompt

Change the Launching programs and files in an IFRAME to Prompt

Change the Navigate sub-frames across different domains to Prompt

When all these settings have been made, click on the OK button.

If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.

Update your AntiVirus Software - It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.


Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com (http://www.windowsupdate.com) regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.


Install Ad-Aware - Install and download Ad-Aware. You should also scan your computer with program on a regular basis just as you would an antivirus software in conjunction with Spybot.

A tutorial on installing & using this product can be found here:

Using Ad-aware 2007 to remove Spyware, Malware, & Hijackers from Your Computer (http://www.bleepingcomputer.com/forums/?showtutorial=48)


Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

A tutorial on installing & using this product can be found here:

Using SpywareBlaster to protect your computer from Spyware and Malware (http://www.bleepingcomputer.com/tutorials/tutorial49.html)


Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.

Here are some additional utilities that will enhance your safety

MVPS Hosts file (http://mvps.org/winhelp2002/hosts.htm) <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
Google Toolbar (http://toolbar.google.com/) <= Get the free google toolbar to help stop pop up windows.
Comodo BOCLEAN (http://www.comodo.com/boclean/boclean.html) <= Stop identity thieves from getting personal information. Instantly detects well over 1,000,000 unique, variant and repack malware in total. And it's free.
Winpatrol (http://www.winpatrol.com/) <= Download and install the free version of Winpatrol. a tutorial for this product is located here:
Using Winpatrol to protect your computer from malicious software (http://www.winpatrol.com/features.html)

Stand Up and Be Counted ---> Malware Complaints (http://www.malwarecomplaints.info/index.php) <--- where you can make difference!

The site offers people who have been (or are) victims of malware the opportunity to document their story and, in that way, launch a complaint against the malware and the makers of the malware.

Also, please read this great article by Tony Klein So How Did I Get Infected In First Place (http://castlecops.com/postlite7736-.html)

Happy surfing and stay clean!

rjlittin
2007-12-16, 21:32
One question re java. I use the jdk for development. Do I also need a seperate instalation of jre or will the one in the jdk do the job?

Shaba
2007-12-17, 10:18
Hi

Then both should be updated.

rjlittin
2007-12-17, 19:16
took out the old java instalations and installed latest jdk which also installed new jre automatically.

All updated and locked down so hopefully wont be back asking for help for a long time.

Thanks again for all your help.

Roger.

Shaba
2007-12-19, 11:01
Since this issue appears resolved ... this Topic is closed.

If you need this topic reopened, please request this by sending the moderating team
a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic.