PDA

View Full Version : Trojan?



Sarpi
2008-02-18, 00:27
EDIT************ I had to split this post up cos of the 20,000 character limit of the fourm.

My computer randomly started opening IE and going to pages such as:


http://www.setthetrend.com/search.php?query=t=1&source=ao&adgroupid=LocalList15aojwhite&adpartner=112194&adkw=t=1&
https://www.planetonline.com/online_shopping/shopperregistration_coupon.asp
http://college.us.com/Aff/?partner=1268&source=1014&key=adon
http://www.wallst.net/
http://www.nightlifetelevision.com/?utm_source=AO&utm_medium=banner2=112194
https://www.planetonline.com/online_shopping/shopperregistration_coupon.aspThey started coming up every 5 minutes or so but now they are about once a minute.

I normally use Firefox.

I did Spybot scans and they come up with various things, smitfraud is a common one. It always says it cleans them.

I did a virus scan:

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Friday, February 15, 2008 6:01:49 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 15/02/2008
Kaspersky Anti-Virus database records: 567337
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\

Scan Statistics:
Total number of scanned objects: 65772
Number of viruses found: 7
Number of infected objects: 15
Number of suspicious objects: 0
Duration of the scan process: 00:56:20

Infected Object Name / Virus Name / Last Action
C:\itouch_crash_info.txt Object is locked skipped
C:\Program Files\Internet Explorer\keygen.exe/data0000.cab/update.exe Infected: Trojan.Win32.Agent.efb skipped
C:\Program Files\Internet Explorer\keygen.exe/data0000.cab Infected: Trojan.Win32.Agent.efb skipped
C:\Program Files\Internet Explorer\keygen.exe Rsrc-Package: infected - 2 skipped
C:\Program Files\Internet Explorer\keygen.exe UPX: infected - 2 skipped
C:\Program Files\Internet Explorer\keygen.exe PE_Patch.UPX: infected - 2 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{6C8960AE-6C34-4A55-9874-730A9A03C459}\RP115\A0016808.exe Object is locked skipped
C:\System Volume Information\_restore{6C8960AE-6C34-4A55-9874-730A9A03C459}\RP115\change.log Object is locked skipped
C:\xDocuments and Settings\adam\Old computer\Bits and pieces\Bits and Pieces\free rip mp3.exe/data0011 Infected: not-a-virus:AdWare.Win32.MyWay.j skipped
C:\xDocuments and Settings\adam\Old computer\Bits and pieces\Bits and Pieces\free rip mp3.exe Inno: infected - 1 skipped
C:\xDocuments and Settings\adam\Old computer\Bits and pieces\Bits and Pieces\vnc-3.3.3r9_x86_win32.zip/vnc_x86_win32/vncviewer/vncviewer.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.333 skipped
C:\xDocuments and Settings\adam\Old computer\Bits and pieces\Bits and Pieces\vnc-3.3.3r9_x86_win32.zip ZIP: infected - 1 skipped
C:\xDocuments and Settings\adam\Old computer\Bits and pieces\Bits and Pieces\vnc-4_1_1-x86_win32.exe/file1 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4110 skipped
C:\xDocuments and Settings\adam\Old computer\Bits and pieces\Bits and Pieces\vnc-4_1_1-x86_win32.exe/file3 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\xDocuments and Settings\adam\Old computer\Bits and pieces\Bits and Pieces\vnc-4_1_1-x86_win32.exe Inno: infected - 2 skipped
C:\xDocuments and Settings\adam\Old computer\Bits and pieces\Bits and Pieces\vncviewer.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.333 skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0522f592f6c0dceea18444012f0fe77a_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0538940fc5823ea3b6b04d3836ff7245_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\06817489d4f2c76b51a303939f5efe19_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\06b6f1f5b3693bcf4aed9f7e535700a8_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\06cbc44cebcdc6fb17cedccbbf79beb0_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\06fda4f0db54a2eaac4647c7ce4d5b4b_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\07a410e89f65949f9b1cb56fc536cbd7_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\07a850a521d103d56d039b941f062af4_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\087c867220193124df1c23d76785be0f_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0b4b77a2214019feda9c349a0c9f5f3f_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0b8d54b015ca6a1473202089104d09d7_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0b9e29fa5be157851d629f171d0e522d_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0df10d3668bc72c18ef0e38c6d5fbca2_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0e808b2bf26a0d9df40a609b3c7532ac_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0f269423080e13c04f5adc8c136a9c63_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0f2dcd85cd3a6366c8a25cb147765f3c_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0f30847a0b509fb3d272de6bf0fe7826_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0f768ba464102869d92391fe98f8f58a_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0f9fe93d9450cb3d219e8260c2771be9_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0fb19b17fc2a88034246b1857feb1c4b_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0fb990dc2a1512df699695ddb500c0d1_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0fbeec92e6e6b7d2a60daea1bca1fcaf_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1067c31fe6274ef4a83dd79eb79fda30_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\10fcf92dd7cd4361e1ef7f0a1a6ce6cf_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1171a9dcec7c9120a269314173fbda6d_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\12025b469e4abab673839d2ad5a744be_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\12424d5dc311a4856d0b2af7ab75be88_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1545713ea75917dda27a7dc2d41586bc_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\155ba891e883a1957eb9d703b378d697_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1569a2ac17d97a9e7a80be64134840e1_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\166c4dd2d095b0eaed71abc85e7b8897_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1858a28835770e611f6cfe5cbabff123_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\185b265d465711cc795c435e24b49ae3_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1879c35b7de72ce57c2bd55ef825788d_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\18891e602e3b9b9cdb727f8cd2b1494e_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\18c8eb1076db8d976589146ed8fbea96_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\18d4d635fb11b84748096b288cf96184_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\19239e9adc60bf04f7604fe66f33a8f2_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped

Sarpi
2008-02-18, 00:28
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1a604a719d2a97f33528ed043adac5ee_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1a6c021d48839b18b5b7e9a7df30735b_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1aba73d32891137e6eff71ac2bbe3120_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1bf580236eeba3063cb5d1f1ab93b7a5_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1c141cc72c5ad8386b2a6247cdaeba2b_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\20d6bb0dc957d1e5630871588a27753e_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2193b010c2f44af41345e0a42d202a29_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\220c0f12551d168f4b4c0af02c8bf8dd_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\222c13fb1ba68284d00772cfad84803e_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\22a6e530c09d3d525e11dabd6d084dbe_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\23ccffebee33a313330ba1d5a4b3e4b7_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\23ee5fdd4d48b4b66bd9eb36d3c0d950_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\24ac180d01f5f48d6f544a018f5fa071_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2583d52529ebea29f0c0ebaba81640b8_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\25c0043778eb12742acd22f671f88736_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\26e689d06da63d2bde792b5e2b71b113_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2762c5c2e85209feb99c764a6b84506e_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2908f9c97321a7899312e35ffee3e836_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\29ce5438b02219e7f7bc51e4b5b7dd3e_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\311df0444f9964a187ef7c3ee116d8de_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\32028686956060a7461b3f151ecec99e_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3299712b1929b39e9b3bdf52650f13f7_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\32e09cc025da562417950856322598d0_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3314a6a6354b0597bad3ba3cdd65b39e_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\33660842a8a3f19964051938723e1bb1_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3398230b85016bd2dbfdbcc81ee3cd98_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\33a9a47c30534daae71d375606c4b29f_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\35b417192fb10894c416c616722fe384_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\362aab780af9175676e6df15d323ef24_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\368e578e090a236e2e13d2bdc6f2300c_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\36d4db491ad3dde4842421bd8807eaa1_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\372c39cf328d1817924c06e252a72332_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\377bc155aa256b96b7ace0fcc0687bd9_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\382d9c80c4ab8228d56e8e94964f184c_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\387078ca976d19c489fdc7052f4cc2e6_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\387ffb1d64f06a8183a5ae4a6488c61c_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\38fefd0a13276ee6bac5142ab10c647e_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3954cc049d666e909a0d2cb95b1b46e5_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\39c02a60b91c6f1586cd8bb19613581c_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4015caaf7ead815c16eda805375fdaa7_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\41448116dc3bef663e4d996424e9e3c0_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\414e88b7fcd0a473dc085400dc5e46e6_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\41811b3405250e442676c60a56c6db06_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4215a84ec6fbd44f824ec59aaa38f54c_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\42416d5cdb5ea8765204a781f43ba7ae_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\436eba82994100146648bff356c7fee1_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\444bf50563755cde069094abc64790df_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\451ce12317e7ed02b09b0b45139d3122_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\45718cfe54c95b80bedcee1e77e55f39_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\462e32bdcce0c7d75496587ef563d1d1_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\47cf0958cc3116ced412fe744ab22704_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\48930e9b15130a131f4f60a096894650_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\501bf5a935993384d1c33d7c38a3fd4d_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5034478c56b0207952c0f71f3b3c3926_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5119fb351ddae589a31c6ec442b72896_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\51454fe9eaab000f11781cce793a38b5_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\514a0b6d63eb5ede3690413649aad819_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5153d4ddbd0192d006e2312fd69acc1d_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\51ecd2ab7cf2ccece07066e03d0d694a_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\52a39efecc6c64c85a70ac3087e54174_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\52b2fc6244a2475f42855421d3da601d_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\53502e958842821ed02cd24cf8e6b23f_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5466a29c850653c5840eb900993ca48f_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\54badb8505911572e8defde127e379dd_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\54fc51fdfa1cf25bdd90b4be29b482d0_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5578ded45c85e3b4944440f8aa444142_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\55c5a35bb6ff1a862e3089d94e166241_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\56256c3b32769c37d40ce623611398ae_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5692431109c221993ef9189f3cf229f0_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\57a3a464c046edb1af69b67704d247ba_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\57cdf3aef5a5f22648fc0eb23ab5518b_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\57ea79c9e31cd07176434aa298c13052_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5817246e460c25f4ed2dd2984b197aa4_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\582a5a1b69962e1bc48e948a091480e6_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\590dc82bdc33d38c23e994c8238883ed_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\591abd90d7eeeacfde241a8f35c931e1_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\598602ffac9dd7df72001230dbde56e5_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5c87489eb46cbf87c08e99c044548971_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5cd8e3f78662845253b91f50f5ca2439_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5deb59085d2603b9a673a9df6d296462_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5f14558a527405ad580db0d9477c8827_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5f5344457c51568002c46cd841dc8436_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5f93aa9d9921af502aee2fe39edd3e29_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5fbf6b0764064ac26d4ff0e791beefe3_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\615168dc9c9a2f7d7548313ef184fa29_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6162f6c24bae3f4f07fbee9b40164f51_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\61a82a2d01159d42996bcaf04e3f60ca_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\61faf147cf2c4726f76a652b02e05daa_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\648b074e84fd2eaa062505b467bcc2a4_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\650969efcc99728251fa0cb924dbc708_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\656b94c075d1ad8195c72ad854944b87_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\665bbe0eb8a0df7eb0ef8e7e04bd9721_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6670b91f8c33a4d91ca854c6f8e819d0_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\66a3246c45fa911a28466cb54bed4824_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6827e29132971e5ba5c56a7ad766268a_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\68ab5a91c94fd91eac274883b81d202d_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\69fbcff8aabcea4422f4aa72767c2d97_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6a051c1d5817186d450fd596f4080027_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6cd7947b5a72f479364f62a636c43a2d_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6ce6108522e9c399a18dbf2e592cf44e_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6f5bc092ddb0bb241da522dc2565984e_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped

Sarpi
2008-02-18, 00:30
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6f7004ebceef550a4859ad73ea4bf004_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\70170547ea4fdf564ebf18df7de3f8a3_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7050671260d67bf90ec4ba8ce8845696_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\708469a1faeb7347805fc0d0b5ca589c_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\70e29e2ac0e35195c844840d74e99cad_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7368aa110742669513262ebaf5d15130_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\739afea9f69e04eb8989e1521b07a52a_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\73eb102ac45c38c8807a36da6e191df1_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\742950359fbc488a53dc6768792f63d0_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\75c1f43eeeba77f8bb869cc125f60fa2_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\76acb47fc29b30a228f17427331177af_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\77a954e4f77c46aa5cfeaf539861d937_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\77ef5e50c71a0c4e8b54300f29791f82_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7852b174147a520650a8f1cbc3da9c2a_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\78c7ebcf50d50699fd339dd3c2fcde85_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\78e113879c956f252b67ac8ac1228be9_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7933dd1519fc1be0646c1cfc778e6522_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7a4240c4f9d0e211df5f0a7f47f3e7df_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7beb02f3f2c6318e3a195a185e8c20f0_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7c2981618c8eee95e5f6aa2bd0468c85_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7fe38dfedca4438aa77e426ec7fa7e5d_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\800c54222199ae0dcffffd7ffb1576a0_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\80f2eb2707948783812f9610392572d5_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\81984fd380194c4df1bb9d4fdc305ee5_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\829bdeb7714bc534d485162b8dfafc5b_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\82d9dbca4d4a8e7573a8ea580e5c37e6_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\82e5b32e0f81b3a8f6a9b445db0443a4_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8353e243d8446289084754218565bcc2_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\83f050f55852d5784f1b80af243beba2_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\84120ed303f54e1e958dd4136bf9a24d_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8422c3621ffe9b2683c21e3a4b30de64_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\847114a0c0696adc3276f7831ae54f36_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\84eb70ee3cfd516526cd8917fe901b4d_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\85760248631bb82c141cea47e1374351_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\86163e38280d6776d7159014f4830ddb_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\870a26280486a1852a2e8728394e5738_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\879d2d2000ad60b9f3ab5abb231922ac_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\87dc843c226dddb5172bab1fd4f4ac3f_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\88a8b1dd2e072cb89a6cddebaaf0fef5_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\89a2f8e5a55d578c90fdead9e68b9f28_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\89bd98aa3dff9dd34f7f607ab30de542_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8b0fd9ed63d036e0596365ae6224aafd_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8c85f2fc0983ca368c42d9dcca8ddf49_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8c8a2844baeb9298486dac3bb965acbf_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8d518f61c4a0b71d7cfcc2df64471f3a_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8e24f236e3162e7b2d0bb8303eff4649_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8e8b55129164ca7af56160d1b5bd5db3_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9031498859ef88094b396dbe998c3118_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\910df171de4e1446ae2e77b87e77b932_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\91181c608137dbcca3ddd9721a51d095_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\91b98a5b564939b405558a3bdb683614_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\931303a2a16c07f17ec5c226ef26fcab_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9321aed84330dee4481b236c55ab2a6f_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\941a1646a521bd0d4ff2b17b56a8e6db_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\947f0272f73df3a9ec09d6be56a2b34c_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\94d0e8b896035919fe21fe059fe10600_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9522d80105631c3e78697648d84e34ce_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\96101b145c2738a92941d50220e1f631_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\968888428804c779da892b0c30402b55_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\97554f31e0bd57503305c0651c9ce5a4_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\97b8cb7478eabb326ba97885f0eb4af0_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9803d77a79eb4f04845a00d1818f6277_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\982befbb7a6f1c4acb77f5dd4d9fc6c6_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\984376575c4e6cc910125e24b5aadcf8_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\98ec85c81113bb7c5a44226a914154f9_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\990152979e57bd4db41ea4d9199f216f_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9a701eecdeb89b336d20a2d9fb0a6f8c_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9a714ea2baada825c1fa6ad86c84a184_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9ae992d99cf87cd497c55d3ad687a98d_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9bad63aaa74acbaa80c72031da9f9292_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9c2f04df0575dc1ea325b97035ce1585_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9e34cc81aa229014c726bddf6b54dea1_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a1485c8513804e52f2026465076c93ac_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a1c604412f49e98771d94700e1c8f82d_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a27491f5e0b3413ddab37776f989b695_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a3a2702f2feba36b871ed1df4adf4f30_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a40e466c5b06c6957d56cb9deb7b9f8a_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a5c4869e2e61c72e54bc5e22e34fdf68_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a5ed8cbfba861d6663619271387b5fb5_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a714e011f3a44f05e378476d08540f62_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a72f9f0bba1872978858d0cfd18883c1_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a7341a549b3be4ed9df0d9b089d7e938_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a7a5611ee279c92c4c39425a5b20a1ac_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a914cfd3afd98ef2ea494651c6f8e005_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a965016ff7043a34379ded7860ce224c_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\aa4aeff5c66561db8bc616ccaed8d5b0_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\aae8bac7d2ee357da82af091454582d0_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ab87c8b8097697dd59d380ee46ef514d_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ab8cc9562598567f61e615d4ecbd6ee3_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ac5fb27acde10f87ece9bfceadac935b_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ad347cda43f6886c9beb757a64fd74c5_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\af73721b3d944f3f384341391192f4a8_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
C:\xDocuments and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b0eef678c9f1d03a302b24b72a14d506_4bc421ab-97ef-4d8a-92f1-48ef78fd55ba Object is locked skipped
D:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\jjf9o7n9.default\cert8.db Object is locked skipped
D:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\jjf9o7n9.default\formhistory.dat Object is locked skipped
D:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\jjf9o7n9.default\history.dat Object is locked skipped
D:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\jjf9o7n9.default\key3.db Object is locked skipped
D:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\jjf9o7n9.default\parent.lock Object is locked skipped
D:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\jjf9o7n9.default\search.sqlite Object is locked skipped
D:\Documents and Settings\Adam\Application Data\Mozilla\Firefox\Profiles\jjf9o7n9.default\urlclassifier2.sqlite Object is locked skipped
D:\Documents and Settings\Adam\Cookies\index.dat Object is locked skipped
D:\Documents and Settings\Adam\Local Settings\Application Data\Microsoft\Messenger\sarpi@punkass.com\SharingMetadata\Logs\Dfsr00005.log Object is locked skipped
D:\Documents and Settings\Adam\Local

Sarpi
2008-02-18, 00:30
Settings\Application Data\Microsoft\Messenger\sarpi@punkass.com\SharingMetadata\pending.dat Object is locked skipped
D:\Documents and Settings\Adam\Local Settings\Application Data\Microsoft\Messenger\sarpi@punkass.com\SharingMetadata\Working\database_28E4_9B8_E409_88F0\dfsr.db Object is locked skipped
D:\Documents and Settings\Adam\Local Settings\Application Data\Microsoft\Messenger\sarpi@punkass.com\SharingMetadata\Working\database_28E4_9B8_E409_88F0\fsr.log Object is locked skipped
D:\Documents and Settings\Adam\Local Settings\Application Data\Microsoft\Messenger\sarpi@punkass.com\SharingMetadata\Working\database_28E4_9B8_E409_88F0\fsrtmp.log Object is locked skipped
D:\Documents and Settings\Adam\Local Settings\Application Data\Microsoft\Messenger\sarpi@punkass.com\SharingMetadata\Working\database_28E4_9B8_E409_88F0\tmp.edb Object is locked skipped
D:\Documents and Settings\Adam\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
D:\Documents and Settings\Adam\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
D:\Documents and Settings\Adam\Local Settings\Application Data\Microsoft\Windows Live Contacts\sarpi@punkass.com\real\members.stg Object is locked skipped
D:\Documents and Settings\Adam\Local Settings\Application Data\Mozilla\Firefox\Profiles\jjf9o7n9.default\Cache\_CACHE_001_ Object is locked skipped
D:\Documents and Settings\Adam\Local Settings\Application Data\Mozilla\Firefox\Profiles\jjf9o7n9.default\Cache\_CACHE_002_ Object is locked skipped
D:\Documents and Settings\Adam\Local Settings\Application Data\Mozilla\Firefox\Profiles\jjf9o7n9.default\Cache\_CACHE_003_ Object is locked skipped
D:\Documents and Settings\Adam\Local Settings\Application Data\Mozilla\Firefox\Profiles\jjf9o7n9.default\Cache\_CACHE_MAP_ Object is locked skipped
D:\Documents and Settings\Adam\Local Settings\History\History.IE5\index.dat Object is locked skipped
D:\Documents and Settings\Adam\Local Settings\History\History.IE5\MSHist012008021520080216\index.dat Object is locked skipped
D:\Documents and Settings\Adam\Local Settings\Temp\359D.tmp Object is locked skipped
D:\Documents and Settings\Adam\Local Settings\Temp\AVP36A.tmp Object is locked skipped
D:\Documents and Settings\Adam\Local Settings\Temp\AVP36B.tmp Object is locked skipped
D:\Documents and Settings\Adam\Local Settings\Temp\~DFB0E9.tmp Object is locked skipped
D:\Documents and Settings\Adam\Local Settings\Temp\~DFBAC2.tmp Object is locked skipped
D:\Documents and Settings\Adam\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
D:\Documents and Settings\Adam\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
D:\Documents and Settings\Adam\NTUSER.DAT Object is locked skipped
D:\Documents and Settings\Adam\ntuser.dat.LOG Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
D:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
D:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
D:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
D:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
D:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
D:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
D:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
D:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
D:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
D:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
D:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
D:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\logs\access_log Object is locked skipped
D:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\logs\error.log Object is locked skipped
D:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\logs\error_log Object is locked skipped
D:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\logs\ssl_request_log Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
D:\System Volume Information\_restore{6C8960AE-6C34-4A55-9874-730A9A03C459}\RP115\A0016824.exe Object is locked skipped
D:\System Volume Information\_restore{6C8960AE-6C34-4A55-9874-730A9A03C459}\RP115\A0016825.exe Object is locked skipped
D:\System Volume Information\_restore{6C8960AE-6C34-4A55-9874-730A9A03C459}\RP115\change.log Object is locked skipped
D:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
D:\WINDOWS\SchedLgU.Txt Object is locked skipped
D:\WINDOWS\SoftwareDistribution\EventCache\{64B846F7-9FD8-44D1-89FB-7CA016980295}.bin Object is locked skipped
D:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
D:\WINDOWS\Sti_Trace.log Object is locked skipped
D:\WINDOWS\system32\andt.sys Infected: Trojan-Downloader.Win32.Delf.elk skipped
D:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
D:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
D:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
D:\WINDOWS\system32\config\default Object is locked skipped
D:\WINDOWS\system32\config\DEFAULT.LOG Object is locked skipped
D:\WINDOWS\system32\config\Internet.evt Object is locked skipped
D:\WINDOWS\system32\config\SAM Object is locked skipped
D:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
D:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
D:\WINDOWS\system32\config\SECURITY Object is locked skipped
D:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
D:\WINDOWS\system32\config\software Object is locked skipped
D:\WINDOWS\system32\config\SOFTWARE.LOG Object is locked skipped
D:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
D:\WINDOWS\system32\config\system Object is locked skipped
D:\WINDOWS\system32\config\SYSTEM.LOG Object is locked skipped
D:\WINDOWS\system32\drivers\core.cache.dsk Object is locked skipped
D:\WINDOWS\system32\drivers\pciidexx.sys Object is locked skipped
D:\WINDOWS\system32\h323log.txt Object is locked skipped
D:\WINDOWS\system32\Indt2.sys Infected: Trojan-Clicker.Win32.VB.adf skipped
D:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
D:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
D:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
D:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
D:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped

Sarpi
2008-02-18, 00:32
D:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
D:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
D:\WINDOWS\wiadebug.log Object is locked skipped
D:\WINDOWS\wiaservc.log Object is locked skipped
D:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.


When I do an AVG scan it only finds one trojan which it says it heals but of course it's not healed at all.

Here is my HJT log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:22:26 AM, on 18/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
D:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
D:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
D:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
D:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
D:\WINDOWS\system32\nvsvc32.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\Logitech\iTouch\iTouch.exe
D:\Program Files\Logitech\MouseWare\system\em_exec.exe
D:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
D:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
D:\WINDOWS\RTHDCPL.EXE
D:\WINDOWS\system32\RUNDLL32.EXE
D:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
D:\Program Files\iTunes\iTunesHelper.exe
D:\PROGRA~1\Grisoft\AVG7\avgcc.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\MSN Messenger\MsnMsgr.Exe
D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
D:\Program Files\Caplio Software\RGateLXP.exe
D:\Program Files\RMClient\PMCTray.exe
D:\Program Files\iPod\bin\iPodService.exe
D:\Program Files\MSN Messenger\usnsvc.exe
D:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
D:\PROGRA~1\MOZILL~1\FIREFOX.EXE
D:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.estc.net.au:8080
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [zBrowser Launcher] D:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [JobHisInit] D:\Program Files\RMClient\JobHisInit.exe
O4 - HKLM\..\Run: [MplSetUp] D:\Program Files\RMClient\MplSetUp.exe
O4 - HKLM\..\Run: [NeroFilterCheck] D:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] D:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG7_CC] D:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\RunOnce: [SpybotDeletingA3501] command /c del "D:\WINDOWS\system32\drivers\core.cache.dsk"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5816] cmd /c del "D:\WINDOWS\system32\drivers\core.cache.dsk"
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "D:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [NBJ] "D:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingB7723] command /c del "D:\WINDOWS\system32\drivers\core.cache.dsk"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2058] cmd /c del "D:\WINDOWS\system32\drivers\core.cache.dsk"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] D:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: RICOH Gate La.lnk = ?
O4 - Global Startup: SmartNetMonitor for Client.lnk = D:\Program Files\RMClient\PMClient.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.msi.com.tw
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} (WebSDev Control) - http://liveupdate.msi.com.tw/autobios/LOnline/install.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - D:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - D:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\system32\nvsvc32.exe
O23 - Service: perfmons Service (perfmons) - Unknown owner - D:\WINDOWS\system32\perfs.exe (file missing)
O23 - Service: Routing Service (Routing) - Unknown owner - D:\WINDOWS\system32\routing.exe (file missing)

--
End of file - 9015 bytes


Thank you very much for your time. I appreciate it.


"BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288)

Sarpi
2008-02-18, 07:03
I appear to have fixed the problem with what I read here - http://forums.spybot.info/showthread.php?t=23882

Sarpi
2008-02-20, 01:07
Yup, definitely fixed it with the combofix thing.

tashi
2008-02-28, 18:36
Hello.

"BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288)



Until a helper responds, the HJT log has not been analyzed. Please wait to be advised and don't run fixes until asked. This is especially important if your Operating System is Windows Vista!

Please note that all instructions given are customized for that member's computer only, the tools used may cause damage if run on a computer with different infections. Your symptoms may only appear to be similar.
There is always risk involved in installing and removing any software. Even a fix that time has shown to be useful to thousands of users, can present problems to a few or be found to have a bug in development.Because of the volume of posts to your own topic, it may have appeared you were already being assisted.

For people waiting who have not resolved their problem, we have a sticky topic:
The Waiting Room: Post here if waiting for help longer than four days (http://forums.spybot.info/forumdisplay.php?f=37)
However if members waiting for assistance do not post to flag a helper, their topic will be be archived as said in the sticky. ;)

If you still require help, please start a new topic and include a fresh HijackThis log and a link to this thread in your new topic.

Best regards.