Page 1 of 3 123 LastLast
Results 1 to 10 of 26

Thread: my comp is lagging 30 fold in 2 weeks... help please??!?

  1. #1
    Junior Member
    Join Date
    Jan 2008
    Posts
    17

    Default my comp is lagging 30 fold in 2 weeks... help please??!?

    i recently just made the switch from dial up to highspeed, as it is now available in my area. since i made the switch... less than 2 weeks ago, my comp has been crushed with trojan horses and worms. i was using avast!, and a friend told me to get antivir, so i did... and it found 103 viruses.

    i moved them all to quarantine, and now my comp is super slow.

    what do i do??!?

    here is a HJT log:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 12:55:02 AM, on 15/01/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16574)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
    C:\Program Files\Yahoo!\Search Protection\SearchProtection .exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\PROGRA~1\FASTRE~1\IQWebFTPServerEngine.exe
    C:\WINDOWS\system32\ctfmon .exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\Documents and Settings\User\Desktop\OTHER PROGRAMS\HiJackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/yco...search/ie.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/...ch/search.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com
    O2 - BHO: (no name) - {00DC0058-A87E-4D19-9C26-F1AAC98AD4D7} - C:\WINDOWS\system32\opnnkjk.dll (file missing)
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {4115122B-85FF-4DD3-9515-F075BEDE5EB5} - (no file)
    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O2 - BHO: (no name) - {75E498B1-BA91-469F-B016-10917DB2ECB0} - C:\WINDOWS\system32\gebyv.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: (no name) - {9AA2F14F-E956-44B8-8694-A5B615CDF341} - (no file)
    O2 - BHO: {12a46017-4d79-1c78-6a24-e3b29d03a00a} - {a00a30d9-2b3e-42a6-87c1-97d471064a21} - C:\WINDOWS\system32\dkvgmhbx.dll (file missing)
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
    O3 - Toolbar: (no name) - {8B79EE88-E62D-4AA8-B530-CC357BA112B7} - (no file)
    O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
    O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ .exe"
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe (file missing)
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://www.surenet.net/
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02...s/MSNPUpld.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{A179016E-6D38-49BB-B4B9-08625140F7CD}: NameServer = 209.91.128.11 204.187.88.10
    O20 - Winlogon Notify: opnnkjk - opnnkjk.dll (file missing)
    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\ssvtdxrd.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Fastream IQ Web/FTP Server (NFService) - Fastream Technologies - C:\PROGRA~1\FASTRE~1\IQWebFTPServerEngine.exe

    --
    End of file - 7933 bytes


    please help!

    thank you.

  2. #2
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Hi Sike-1 and welcome to Safer Networking Forums

    You are running two antiviruses, AntiVir and avast!

    Please uninstall one of them.

    After that:

    1. Download combofix from any of these links and save it to Desktop:
    Link 1
    Link 2
    Link 3

    **Note: It is important that it is saved directly to your desktop**

    2. Double click combofix.exe & follow the prompts.
    3. When finished, it shall produce a log for you (C:\ComboFix.txt). Post that log in your next reply

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall

    Combofix should never take more that 20 minutes including the reboot if malware is detected.
    If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
    If that happened we want to know, and also what process you had to end.

    If you have problems with Combofix usage, see here

    Post:

    - a fresh HijackThis log
    - combofix report
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  3. #3
    Junior Member
    Join Date
    Jan 2008
    Posts
    17

    Default

    Thank you SOOOO sooo much shaba, i appreciate it alot

    HJT log:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 2:48:57 PM, on 15/01/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16574)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\ctfmon.exe
    C:\PROGRA~1\FASTRE~1\IQWebFTPServerEngine.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\notepad.exe
    C:\Documents and Settings\User\Desktop\OTHER PROGRAMS\HiJackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/...ch/search.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: {12a46017-4d79-1c78-6a24-e3b29d03a00a} - {a00a30d9-2b3e-42a6-87c1-97d471064a21} - C:\WINDOWS\system32\dkvgmhbx.dll (file missing)
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
    O3 - Toolbar: (no name) - {8B79EE88-E62D-4AA8-B530-CC357BA112B7} - (no file)
    O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp .exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ .exe"
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe (file missing)
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://www.surenet.net/
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02...s/MSNPUpld.cab
    O20 - Winlogon Notify: opnnkjk - opnnkjk.dll (file missing)
    O23 - Service: AVP - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp .exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Fastream IQ Web/FTP Server (NFService) - Fastream Technologies - C:\PROGRA~1\FASTRE~1\IQWebFTPServerEngine.exe

    --
    End of file - 5248 bytes

  4. #4
    Junior Member
    Join Date
    Jan 2008
    Posts
    17

    Default

    combofix log pt 1:


    ComboFix 08-01-15.4 - User 2008-01-15 13:56:18.1 - NTFSx86
    Running from: C:\Documents and Settings\User\Desktop\ComboFix.exe

    WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\Documents and Settings\User\Application Data\WinTouch
    C:\Documents and Settings\User\Application Data\WinTouch\wintouch.cfg
    C:\pos1.tmp
    C:\pos10.tmp
    C:\pos100.tmp
    C:\pos101.tmp
    C:\pos102.tmp
    C:\pos103.tmp
    C:\pos104.tmp
    C:\pos105.tmp
    C:\pos106.tmp
    C:\pos107.tmp
    C:\pos108.tmp
    C:\pos109.tmp
    C:\pos10A.tmp
    C:\pos10B.tmp
    C:\pos10C.tmp
    C:\pos10D.tmp
    C:\pos10E.tmp
    C:\pos10F.tmp
    C:\pos11.tmp
    C:\pos110.tmp
    C:\pos111.tmp
    C:\pos112.tmp
    C:\pos113.tmp
    C:\pos114.tmp
    C:\pos115.tmp
    C:\pos116.tmp
    C:\pos117.tmp
    C:\pos118.tmp
    C:\pos119.tmp
    C:\pos11A.tmp
    C:\pos11B.tmp
    C:\pos11C.tmp
    C:\pos11D.tmp
    C:\pos11E.tmp
    C:\pos11F.tmp
    C:\pos12.tmp
    C:\pos120.tmp
    C:\pos121.tmp
    C:\pos122.tmp
    C:\pos123.tmp
    C:\pos124.tmp
    C:\pos125.tmp
    C:\pos126.tmp
    C:\pos127.tmp
    C:\pos128.tmp
    C:\pos129.tmp
    C:\pos12A.tmp
    C:\pos12B.tmp
    C:\pos12C.tmp
    C:\pos12D.tmp
    C:\pos12E.tmp
    C:\pos12F.tmp
    C:\pos13.tmp
    C:\pos130.tmp
    C:\pos131.tmp
    C:\pos132.tmp
    C:\pos133.tmp
    C:\pos134.tmp
    C:\pos135.tmp
    C:\pos136.tmp
    C:\pos137.tmp
    C:\pos138.tmp
    C:\pos139.tmp
    C:\pos13A.tmp
    C:\pos13B.tmp
    C:\pos13C.tmp
    C:\pos13D.tmp
    C:\pos13E.tmp
    C:\pos13F.tmp
    C:\pos14.tmp
    C:\pos140.tmp
    C:\pos141.tmp
    C:\pos142.tmp
    C:\pos143.tmp
    C:\pos144.tmp
    C:\pos145.tmp
    C:\pos146.tmp
    C:\pos147.tmp
    C:\pos148.tmp
    C:\pos149.tmp
    C:\pos14A.tmp
    C:\pos14B.tmp
    C:\pos14C.tmp
    C:\pos14D.tmp
    C:\pos14E.tmp
    C:\pos14F.tmp
    C:\pos15.tmp
    C:\pos150.tmp
    C:\pos151.tmp
    C:\pos152.tmp
    C:\pos153.tmp
    C:\pos154.tmp
    C:\pos155.tmp
    C:\pos156.tmp
    C:\pos157.tmp
    C:\pos158.tmp
    C:\pos159.tmp
    C:\pos15A.tmp
    C:\pos15B.tmp
    C:\pos15C.tmp
    C:\pos15D.tmp
    C:\pos15E.tmp
    C:\pos15F.tmp
    C:\pos16.tmp
    C:\pos160.tmp
    C:\pos161.tmp
    C:\pos162.tmp
    C:\pos163.tmp
    C:\pos164.tmp
    C:\pos165.tmp
    C:\pos166.tmp
    C:\pos167.tmp
    C:\pos168.tmp
    C:\pos169.tmp
    C:\pos16A.tmp
    C:\pos16B.tmp
    C:\pos16C.tmp
    C:\pos16D.tmp
    C:\pos16E.tmp
    C:\pos16F.tmp
    C:\pos17.tmp
    C:\pos170.tmp
    C:\pos171.tmp
    C:\pos172.tmp
    C:\pos173.tmp
    C:\pos174.tmp
    C:\pos175.tmp
    C:\pos176.tmp
    C:\pos177.tmp
    C:\pos178.tmp
    C:\pos179.tmp
    C:\pos17A.tmp
    C:\pos17B.tmp
    C:\pos17C.tmp
    C:\pos17D.tmp
    C:\pos17E.tmp
    C:\pos17F.tmp
    C:\pos18.tmp
    C:\pos180.tmp
    C:\pos181.tmp
    C:\pos182.tmp
    C:\pos183.tmp
    C:\pos184.tmp
    C:\pos185.tmp
    C:\pos186.tmp
    C:\pos187.tmp
    C:\pos188.tmp
    C:\pos189.tmp
    C:\pos18A.tmp
    C:\pos18B.tmp
    C:\pos18C.tmp
    C:\pos18D.tmp
    C:\pos18E.tmp
    C:\pos18F.tmp
    C:\pos19.tmp
    C:\pos190.tmp
    C:\pos191.tmp
    C:\pos192.tmp
    C:\pos193.tmp
    C:\pos194.tmp
    C:\pos195.tmp
    C:\pos196.tmp
    C:\pos197.tmp
    C:\pos198.tmp
    C:\pos199.tmp
    C:\pos19A.tmp
    C:\pos19B.tmp
    C:\pos19C.tmp
    C:\pos19D.tmp
    C:\pos19E.tmp
    C:\pos19F.tmp
    C:\pos1A.tmp
    C:\pos1A0.tmp
    C:\pos1A1.tmp
    C:\pos1A2.tmp
    C:\pos1A3.tmp
    C:\pos1A4.tmp
    C:\pos1A5.tmp
    C:\pos1A6.tmp
    C:\pos1A7.tmp
    C:\pos1A8.tmp
    C:\pos1A9.tmp
    C:\pos1AA.tmp
    C:\pos1AB.tmp
    C:\pos1AC.tmp
    C:\pos1AD.tmp
    C:\pos1AE.tmp
    C:\pos1AF.tmp
    C:\pos1B.tmp
    C:\pos1B0.tmp
    C:\pos1B1.tmp
    C:\pos1B2.tmp
    C:\pos1B3.tmp
    C:\pos1B4.tmp
    C:\pos1B5.tmp
    C:\pos1B6.tmp
    C:\pos1B7.tmp
    C:\pos1B8.tmp
    C:\pos1B9.tmp
    C:\pos1BA.tmp
    C:\pos1BB.tmp
    C:\pos1BC.tmp
    C:\pos1BD.tmp
    C:\pos1BE.tmp
    C:\pos1BF.tmp
    C:\pos1C.tmp
    C:\pos1C0.tmp
    C:\pos1C1.tmp
    C:\pos1C2.tmp
    C:\pos1C3.tmp
    C:\pos1C4.tmp
    C:\pos1C5.tmp
    C:\pos1C6.tmp
    C:\pos1C7.tmp
    C:\pos1C8.tmp
    C:\pos1C9.tmp
    C:\pos1CA.tmp
    C:\pos1CB.tmp
    C:\pos1CC.tmp
    C:\pos1CD.tmp
    C:\pos1CE.tmp
    C:\pos1CF.tmp
    C:\pos1D.tmp
    C:\pos1D0.tmp
    C:\pos1D1.tmp
    C:\pos1D2.tmp
    C:\pos1D3.tmp
    C:\pos1D4.tmp
    C:\pos1D5.tmp
    C:\pos1D6.tmp
    C:\pos1D7.tmp
    C:\pos1D8.tmp
    C:\pos1D9.tmp
    C:\pos1DA.tmp
    C:\pos1DB.tmp
    C:\pos1DC.tmp
    C:\pos1DD.tmp
    C:\pos1DE.tmp
    C:\pos1DF.tmp
    C:\pos1E.tmp
    C:\pos1E0.tmp
    C:\pos1E1.tmp
    C:\pos1E2.tmp
    C:\pos1E3.tmp
    C:\pos1E4.tmp
    C:\pos1E5.tmp
    C:\pos1E6.tmp
    C:\pos1E7.tmp
    C:\pos1E8.tmp
    C:\pos1E9.tmp
    C:\pos1EA.tmp
    C:\pos1EB.tmp
    C:\pos1EC.tmp
    C:\pos1ED.tmp
    C:\pos1EE.tmp
    C:\pos1EF.tmp
    C:\pos1F.tmp
    C:\pos1F0.tmp
    C:\pos1F1.tmp
    C:\pos1F2.tmp
    C:\pos1F3.tmp
    C:\pos1F4.tmp
    C:\pos1F5.tmp
    C:\pos1F6.tmp
    C:\pos1F7.tmp
    C:\pos1F8.tmp
    C:\pos1F9.tmp
    C:\pos1FA.tmp
    C:\pos1FB.tmp
    C:\pos1FC.tmp
    C:\pos1FD.tmp
    C:\pos1FE.tmp
    C:\pos1FF.tmp
    C:\pos2.tmp
    C:\pos20.tmp
    C:\pos200.tmp
    C:\pos201.tmp
    C:\pos202.tmp
    C:\pos203.tmp
    C:\pos204.tmp
    C:\pos205.tmp
    C:\pos206.tmp
    C:\pos207.tmp
    C:\pos208.tmp
    C:\pos209.tmp
    C:\pos20A.tmp
    C:\pos20B.tmp
    C:\pos20C.tmp
    C:\pos20D.tmp
    C:\pos20E.tmp
    C:\pos20F.tmp
    C:\pos21.tmp
    C:\pos210.tmp
    C:\pos211.tmp
    C:\pos212.tmp
    C:\pos213.tmp
    C:\pos214.tmp
    C:\pos215.tmp
    C:\pos216.tmp
    C:\pos217.tmp
    C:\pos218.tmp
    C:\pos219.tmp
    C:\pos21A.tmp
    C:\pos21B.tmp
    C:\pos21C.tmp
    C:\pos21D.tmp
    C:\pos21E.tmp
    C:\pos21F.tmp
    C:\pos22.tmp
    C:\pos220.tmp
    C:\pos221.tmp
    C:\pos222.tmp
    C:\pos223.tmp
    C:\pos224.tmp
    C:\pos225.tmp
    C:\pos226.tmp
    C:\pos227.tmp
    C:\pos228.tmp
    C:\pos229.tmp
    C:\pos22A.tmp
    C:\pos22B.tmp
    C:\pos22C.tmp
    C:\pos22D.tmp
    C:\pos22E.tmp
    C:\pos22F.tmp
    C:\pos23.tmp
    C:\pos230.tmp
    C:\pos231.tmp
    C:\pos232.tmp
    C:\pos233.tmp
    C:\pos234.tmp
    C:\pos235.tmp
    C:\pos236.tmp
    C:\pos237.tmp
    C:\pos238.tmp
    C:\pos239.tmp
    C:\pos23A.tmp
    C:\pos23B.tmp
    C:\pos23C.tmp
    C:\pos23D.tmp
    C:\pos23E.tmp
    C:\pos23F.tmp
    C:\pos24.tmp
    C:\pos240.tmp
    C:\pos241.tmp
    C:\pos242.tmp
    C:\pos243.tmp
    C:\pos244.tmp
    C:\pos245.tmp
    C:\pos246.tmp
    C:\pos247.tmp
    C:\pos248.tmp
    C:\pos249.tmp
    C:\pos24A.tmp
    C:\pos24B.tmp
    C:\pos24C.tmp
    C:\pos24D.tmp
    C:\pos24E.tmp
    C:\pos24F.tmp
    C:\pos25.tmp
    C:\pos250.tmp
    C:\pos251.tmp
    C:\pos252.tmp
    C:\pos253.tmp
    C:\pos254.tmp
    C:\pos255.tmp
    C:\pos256.tmp
    C:\pos257.tmp
    C:\pos258.tmp
    C:\pos259.tmp
    C:\pos25A.tmp
    C:\pos25B.tmp
    C:\pos25C.tmp
    C:\pos25D.tmp
    C:\pos25E.tmp
    C:\pos25F.tmp
    C:\pos26.tmp
    C:\pos260.tmp
    C:\pos261.tmp
    C:\pos262.tmp
    C:\pos263.tmp
    C:\pos264.tmp
    C:\pos265.tmp
    C:\pos266.tmp
    C:\pos267.tmp
    C:\pos268.tmp
    C:\pos269.tmp
    C:\pos26A.tmp
    C:\pos26B.tmp
    C:\pos26C.tmp
    C:\pos26D.tmp
    C:\pos26E.tmp
    C:\pos26F.tmp
    C:\pos27.tmp
    C:\pos270.tmp
    C:\pos271.tmp
    C:\pos272.tmp
    C:\pos273.tmp
    C:\pos274.tmp
    C:\pos275.tmp
    C:\pos276.tmp
    C:\pos277.tmp
    C:\pos278.tmp
    C:\pos279.tmp
    C:\pos27A.tmp
    C:\pos27B.tmp
    C:\pos27C.tmp
    C:\pos27D.tmp
    C:\pos27E.tmp
    C:\pos27F.tmp
    C:\pos28.tmp
    C:\pos280.tmp
    C:\pos281.tmp
    C:\pos282.tmp
    C:\pos283.tmp
    C:\pos284.tmp
    C:\pos285.tmp
    C:\pos286.tmp
    C:\pos287.tmp
    C:\pos288.tmp
    C:\pos289.tmp
    C:\pos28A.tmp
    C:\pos28B.tmp
    C:\pos28C.tmp
    C:\pos28D.tmp
    C:\pos28E.tmp
    C:\pos28F.tmp
    C:\pos29.tmp
    C:\pos290.tmp
    C:\pos291.tmp
    C:\pos292.tmp
    C:\pos293.tmp
    C:\pos294.tmp
    C:\pos295.tmp
    C:\pos296.tmp
    C:\pos297.tmp
    C:\pos298.tmp
    C:\pos299.tmp
    C:\pos29A.tmp
    C:\pos29B.tmp
    C:\pos29C.tmp
    C:\pos29D.tmp
    C:\pos29E.tmp
    C:\pos29F.tmp
    C:\pos2A.tmp
    C:\pos2A0.tmp
    C:\pos2A1.tmp
    C:\pos2A2.tmp
    C:\pos2A3.tmp
    C:\pos2A4.tmp
    C:\pos2A5.tmp
    C:\pos2A6.tmp
    C:\pos2A7.tmp
    C:\pos2A8.tmp
    C:\pos2A9.tmp
    C:\pos2AA.tmp
    C:\pos2AB.tmp
    C:\pos2AC.tmp
    C:\pos2AD.tmp
    C:\pos2AE.tmp
    C:\pos2AF.tmp
    C:\pos2B.tmp
    C:\pos2B0.tmp
    C:\pos2B1.tmp
    C:\pos2B2.tmp
    C:\pos2B3.tmp
    C:\pos2B4.tmp
    C:\pos2B5.tmp
    C:\pos2B6.tmp
    C:\pos2B7.tmp
    C:\pos2B8.tmp
    C:\pos2B9.tmp
    C:\pos2BA.tmp
    C:\pos2BB.tmp
    C:\pos2BC.tmp
    C:\pos2BD.tmp
    C:\pos2BE.tmp
    C:\pos2BF.tmp
    C:\pos2C.tmp
    C:\pos2C0.tmp
    C:\pos2C1.tmp
    C:\pos2C2.tmp
    C:\pos2C3.tmp
    C:\pos2C4.tmp
    C:\pos2C5.tmp
    C:\pos2C6.tmp
    C:\pos2C7.tmp
    C:\pos2C8.tmp
    C:\pos2C9.tmp
    C:\pos2CA.tmp
    C:\pos2CB.tmp
    C:\pos2CC.tmp
    C:\pos2CD.tmp
    C:\pos2CE.tmp
    C:\pos2CF.tmp
    C:\pos2D.tmp
    C:\pos2D0.tmp
    C:\pos2D1.tmp
    C:\pos2D2.tmp
    C:\pos2D3.tmp
    C:\pos2D4.tmp
    C:\pos2D5.tmp
    C:\pos2D6.tmp
    C:\pos2D7.tmp
    C:\pos2D8.tmp
    C:\pos2D9.tmp
    C:\pos2DA.tmp
    C:\pos2DB.tmp
    C:\pos2DC.tmp
    C:\pos2DD.tmp
    C:\pos2DE.tmp
    C:\pos2DF.tmp
    C:\pos2E.tmp
    C:\pos2E0.tmp
    C:\pos2E1.tmp
    C:\pos2E2.tmp
    C:\pos2E3.tmp
    C:\pos2E4.tmp
    C:\pos2E5.tmp
    C:\pos2E6.tmp
    C:\pos2E7.tmp
    C:\pos2E8.tmp
    C:\pos2E9.tmp
    C:\pos2EA.tmp
    C:\pos2EB.tmp
    C:\pos2EC.tmp
    C:\pos2ED.tmp
    C:\pos2EE.tmp
    C:\pos2EF.tmp
    C:\pos2F.tmp
    C:\pos2F0.tmp
    C:\pos2F1.tmp
    C:\pos2F2.tmp

  5. #5
    Junior Member
    Join Date
    Jan 2008
    Posts
    17

    Default

    combofix log pt 2:

    C:\pos2F3.tmp
    C:\pos2F4.tmp
    C:\pos2F5.tmp
    C:\pos2F6.tmp
    C:\pos2F7.tmp
    C:\pos2F8.tmp
    C:\pos2F9.tmp
    C:\pos2FA.tmp
    C:\pos2FB.tmp
    C:\pos2FC.tmp
    C:\pos2FD.tmp
    C:\pos2FE.tmp
    C:\pos2FF.tmp
    C:\pos3.tmp
    C:\pos30.tmp
    C:\pos300.tmp
    C:\pos301.tmp
    C:\pos302.tmp
    C:\pos303.tmp
    C:\pos304.tmp
    C:\pos305.tmp
    C:\pos306.tmp
    C:\pos307.tmp
    C:\pos308.tmp
    C:\pos309.tmp
    C:\pos30A.tmp
    C:\pos30B.tmp
    C:\pos30C.tmp
    C:\pos30D.tmp
    C:\pos30E.tmp
    C:\pos30F.tmp
    C:\pos31.tmp
    C:\pos310.tmp
    C:\pos311.tmp
    C:\pos312.tmp
    C:\pos313.tmp
    C:\pos314.tmp
    C:\pos315.tmp
    C:\pos316.tmp
    C:\pos317.tmp
    C:\pos318.tmp
    C:\pos319.tmp
    C:\pos31A.tmp
    C:\pos31B.tmp
    C:\pos31C.tmp
    C:\pos31D.tmp
    C:\pos31E.tmp
    C:\pos31F.tmp
    C:\pos32.tmp
    C:\pos320.tmp
    C:\pos321.tmp
    C:\pos322.tmp
    C:\pos323.tmp
    C:\pos324.tmp
    C:\pos325.tmp
    C:\pos326.tmp
    C:\pos327.tmp
    C:\pos328.tmp
    C:\pos329.tmp
    C:\pos32A.tmp
    C:\pos32B.tmp
    C:\pos32C.tmp
    C:\pos32D.tmp
    C:\pos32E.tmp
    C:\pos32F.tmp
    C:\pos33.tmp
    C:\pos330.tmp
    C:\pos331.tmp
    C:\pos332.tmp
    C:\pos333.tmp
    C:\pos334.tmp
    C:\pos335.tmp
    C:\pos336.tmp
    C:\pos337.tmp
    C:\pos338.tmp
    C:\pos339.tmp
    C:\pos33A.tmp
    C:\pos33B.tmp
    C:\pos33C.tmp
    C:\pos33D.tmp
    C:\pos33E.tmp
    C:\pos33F.tmp
    C:\pos34.tmp
    C:\pos340.tmp
    C:\pos341.tmp
    C:\pos342.tmp
    C:\pos343.tmp
    C:\pos344.tmp
    C:\pos345.tmp
    C:\pos346.tmp
    C:\pos347.tmp
    C:\pos348.tmp
    C:\pos349.tmp
    C:\pos34A.tmp
    C:\pos34B.tmp
    C:\pos34C.tmp
    C:\pos34D.tmp
    C:\pos34E.tmp
    C:\pos34F.tmp
    C:\pos35.tmp
    C:\pos350.tmp
    C:\pos351.tmp
    C:\pos352.tmp
    C:\pos353.tmp
    C:\pos354.tmp
    C:\pos355.tmp
    C:\pos356.tmp
    C:\pos357.tmp
    C:\pos358.tmp
    C:\pos359.tmp
    C:\pos35A.tmp
    C:\pos35B.tmp
    C:\pos35C.tmp
    C:\pos35D.tmp
    C:\pos35E.tmp
    C:\pos35F.tmp
    C:\pos36.tmp
    C:\pos360.tmp
    C:\pos361.tmp
    C:\pos362.tmp
    C:\pos363.tmp
    C:\pos364.tmp
    C:\pos365.tmp
    C:\pos366.tmp
    C:\pos367.tmp
    C:\pos368.tmp
    C:\pos369.tmp
    C:\pos36A.tmp
    C:\pos36B.tmp
    C:\pos36C.tmp
    C:\pos36D.tmp
    C:\pos36E.tmp
    C:\pos36F.tmp
    C:\pos37.tmp
    C:\pos370.tmp
    C:\pos371.tmp
    C:\pos372.tmp
    C:\pos373.tmp
    C:\pos374.tmp
    C:\pos375.tmp
    C:\pos376.tmp
    C:\pos377.tmp
    C:\pos378.tmp
    C:\pos379.tmp
    C:\pos37A.tmp
    C:\pos37B.tmp
    C:\pos37C.tmp
    C:\pos37D.tmp
    C:\pos37E.tmp
    C:\pos37F.tmp
    C:\pos38.tmp
    C:\pos380.tmp
    C:\pos381.tmp
    C:\pos382.tmp
    C:\pos383.tmp
    C:\pos384.tmp
    C:\pos385.tmp
    C:\pos386.tmp
    C:\pos387.tmp
    C:\pos388.tmp
    C:\pos389.tmp
    C:\pos38A.tmp
    C:\pos38B.tmp
    C:\pos38C.tmp
    C:\pos38D.tmp
    C:\pos38E.tmp
    C:\pos38F.tmp
    C:\pos39.tmp
    C:\pos390.tmp
    C:\pos391.tmp
    C:\pos392.tmp
    C:\pos393.tmp
    C:\pos394.tmp
    C:\pos395.tmp
    C:\pos396.tmp
    C:\pos397.tmp
    C:\pos398.tmp
    C:\pos399.tmp
    C:\pos39A.tmp
    C:\pos39B.tmp
    C:\pos39C.tmp
    C:\pos39D.tmp
    C:\pos39E.tmp
    C:\pos39F.tmp
    C:\pos3A.tmp
    C:\pos3A0.tmp
    C:\pos3A1.tmp
    C:\pos3A2.tmp
    C:\pos3A3.tmp
    C:\pos3A4.tmp
    C:\pos3A5.tmp
    C:\pos3A6.tmp
    C:\pos3A7.tmp
    C:\pos3A8.tmp
    C:\pos3A9.tmp
    C:\pos3AA.tmp
    C:\pos3AB.tmp
    C:\pos3AC.tmp
    C:\pos3AD.tmp
    C:\pos3AE.tmp
    C:\pos3AF.tmp
    C:\pos3B.tmp
    C:\pos3B0.tmp
    C:\pos3B1.tmp
    C:\pos3B2.tmp
    C:\pos3B3.tmp
    C:\pos3B4.tmp
    C:\pos3B5.tmp
    C:\pos3B6.tmp
    C:\pos3B7.tmp
    C:\pos3B8.tmp
    C:\pos3B9.tmp
    C:\pos3BA.tmp
    C:\pos3BB.tmp
    C:\pos3BC.tmp
    C:\pos3BD.tmp
    C:\pos3BE.tmp
    C:\pos3BF.tmp
    C:\pos3C.tmp
    C:\pos3C0.tmp
    C:\pos3C1.tmp
    C:\pos3C2.tmp
    C:\pos3C3.tmp
    C:\pos3C4.tmp
    C:\pos3C5.tmp
    C:\pos3C6.tmp
    C:\pos3C7.tmp
    C:\pos3C8.tmp
    C:\pos3C9.tmp
    C:\pos3CA.tmp
    C:\pos3CB.tmp
    C:\pos3CC.tmp
    C:\pos3CD.tmp
    C:\pos3CE.tmp
    C:\pos3CF.tmp
    C:\pos3D.tmp
    C:\pos3D0.tmp
    C:\pos3D1.tmp
    C:\pos3D2.tmp
    C:\pos3D3.tmp
    C:\pos3D4.tmp
    C:\pos3D5.tmp
    C:\pos3D6.tmp
    C:\pos3D7.tmp
    C:\pos3D8.tmp
    C:\pos3D9.tmp
    C:\pos3DA.tmp
    C:\pos3DB.tmp
    C:\pos3DC.tmp
    C:\pos3DD.tmp
    C:\pos3DE.tmp
    C:\pos3DF.tmp
    C:\pos3E.tmp
    C:\pos3E0.tmp
    C:\pos3E1.tmp
    C:\pos3E2.tmp
    C:\pos3E3.tmp
    C:\pos3E4.tmp
    C:\pos3E5.tmp
    C:\pos3E6.tmp
    C:\pos3E7.tmp
    C:\pos3E8.tmp
    C:\pos3E9.tmp
    C:\pos3EA.tmp
    C:\pos3EB.tmp
    C:\pos3EC.tmp
    C:\pos3ED.tmp
    C:\pos3EE.tmp
    C:\pos3EF.tmp
    C:\pos3F.tmp
    C:\pos3F0.tmp
    C:\pos3F1.tmp
    C:\pos3F2.tmp
    C:\pos3F3.tmp
    C:\pos3F4.tmp
    C:\pos3F5.tmp
    C:\pos3F6.tmp
    C:\pos3F7.tmp
    C:\pos3F8.tmp
    C:\pos3F9.tmp
    C:\pos3FA.tmp
    C:\pos3FB.tmp
    C:\pos3FC.tmp
    C:\pos3FD.tmp
    C:\pos3FE.tmp
    C:\pos3FF.tmp
    C:\pos4.tmp
    C:\pos40.tmp
    C:\pos400.tmp
    C:\pos401.tmp
    C:\pos402.tmp
    C:\pos403.tmp
    C:\pos404.tmp
    C:\pos405.tmp
    C:\pos406.tmp
    C:\pos407.tmp
    C:\pos408.tmp
    C:\pos409.tmp
    C:\pos40A.tmp
    C:\pos40B.tmp
    C:\pos40C.tmp
    C:\pos40D.tmp
    C:\pos40E.tmp
    C:\pos40F.tmp
    C:\pos41.tmp
    C:\pos410.tmp
    C:\pos411.tmp
    C:\pos412.tmp
    C:\pos413.tmp
    C:\pos414.tmp
    C:\pos415.tmp
    C:\pos416.tmp
    C:\pos417.tmp
    C:\pos418.tmp
    C:\pos419.tmp
    C:\pos41A.tmp
    C:\pos41B.tmp
    C:\pos41C.tmp
    C:\pos41D.tmp
    C:\pos41E.tmp
    C:\pos41F.tmp
    C:\pos42.tmp
    C:\pos420.tmp
    C:\pos421.tmp
    C:\pos422.tmp
    C:\pos423.tmp
    C:\pos424.tmp
    C:\pos425.tmp
    C:\pos426.tmp
    C:\pos427.tmp
    C:\pos428.tmp
    C:\pos429.tmp
    C:\pos42A.tmp
    C:\pos42B.tmp
    C:\pos42C.tmp
    C:\pos42D.tmp
    C:\pos42E.tmp
    C:\pos42F.tmp
    C:\pos43.tmp
    C:\pos430.tmp
    C:\pos431.tmp
    C:\pos432.tmp
    C:\pos433.tmp
    C:\pos434.tmp
    C:\pos435.tmp
    C:\pos436.tmp
    C:\pos437.tmp
    C:\pos438.tmp
    C:\pos439.tmp
    C:\pos43A.tmp
    C:\pos43B.tmp
    C:\pos43C.tmp
    C:\pos43D.tmp
    C:\pos43E.tmp
    C:\pos43F.tmp
    C:\pos44.tmp
    C:\pos440.tmp
    C:\pos441.tmp
    C:\pos442.tmp
    C:\pos443.tmp
    C:\pos444.tmp
    C:\pos445.tmp
    C:\pos446.tmp
    C:\pos447.tmp
    C:\pos448.tmp
    C:\pos449.tmp
    C:\pos44A.tmp
    C:\pos44B.tmp
    C:\pos44C.tmp
    C:\pos44D.tmp
    C:\pos44E.tmp
    C:\pos44F.tmp
    C:\pos45.tmp
    C:\pos450.tmp
    C:\pos451.tmp
    C:\pos452.tmp
    C:\pos453.tmp
    C:\pos454.tmp
    C:\pos455.tmp
    C:\pos456.tmp
    C:\pos457.tmp
    C:\pos458.tmp
    C:\pos459.tmp
    C:\pos45A.tmp
    C:\pos45B.tmp
    C:\pos45C.tmp
    C:\pos45D.tmp
    C:\pos45E.tmp
    C:\pos45F.tmp
    C:\pos46.tmp
    C:\pos460.tmp
    C:\pos461.tmp
    C:\pos462.tmp
    C:\pos463.tmp
    C:\pos464.tmp
    C:\pos465.tmp
    C:\pos466.tmp
    C:\pos467.tmp
    C:\pos468.tmp
    C:\pos469.tmp
    C:\pos46A.tmp
    C:\pos46B.tmp
    C:\pos46C.tmp
    C:\pos46D.tmp
    C:\pos46E.tmp
    C:\pos46F.tmp
    C:\pos47.tmp
    C:\pos470.tmp
    C:\pos471.tmp
    C:\pos472.tmp
    C:\pos473.tmp
    C:\pos474.tmp
    C:\pos475.tmp
    C:\pos476.tmp
    C:\pos477.tmp
    C:\pos478.tmp
    C:\pos479.tmp
    C:\pos47A.tmp
    C:\pos47B.tmp
    C:\pos47C.tmp
    C:\pos47D.tmp
    C:\pos47E.tmp
    C:\pos47F.tmp
    C:\pos48.tmp
    C:\pos480.tmp
    C:\pos481.tmp
    C:\pos482.tmp
    C:\pos483.tmp
    C:\pos484.tmp
    C:\pos485.tmp
    C:\pos486.tmp
    C:\pos487.tmp
    C:\pos488.tmp
    C:\pos489.tmp
    C:\pos48A.tmp
    C:\pos48B.tmp
    C:\pos48C.tmp
    C:\pos48D.tmp
    C:\pos48E.tmp
    C:\pos48F.tmp
    C:\pos49.tmp
    C:\pos490.tmp
    C:\pos491.tmp
    C:\pos492.tmp
    C:\pos493.tmp
    C:\pos494.tmp
    C:\pos495.tmp
    C:\pos496.tmp
    C:\pos497.tmp
    C:\pos498.tmp
    C:\pos499.tmp
    C:\pos49A.tmp
    C:\pos49B.tmp
    C:\pos49C.tmp
    C:\pos49D.tmp
    C:\pos49E.tmp
    C:\pos49F.tmp
    C:\pos4A.tmp
    C:\pos4A0.tmp
    C:\pos4A1.tmp
    C:\pos4A2.tmp
    C:\pos4A3.tmp
    C:\pos4A4.tmp
    C:\pos4A5.tmp
    C:\pos4A6.tmp
    C:\pos4A7.tmp
    C:\pos4A8.tmp
    C:\pos4A9.tmp
    C:\pos4AA.tmp
    C:\pos4AB.tmp
    C:\pos4AC.tmp
    C:\pos4AD.tmp
    C:\pos4AE.tmp
    C:\pos4AF.tmp
    C:\pos4B.tmp
    C:\pos4B0.tmp
    C:\pos4B1.tmp
    C:\pos4B2.tmp
    C:\pos4B3.tmp
    C:\pos4B4.tmp
    C:\pos4B5.tmp
    C:\pos4B6.tmp
    C:\pos4B7.tmp
    C:\pos4B8.tmp
    C:\pos4B9.tmp
    C:\pos4BA.tmp
    C:\pos4BB.tmp
    C:\pos4BC.tmp
    C:\pos4BD.tmp
    C:\pos4BE.tmp
    C:\pos4BF.tmp
    C:\pos4C.tmp
    C:\pos4C0.tmp
    C:\pos4C1.tmp
    C:\pos4C2.tmp
    C:\pos4C3.tmp
    C:\pos4C4.tmp
    C:\pos4C5.tmp
    C:\pos4C6.tmp
    C:\pos4C7.tmp
    C:\pos4C8.tmp
    C:\pos4C9.tmp
    C:\pos4CA.tmp
    C:\pos4CB.tmp
    C:\pos4CC.tmp
    C:\pos4CD.tmp
    C:\pos4CE.tmp
    C:\pos4CF.tmp
    C:\pos4D.tmp
    C:\pos4D0.tmp
    C:\pos4D1.tmp
    C:\pos4D2.tmp
    C:\pos4D3.tmp
    C:\pos4D4.tmp
    C:\pos4D5.tmp
    C:\pos4D6.tmp
    C:\pos4D7.tmp
    C:\pos4D8.tmp
    C:\pos4D9.tmp
    C:\pos4DA.tmp
    C:\pos4DB.tmp
    C:\pos4DC.tmp
    C:\pos4DD.tmp
    C:\pos4DE.tmp
    C:\pos4DF.tmp
    C:\pos4E.tmp
    C:\pos4E0.tmp
    C:\pos4E1.tmp
    C:\pos4E2.tmp
    C:\pos4E3.tmp
    C:\pos4E4.tmp
    C:\pos4E5.tmp
    C:\pos4E6.tmp
    C:\pos4E7.tmp
    C:\pos4E8.tmp
    C:\pos4E9.tmp
    C:\pos4EA.tmp
    C:\pos4EB.tmp
    C:\pos4EC.tmp
    C:\pos4ED.tmp
    C:\pos4EE.tmp
    C:\pos4EF.tmp
    C:\pos4F.tmp
    C:\pos4F0.tmp
    C:\pos4F1.tmp
    C:\pos4F2.tmp
    C:\pos4F3.tmp
    C:\pos4F4.tmp
    C:\pos4F5.tmp
    C:\pos4F6.tmp
    C:\pos4F7.tmp
    C:\pos4F8.tmp
    C:\pos4F9.tmp
    C:\pos4FA.tmp
    C:\pos4FB.tmp
    C:\pos4FC.tmp
    C:\pos4FD.tmp
    C:\pos4FE.tmp
    C:\pos4FF.tmp
    C:\pos5.tmp
    C:\pos50.tmp
    C:\pos500.tmp
    C:\pos501.tmp
    C:\pos502.tmp
    C:\pos503.tmp
    C:\pos504.tmp
    C:\pos505.tmp
    C:\pos506.tmp
    C:\pos507.tmp
    C:\pos508.tmp
    C:\pos509.tmp
    C:\pos50A.tmp
    C:\pos50B.tmp
    C:\pos50C.tmp
    C:\pos50D.tmp
    C:\pos50E.tmp
    C:\pos50F.tmp
    C:\pos51.tmp
    C:\pos510.tmp
    C:\pos511.tmp
    C:\pos512.tmp
    C:\pos513.tmp
    C:\pos514.tmp
    C:\pos515.tmp
    C:\pos516.tmp
    C:\pos517.tmp
    C:\pos518.tmp
    C:\pos519.tmp
    C:\pos51A.tmp
    C:\pos51B.tmp
    C:\pos51C.tmp
    C:\pos51D.tmp
    C:\pos51E.tmp
    C:\pos51F.tmp
    C:\pos52.tmp
    C:\pos520.tmp
    C:\pos521.tmp
    C:\pos522.tmp
    C:\pos523.tmp
    C:\pos524.tmp
    C:\pos525.tmp
    C:\pos526.tmp
    C:\pos527.tmp
    C:\pos528.tmp
    C:\pos529.tmp
    C:\pos52A.tmp
    C:\pos52B.tmp
    C:\pos52C.tmp
    C:\pos52D.tmp
    C:\pos52E.tmp
    C:\pos52F.tmp
    C:\pos53.tmp
    C:\pos530.tmp
    C:\pos531.tmp
    C:\pos532.tmp
    C:\pos533.tmp
    C:\pos534.tmp
    C:\pos535.tmp
    C:\pos536.tmp
    C:\pos537.tmp
    C:\pos538.tmp
    C:\pos539.tmp
    C:\pos53A.tmp
    C:\pos53B.tmp
    C:\pos53C.tmp
    C:\pos53D.tmp
    C:\pos53E.tmp
    C:\pos53F.tmp
    C:\pos54.tmp
    C:\pos540.tmp
    C:\pos541.tmp
    C:\pos542.tmp
    C:\pos543.tmp
    C:\pos544.tmp
    C:\pos545.tmp
    C:\pos546.tmp
    C:\pos547.tmp
    C:\pos548.tmp
    C:\pos549.tmp
    C:\pos54A.tmp
    C:\pos54B.tmp
    C:\pos54C.tmp
    C:\pos54D.tmp
    C:\pos54E.tmp
    C:\pos54F.tmp
    C:\pos55.tmp
    C:\pos550.tmp
    C:\pos551.tmp
    C:\pos552.tmp
    C:\pos553.tmp
    C:\pos554.tmp
    C:\pos555.tmp
    C:\pos556.tmp
    C:\pos557.tmp
    C:\pos558.tmp
    C:\pos559.tmp
    C:\pos55A.tmp
    C:\pos55B.tmp
    C:\pos55C.tmp
    C:\pos55D.tmp
    C:\pos55E.tmp
    C:\pos55F.tmp
    C:\pos56.tmp
    C:\pos560.tmp
    C:\pos561.tmp
    C:\pos562.tmp
    C:\pos563.tmp
    C:\pos564.tmp
    C:\pos565.tmp
    C:\pos566.tmp
    C:\pos567.tmp
    C:\pos568.tmp
    C:\pos569.tmp
    C:\pos56A.tmp
    C:\pos56B.tmp
    C:\pos56C.tmp
    C:\pos56D.tmp
    C:\pos56E.tmp
    C:\pos56F.tmp
    C:\pos57.tmp
    C:\pos570.tmp
    C:\pos571.tmp
    C:\pos572.tmp
    C:\pos573.tmp
    C:\pos574.tmp
    C:\pos575.tmp
    C:\pos576.tmp
    C:\pos577.tmp
    C:\pos578.tmp
    C:\pos579.tmp
    C:\pos57A.tmp
    C:\pos57B.tmp
    C:\pos57C.tmp
    C:\pos57D.tmp
    C:\pos57E.tmp
    C:\pos57F.tmp
    C:\pos58.tmp
    C:\pos580.tmp
    C:\pos581.tmp
    C:\pos582.tmp
    C:\pos583.tmp
    C:\pos584.tmp
    C:\pos585.tmp
    C:\pos586.tmp
    C:\pos587.tmp
    C:\pos588.tmp
    C:\pos589.tmp
    C:\pos58A.tmp
    C:\pos58B.tmp
    C:\pos58C.tmp
    C:\pos58D.tmp
    C:\pos58E.tmp
    C:\pos58F.tmp
    C:\pos59.tmp
    C:\pos590.tmp
    C:\pos591.tmp
    C:\pos592.tmp
    C:\pos593.tmp
    C:\pos594.tmp
    C:\pos595.tmp
    C:\pos596.tmp
    C:\pos597.tmp
    C:\pos598.tmp
    C:\pos599.tmp
    C:\pos59A.tmp
    C:\pos59B.tmp
    C:\pos59C.tmp
    C:\pos59D.tmp
    C:\pos59E.tmp
    C:\pos59F.tmp
    C:\pos5A.tmp
    C:\pos5A0.tmp
    C:\pos5A1.tmp
    C:\pos5A2.tmp
    C:\pos5A3.tmp
    C:\pos5A4.tmp
    C:\pos5A5.tmp
    C:\pos5A6.tmp
    C:\pos5A7.tmp
    C:\pos5A8.tmp
    C:\pos5A9.tmp
    C:\pos5AA.tmp
    C:\pos5AB.tmp
    C:\pos5AC.tmp
    C:\pos5AD.tmp
    C:\pos5AE.tmp
    C:\pos5AF.tmp
    C:\pos5B.tmp
    C:\pos5B0.tmp
    C:\pos5B1.tmp
    C:\pos5B2.tmp
    C:\pos5B3.tmp
    C:\pos5B4.tmp
    C:\pos5B5.tmp
    C:\pos5B6.tmp
    C:\pos5B7.tmp
    C:\pos5B8.tmp
    C:\pos5B9.tmp
    C:\pos5BA.tmp
    C:\pos5BB.tmp
    C:\pos5BC.tmp
    C:\pos5BD.tmp
    C:\pos5BE.tmp
    C:\pos5BF.tmp
    C:\pos5C.tmp
    C:\pos5C0.tmp
    C:\pos5C1.tmp
    C:\pos5C2.tmp
    C:\pos5C3.tmp
    C:\pos5C4.tmp
    C:\pos5C5.tmp
    C:\pos5C6.tmp
    C:\pos5C7.tmp
    C:\pos5C8.tmp
    C:\pos5C9.tmp
    C:\pos5CA.tmp
    C:\pos5CB.tmp
    C:\pos5CC.tmp
    C:\pos5CD.tmp
    C:\pos5CE.tmp
    C:\pos5CF.tmp
    C:\pos5D.tmp
    C:\pos5D0.tmp
    C:\pos5D1.tmp
    C:\pos5D2.tmp
    C:\pos5D3.tmp
    C:\pos5D4.tmp
    C:\pos5D5.tmp
    C:\pos5D6.tmp
    C:\pos5D7.tmp
    C:\pos5D8.tmp
    C:\pos5D9.tmp
    C:\pos5DA.tmp
    C:\pos5DB.tmp
    C:\pos5DC.tmp
    C:\pos5DD.tmp
    C:\pos5DE.tmp
    C:\pos5DF.tmp
    C:\pos5E.tmp
    C:\pos5E0.tmp
    C:\pos5E1.tmp
    C:\pos5E2.tmp
    C:\pos5E3.tmp
    C:\pos5E4.tmp
    C:\pos5E5.tmp
    C:\pos5E6.tmp
    C:\pos5E7.tmp
    C:\pos5E8.tmp
    C:\pos5E9.tmp
    C:\pos5EA.tmp
    C:\pos5EB.tmp
    C:\pos5EC.tmp
    C:\pos5ED.tmp
    C:\pos5EE.tmp
    C:\pos5EF.tmp
    C:\pos5F.tmp
    C:\pos5F0.tmp
    C:\pos5F1.tmp
    C:\pos5F2.tmp
    C:\pos5F3.tmp
    C:\pos5F4.tmp
    C:\pos5F5.tmp
    C:\pos5F6.tmp
    C:\pos5F7.tmp
    C:\pos5F8.tmp
    C:\pos5F9.tmp
    C:\pos5FA.tmp
    C:\pos5FB.tmp
    C:\pos5FC.tmp
    C:\pos5FD.tmp
    C:\pos5FE.tmp
    C:\pos5FF.tmp
    C:\pos6.tmp
    C:\pos60.tmp
    C:\pos600.tmp
    C:\pos601.tmp
    C:\pos602.tmp
    C:\pos603.tmp
    C:\pos604.tmp
    C:\pos605.tmp
    C:\pos606.tmp
    C:\pos607.tmp
    C:\pos608.tmp
    C:\pos609.tmp
    C:\pos60A.tmp
    C:\pos60B.tmp
    C:\pos60C.tmp
    C:\pos60D.tmp
    C:\pos60E.tmp
    C:\pos60F.tmp
    C:\pos61.tmp
    C:\pos610.tmp
    C:\pos611.tmp
    C:\pos612.tmp
    C:\pos613.tmp
    C:\pos614.tmp
    C:\pos615.tmp
    C:\pos616.tmp
    C:\pos617.tmp
    C:\pos618.tmp
    C:\pos619.tmp
    C:\pos61A.tmp
    C:\pos61B.tmp
    C:\pos61C.tmp
    C:\pos61D.tmp
    C:\pos61E.tmp
    C:\pos61F.tmp
    C:\pos62.tmp
    C:\pos620.tmp
    C:\pos621.tmp
    C:\pos622.tmp
    C:\pos623.tmp
    C:\pos624.tmp
    C:\pos625.tmp
    C:\pos626.tmp
    C:\pos627.tmp
    C:\pos628.tmp
    C:\pos629.tmp
    C:\pos62A.tmp
    C:\pos62B.tmp
    C:\pos62C.tmp
    C:\pos62D.tmp
    C:\pos62E.tmp
    C:\pos62F.tmp
    C:\pos63.tmp
    C:\pos630.tmp
    C:\pos631.tmp
    C:\pos632.tmp
    C:\pos633.tmp
    C:\pos634.tmp
    C:\pos635.tmp
    C:\pos636.tmp
    C:\pos637.tmp
    C:\pos638.tmp
    C:\pos639.tmp
    C:\pos63A.tmp
    C:\pos63B.tmp
    C:\pos63C.tmp
    C:\pos63D.tmp
    C:\pos63E.tmp
    C:\pos63F.tmp
    C:\pos64.tmp
    C:\pos640.tmp
    C:\pos641.tmp
    C:\pos642.tmp
    C:\pos643.tmp
    C:\pos644.tmp
    C:\pos645.tmp
    C:\pos646.tmp
    C:\pos647.tmp
    C:\pos648.tmp
    C:\pos649.tmp
    C:\pos64A.tmp
    C:\pos64B.tmp
    C:\pos64C.tmp
    C:\pos64D.tmp
    C:\pos64E.tmp
    C:\pos64F.tmp
    C:\pos65.tmp
    C:\pos650.tmp
    C:\pos651.tmp
    C:\pos652.tmp
    C:\pos653.tmp
    C:\pos654.tmp
    C:\pos655.tmp
    C:\pos656.tmp
    C:\pos657.tmp
    C:\pos658.tmp
    C:\pos659.tmp
    C:\pos65A.tmp
    C:\pos65B.tmp
    C:\pos65C.tmp
    C:\pos65D.tmp
    C:\pos65E.tmp
    C:\pos65F.tmp
    C:\pos66.tmp
    C:\pos660.tmp
    C:\pos661.tmp
    C:\pos662.tmp
    C:\pos663.tmp
    C:\pos664.tmp
    C:\pos665.tmp
    C:\pos666.tmp
    C:\pos667.tmp
    C:\pos668.tmp
    C:\pos669.tmp
    C:\pos66A.tmp
    C:\pos66B.tmp
    C:\pos66C.tmp
    C:\pos66D.tmp
    C:\pos66E.tmp
    C:\pos66F.tmp
    C:\pos67.tmp
    C:\pos670.tmp
    C:\pos671.tmp
    C:\pos672.tmp
    C:\pos673.tmp
    C:\pos674.tmp
    C:\pos675.tmp
    C:\pos676.tmp
    C:\pos677.tmp
    C:\pos678.tmp
    C:\pos679.tmp
    C:\pos67A.tmp
    C:\pos67B.tmp
    C:\pos67C.tmp
    C:\pos67D.tmp
    C:\pos67E.tmp
    C:\pos67F.tmp

  6. #6
    Junior Member
    Join Date
    Jan 2008
    Posts
    17

    Default

    combofix log pt 3:

    C:\pos68.tmp
    C:\pos680.tmp
    C:\pos681.tmp
    C:\pos682.tmp
    C:\pos683.tmp
    C:\pos684.tmp
    C:\pos685.tmp
    C:\pos686.tmp
    C:\pos687.tmp
    C:\pos688.tmp
    C:\pos689.tmp
    C:\pos68A.tmp
    C:\pos68B.tmp
    C:\pos68C.tmp
    C:\pos68D.tmp
    C:\pos68E.tmp
    C:\pos68F.tmp
    C:\pos69.tmp
    C:\pos690.tmp
    C:\pos691.tmp
    C:\pos692.tmp
    C:\pos693.tmp
    C:\pos694.tmp
    C:\pos695.tmp
    C:\pos696.tmp
    C:\pos697.tmp
    C:\pos698.tmp
    C:\pos699.tmp
    C:\pos69A.tmp
    C:\pos69B.tmp
    C:\pos69C.tmp
    C:\pos69D.tmp
    C:\pos69E.tmp
    C:\pos69F.tmp
    C:\pos6A.tmp
    C:\pos6A0.tmp
    C:\pos6A1.tmp
    C:\pos6A2.tmp
    C:\pos6A3.tmp
    C:\pos6A4.tmp
    C:\pos6A5.tmp
    C:\pos6A6.tmp
    C:\pos6A7.tmp
    C:\pos6A8.tmp
    C:\pos6A9.tmp
    C:\pos6AA.tmp
    C:\pos6AB.tmp
    C:\pos6AC.tmp
    C:\pos6AD.tmp
    C:\pos6AE.tmp
    C:\pos6AF.tmp
    C:\pos6B.tmp
    C:\pos6B0.tmp
    C:\pos6B1.tmp
    C:\pos6B2.tmp
    C:\pos6B3.tmp
    C:\pos6B4.tmp
    C:\pos6B5.tmp
    C:\pos6B6.tmp
    C:\pos6B7.tmp
    C:\pos6B8.tmp
    C:\pos6B9.tmp
    C:\pos6BA.tmp
    C:\pos6BB.tmp
    C:\pos6BC.tmp
    C:\pos6BD.tmp
    C:\pos6BE.tmp
    C:\pos6BF.tmp
    C:\pos6C.tmp
    C:\pos6C0.tmp
    C:\pos6C1.tmp
    C:\pos6C2.tmp
    C:\pos6C3.tmp
    C:\pos6C4.tmp
    C:\pos6C5.tmp
    C:\pos6C6.tmp
    C:\pos6C7.tmp
    C:\pos6C8.tmp
    C:\pos6C9.tmp
    C:\pos6CA.tmp
    C:\pos6CB.tmp
    C:\pos6CC.tmp
    C:\pos6CD.tmp
    C:\pos6D.tmp
    C:\pos6E.tmp
    C:\pos6F.tmp
    C:\pos7.tmp
    C:\pos70.tmp
    C:\pos71.tmp
    C:\pos72.tmp
    C:\pos73.tmp
    C:\pos74.tmp
    C:\pos75.tmp
    C:\pos76.tmp
    C:\pos77.tmp
    C:\pos78.tmp
    C:\pos79.tmp
    C:\pos7A.tmp
    C:\pos7B.tmp
    C:\pos7C.tmp
    C:\pos7D.tmp
    C:\pos7E.tmp
    C:\pos7F.tmp
    C:\pos8.tmp
    C:\pos80.tmp
    C:\pos81.tmp
    C:\pos82.tmp
    C:\pos83.tmp
    C:\pos84.tmp
    C:\pos85.tmp
    C:\pos86.tmp
    C:\pos87.tmp
    C:\pos88.tmp
    C:\pos89.tmp
    C:\pos8A.tmp
    C:\pos8B.tmp
    C:\pos8C.tmp
    C:\pos8D.tmp
    C:\pos8E.tmp
    C:\pos8F.tmp
    C:\pos9.tmp
    C:\pos90.tmp
    C:\pos91.tmp
    C:\pos92.tmp
    C:\pos93.tmp
    C:\pos94.tmp
    C:\pos95.tmp
    C:\pos96.tmp
    C:\pos97.tmp
    C:\pos98.tmp
    C:\pos99.tmp
    C:\pos9A.tmp
    C:\pos9B.tmp
    C:\pos9C.tmp
    C:\pos9D.tmp
    C:\pos9E.tmp
    C:\pos9F.tmp
    C:\posA.tmp
    C:\posA0.tmp
    C:\posA1.tmp
    C:\posA2.tmp
    C:\posA3.tmp
    C:\posA4.tmp
    C:\posA5.tmp
    C:\posA6.tmp
    C:\posA7.tmp
    C:\posA8.tmp
    C:\posA9.tmp
    C:\posAA.tmp
    C:\posAB.tmp
    C:\posAC.tmp
    C:\posAD.tmp
    C:\posAE.tmp
    C:\posAF.tmp
    C:\posB.tmp
    C:\posB0.tmp
    C:\posB1.tmp
    C:\posB2.tmp
    C:\posB3.tmp
    C:\posB4.tmp
    C:\posB5.tmp
    C:\posB6.tmp
    C:\posB7.tmp
    C:\posB8.tmp
    C:\posB9.tmp
    C:\posBA.tmp
    C:\posBB.tmp
    C:\posBC.tmp
    C:\posBD.tmp
    C:\posBE.tmp
    C:\posBF.tmp
    C:\posC.tmp
    C:\posC0.tmp
    C:\posC1.tmp
    C:\posC2.tmp
    C:\posC3.tmp
    C:\posC4.tmp
    C:\posC5.tmp
    C:\posC6.tmp
    C:\posC7.tmp
    C:\posC8.tmp
    C:\posC9.tmp
    C:\posCA.tmp
    C:\posCB.tmp
    C:\posCC.tmp
    C:\posCD.tmp
    C:\posCE.tmp
    C:\posCF.tmp
    C:\posD.tmp
    C:\posD0.tmp
    C:\posD1.tmp
    C:\posD2.tmp
    C:\posD3.tmp
    C:\posD4.tmp
    C:\posD5.tmp
    C:\posD6.tmp
    C:\posD7.tmp
    C:\posD8.tmp
    C:\posD9.tmp
    C:\posDA.tmp
    C:\posDB.tmp
    C:\posDC.tmp
    C:\posDD.tmp
    C:\posDE.tmp
    C:\posDF.tmp
    C:\posE.tmp
    C:\posE0.tmp
    C:\posE1.tmp
    C:\posE2.tmp
    C:\posE3.tmp
    C:\posE4.tmp
    C:\posE5.tmp
    C:\posE6.tmp
    C:\posE7.tmp
    C:\posE8.tmp
    C:\posE9.tmp
    C:\posEA.tmp
    C:\posEB.tmp
    C:\posEC.tmp
    C:\posED.tmp
    C:\posEE.tmp
    C:\posEF.tmp
    C:\posF.tmp
    C:\posF0.tmp
    C:\posF1.tmp
    C:\posF2.tmp
    C:\posF3.tmp
    C:\posF4.tmp
    C:\posF5.tmp
    C:\posF6.tmp
    C:\posF7.tmp
    C:\posF8.tmp
    C:\posF9.tmp
    C:\posFA.tmp
    C:\posFB.tmp
    C:\posFC.tmp
    C:\posFD.tmp
    C:\posFE.tmp
    C:\posFF.tmp
    C:\WINDOWS\cookies.ini
    C:\WINDOWS\system32\ctfmon.exe.tmp
    C:\WINDOWS\system32\gebyv.dll
    C:\WINDOWS\system32\mcrh.tmp
    C:\WINDOWS\system32\msvcsv60.dll
    C:\WINDOWS\system32\rbcvuxrp.ini
    C:\WINDOWS\system32\vybeg.ini
    C:\WINDOWS\system32\vybeg.ini2

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

    .
    -------\LEGACY_DOMAINSERVICE


    ((((((((((((((((((((((((( Files Created from 2007-12-15 to 2008-01-15 )))))))))))))))))))))))))))))))
    .

    2008-01-15 13:50 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
    2008-01-15 02:33 . 2008-01-15 14:42 2,128,928 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
    2008-01-15 02:33 . 2008-01-15 14:42 7,148 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
    2008-01-15 01:36 . 2008-01-15 14:42 9,504 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
    2008-01-15 01:36 . 2008-01-15 14:42 1,940 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
    2008-01-15 01:19 . 2008-01-15 01:19 <DIR> d-------- C:\Program Files\Kaspersky Lab
    2008-01-15 01:19 . 2008-01-15 13:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
    2008-01-15 01:13 . 2008-01-15 01:13 <DIR> d-------- C:\KAV
    2008-01-14 18:04 . 2008-01-14 19:48 <DIR> d-------- C:\VundoFix Backups
    2008-01-13 11:52 . 2008-01-14 00:16 <DIR> d-------- C:\Documents and Settings\User\Application Data\Uniblue
    2008-01-13 11:46 . 2008-01-13 23:51 <DIR> d-------- C:\Program Files\Uniblue
    2008-01-12 03:23 . 2008-01-14 21:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avira
    2008-01-11 20:25 . 2008-01-11 20:25 <DIR> d-------- C:\Program Files\AVI MPEG RM WMV Joiner
    2008-01-07 23:40 . 2008-01-15 13:28 15,360 --a------ C:\WINDOWS\system32\ctfmon .exe
    2008-01-07 15:58 . 2008-01-07 19:24 <DIR> d-------- C:\DVD_01_1
    2008-01-07 14:46 . 2008-01-07 14:47 1,067 --a------ C:\WINDOWS\ARPR.INI
    2008-01-07 13:46 . 2008-01-07 13:46 <DIR> d-------- C:\WINDOWS\WinAVI Video Converter 9.0
    2008-01-07 13:46 . 2008-01-07 13:46 <DIR> d-------- C:\Program Files\WinAVI Video Converter 9.0
    2008-01-06 00:00 . 2008-01-06 00:00 <DIR> d-------- C:\Program Files\uTorrent
    2008-01-06 00:00 . 2008-01-14 00:16 <DIR> d-------- C:\Documents and Settings\User\Application Data\uTorrent
    2008-01-05 14:59 . 2008-01-14 14:39 54,156 --ah----- C:\WINDOWS\QTFont.qfn
    2008-01-05 14:59 . 2008-01-05 14:59 1,409 --a------ C:\WINDOWS\QTFont.for
    2008-01-05 13:42 . 2008-01-05 13:42 <DIR> d-------- C:\Documents and Settings\User\Application Data\Flickr
    2008-01-05 13:41 . 2008-01-05 13:42 <DIR> d-------- C:\Program Files\Flickr Uploadr
    2008-01-04 16:27 . 2008-01-05 00:15 <DIR> d-------- C:\Documents and Settings\User\Application Data\FileZilla
    2008-01-04 15:51 . 2008-01-04 15:51 <DIR> d-------- C:\NFRoot
    2008-01-04 15:47 . 2008-01-04 15:47 <DIR> d-------- C:\Program Files\FileZilla FTP Client
    2008-01-04 15:46 . 2008-01-04 16:00 <DIR> d-------- C:\Program Files\Fastream IQ Web FTP Server GUI
    2008-01-04 15:45 . 2008-01-04 19:23 <DIR> d-------- C:\Program Files\Fastream IQ Web FTP Server Engine
    2008-01-04 15:04 . 2008-01-04 15:04 <DIR> d-------- C:\Program Files\Ableton
    2008-01-04 15:03 . 2003-06-20 12:28 1,777,664 --a------ C:\WINDOWS\system32\gdiplus.dll
    2008-01-01 12:41 . 2007-03-17 11:11 675,840 -ra------ C:\WINDOWS\system32\hpowiax3.dll
    2008-01-01 12:41 . 2007-03-17 11:11 569,344 -ra------ C:\WINDOWS\system32\hpotscl3.dll
    2008-01-01 12:41 . 2007-03-17 11:11 303,104 -ra------ C:\WINDOWS\system32\hpovst10.dll
    2007-12-31 16:22 . 2007-12-31 16:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
    2007-12-31 16:22 . 2007-03-07 23:20 49,920 -ra------ C:\WINDOWS\system32\drivers\HPZid412.sys
    2007-12-31 16:22 . 2007-03-07 23:20 16,496 -ra------ C:\WINDOWS\system32\drivers\HPZipr12.sys
    2007-12-31 16:21 . 2007-03-07 23:20 364,544 -ra------ C:\WINDOWS\system32\hppldcoi.dll
    2007-12-31 16:21 . 2007-03-07 23:20 309,760 -ra------ C:\WINDOWS\system32\difxapi.dll
    2007-12-31 16:21 . 2007-03-30 10:07 267,864 -ra------ C:\WINDOWS\system32\hpzids01.dll
    2007-12-31 16:21 . 2007-03-28 14:01 117,760 --a------ C:\WINDOWS\system32\hpzll5ha.dll
    2007-12-31 16:21 . 2007-03-07 23:20 21,568 -ra------ C:\WINDOWS\system32\drivers\HPZius12.sys

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-01-15 18:27 96,256 ----a-w C:\WINDOWS\system32\drivers\sptd0253.sys
    2008-01-15 17:34 --------- d-----w C:\Program Files\QuickTime
    2008-01-14 02:47 --------- d-----w C:\Program Files\Apple Software Update
    2008-01-13 17:07 --------- d-----w C:\Program Files\Soulseek-Test
    2008-01-11 00:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
    2008-01-09 00:12 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2008-01-04 20:04 --------- d-----w C:\Documents and Settings\User\Application Data\Ableton
    2008-01-04 06:14 --------- d-----w C:\Program Files\Soulseek
    2008-01-03 23:40 --------- d-----w C:\Documents and Settings\User\Application Data\RipIt4Me
    2007-12-27 08:42 --------- d-----w C:\Program Files\Yahoo!
    2007-12-27 08:41 --------- d-----w C:\Program Files\CyberLink DVD Solution
    2007-12-27 08:37 --------- d-----w C:\Program Files\Sonic Foundry
    2007-12-24 07:46 --------- d-----w C:\Documents and Settings\User\Application Data\REAPER
    2007-12-07 17:21 --------- d-----w C:\Program Files\REAPER
    2007-11-23 21:07 --------- d-----w C:\Program Files\Freecorder
    2007-11-23 00:15 560 ----a-w C:\Documents and Settings\User\Application Data\ViewerApp.dat
    2007-11-18 07:41 --------- d-----w C:\Program Files\Waves
    2007-11-18 07:40 --------- d-----w C:\Program Files\Common Files\PACE Anti-Piracy
    2007-11-18 07:40 --------- d-----w C:\Documents and Settings\User\Application Data\Waves Audio
    2007-11-18 07:40 --------- d-----w C:\Documents and Settings\User\Application Data\PACE Anti-Piracy
    2007-11-18 07:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\PACE Anti-Piracy
    2007-11-18 07:36 72,032 ----a-w C:\WINDOWS\system32\drivers\TPkd.sys
    2007-11-18 07:36 27,328 ----a-w C:\WINDOWS\system32\drivers\iLokDrvr.sys
    2007-11-17 22:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\yahoo!
    2007-11-16 03:10 --------- d-----w C:\Program Files\Common Files\Scanner
    2007-11-16 02:45 --------- d-----w C:\Program Files\Windows Live
    2007-11-16 02:44 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
    2007-11-16 02:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
    2007-11-15 22:34 --------- d-----w C:\Program Files\iZotope
    2007-05-24 02:42 298 ----a-w C:\Program Files\INSTALL.LOG
    2004-03-11 17:27 40,960 ----a-w C:\Program Files\Uninstall_CDS.exe
    .
    Code:
    <pre>
    ----a-w         1,871,872 2008-01-15 18:28:38  C:\Program Files\Ahead\Nero BackItUp\NBJ                     .exe
    ----a-w         2,234,368 2008-01-15 18:28:13  C:\Program Files\Ahead\Nero BackItUp\NBJ                    .exe
    ----a-w         2,234,368 2008-01-15 18:20:09  C:\Program Files\Ahead\Nero BackItUp\NBJ                   .exe
    ----a-w         2,234,368 2008-01-15 18:10:06  C:\Program Files\Ahead\Nero BackItUp\NBJ                  .exe
    ----a-w           231,952 2008-01-15 18:28:28  C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp   .exe
    ----a-w           231,952 2008-01-15 19:44:28  C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp  .exe
    ----a-w           569,856 2008-01-15 18:20:11  C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp .exe
    ----a-w         1,877,272 2008-01-14 16:05:49  C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster .exe
    ----a-w         9,495,832 2008-01-14 16:06:35  C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC .exe
    ----a-w         1,269,000 2008-01-14 16:05:47  C:\Program Files\Uniblue\SpyEraser\SpyEraser .exe
    ----a-w           224,248 2008-01-15 07:32:42  C:\Program Files\Yahoo!\Search Protection\SearchProtection .exe
    ----a-w            15,360 2008-01-15 18:28:31  C:\WINDOWS\system32\ctfmon .exe
    </pre>

    ((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a00a30d9-2b3e-42a6-87c1-97d471064a21}]
    C:\WINDOWS\system32\dkvgmhbx.dll

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:00 15360]
    "NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ .exe" [2008-01-15 13:28 1871872]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp .exe" [2008-01-15 14:44 231952]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 07:00 15360]
    "DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 15:38 39264]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\opnnkjk]
    opnnkjk.dll

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    Authentication Packages REG_MULTI_SZ msv1_0 C:\\WINDOWS\\system32\\gebyv

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ]
    C:\Program Files\Ahead\Nero BackItUp\NBJ.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
    --a------ 2007-12-17 17:13 3810544 C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe

    R1 Asapi;Asapi;C:\WINDOWS\system32\drivers\Asapi.sys [2002-04-17 19:27]
    R2 NFService;Fastream IQ Web/FTP Server;C:\PROGRA~1\FASTRE~1\IQWebFTPServerEngine.exe [2007-07-21 13:28]
    R3 CLEDX;Team H2O CLEDX service;C:\WINDOWS\system32\DRIVERS\cledx.sys [2005-05-09 20:08]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a910635d-19d7-11da-952a-806d6172696f}]
    \Shell\AutoRun\command - D:\setup.exe

    .
    Contents of the 'Scheduled Tasks' folder
    "2008-01-15 19:46:20 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
    - C:\Program Files\Windows Defender\MpCmdRun.exe
    .
    **************************************************************************

    catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-01-15 14:43:34
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    C:\WINDOWS\system32\gebyv.dll 324608 bytes executable

    scan completed successfully
    hidden files: 1

    **************************************************************************
    .
    Completion time: 2008-01-15 14:47:27 - machine was rebooted
    ComboFix-quarantined-files.txt 2008-01-15 19:47:23
    .
    2008-01-11 22:37:58 --- E O F ---

    thanks again!

  7. #7
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Hi

    Vundo file infector there.

    It means that you may need to uninstall/re-install certain programs when you're clean, including KAV.

    Don't do it now.

    Open notepad and copy/paste the text in the quotebox below into it:

    Code:
    Rootkit::
    C:\WINDOWS\system32\gebyv.dll 
    
    File::
    C:\WINDOWS\system32\ctfmon .exe
    C:\Program Files\Ahead\Nero BackItUp\NBJ                     .exe
    C:\Program Files\Ahead\Nero BackItUp\NBJ                    .exe
    C:\Program Files\Ahead\Nero BackItUp\NBJ                   .exe
    C:\Program Files\Ahead\Nero BackItUp\NBJ                  .exe
    C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp   .exe
    C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp  .exe
    C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp .exe
    C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster .exe
    C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC .exe
    C:\Program Files\Uniblue\SpyEraser\SpyEraser .exe
    C:\Program Files\Yahoo!\Search Protection\SearchProtection .exe
    
    Registry::
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a00a30d9-2b3e-42a6-87c1-97d471064a21}]
    
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\opnnkjk]
    
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
    "Authentication Packages"=hex(7):6d,73,76,31,5f,30,00,00
    Save this as "CFScript"

    Then drag the CFScript into ComboFix.exe as you see in the screenshot below.



    This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.

    Combofix should never take more that 20 minutes including the reboot if malware is detected.
    If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
    If that happened we want to know, and also what process you had to end.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  8. #8
    Junior Member
    Join Date
    Jan 2008
    Posts
    17

    Default

    thanks alot for your help, this is really cool of you.

    combofix log:

    ComboFix 08-01-15.4 - User 2008-01-16 11:12:10.2 - NTFSx86
    Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.47 [GMT -5:00]
    Running from: C:\Documents and Settings\User\Desktop\ComboFix.exe
    Command switches used :: C:\Documents and Settings\User\Desktop\CFScript.txt
    * Created a new restore point

    WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

    FILE
    C:\Program Files\Ahead\Nero BackItUp\NBJ .exe
    C:\Program Files\Ahead\Nero BackItUp\NBJ .exe
    C:\Program Files\Ahead\Nero BackItUp\NBJ .exe
    C:\Program Files\Ahead\Nero BackItUp\NBJ .exe
    C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp .exe
    C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp .exe
    C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp .exe
    C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster .exe
    C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC .exe
    C:\Program Files\Uniblue\SpyEraser\SpyEraser .exe
    C:\Program Files\Yahoo!\Search Protection\SearchProtection .exe
    C:\WINDOWS\system32\ctfmon .exe
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\Program Files\Ahead\Nero BackItUp\NBJ .exe
    C:\Program Files\Ahead\Nero BackItUp\NBJ .exe
    C:\Program Files\Ahead\Nero BackItUp\NBJ .exe
    C:\Program Files\Ahead\Nero BackItUp\NBJ .exe
    C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp .exe
    C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp .exe
    C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp .exe
    C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster .exe
    C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC .exe
    C:\Program Files\Uniblue\SpyEraser\SpyEraser .exe
    C:\Program Files\Yahoo!\Search Protection\SearchProtection .exe
    C:\WINDOWS\system32\ctfmon .exe
    C:\WINDOWS\system32\ctfmon.exe.tmp
    C:\WINDOWS\system32\gebyv.dll
    C:\WINDOWS\system32\gebyv.exe
    C:\WINDOWS\system32\vybeg.ini
    C:\WINDOWS\system32\vybeg.ini2

    .
    ((((((((((((((((((((((((( Files Created from 2007-12-16 to 2008-01-16 )))))))))))))))))))))))))))))))
    .

    2008-01-15 13:50 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
    2008-01-15 02:33 . 2008-01-16 11:20 2,128,928 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
    2008-01-15 02:33 . 2008-01-16 11:20 25,076 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
    2008-01-15 01:36 . 2008-01-16 11:20 21,024 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
    2008-01-15 01:36 . 2008-01-16 11:20 3,044 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
    2008-01-15 01:19 . 2008-01-15 01:19 <DIR> d-------- C:\Program Files\Kaspersky Lab
    2008-01-15 01:19 . 2008-01-16 10:38 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
    2008-01-15 01:13 . 2008-01-15 01:13 <DIR> d-------- C:\KAV
    2008-01-14 18:04 . 2008-01-14 19:48 <DIR> d-------- C:\VundoFix Backups
    2008-01-13 11:52 . 2008-01-14 00:16 <DIR> d-------- C:\Documents and Settings\User\Application Data\Uniblue
    2008-01-13 11:46 . 2008-01-13 23:51 <DIR> d-------- C:\Program Files\Uniblue
    2008-01-12 03:23 . 2008-01-14 21:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avira
    2008-01-11 20:25 . 2008-01-11 20:25 <DIR> d-------- C:\Program Files\AVI MPEG RM WMV Joiner
    2008-01-07 14:46 . 2008-01-07 14:47 1,067 --a------ C:\WINDOWS\ARPR.INI
    2008-01-07 13:46 . 2008-01-07 13:46 <DIR> d-------- C:\WINDOWS\WinAVI Video Converter 9.0
    2008-01-07 13:46 . 2008-01-07 13:46 <DIR> d-------- C:\Program Files\WinAVI Video Converter 9.0
    2008-01-06 00:00 . 2008-01-06 00:00 <DIR> d-------- C:\Program Files\uTorrent
    2008-01-06 00:00 . 2008-01-14 00:16 <DIR> d-------- C:\Documents and Settings\User\Application Data\uTorrent
    2008-01-05 14:59 . 2008-01-15 21:54 54,156 --ah----- C:\WINDOWS\QTFont.qfn
    2008-01-05 14:59 . 2008-01-05 14:59 1,409 --a------ C:\WINDOWS\QTFont.for
    2008-01-05 13:42 . 2008-01-05 13:42 <DIR> d-------- C:\Documents and Settings\User\Application Data\Flickr
    2008-01-05 13:41 . 2008-01-15 15:45 <DIR> d-------- C:\Program Files\Flickr Uploadr
    2008-01-04 16:27 . 2008-01-05 00:15 <DIR> d-------- C:\Documents and Settings\User\Application Data\FileZilla
    2008-01-04 15:51 . 2008-01-04 15:51 <DIR> d-------- C:\NFRoot
    2008-01-04 15:47 . 2008-01-04 15:47 <DIR> d-------- C:\Program Files\FileZilla FTP Client
    2008-01-04 15:46 . 2008-01-04 16:00 <DIR> d-------- C:\Program Files\Fastream IQ Web FTP Server GUI
    2008-01-04 15:45 . 2008-01-04 19:23 <DIR> d-------- C:\Program Files\Fastream IQ Web FTP Server Engine
    2008-01-04 15:04 . 2008-01-04 15:04 <DIR> d-------- C:\Program Files\Ableton
    2008-01-04 15:03 . 2003-06-20 12:28 1,777,664 --a------ C:\WINDOWS\system32\gdiplus.dll
    2008-01-01 12:41 . 2007-03-17 11:11 675,840 -ra------ C:\WINDOWS\system32\hpowiax3.dll
    2008-01-01 12:41 . 2007-03-17 11:11 569,344 -ra------ C:\WINDOWS\system32\hpotscl3.dll
    2008-01-01 12:41 . 2007-03-17 11:11 303,104 -ra------ C:\WINDOWS\system32\hpovst10.dll
    2007-12-31 16:22 . 2007-12-31 16:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
    2007-12-31 16:22 . 2007-03-07 23:20 49,920 -ra------ C:\WINDOWS\system32\drivers\HPZid412.sys
    2007-12-31 16:22 . 2007-03-07 23:20 16,496 -ra------ C:\WINDOWS\system32\drivers\HPZipr12.sys
    2007-12-31 16:21 . 2007-03-07 23:20 364,544 -ra------ C:\WINDOWS\system32\hppldcoi.dll
    2007-12-31 16:21 . 2007-03-07 23:20 309,760 -ra------ C:\WINDOWS\system32\difxapi.dll
    2007-12-31 16:21 . 2007-03-30 10:07 267,864 -ra------ C:\WINDOWS\system32\hpzids01.dll
    2007-12-31 16:21 . 2007-03-28 14:01 117,760 --a------ C:\WINDOWS\system32\hpzll5ha.dll
    2007-12-31 16:21 . 2007-03-07 23:20 21,568 -ra------ C:\WINDOWS\system32\drivers\HPZius12.sys

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-01-16 02:16 --------- d-----w C:\Program Files\Soulseek-Test
    2008-01-15 18:27 96,256 ----a-w C:\WINDOWS\system32\drivers\sptd0253.sys
    2008-01-15 17:34 --------- d-----w C:\Program Files\QuickTime
    2008-01-14 02:47 --------- d-----w C:\Program Files\Apple Software Update
    2008-01-11 00:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
    2008-01-09 00:12 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2008-01-04 20:04 --------- d-----w C:\Documents and Settings\User\Application Data\Ableton
    2008-01-04 06:14 --------- d-----w C:\Program Files\Soulseek
    2008-01-03 23:40 --------- d-----w C:\Documents and Settings\User\Application Data\RipIt4Me
    2007-12-27 08:42 --------- d-----w C:\Program Files\Yahoo!
    2007-12-27 08:41 --------- d-----w C:\Program Files\CyberLink DVD Solution
    2007-12-27 08:37 --------- d-----w C:\Program Files\Sonic Foundry
    2007-12-24 07:46 --------- d-----w C:\Documents and Settings\User\Application Data\REAPER
    2007-12-07 17:21 --------- d-----w C:\Program Files\REAPER
    2007-11-23 21:07 --------- d-----w C:\Program Files\Freecorder
    2007-11-23 00:15 560 ----a-w C:\Documents and Settings\User\Application Data\ViewerApp.dat
    2007-11-18 07:41 --------- d-----w C:\Program Files\Waves
    2007-11-18 07:40 --------- d-----w C:\Program Files\Common Files\PACE Anti-Piracy
    2007-11-18 07:40 --------- d-----w C:\Documents and Settings\User\Application Data\Waves Audio
    2007-11-18 07:40 --------- d-----w C:\Documents and Settings\User\Application Data\PACE Anti-Piracy
    2007-11-18 07:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\PACE Anti-Piracy
    2007-11-18 07:36 72,032 ----a-w C:\WINDOWS\system32\drivers\TPkd.sys
    2007-11-18 07:36 27,328 ----a-w C:\WINDOWS\system32\drivers\iLokDrvr.sys
    2007-11-17 22:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\yahoo!
    2007-11-16 03:10 --------- d-----w C:\Program Files\Common Files\Scanner
    2007-11-16 02:45 --------- d-----w C:\Program Files\Windows Live
    2007-11-16 02:44 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
    2007-11-16 02:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
    2007-05-24 02:42 298 ----a-w C:\Program Files\INSTALL.LOG
    2004-03-11 17:27 40,960 ----a-w C:\Program Files\Uninstall_CDS.exe
    .
    Code:
    <pre>
    ----a-w         1,871,872 2008-01-16 16:21:37  C:\Program Files\Ahead\Nero BackItUp\NBJ                         .exe
    ----a-w         2,234,368 2008-01-16 16:12:28  C:\Program Files\Ahead\Nero BackItUp\NBJ                        .exe
    ----a-w         2,234,368 2008-01-16 15:35:49  C:\Program Files\Ahead\Nero BackItUp\NBJ                       .exe
    ----a-w         2,234,368 2008-01-16 04:28:59  C:\Program Files\Ahead\Nero BackItUp\NBJ                      .exe
    ----a-w           231,952 2008-01-16 04:29:04  C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp    .exe
    </pre>

    ((((((((((((((((((((((((((((( snapshot@2008-01-15_14.47.04.18 )))))))))))))))))))))))))))))))))))))))))
    .
    - 2008-01-15 18:53:16 229,376 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
    + 2008-01-16 16:11:01 229,376 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
    - 2008-01-15 18:53:17 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
    + 2008-01-16 16:11:02 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
    - 2008-01-15 18:53:17 229,376 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
    + 2008-01-16 16:11:02 229,376 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
    - 2008-01-15 18:53:17 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
    + 2008-01-16 16:11:02 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
    - 2008-01-15 18:53:18 7,802,880 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\ntuser.dat
    + 2008-01-16 16:11:03 7,802,880 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\ntuser.dat
    - 2008-01-15 18:53:19 118,784 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
    + 2008-01-16 16:11:03 118,784 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
    .
    ((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    ----a-w 180,269 2006-04-24 06:21:50 C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe

    ----a-w 68,856 2007-08-24 19:03:30 C:\Program Files\Google\GoogleToolbarNotifier\bak\GoogleToolbarNotifier.exe

    ----a-w 385,024 2005-10-23 04:00:00 C:\Program Files\Syncrosoft\POS\H2O\bak\cledx.exe
    ----a-w 385,024 2005-10-23 05:00:00 C:\Program Files\Syncrosoft\POS\H2O\cledx.exe

    ----a-w 204,288 2006-10-19 01:05:26 C:\Program Files\Windows Media Player\bak\WMPNSCFG.exe

    ----a-w 15,360 2004-08-04 12:00:00 C:\WINDOWS\system32\bak\ctfmon.exe
    ----a-w 15,360 2004-08-04 12:00:00 C:\WINDOWS\system32\ctfmon.exe

    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:00 15360]
    "NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ .exe" [2008-01-16 11:21 1871872]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp .exe" [ ]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 07:00 15360]
    "DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 15:38 39264]

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    Authentication Packages REG_MULTI_SZ msv1_0 C:\\WINDOWS\\system32\\gebyv

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ]
    C:\Program Files\Ahead\Nero BackItUp\NBJ.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
    --a------ 2007-12-17 17:13 3810544 C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe

    R1 Asapi;Asapi;C:\WINDOWS\system32\drivers\Asapi.sys [2002-04-17 19:27]
    R2 NFService;Fastream IQ Web/FTP Server;C:\PROGRA~1\FASTRE~1\IQWebFTPServerEngine.exe [2007-07-21 13:28]
    R3 CLEDX;Team H2O CLEDX service;C:\WINDOWS\system32\DRIVERS\cledx.sys [2005-05-09 20:08]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a910635d-19d7-11da-952a-806d6172696f}]
    \Shell\AutoRun\command - D:\setup.exe

    .
    Contents of the 'Scheduled Tasks' folder
    "2008-01-16 16:24:19 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
    - C:\Program Files\Windows Defender\MpCmdRun.exe
    .
    **************************************************************************

    catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-01-16 11:21:37
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    Completion time: 2008-01-16 11:25:49 - machine was rebooted
    ComboFix-quarantined-files.txt 2008-01-16 16:25:44
    ComboFix2.txt 2008-01-15 19:47:27
    .
    2008-01-16 00:45:11 --- E O F ---

  9. #9
    Junior Member
    Join Date
    Jan 2008
    Posts
    17

    Default

    and, the HJT log....

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 11:26:53 AM, on 16/01/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16574)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\ctfmon.exe
    C:\PROGRA~1\FASTRE~1\IQWebFTPServerEngine.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\notepad.exe
    C:\Documents and Settings\User\Desktop\OTHER PROGRAMS\HiJackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/...ch/search.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
    O3 - Toolbar: (no name) - {8B79EE88-E62D-4AA8-B530-CC357BA112B7} - (no file)
    O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp .exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ .exe"
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe (file missing)
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://www.surenet.net/
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02...s/MSNPUpld.cab
    O23 - Service: AVP - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp .exe (file missing)
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Fastream IQ Web/FTP Server (NFService) - Fastream Technologies - C:\PROGRA~1\FASTRE~1\IQWebFTPServerEngine.exe

    --
    End of file - 5067 bytes

    thanks again!

  10. #10
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Hi

    Open notepad and copy/paste the text in the quotebox below into it:

    Code:
    File::
    C:\Program Files\Ahead\Nero BackItUp\NBJ                         .exe
    C:\Program Files\Ahead\Nero BackItUp\NBJ                        .exe
    C:\Program Files\Ahead\Nero BackItUp\NBJ                       .exe
    C:\Program Files\Ahead\Nero BackItUp\NBJ                      .exe
    C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp    .exe
    Save this as "CFScript"

    Then drag the CFScript into ComboFix.exe as you see in the screenshot below.



    This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.

    Combofix should never take more that 20 minutes including the reboot if malware is detected.
    If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
    If that happened we want to know, and also what process you had to end.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •