PaulDSC
2009-07-31, 20:22
Hi
I am new to the forum. I'd like some help dealing with the WINTDSSRTK and WINTDSSREG1 trojans. Spybot S&D identifies these but they keep reappearing and the computer has developed many "nasty" symptoms described below. I have run some elementary diagnostics but need some guidance please.
The story so far:
Machine is a Dell Inspiron 8200 laptop running W2K v5 SP4 and IE6 SP1. Rising anti-virus is doing a full scan from startup each time I boot up.
First symptoms:
System slow to boot
Lost webpage dropdown functionality
No version number displayed in IE6 Help/About
Webpage hyperlink buttons stopped working.
Actions:
Applied IEFIX v1.6
Downloaded IE6 SP1 from MS and reapplied
Rebooted after each of these to no effect.
Noticed these additional symptoms:
Can't get into Add/Remove progs
Can't inspect W2K event log entries by double clicking
Can't get into most of the Computer Management > system info screens (error msg: "The connection to could not be established...")
In Services>Applications>Internet Services Manager error: " Unable to connect to target machine...")
Unable to launch some apps from desktop
MS Word and Excel won't open properly (no OLE etc)
Can't print or see connected printers
Tried downloading MBAM but it was "prevented" from executing.
Downloaded Spybot S&D. It identified 3 malware items including WINTDSSRTK and WINTDSSREG1 and appeared to clean them.
Tried to reboot machine but couldn't. Msg: "STOP C000026C unable to load device driver. \SystemRoot\ device driver could not be loaded. Error status 0xc0000020"
Tried rebooting in Safe mode but got same message.
I don't have ERD so attempted boot from a W2K CD using repair option. Failed with same error message.
Ran Dell diagnostics CD on machine - all passed
Eventually booted using last known good config.
Ran Spybot again. Malware items WINTDSSRTK and WINRDSSREG1 entries previously cleaned were there again.
Downloaded Security Check from screen 317 (results below)
Downloaded DDS by sUBS (log file results below)
Downloaded RootRepeal. Failed to run after several tries (various messages, mostly " could not read boot sector..." and occasionally "could not allocate memory for our driver info" and "device I/O control error! Error code = 0x8). Tried adjusting the disk access level in the options dialog but it failed with same messages each time. Tried again in safe mode with same result.
As an alternative downloaded Sophos Anti-rootkit version 1.5, installed it and ran scan. (disconnected from Internet and disabled Spybot first but couldn't get into Rising antivirus to stop it).
Anti-rootkit identified 4 hidden registry keys:
\HKEY_LOCAL_MACHINE\SOFTWARE\UAC
\HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\UACd.sys
\HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\UACd.sys
\HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\UACd.sys
and numerous hidden files. While most of these were Temp Internet Files there were a few .dll's in Temp that looked related to the registry keys above:
C:\Documents and Settings\<user>\LocalSettings\Temp\nss18.tmp\UAC.dll
C:\Documents and Settings\<user>\LocalSettings\Temp\nsq1A.tmp\UAC.dll
C:\Documents and Settings\<user>\LocalSettings\Temp\nsr1E.tmp\UAC.dll
C:\Documents and Settings\<user>\LocalSettings\Temp\nsh21.tmp\UAC.dll
C:\Documents and Settings\<user>\LocalSettings\Temp\UAC5475.tmp
C:\WINNT\System32\drivers\UACKlrlovmycd.sys
C:\WINNT\System32\UACjkmpixnrwb.dll
The 4 hidden registry keys are stated as unremovable in Anti-rootkit
The 7 hidden files listed above were stated as removable but not recommended for cleanup.
I tagged them for clean up anyway and proceeded despite the warning, then restarted the system and opened the sarscan.log shown below,
I suspect there's more I need to do, so I would really appreciate some advice as to where to go from here (intiutively I might have tried Combofix but I'm nervous about doing this without guidance from one of your experts!). Please treat me as a relevant newbie - the steps I've taken above are "best efforts" based on my own web research (and excellent forums like yours) but I'm already several light years outside my comfort zone.
Kind regards
Paul
TEXT FILES:
Results of screen317's Security Check version 0.98.7
Windows 2000 Service Pack 4
``````````````````````````````
Antivirus/Firewall Check:
Rising Antivirus
``````````````````````````````
Anti-malware/Other Utilities Check:
Spybot - Search & Destroy
Malwarebytes' Anti-Malware
Adobe Reader 9
``````````````````````````````
Process Check:
objlist.exe by Laurent
``````````````````````````````
DNS Vulnerability Check:
nslookup.exe missing!
Request Timed Out (Wireless Internet connection/Disconnected Internet/Proxy?)
`````````End of Log```````````
DDS TEXT FILE
DDS (Ver_09-07-30.01) - NTFSx86
Run by paul at 12:23:38.29 on Fri 31/07/2009
Internet Explorer: 6.0.2800.1106
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: EpsonToolBandKicker Class: {e99421fb-68dd-40f0-b4ac-b7027cae2f1a} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
TB: EPSON Web-To-Page: {ee5d279f-081b-4404-994d-c6b60aaeba6d} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
EB: Media Band: {32683183-48a0-441b-a342-7c2a440a9478} - %SystemRoot%\system32\browseui.dll
uRun: [internat.exe] internat.exe
uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\wcescomm.exe"
mRun: [Synchronization Manager] mobsync.exe /logon
mRun: [NvCplDaemon] RUNDLL32.EXE c:\winnt\system32\NvCpl.dll,NvStartup
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [DiTask.exe] "c:\program files\eicon\diva\DiTask.exe"
mRun: [Divamon.exe] "c:\program files\eicon\diva\Divamon.exe"
mRun: [Eicon TechnologyLAN_DAEMON] "c:\program files\eicon\diva\watch.exe"
mRun: [CGServer] "c:\program files\eicon\diva\cgserver.exe"
mRun: [nwiz] nwiz.exe /installquiet
mRun: [EPSON Stylus Photo R340 Series] c:\winnt\system32\spool\drivers\w32x86\3\E_FATIAJE.EXE /P30 "EPSON Stylus Photo R340 Series" /O6 "USB001" /M "Stylus Photo R340"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [RavTask] "c:\program files\rising\rav\RavTask.exe" -system
dRun: [internat.exe] internat.exe
dRunOnce: [^SetupICWDesktop] c:\program files\internet explorer\connection wizard\icwconn1.exe /desktop
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: {c95fe080-8f5d-11d2-a20b-00aa003c157a} - %SystemRoot%\web\related.htm
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\micros~3\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\micros~3\INetRepl.dll
DPF: DirectAnimation Java Classes - file://c:\winnt\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\winnt\java\classes\xmldso.cab
DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} - hxxp://support.dell.com/systemprofiler/SysPro.CAB
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} - hxxp://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - hxxp://software-dl.real.com/01dad4cd3d29af0c6206/netzip/RdxIE601.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - hxxp://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37879.4199768519
DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - hxxp://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Notify: ActiveSync - WcesWlgn.dll
Notify: nwprovau - nwprovau.dll
SEH: ShlExecHack Class: {32cd708b-60a7-4c00-9377-d73eaa495f0f} - c:\winnt\system32\RavExt.dll
============= SERVICES / DRIVERS ===============
=============== Created Last 30 ================
2009-07-31 10:13 16,384 a------t c:\winnt\system32\Perflib_Perfdata_38c.dat
2009-07-31 10:07 16,384 a------t c:\winnt\system32\Perflib_Perfdata_390.dat
2009-07-30 20:33 289 a------- c:\winnt\wininit.ini
2009-07-30 19:34 <DIR> a-d----- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2009-07-30 19:34 <DIR> --d----- c:\program files\Spybot - Search & Destroy
2009-07-30 19:27 16,409,960 a------- C:\spybotsd162.exe
2009-07-30 19:24 28,944 ac------ c:\winnt\system32\dllcache\ibmexmp.sys
2009-07-30 19:19 <DIR> --d----- c:\program files\TeamViewer
2009-07-30 19:06 38,160 a------- c:\winnt\system32\drivers\mbamswissarmy.sys
2009-07-30 19:06 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-07-30 19:06 18,456 a------- c:\winnt\system32\drivers\mbam.sys
2009-07-30 19:06 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-07-30 19:04 3,775,176 a------- C:\mbam-setup.exe
2009-07-30 19:02 <DIR> --d----- c:\docume~1\paul\applic~1\TeamViewer
2009-07-30 19:01 <DIR> --d----- c:\documents and settings\paul\temp
2009-07-30 14:46 37,144 a------- c:\winnt\system32\net.net
==================== Find3M ====================
2008-10-08 11:35 12,888 a------- c:\docume~1\paul\applic~1\GDIPFONTCACHEV1.DAT
2003-03-17 16:59 21,952 ----h--- c:\program files\folder.htt
2003-03-17 16:59 271 ----h--- c:\program files\desktop.ini
1999-12-06 14:00 32,528 a------- c:\winnt\inf\wbfirdma.sys
============= FINISH: 12:23:53.39 ===============
DDS attach.TXT
==== Installed Programs ======================
Acrobat.com
Actiontec MD56ORD V92 MDC Modem
Adobe Acrobat 5.0
Adobe AIR
Adobe Flash Player ActiveX
Adobe MPEG Encoder
Adobe Premiere 6.5
Adobe Reader 9
Advanced Excel Repair v1.4
Advertisement Service
AT&T Global Network Client
Borland Delphi 6
Cimaware OfficeFIX 6
Diva Assistant
Diva Tools
EPSON Attach To Email
EPSON Easy Photo Print
EPSON File Manager
EPSON Print CD
EPSON PRINT Image Framer Tool
EPSON Printer Software
EPSON Scan Assistant
EPSON Web-To-Page
ESPR340 User's Guide
getPlus(R) for Adobe
Internet Explorer Q822925
Kernel for Excel ver 7.05.01
Malwarebytes' Anti-Malware
Microsoft ActiveSync
Microsoft Internet Explorer 6 SP1
Microsoft Office XP Professional with FrontPage
Microsoft SQL Server 2000
Microsoft SQL Server 2000 Windows CE Edition
Microsoft SQL Server CE Server Tools
Microsoft Visio Professional 2002 [English]
NVIDIA Windows 2000/XP Display Drivers
ORiNOCO AP Manager
Panda ActiveScan 2.0
PIF DESIGNER
QuickTime
Rising Antivirus
Sony Ericsson PC Suite
Spybot - Search & Destroy
TeamViewer 4
Terminal Services Client
The Operations Database
WAP11 Utility
WebFldrs
Windows 2000 Hotfix - KB823559
Windows 2000 Hotfix - KB824105
Windows 2000 Hotfix - KB824146
Windows Installer 3.1 (KB893803)
Windows Media Player system update (9 Series)
WinZip
==== End Of File ===========================
SOPHOS ANTI-ROOTKIT SCAN LOG
Sophos Anti-Rootkit Version 1.5.0 (c) 2009 Sophos Plc
Started logging on 31/07/2009 at 13:28:17
User "paul" on computer "ARIEL"
Windows version 5.0 SP 4.0 Service Pack 4 build 2195 SM=0x0 PT=0x1 Win32
Info: Starting process scan.
Info: Starting registry scan.
Hidden: registry item \HKEY_LOCAL_MACHINE\SOFTWARE\UAC
Hidden: registry item \HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\UACd.sys
Hidden: registry item \HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\UACd.sys
Hidden: registry item \HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\UACd.sys
Info: Starting disk scan of C: (NTFS).
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\4TCFOFWR\search[1].sys
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\G5QJ45QB\search[1].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\4TCFOFWR\mode_hybrid[1].gif
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\YLOBITI5\SecurityCheck[2].exe
Hidden: file C:\Transfer\Projects\CHS_I\StockBrowser\UActors.pas
Hidden: file C:\Transfer\Projects\CHS_I\Invoicing\UActors.bkm
Hidden: file C:\Transfer\Projects\CHS_I\Invoicing\UActors.pas
Hidden: file C:\Transfer\Projects\CHS_I\Invoicing\UActors.~pas
Hidden: file C:\Documents and Settings\paul\Local Settings\Temp\nss18.tmp\UAC.dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temp\nsq1A.tmp\UAC.dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temp\nsr1E.tmp\UAC.dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\WCK2HJ41\ie6setup[1].exe
Hidden: file C:\Documents and Settings\paul\Local Settings\Temp\nsh21.tmp\UAC.dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\3H87B04O\sar_15_sfx[2].exe
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\X7VJXXSE\eBayISAPI[5].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\TF3JH5CE\eBayISAPI[3].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\TF3JH5CE\eBayISAPI[4].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\TF3JH5CE\emailVal[2].js
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\G71RM2Z5\eBayISAPI[4].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\G71RM2Z5\eBayISAPI[5].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\G71RM2Z5\SYS_vjo_e595i7697294_1_en_GB[23].js
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\G71RM2Z5\Fastfold-projector-screen-10x7-5-Screenworks-F-R_W0QQitemZ330299044646QQcmdZViewItemQQptZUK_BOI_Office_Equipment_Supplies_Presentation_Projection_Accessories_[1].htm
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\G71RM2Z5\Fastfold-projector-screen-10x7-5-Screenworks-F-R_W0QQitemZ330299044646QQcmdZViewItemQQptZUK_BOI_Office_Equipment_Supplies_Presentation_Projection_Accessories_[2].htm
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\WTGJOXM5\eBayISAPI[2].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\WTGJOXM5\SYS_vjo_e595i7697294_1_en_GB[15].js
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\UNOWHDFY\eBayISAPI[2].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\UNOWHDFY\eBayISAPI[3].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\UNOWHDFY\CAEFTV96.js
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\4TCFOFWR\eBayISAPI[2].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\4TCFOFWR\eBayISAPI[3].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\4TCFOFWR\CAU1KN81.css
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\6FOZQ9AN\eBayISAPI[2].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\6FOZQ9AN\SYS_vjo_e599i7773850_1_en_GB[46].js
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\6FOZQ9AN\eBayISAPI[3].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\6FOZQ9AN\SYS_vjo_e599i7773850_1_en_GB[76].js
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\G5QJ45QB\eBayISAPI[2].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\G5QJ45QB\eBayISAPI[3].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\G5QJ45QB\SYS_vjo_e599i7773850_1_en_GB[43].js
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\X7VJXXSE\eBayISAPI[6].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\X7VJXXSE\SYS_vjo_e599i7773850_1_en_GB[45].js
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\3H87B04O\eBayISAPI[2].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\3H87B04O\eBayISAPI[4].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\3H87B04O\SYS_vjo_e599i7773850_1_en_GB[39].js
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\836DWVG1\eBayISAPI[2].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\836DWVG1\SYS_vjo_e599i7773850_1_en_GB[68].js
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\SRIBATTB\eBayISAPI[2].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\SRIBATTB\SYS_vjo_e599i7773850_1_en_GB[51].js
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\CJ63MQCO\eBayISAPI[2].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\CJ63MQCO\SYS_vjo_e599i7773850_1_en_GB[12].js
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\SRIBATTB\RavINT_AU[1].exe
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\SRIBATTB\google.co[13]
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\X7VJXXSE\eBayISAPI[7].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\8D07CNI9\eBayISAPI[2].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\SRIBATTB\eBayISAPI[3].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\UNOWHDFY\eBayISAPI[4].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\UNOWHDFY\GlobalNavVjoOpt23_Ebay_e601i7856465_en_GB[15].css
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\UNOWHDFY\eBayISAPI[5].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\UNOWHDFY\GlobalNavVjoOpt23_Ebay_e601i7856465_en_GB[28].css
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\6VEFG1YF\eBayISAPI[2].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\X7VJXXSE\eBayISAPI[8].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\X7VJXXSE\GlobalNavVjoOpt23_Ebay_e601i7856465_en_GB[42].css
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\G5QJ45QB\eBayISAPI[4].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\G5QJ45QB\eBayISAPI[5].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\G5QJ45QB\GlobalNavVjoOpt23_Ebay_e601i7856465_en_GB[48].css
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\3H87B04O\eBayISAPI[3].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\3H87B04O\eBayISAPI[5].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\3H87B04O\GlobalNavVjoOpt23_Ebay_e601i7856465_en_GB[47].css
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\CJ63MQCO\eBayISAPI[3].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\CJ63MQCO\eBayISAPI[4].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\6FOZQ9AN\eBayISAPI[8].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\6FOZQ9AN\GlobalNavVjoOpt23_Ebay_e601i7856465_en_GB[50].css
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\WTGJOXM5\eBayISAPI[3].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\WTGJOXM5\GlobalNavVjoOpt23_EbayR2_e601i7856465_en_GB[8].css
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\WTGJOXM5\eBayISAPI[4].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\WTGJOXM5\GlobalNavVjoOpt23_EbayR2_e601i7856465_en_GB[16].css
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\YLOBITI5\eBayISAPI[2].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\G5QJ45QB\eBayISAPI[6].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\G5QJ45QB\eBayISAPI[7].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\G5QJ45QB\GlobalNavVjoOpt23_Ebay_e603i7942770_en_GB[50].css
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\A4NCCH29\eBayISAPI[3].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\A4NCCH29\GlobalNavVjoOpt23_Ebay_e603i7942770_en_GB[9].css
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\A4NCCH29\eBayISAPI[4].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\A4NCCH29\CAE7WHA2.css
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\4TCFOFWR\eBayISAPI[4].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\8TKTE709\eBayISAPI[3].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\8TKTE709\SYS_vjo_e601i7856464_1_en_GB[38].js
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\ZQON7HWD\eBayISAPI[2].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\6FOZQ9AN\eBayISAPI[9].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\6FOZQ9AN\GlobalNavVjoOpt23_Ebay_e603i7942770_en_GB[25].css
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\WTGJOXM5\eBayISAPI[10].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\CJ63MQCO\%7Bmod_zoom,mod_trends,mod_transitlyr,mod_traffic_app,mod_scrollwheel,mod_lyrsctrl,mod_lyrs,mod_keyboard,mod_jslinker,mod_extended_dom,mod_drag,mod_controls,mo[2].js
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\WTGJOXM5\eBayISAPI[11].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\WTGJOXM5\CAYPB6FF
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\GPYJOXUB\eBayISAPI[3].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\OOSRBOWZ\procexp[1].exe
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\836DWVG1\eBayISAPI[3].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\836DWVG1\GlobalNav14_Ebay_e605i8038212_en_GB[27].css
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\836DWVG1\_WINNT_system32_dxtrans[1].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\836DWVG1\Scopus728x90_flash[1].swf
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\8TKTE709\eBayISAPI[4].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\G5QJ45QB\eBayISAPI[8].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\BU8RBDWD\eBayISAPI[17].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\X7VJXXSE\eBayISAPI[10].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\X7VJXXSE\GlobalNav14_EbayR2_e605i8085187_en_GB[24].css
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\X7VJXXSE\eBayISAPI[11].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\X7VJXXSE\GlobalNav14_EbayR2_e605i8085187_en_GB[30].css
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\TF3JH5CE\eBayISAPI[6].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\TF3JH5CE\eBayISAPI[7].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\OOSRBOWZ\eBayISAPI[3].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\A4NCCH29\eBayISAPI[6].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\A4NCCH29\GlobalNav14_EbayR2_e605i8085187_en_GB[4].css
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\JXH8395C\eBayISAPI[5].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\8D07CNI9\eBayISAPI[3].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\YJUJO9IZ\eBayISAPI[3].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\YJUJO9IZ\eBayISAPI[4].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\YJUJO9IZ\CATTEZDE
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\BU8RBDWD\eBayISAPI[18].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\WCK2HJ41\eBayISAPI[2].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\MXLMZ65W\eBayISAPI[3].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\8TKTE709\DA-LITE-FAST-FOLD-REAR-PROJECTION-SCREEN-COMPLETE-BOXED_W0QQitemZ190295243279QQcmdZViewItemQQptZUK_BOI_Office_Equipment_Supplies_Presentation_Projection_Acces[1].htm
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\8TKTE709\eBayISAPI[5].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\8TKTE709\GlobalNav14_EbayR2_e607i8123656_en_GB[36].css
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\SRIBATTB\eBayISAPI[4].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\SRIBATTB\main_e6071uk[3].css
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\MXLMZ65W\eBayISAPI[4].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\MXLMZ65W\GlobalNav14_EbayR2_e607i8123656_en_GB[48].css
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\SRIBATTB\eBayISAPI[5].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\SRIBATTB\globals_e6091uk[3].js
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\X7VJXXSE\eBayISAPI[12].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\6VEFG1YF\Unicol-AV-Mounting-Brackets-Selection-of-17-parts_W0QQitemZ280326282262QQcmdZViewItemQQptZUK_BOI_Office_Equipment_Supplies_Presentation_Projection_Accessories[1].htm
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\6VEFG1YF\Unicol-AV-Mounting-Brackets-Selection-of-17-parts_W0QQitemZ280326282262QQcmdZViewItemQQptZUK_BOI_Office_Equipment_Supplies_Presentation_Projection_Accessories[2].htm
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\4TCFOFWR\eBayISAPI[5].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\I5DAJM10\eBayISAPI[18].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\6VEFG1YF\eBayISAPI[3].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\6FOZQ9AN\eBayISAPI[11].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\6FOZQ9AN\GlobalNav14_EbayR2_e607i8123656_en_GB[17].css
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\YJUJO9IZ\eBayISAPI[7].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\GPYJOXUB\eBayISAPI[4].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\STE7K52Z\eBayISAPI[2].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\8TKTE709\eBayISAPI[6].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\836DWVG1\Nucleus-Kernel-Excel[1].exe
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\836DWVG1\excelfixinstaller[2].exe
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\836DWVG1\expansion_embed[42].js
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\UNOWHDFY\eBayISAPI[8].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\I5DAJM10\eBayISAPI[2].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\WCK2HJ41\Fastfold-Fast-fold-Screen-Drape-Kit-Case-BARGAIN_W0QQitemZ170332710990QQcmdZViewItemQQptZUK_BOI_Office_Equipment_Supplies_Presentation_Projection_Accessories_[1].htm
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\STE7K52Z\Excalibur5-5-0[1].exe
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\I5DAJM10\eBayISAPI[3].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\OOSRBOWZ\eBayISAPI[4].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\TF3JH5CE\eBayISAPI[8].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\TF3JH5CE\eBayISAPI[9].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\CBEFCVKZ\eBayISAPI[8].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\CBEFCVKZ\eBayISAPI[7].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\CBEFCVKZ\eBayISAPI[12]
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\KLEJSXMF\eBayISAPI[2].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\YLOBITI5\eBayISAPI[3].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\MXLMZ65W\eBayISAPI[2].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\8TKTE709\eBayISAPI[7].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\KLEJSXMF\eBayISAPI[3].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\BU8RBDWD\eBayISAPI[4].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\X7VJXXSE\eBayISAPI[4].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\X7VJXXSE\SYS_YODA2_vjo_e625i9680358_1_en_GB[9].js
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\CNDN2QFD\eBayISAPI[3].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\CNDN2QFD\eBayISAPI[4].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\MXLMZ65W\Setup-e92_02009-1938[1].exe
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\MXLMZ65W\gorcheoronte[1].html
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\MXLMZ65W\Setup-6a1_02009-1938[1].exe
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\836DWVG1\eBayISAPI[21].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\836DWVG1\GH_YODA1_Ebay_e623i9600654_en_GB[27].css
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\KLEJSXMF\eBayISAPI[4].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\KLEJSXMF\SYS_YODA2_vjo_e625i9680358_1_en_GB[24].js
Hidden: file C:\Documents and Settings\paul\Local Settings\Temp\UAC5475.tmp
Hidden: file C:\WINNT\system32\drivers\UACklrlovmycd.sys
Hidden: file C:\WINNT\system32\UACjkmpixnrwb.dll
Stopped logging on 31/07/2009 at 17:25:30
I am new to the forum. I'd like some help dealing with the WINTDSSRTK and WINTDSSREG1 trojans. Spybot S&D identifies these but they keep reappearing and the computer has developed many "nasty" symptoms described below. I have run some elementary diagnostics but need some guidance please.
The story so far:
Machine is a Dell Inspiron 8200 laptop running W2K v5 SP4 and IE6 SP1. Rising anti-virus is doing a full scan from startup each time I boot up.
First symptoms:
System slow to boot
Lost webpage dropdown functionality
No version number displayed in IE6 Help/About
Webpage hyperlink buttons stopped working.
Actions:
Applied IEFIX v1.6
Downloaded IE6 SP1 from MS and reapplied
Rebooted after each of these to no effect.
Noticed these additional symptoms:
Can't get into Add/Remove progs
Can't inspect W2K event log entries by double clicking
Can't get into most of the Computer Management > system info screens (error msg: "The connection to could not be established...")
In Services>Applications>Internet Services Manager error: " Unable to connect to target machine...")
Unable to launch some apps from desktop
MS Word and Excel won't open properly (no OLE etc)
Can't print or see connected printers
Tried downloading MBAM but it was "prevented" from executing.
Downloaded Spybot S&D. It identified 3 malware items including WINTDSSRTK and WINTDSSREG1 and appeared to clean them.
Tried to reboot machine but couldn't. Msg: "STOP C000026C unable to load device driver. \SystemRoot\ device driver could not be loaded. Error status 0xc0000020"
Tried rebooting in Safe mode but got same message.
I don't have ERD so attempted boot from a W2K CD using repair option. Failed with same error message.
Ran Dell diagnostics CD on machine - all passed
Eventually booted using last known good config.
Ran Spybot again. Malware items WINTDSSRTK and WINRDSSREG1 entries previously cleaned were there again.
Downloaded Security Check from screen 317 (results below)
Downloaded DDS by sUBS (log file results below)
Downloaded RootRepeal. Failed to run after several tries (various messages, mostly " could not read boot sector..." and occasionally "could not allocate memory for our driver info" and "device I/O control error! Error code = 0x8). Tried adjusting the disk access level in the options dialog but it failed with same messages each time. Tried again in safe mode with same result.
As an alternative downloaded Sophos Anti-rootkit version 1.5, installed it and ran scan. (disconnected from Internet and disabled Spybot first but couldn't get into Rising antivirus to stop it).
Anti-rootkit identified 4 hidden registry keys:
\HKEY_LOCAL_MACHINE\SOFTWARE\UAC
\HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\UACd.sys
\HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\UACd.sys
\HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\UACd.sys
and numerous hidden files. While most of these were Temp Internet Files there were a few .dll's in Temp that looked related to the registry keys above:
C:\Documents and Settings\<user>\LocalSettings\Temp\nss18.tmp\UAC.dll
C:\Documents and Settings\<user>\LocalSettings\Temp\nsq1A.tmp\UAC.dll
C:\Documents and Settings\<user>\LocalSettings\Temp\nsr1E.tmp\UAC.dll
C:\Documents and Settings\<user>\LocalSettings\Temp\nsh21.tmp\UAC.dll
C:\Documents and Settings\<user>\LocalSettings\Temp\UAC5475.tmp
C:\WINNT\System32\drivers\UACKlrlovmycd.sys
C:\WINNT\System32\UACjkmpixnrwb.dll
The 4 hidden registry keys are stated as unremovable in Anti-rootkit
The 7 hidden files listed above were stated as removable but not recommended for cleanup.
I tagged them for clean up anyway and proceeded despite the warning, then restarted the system and opened the sarscan.log shown below,
I suspect there's more I need to do, so I would really appreciate some advice as to where to go from here (intiutively I might have tried Combofix but I'm nervous about doing this without guidance from one of your experts!). Please treat me as a relevant newbie - the steps I've taken above are "best efforts" based on my own web research (and excellent forums like yours) but I'm already several light years outside my comfort zone.
Kind regards
Paul
TEXT FILES:
Results of screen317's Security Check version 0.98.7
Windows 2000 Service Pack 4
``````````````````````````````
Antivirus/Firewall Check:
Rising Antivirus
``````````````````````````````
Anti-malware/Other Utilities Check:
Spybot - Search & Destroy
Malwarebytes' Anti-Malware
Adobe Reader 9
``````````````````````````````
Process Check:
objlist.exe by Laurent
``````````````````````````````
DNS Vulnerability Check:
nslookup.exe missing!
Request Timed Out (Wireless Internet connection/Disconnected Internet/Proxy?)
`````````End of Log```````````
DDS TEXT FILE
DDS (Ver_09-07-30.01) - NTFSx86
Run by paul at 12:23:38.29 on Fri 31/07/2009
Internet Explorer: 6.0.2800.1106
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: EpsonToolBandKicker Class: {e99421fb-68dd-40f0-b4ac-b7027cae2f1a} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
TB: EPSON Web-To-Page: {ee5d279f-081b-4404-994d-c6b60aaeba6d} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
EB: Media Band: {32683183-48a0-441b-a342-7c2a440a9478} - %SystemRoot%\system32\browseui.dll
uRun: [internat.exe] internat.exe
uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\wcescomm.exe"
mRun: [Synchronization Manager] mobsync.exe /logon
mRun: [NvCplDaemon] RUNDLL32.EXE c:\winnt\system32\NvCpl.dll,NvStartup
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [DiTask.exe] "c:\program files\eicon\diva\DiTask.exe"
mRun: [Divamon.exe] "c:\program files\eicon\diva\Divamon.exe"
mRun: [Eicon TechnologyLAN_DAEMON] "c:\program files\eicon\diva\watch.exe"
mRun: [CGServer] "c:\program files\eicon\diva\cgserver.exe"
mRun: [nwiz] nwiz.exe /installquiet
mRun: [EPSON Stylus Photo R340 Series] c:\winnt\system32\spool\drivers\w32x86\3\E_FATIAJE.EXE /P30 "EPSON Stylus Photo R340 Series" /O6 "USB001" /M "Stylus Photo R340"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [RavTask] "c:\program files\rising\rav\RavTask.exe" -system
dRun: [internat.exe] internat.exe
dRunOnce: [^SetupICWDesktop] c:\program files\internet explorer\connection wizard\icwconn1.exe /desktop
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: {c95fe080-8f5d-11d2-a20b-00aa003c157a} - %SystemRoot%\web\related.htm
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\micros~3\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\micros~3\INetRepl.dll
DPF: DirectAnimation Java Classes - file://c:\winnt\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\winnt\java\classes\xmldso.cab
DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} - hxxp://support.dell.com/systemprofiler/SysPro.CAB
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} - hxxp://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - hxxp://software-dl.real.com/01dad4cd3d29af0c6206/netzip/RdxIE601.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - hxxp://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37879.4199768519
DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - hxxp://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Notify: ActiveSync - WcesWlgn.dll
Notify: nwprovau - nwprovau.dll
SEH: ShlExecHack Class: {32cd708b-60a7-4c00-9377-d73eaa495f0f} - c:\winnt\system32\RavExt.dll
============= SERVICES / DRIVERS ===============
=============== Created Last 30 ================
2009-07-31 10:13 16,384 a------t c:\winnt\system32\Perflib_Perfdata_38c.dat
2009-07-31 10:07 16,384 a------t c:\winnt\system32\Perflib_Perfdata_390.dat
2009-07-30 20:33 289 a------- c:\winnt\wininit.ini
2009-07-30 19:34 <DIR> a-d----- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2009-07-30 19:34 <DIR> --d----- c:\program files\Spybot - Search & Destroy
2009-07-30 19:27 16,409,960 a------- C:\spybotsd162.exe
2009-07-30 19:24 28,944 ac------ c:\winnt\system32\dllcache\ibmexmp.sys
2009-07-30 19:19 <DIR> --d----- c:\program files\TeamViewer
2009-07-30 19:06 38,160 a------- c:\winnt\system32\drivers\mbamswissarmy.sys
2009-07-30 19:06 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-07-30 19:06 18,456 a------- c:\winnt\system32\drivers\mbam.sys
2009-07-30 19:06 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-07-30 19:04 3,775,176 a------- C:\mbam-setup.exe
2009-07-30 19:02 <DIR> --d----- c:\docume~1\paul\applic~1\TeamViewer
2009-07-30 19:01 <DIR> --d----- c:\documents and settings\paul\temp
2009-07-30 14:46 37,144 a------- c:\winnt\system32\net.net
==================== Find3M ====================
2008-10-08 11:35 12,888 a------- c:\docume~1\paul\applic~1\GDIPFONTCACHEV1.DAT
2003-03-17 16:59 21,952 ----h--- c:\program files\folder.htt
2003-03-17 16:59 271 ----h--- c:\program files\desktop.ini
1999-12-06 14:00 32,528 a------- c:\winnt\inf\wbfirdma.sys
============= FINISH: 12:23:53.39 ===============
DDS attach.TXT
==== Installed Programs ======================
Acrobat.com
Actiontec MD56ORD V92 MDC Modem
Adobe Acrobat 5.0
Adobe AIR
Adobe Flash Player ActiveX
Adobe MPEG Encoder
Adobe Premiere 6.5
Adobe Reader 9
Advanced Excel Repair v1.4
Advertisement Service
AT&T Global Network Client
Borland Delphi 6
Cimaware OfficeFIX 6
Diva Assistant
Diva Tools
EPSON Attach To Email
EPSON Easy Photo Print
EPSON File Manager
EPSON Print CD
EPSON PRINT Image Framer Tool
EPSON Printer Software
EPSON Scan Assistant
EPSON Web-To-Page
ESPR340 User's Guide
getPlus(R) for Adobe
Internet Explorer Q822925
Kernel for Excel ver 7.05.01
Malwarebytes' Anti-Malware
Microsoft ActiveSync
Microsoft Internet Explorer 6 SP1
Microsoft Office XP Professional with FrontPage
Microsoft SQL Server 2000
Microsoft SQL Server 2000 Windows CE Edition
Microsoft SQL Server CE Server Tools
Microsoft Visio Professional 2002 [English]
NVIDIA Windows 2000/XP Display Drivers
ORiNOCO AP Manager
Panda ActiveScan 2.0
PIF DESIGNER
QuickTime
Rising Antivirus
Sony Ericsson PC Suite
Spybot - Search & Destroy
TeamViewer 4
Terminal Services Client
The Operations Database
WAP11 Utility
WebFldrs
Windows 2000 Hotfix - KB823559
Windows 2000 Hotfix - KB824105
Windows 2000 Hotfix - KB824146
Windows Installer 3.1 (KB893803)
Windows Media Player system update (9 Series)
WinZip
==== End Of File ===========================
SOPHOS ANTI-ROOTKIT SCAN LOG
Sophos Anti-Rootkit Version 1.5.0 (c) 2009 Sophos Plc
Started logging on 31/07/2009 at 13:28:17
User "paul" on computer "ARIEL"
Windows version 5.0 SP 4.0 Service Pack 4 build 2195 SM=0x0 PT=0x1 Win32
Info: Starting process scan.
Info: Starting registry scan.
Hidden: registry item \HKEY_LOCAL_MACHINE\SOFTWARE\UAC
Hidden: registry item \HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\UACd.sys
Hidden: registry item \HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\UACd.sys
Hidden: registry item \HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\UACd.sys
Info: Starting disk scan of C: (NTFS).
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\4TCFOFWR\search[1].sys
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\G5QJ45QB\search[1].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\4TCFOFWR\mode_hybrid[1].gif
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\YLOBITI5\SecurityCheck[2].exe
Hidden: file C:\Transfer\Projects\CHS_I\StockBrowser\UActors.pas
Hidden: file C:\Transfer\Projects\CHS_I\Invoicing\UActors.bkm
Hidden: file C:\Transfer\Projects\CHS_I\Invoicing\UActors.pas
Hidden: file C:\Transfer\Projects\CHS_I\Invoicing\UActors.~pas
Hidden: file C:\Documents and Settings\paul\Local Settings\Temp\nss18.tmp\UAC.dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temp\nsq1A.tmp\UAC.dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temp\nsr1E.tmp\UAC.dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\WCK2HJ41\ie6setup[1].exe
Hidden: file C:\Documents and Settings\paul\Local Settings\Temp\nsh21.tmp\UAC.dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\3H87B04O\sar_15_sfx[2].exe
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\X7VJXXSE\eBayISAPI[5].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\TF3JH5CE\eBayISAPI[3].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\TF3JH5CE\eBayISAPI[4].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\TF3JH5CE\emailVal[2].js
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\G71RM2Z5\eBayISAPI[4].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\G71RM2Z5\eBayISAPI[5].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\G71RM2Z5\SYS_vjo_e595i7697294_1_en_GB[23].js
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\G71RM2Z5\Fastfold-projector-screen-10x7-5-Screenworks-F-R_W0QQitemZ330299044646QQcmdZViewItemQQptZUK_BOI_Office_Equipment_Supplies_Presentation_Projection_Accessories_[1].htm
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\G71RM2Z5\Fastfold-projector-screen-10x7-5-Screenworks-F-R_W0QQitemZ330299044646QQcmdZViewItemQQptZUK_BOI_Office_Equipment_Supplies_Presentation_Projection_Accessories_[2].htm
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\WTGJOXM5\eBayISAPI[2].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\WTGJOXM5\SYS_vjo_e595i7697294_1_en_GB[15].js
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\UNOWHDFY\eBayISAPI[2].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\UNOWHDFY\eBayISAPI[3].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\UNOWHDFY\CAEFTV96.js
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\4TCFOFWR\eBayISAPI[2].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\4TCFOFWR\eBayISAPI[3].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\4TCFOFWR\CAU1KN81.css
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\6FOZQ9AN\eBayISAPI[2].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\6FOZQ9AN\SYS_vjo_e599i7773850_1_en_GB[46].js
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\6FOZQ9AN\eBayISAPI[3].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\6FOZQ9AN\SYS_vjo_e599i7773850_1_en_GB[76].js
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\G5QJ45QB\eBayISAPI[2].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\G5QJ45QB\eBayISAPI[3].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\G5QJ45QB\SYS_vjo_e599i7773850_1_en_GB[43].js
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\X7VJXXSE\eBayISAPI[6].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\X7VJXXSE\SYS_vjo_e599i7773850_1_en_GB[45].js
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\3H87B04O\eBayISAPI[2].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\3H87B04O\eBayISAPI[4].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\3H87B04O\SYS_vjo_e599i7773850_1_en_GB[39].js
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\836DWVG1\eBayISAPI[2].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\836DWVG1\SYS_vjo_e599i7773850_1_en_GB[68].js
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\SRIBATTB\eBayISAPI[2].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\SRIBATTB\SYS_vjo_e599i7773850_1_en_GB[51].js
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\CJ63MQCO\eBayISAPI[2].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\CJ63MQCO\SYS_vjo_e599i7773850_1_en_GB[12].js
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\SRIBATTB\RavINT_AU[1].exe
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\SRIBATTB\google.co[13]
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\X7VJXXSE\eBayISAPI[7].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\8D07CNI9\eBayISAPI[2].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\SRIBATTB\eBayISAPI[3].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\UNOWHDFY\eBayISAPI[4].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\UNOWHDFY\GlobalNavVjoOpt23_Ebay_e601i7856465_en_GB[15].css
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\UNOWHDFY\eBayISAPI[5].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\UNOWHDFY\GlobalNavVjoOpt23_Ebay_e601i7856465_en_GB[28].css
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\6VEFG1YF\eBayISAPI[2].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\X7VJXXSE\eBayISAPI[8].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\X7VJXXSE\GlobalNavVjoOpt23_Ebay_e601i7856465_en_GB[42].css
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\G5QJ45QB\eBayISAPI[4].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\G5QJ45QB\eBayISAPI[5].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\G5QJ45QB\GlobalNavVjoOpt23_Ebay_e601i7856465_en_GB[48].css
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\3H87B04O\eBayISAPI[3].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\3H87B04O\eBayISAPI[5].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\3H87B04O\GlobalNavVjoOpt23_Ebay_e601i7856465_en_GB[47].css
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\CJ63MQCO\eBayISAPI[3].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\CJ63MQCO\eBayISAPI[4].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\6FOZQ9AN\eBayISAPI[8].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\6FOZQ9AN\GlobalNavVjoOpt23_Ebay_e601i7856465_en_GB[50].css
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\WTGJOXM5\eBayISAPI[3].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\WTGJOXM5\GlobalNavVjoOpt23_EbayR2_e601i7856465_en_GB[8].css
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\WTGJOXM5\eBayISAPI[4].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\WTGJOXM5\GlobalNavVjoOpt23_EbayR2_e601i7856465_en_GB[16].css
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\YLOBITI5\eBayISAPI[2].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\G5QJ45QB\eBayISAPI[6].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\G5QJ45QB\eBayISAPI[7].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\G5QJ45QB\GlobalNavVjoOpt23_Ebay_e603i7942770_en_GB[50].css
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\A4NCCH29\eBayISAPI[3].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\A4NCCH29\GlobalNavVjoOpt23_Ebay_e603i7942770_en_GB[9].css
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\A4NCCH29\eBayISAPI[4].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\A4NCCH29\CAE7WHA2.css
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\4TCFOFWR\eBayISAPI[4].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\8TKTE709\eBayISAPI[3].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\8TKTE709\SYS_vjo_e601i7856464_1_en_GB[38].js
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\ZQON7HWD\eBayISAPI[2].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\6FOZQ9AN\eBayISAPI[9].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\6FOZQ9AN\GlobalNavVjoOpt23_Ebay_e603i7942770_en_GB[25].css
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\WTGJOXM5\eBayISAPI[10].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\CJ63MQCO\%7Bmod_zoom,mod_trends,mod_transitlyr,mod_traffic_app,mod_scrollwheel,mod_lyrsctrl,mod_lyrs,mod_keyboard,mod_jslinker,mod_extended_dom,mod_drag,mod_controls,mo[2].js
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\WTGJOXM5\eBayISAPI[11].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\WTGJOXM5\CAYPB6FF
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\GPYJOXUB\eBayISAPI[3].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\OOSRBOWZ\procexp[1].exe
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\836DWVG1\eBayISAPI[3].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\836DWVG1\GlobalNav14_Ebay_e605i8038212_en_GB[27].css
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\836DWVG1\_WINNT_system32_dxtrans[1].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\836DWVG1\Scopus728x90_flash[1].swf
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\8TKTE709\eBayISAPI[4].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\G5QJ45QB\eBayISAPI[8].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\BU8RBDWD\eBayISAPI[17].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\X7VJXXSE\eBayISAPI[10].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\X7VJXXSE\GlobalNav14_EbayR2_e605i8085187_en_GB[24].css
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\X7VJXXSE\eBayISAPI[11].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\X7VJXXSE\GlobalNav14_EbayR2_e605i8085187_en_GB[30].css
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\TF3JH5CE\eBayISAPI[6].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\TF3JH5CE\eBayISAPI[7].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\OOSRBOWZ\eBayISAPI[3].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\A4NCCH29\eBayISAPI[6].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\A4NCCH29\GlobalNav14_EbayR2_e605i8085187_en_GB[4].css
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\JXH8395C\eBayISAPI[5].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\8D07CNI9\eBayISAPI[3].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\YJUJO9IZ\eBayISAPI[3].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\YJUJO9IZ\eBayISAPI[4].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\YJUJO9IZ\CATTEZDE
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\BU8RBDWD\eBayISAPI[18].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\WCK2HJ41\eBayISAPI[2].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\MXLMZ65W\eBayISAPI[3].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\8TKTE709\DA-LITE-FAST-FOLD-REAR-PROJECTION-SCREEN-COMPLETE-BOXED_W0QQitemZ190295243279QQcmdZViewItemQQptZUK_BOI_Office_Equipment_Supplies_Presentation_Projection_Acces[1].htm
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\8TKTE709\eBayISAPI[5].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\8TKTE709\GlobalNav14_EbayR2_e607i8123656_en_GB[36].css
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\SRIBATTB\eBayISAPI[4].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\SRIBATTB\main_e6071uk[3].css
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\MXLMZ65W\eBayISAPI[4].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\MXLMZ65W\GlobalNav14_EbayR2_e607i8123656_en_GB[48].css
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\SRIBATTB\eBayISAPI[5].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\SRIBATTB\globals_e6091uk[3].js
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\X7VJXXSE\eBayISAPI[12].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\6VEFG1YF\Unicol-AV-Mounting-Brackets-Selection-of-17-parts_W0QQitemZ280326282262QQcmdZViewItemQQptZUK_BOI_Office_Equipment_Supplies_Presentation_Projection_Accessories[1].htm
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\6VEFG1YF\Unicol-AV-Mounting-Brackets-Selection-of-17-parts_W0QQitemZ280326282262QQcmdZViewItemQQptZUK_BOI_Office_Equipment_Supplies_Presentation_Projection_Accessories[2].htm
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\4TCFOFWR\eBayISAPI[5].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\I5DAJM10\eBayISAPI[18].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\6VEFG1YF\eBayISAPI[3].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\6FOZQ9AN\eBayISAPI[11].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\6FOZQ9AN\GlobalNav14_EbayR2_e607i8123656_en_GB[17].css
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\YJUJO9IZ\eBayISAPI[7].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\GPYJOXUB\eBayISAPI[4].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\STE7K52Z\eBayISAPI[2].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\8TKTE709\eBayISAPI[6].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\836DWVG1\Nucleus-Kernel-Excel[1].exe
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\836DWVG1\excelfixinstaller[2].exe
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\836DWVG1\expansion_embed[42].js
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\UNOWHDFY\eBayISAPI[8].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\I5DAJM10\eBayISAPI[2].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\WCK2HJ41\Fastfold-Fast-fold-Screen-Drape-Kit-Case-BARGAIN_W0QQitemZ170332710990QQcmdZViewItemQQptZUK_BOI_Office_Equipment_Supplies_Presentation_Projection_Accessories_[1].htm
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\STE7K52Z\Excalibur5-5-0[1].exe
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\I5DAJM10\eBayISAPI[3].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\OOSRBOWZ\eBayISAPI[4].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\TF3JH5CE\eBayISAPI[8].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\TF3JH5CE\eBayISAPI[9].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\CBEFCVKZ\eBayISAPI[8].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\CBEFCVKZ\eBayISAPI[7].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\CBEFCVKZ\eBayISAPI[12]
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\KLEJSXMF\eBayISAPI[2].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\YLOBITI5\eBayISAPI[3].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\MXLMZ65W\eBayISAPI[2].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\8TKTE709\eBayISAPI[7].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\KLEJSXMF\eBayISAPI[3].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\BU8RBDWD\eBayISAPI[4].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\X7VJXXSE\eBayISAPI[4].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\X7VJXXSE\SYS_YODA2_vjo_e625i9680358_1_en_GB[9].js
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\CNDN2QFD\eBayISAPI[3].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\CNDN2QFD\eBayISAPI[4].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\MXLMZ65W\Setup-e92_02009-1938[1].exe
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\MXLMZ65W\gorcheoronte[1].html
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\MXLMZ65W\Setup-6a1_02009-1938[1].exe
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\836DWVG1\eBayISAPI[21].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\836DWVG1\GH_YODA1_Ebay_e623i9600654_en_GB[27].css
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\KLEJSXMF\eBayISAPI[4].dll
Hidden: file C:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\KLEJSXMF\SYS_YODA2_vjo_e625i9680358_1_en_GB[24].js
Hidden: file C:\Documents and Settings\paul\Local Settings\Temp\UAC5475.tmp
Hidden: file C:\WINNT\system32\drivers\UACklrlovmycd.sys
Hidden: file C:\WINNT\system32\UACjkmpixnrwb.dll
Stopped logging on 31/07/2009 at 17:25:30