Can't get rid of popups

rjlittin

New member
Hi,

Please help. I've been getting popups for the last few days and I can't seem to get rid of them. I have done virus scans and spybot scans that say that they have fixed the problem but they keep coming back.
Today I have tried a fresh spybot scan but it now stops by it's self after a few minutes saying that the user stopped it. Kaspersky has been running for the last 1 and a half hours and is 9% through it's scan so it will be a while. Here is a copy of my HJT log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:30:17, on 14/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\crypserv.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
c:\program files\common files\installshield\updateservice\isuspm.exe
C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
C:\Program Files\JGsoft\EditPadPro6\EditPadPro.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Trend Micro\HijackThis\scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.fluidmd.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Tiscali
N3 - Netscape 7: # Mozilla User Preferences

/* Do not edit this file.
*
* If you make changes to this file while the browser is running,
* the changes will be overwritten when the browser exits.
*
* To make a manual change to preferences, you can visit the URL about:config
* For more information, see http://www.mozilla.org/unix/customizing.html#prefs
*/

user_pref("browser.activation.checkedNNFlag", true);
user_pref("browser.bookmarks.added_static_root", true);
user_pref("browser.cache.disk.parent_directory", "C:\\DOCUMENTS AND SETTINGS\\ROGER LITTIN\\APPLICATION DATA\\Mozilla\\Profiles\\default\\7n1juq48.slt");
user_pref("browser.download.dir", "C:\\Documents and Settings\\Roger Littin\\My Documents");
user_pref("browser.search.defaultengine", "engine://C%3A%5CPROGRA%7E1%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src");
user_pref("browser.startup.homepage_override.mstone", "rv:1.7.2");
user_pref("browser.tabs.forceHide", true);
user_pref("browser.turbo.showDialog", false);
user_pref("dom.disabl
O1 - Hosts: ##.##.###.### roger ## router ip address
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {4261813A-FAF3-44B7-BCE4-38DA3D8A7309} - C:\WINDOWS\system32\awtqq.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7A03615A-4799-4B8E-B033-B105481CF1D4} - (no file)
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: IE DevToolbar BHO - {CC7E636D-39AA-49b6-B511-65413DA137A1} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O2 - BHO: (no name) - {FED51DF2-9644-4C58-9104-90244EDD6EEC} - C:\WINDOWS\system32\awtqpnm.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Developer Toolbar - {CC962137-2E78-4f94-975E-FC0C07DBD78F} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\RunServices: [SchedulingAgent] C:\WINDOWS\system32\mstask.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Program Files\VisualRoute\vrie.dll
O9 - Extra 'Tools' menuitem: VisualRoute Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Program Files\VisualRoute\vrie.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: IE Developer Toolbar - {48FFE35F-36D9-44bd-A6CC-1D34414EAC0D} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O9 - Extra button: Europa Casino - {4C826F10-D34B-4ba8-B609-1FB8C6482A05} - C:\Casino\Europa Casino\casino.exe (file missing)
O9 - Extra 'Tools' menuitem: Europa Casino - {4C826F10-D34B-4ba8-B609-1FB8C6482A05} - C:\Casino\Europa Casino\casino.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\flashget.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra 'Tools' menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .ocx: C:\Program Files\Opera\PLUGINS\NPFgc1.dll
O12 - Plugin for .ps: C:\Program Files\Opera\PLUGINS\NPFgc1.dll
O12 - Plugin for .tar: C:\Program Files\Opera\PLUGINS\NPFgc1.dll
O12 - Plugin for .zip: C:\Program Files\Opera\PLUGINS\NPFgc1.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.tiscali.co.uk/
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1108071541436
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
O16 - DPF: {E5ABEB00-B357-4884-9949-77B2C71A7EE3} (BoardCtl Class) - http://www.intel.com/design/motherbd/boardid/BoardID.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O18 - Filter hijack: text/html - (no CLSID) - (no file)
O20 - Winlogon Notify: awtqpnm - C:\WINDOWS\SYSTEM32\awtqpnm.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: Flash Media Server (FMS) (FMS) - Macromedia, Inc. - C:\Program Files\Macromedia\Flash Media Server 2\FMSMaster.exe
O23 - Service: Flash Media Administration Server (FMSAdmin) - Macromedia, Inc. - C:\Program Files\Macromedia\Flash Media Server 2\FMSAdmin.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: MySQL5 - Unknown owner - C:\Program.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Wowza Media Server Pro (WowzaMediaServerPro) - Unknown owner - C:\Program Files\Wowza Media Systems\Wowza Media Server Pro\bin\wrapper.exe

--
End of file - 12067 bytes
 
Hi rjlittin and welcome to Safer Networking forums :)

1. Download combofix from any of these links and save it to Desktop:
Link 1
Link 2
Link 3

**Note: It is important that it is saved directly to your desktop**

2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you (C:\ComboFix.txt). Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.

Post:

- a fresh HijackThis log
- combofix report
 
Hi Shaba,

Iv got a bit of a problem at the moment:sad:. Was fiddling around last night and have broken something in the registry. I think I have got it back with a bartpe cd. Just managed to start up in safe mode and in the middle of a system restore to a few days ago. When I am up and running again I will let you know.

p.s. I won't fiddle any more:D:.

Roger.
 
Hi

Ok, let me know after that and please keep just following instructions in the future, no soloing :)
 
Back up and running.

Hi there,

I'm back up and running. combofix has been running for about an hour but it has stopped on Deleting Files/Folders:. There is no disk activity and it seems to have shut down explorer.exe as all the icons and the task bar have disappeared.

I will await further instructions.
 
Hi there,

I'm back up and running. combofix has been running for about an hour but it has stopped on Deleting Files/Folders:. There is no disk activity and it seems to have shut down explorer.exe as all the icons and the task bar have disappeared.

I will await further instructions.

Sorry, missed part of you first post. ended sed.cexe process and it started up again.
 
Fresh HJT Log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:31:12, on 15/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\crypserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\MySQL\MySQL Server 4.1\bin\mysqld-nt.exe
C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
C:\Program Files\Sawmill 7\SawmillService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sawmill 7\SawmillCL.exe
C:\Program Files\Sawmill 7\SawmillCL.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\V0230Mon.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.fluidmd.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
N3 - Netscape 7: # Mozilla User Preferences

/* Do not edit this file.
*
* If you make changes to this file while the browser is running,
* the changes will be overwritten when the browser exits.
*
* To make a manual change to preferences, you can visit the URL about:config
* For more information, see http://www.mozilla.org/unix/customizing.html#prefs
*/

user_pref("browser.activation.checkedNNFlag", true);
user_pref("browser.bookmarks.added_static_root", true);
user_pref("browser.cache.disk.parent_directory", "C:\\DOCUMENTS AND SETTINGS\\ROGER LITTIN\\APPLICATION DATA\\Mozilla\\Profiles\\default\\7n1juq48.slt");
user_pref("browser.download.dir", "C:\\Documents and Settings\\Roger Littin\\My Documents");
user_pref("browser.search.defaultengine", "engine://C%3A%5CPROGRA%7E1%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src");
user_pref("browser.startup.homepage_override.mstone", "rv:1.7.2");
user_pref("browser.tabs.forceHide", true);
user_pref("browser.turbo.showDialog", false);
user_pref("dom.disabl
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: IE DevToolbar BHO - {CC7E636D-39AA-49b6-B511-65413DA137A1} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Developer Toolbar - {CC962137-2E78-4f94-975E-FC0C07DBD78F} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [V0230Mon.exe] C:\WINDOWS\system32\V0230Mon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\RunServices: [SchedulingAgent] C:\WINDOWS\system32\mstask.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Program Files\VisualRoute\vrie.dll
O9 - Extra 'Tools' menuitem: VisualRoute Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Program Files\VisualRoute\vrie.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: IE Developer Toolbar - {48FFE35F-36D9-44bd-A6CC-1D34414EAC0D} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O9 - Extra button: Europa Casino - {4C826F10-D34B-4ba8-B609-1FB8C6482A05} - C:\Casino\Europa Casino\casino.exe (file missing)
O9 - Extra 'Tools' menuitem: Europa Casino - {4C826F10-D34B-4ba8-B609-1FB8C6482A05} - C:\Casino\Europa Casino\casino.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\flashget.exe
O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra 'Tools' menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .ocx: C:\Program Files\Opera\PLUGINS\NPFgc1.dll
O12 - Plugin for .ps: C:\Program Files\Opera\PLUGINS\NPFgc1.dll
O12 - Plugin for .tar: C:\Program Files\Opera\PLUGINS\NPFgc1.dll
O12 - Plugin for .zip: C:\Program Files\Opera\PLUGINS\NPFgc1.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.tiscali.co.uk/
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} -
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1108071541436
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
O16 - DPF: {E5ABEB00-B357-4884-9949-77B2C71A7EE3} (BoardCtl Class) - http://www.intel.com/design/motherbd/boardid/BoardID.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: Flash Media Server (FMS) (FMS) - Macromedia, Inc. - C:\Program Files\Macromedia\Flash Media Server 2\FMSMaster.exe
O23 - Service: Flash Media Administration Server (FMSAdmin) - Macromedia, Inc. - C:\Program Files\Macromedia\Flash Media Server 2\FMSAdmin.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: MySQL41 - Unknown owner - C:\Program.exe (file missing)
O23 - Service: MySQL5 - Unknown owner - C:\Program.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sawmill - Unknown owner - C:\Program Files\Sawmill 7\SawmillService.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Wowza Media Server Pro (WowzaMediaServerPro) - Unknown owner - C:\Program Files\Wowza Media Systems\Wowza Media Server Pro\bin\wrapper.exe

--
End of file - 11542 bytes
 
And Combofix log

Should I have shut down tea timer before doing this. It started complaining big time about bho's getting deleted and trying to get renistated. Got a copy of resident.log if you need it.

ComboFix 07-12-15.1 - Roger Littin 2007-12-15 13:20:59.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.507 [GMT 0:00]
Running from: C:\Documents and Settings\Roger Littin\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Roger Littin\Application Data\MBSPicturePlugin4070.dll
C:\Documents and Settings\Roger Littin\Application Data\MBSQTImporterPlugin4175.dll
C:\Documents and Settings\Roger Littin\Application Data\MBSRectPlugin4070.dll
C:\Documents and Settings\Roger Littin\Application Data\MBSRegistrationPlugin4071.dll
C:\Documents and Settings\Roger Littin\Application Data\Rb3D350.dll
C:\Documents and Settings\Roger Littin\Application Data\rbap450.dll
C:\Documents and Settings\Roger Littin\Application Data\rbqt450.DLL
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\agjveouc.ini
C:\WINDOWS\system32\awtqpnm.dll
C:\WINDOWS\system32\awtqq.dll
C:\WINDOWS\system32\Cache
C:\WINDOWS\system32\cuoevjga.dll
C:\WINDOWS\system32\qqtwa.ini
C:\WINDOWS\system32\qqtwa.ini2

.
((((((((((((((((((((((((( Files Created from 2007-11-15 to 2007-12-15 )))))))))))))))))))))))))))))))
.

2007-12-15 13:07 . 2007-12-15 13:07 3,948 --a------ C:\WINDOWS\system32\PerfStringBackup.TMP
2007-12-15 12:41 . 2007-12-15 14:23 2,422 --a------ C:\WINDOWS\system32\wpa.dbl
2007-12-14 18:48 . 2007-12-14 18:48 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-12-14 18:48 . 2007-12-14 18:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-12-13 22:29 . 2007-12-13 23:03 <DIR> d-------- C:\VundoFix Backups
2007-12-13 22:09 . 2007-12-13 22:09 <DIR> d-------- C:\Program Files\Trend Micro
2007-12-08 10:55 . 2007-12-08 10:55 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2007-12-08 10:55 . 2007-12-08 10:55 1,409 --a------ C:\WINDOWS\QTFont.for
2007-11-25 19:33 . 2007-11-25 19:53 <DIR> d-------- C:\Program Files\SEPY ActionScript Editor
2007-11-21 00:00 . 2007-11-21 00:00 <DIR> d-------- C:\Documents and Settings\Roger Littin\Application Data\Subversion
2007-11-20 19:00 . 2007-11-20 19:00 <DIR> d-------- C:\Program Files\MTASC
2007-11-17 10:16 . 2007-12-15 14:21 4,171,808 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2007-11-17 10:16 . 2007-12-15 14:21 44,120 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2007-11-17 10:13 . 2007-11-17 10:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
2007-11-15 21:27 . 2007-11-15 21:27 <DIR> d-------- C:\Documents and Settings\Peta\Application Data\Corel

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-15 12:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-15 12:49 --------- d-----w C:\Documents and Settings\Roger Littin\Application Data\CoreFTP
2007-12-14 08:39 --------- d-----w C:\Program Files\WinTV
2007-12-07 19:35 --------- d-----w C:\Program Files\Opera
2007-11-23 18:40 --------- d-----w C:\Program Files\PremiumSoft Navicat
2007-11-19 18:26 --------- d-----w C:\Program Files\VisualRoute
2007-11-16 22:43 --------- d-----w C:\Program Files\FlashGet
2007-11-16 19:22 --------- d-----w C:\Program Files\Wowza Media Systems
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-04 22:12 --------- d-----w C:\Program Files\WebCamDV
2007-11-04 15:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-11-04 15:39 --------- d-----w C:\Program Files\BitTorrent
2007-11-04 15:32 --------- d-----w C:\Program Files\Java
2007-11-04 14:10 356,352 ----a-w C:\WINDOWS\eSellerateEngine.dll
2007-11-04 13:51 23,600 ----a-w C:\WINDOWS\system32\drivers\TVICHW32.SYS
2007-11-04 11:01 --------- d-----w C:\Documents and Settings\Roger Littin\Application Data\muvee Technologies
2007-07-03 18:05 4,660 ----a-w C:\Program Files\uninstal.log
2005-03-26 17:27 1,030 --sh--w C:\WINDOWS\system\nodemgr.sys
2007-05-26 10:39 56 --sh--r C:\WINDOWS\system32\430508F299.sys
2007-05-26 10:39 5,018 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4261813A-FAF3-44B7-BCE4-38DA3D8A7309}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7A03615A-4799-4B8E-B033-B105481CF1D4}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{883E49FC-7481-453C-B85E-6F1466DE8D47}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:56]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-01-31 21:10]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-07-27 22:03]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-04-17 12:41]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-04-13 06:07]
"V0230Mon.exe"="C:\WINDOWS\system32\V0230Mon.exe" [2006-07-19 17:00]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 03:00]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-09-06 16:14]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"SchedulingAgent"="C:\WINDOWS\system32\mstask.exe" []

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 07:56]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoCAD Startup Accelerator.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutoCAD Startup Accelerator.lnk
backup=C:\WINDOWS\pss\AutoCAD Startup Accelerator.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Phone Connection Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Phone Connection Monitor.lnk
backup=C:\WINDOWS\pss\Phone Connection Monitor.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Roger Littin^Start Menu^Programs^Startup^WinMySQLadmin.lnk]
path=C:\Documents and Settings\Roger Littin\Start Menu\Programs\Startup\WinMySQLadmin.lnk
backup=C:\WINDOWS\pss\WinMySQLadmin.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcctMgr]
C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe /startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\atwtusb]
atwtusb.exe beta

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GhostStartTrayApp]
2003-05-28 19:11 94208 --a------ C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMONTRAY]
2004-03-10 22:02 32768 --------- C:\Program Files\Intel\Intel(R) Active Monitor\imontray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Parallel Tasking]
C:\Program Files\Parallel Tasking\ptask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PinnacleDriverCheck]
C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
2003-10-23 09:37 962560 --a------ C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeedTouch USB Diagnostics]
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe /icon

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
C:\Program Files\Valve\Steam\Steam.exe -silent

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\STManager]
C:\Program Files\SpeedTouch\Dr SpeedTouch\drst.exe -b

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"GhostStartService"=2 (0x2)
"imonNT"=2 (0x2)
"NVSvc"=2 (0x2)
"MDM"=2 (0x2)

R1 HCW88AUD;Hauppauge WinTV 88x Audio Capture;C:\WINDOWS\system32\drivers\hcw88aud.sys
R2 MySQL41;MySQL41;"C:\Program Files\MySQL\MySQL Server 4.1\bin\mysqld-nt" --defaults-file="C:\Program Files\MySQL\MySQL Server 4.1\my.ini" MySQL41
R2 MySQL5;MySQL5;"C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt" --defaults-file="C:\Program Files\MySQL\MySQL Server 5.0\my.ini" MySQL5
R2 Sawmill;Sawmill;"C:\Program Files\Sawmill 7\SawmillService.exe"
R2 SIODRV;SIODRV;\??\C:\WINDOWS\System32\drivers\SIODRV.SYS
R2 WebCamDV;WebCamDV DV to Webcam Converter;C:\WINDOWS\system32\DRIVERS\WebCamDV.sys
R3 AIRPLUS;D-Link AirPlus Wireless Adapter;C:\WINDOWS\system32\DRIVERS\airplus.sys
R3 hcw88rc5;Hauppauge WinTV 88x IR Decoder;C:\WINDOWS\system32\Drivers\hcw88rc5.sys
R3 HCW88TSE;Hauppauge WinTV 88x MPEG/TS Capture;C:\WINDOWS\system32\drivers\hcw88tse.sys
R3 HCW88TUNE;Hauppauge WinTV 88x Tuner;C:\WINDOWS\system32\drivers\hcw88tun.sys
R3 hcw88vid;Hauppauge WinTV 88x Video;C:\WINDOWS\system32\drivers\hcw88vid.sys
R3 HCW88XBAR;Hauppauge WinTV 88x Crossbar;C:\WINDOWS\system32\drivers\HCW88BAR.sys
R3 Intels51;Sitecom 56K PCI modem DC-010v2;C:\WINDOWS\system32\DRIVERS\Intels51.sys
R3 smbusp;Intel(R) SMBus 2.0 Driver;C:\WINDOWS\system32\DRIVERS\smb.sys
R3 V0230Vfx;V0230Vfx;C:\WINDOWS\system32\DRIVERS\V0230Vfx.sys
R3 V0230VID;Live! Cam Video IM Pro;C:\WINDOWS\system32\DRIVERS\V0230VID.sys
R3 WCDV_Aud;WevCamDV WDM Virtual Audio Device;C:\WINDOWS\system32\drivers\wcdvaud.sys
S3 FMS;Flash Media Server (FMS);"C:\Program Files\Macromedia\Flash Media Server 2\FMSMaster.exe"
S3 FMSAdmin;Flash Media Administration Server;"C:\Program Files\Macromedia\Flash Media Server 2\FMSAdmin.exe"
S3 FTLUND;Lundinova Filter Driver;C:\WINDOWS\system32\drivers\ftlund.sys
S3 HCW88BDA;Hauppauge WinTV 88x DVB Tuner/Demod;C:\WINDOWS\system32\drivers\hcw88bda.sys
S3 idrmkl;idrmkl;\??\C:\WINDOWS\TEMP\idrmkl.sys
S3 rtl8029;Realtek RTL8029(AS)-based PCI Ethernet Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\RTL8029.SYS
S3 WowzaMediaServerPro;Wowza Media Server Pro;"C:\Program Files\Wowza Media Systems\Wowza Media Server Pro\bin\wrapper.exe" -s "C:\Program Files\Wowza Media Systems\Wowza Media Server Pro\bin\WowzaMediaServerPro-Service.conf"

.
Contents of the 'Scheduled Tasks' folder
"2007-12-15 14:00:00 C:\WINDOWS\Tasks\B36E0E949345B864.job"
- c:\docume~1\rogerl~1\applic~1\mfcdan~1\once dupe kind.exe
"2007-12-09 10:10:07 C:\WINDOWS\Tasks\Backups.job"
- C:\Program Files\PremiumSoft Navicat\navicat.exe
"2007-12-14 08:39:20 C:\WINDOWS\Tasks\Dragons_Den.job"
- C:\PROGRA~1\WinTV\WinTV2K.EXE9 -c10 -ntod -startr:Dragons_Den###.mpg -qvcd -limit:1800
"2005-05-17 21:46:13 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1100 series#1108593923.job"
- C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe4-I
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-15 14:23:45
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\MySql]
"ImagePath"="C:/mysql/bin/mysqld-max-nt.exe"
.
Completion time: 2007-12-15 14:25:39 - machine was rebooted
.
2007-11-28 21:17:44 --- E O F ---
 
Hi

Please make sure that you can view all hidden files. Instructions on how to do this can be found here:

How to see hidden files in Windows

Please click this link-->Jotti

When the jotti page has finished loading, click the Browse button and navigate to the following file and click Submit.

C:\WINDOWS\TEMP\idrmkl.sys

Please post back the results of the scan in your next post.

If Jotti is busy, try the same at Virustotal: http://www.virustotal.com/
 
Hi

No that doesn't mean it.

Driver can exist though file doesn't.

Now, go to Start > Run, and copy/paste the following into the Open box:
sc delete idrmkl
Click: OK

Please do an online scan with Kaspersky Online Scanner. You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings
  • In the scan settings make sure that the following are selected:

    o Scan using the following Anti-Virus database:

    + Extended (If available otherwise Standard)

    o Scan Options:

    + Scan Archives
    + Scan Mail Bases
  • Click OK
  • Now under select a target to scan select My Computer
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button
  • Save the file to your desktop.
  • Copy and paste that information in your next post.

Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the license, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.

Post:

- a fresh HijackThis log
- kaspersky report
 
Kaspersky Report

I don't use outlook express any more so that can be removed and also d:\recovered is files off of an old harddrive that crashed about 5 years ago. I can get rid of the outlook folders in there also. I don't use norton any more so how can i get rid of the nprotect folders?

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Sunday, December 16, 2007 10:08:27 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 15/12/2007
Kaspersky Anti-Virus database records: 483280
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\
K:\
L:\

Scan Statistics:
Total number of scanned objects: 291811
Number of viruses found: 13
Number of infected objects: 39
Number of suspicious objects: 4
Duration of the scan process: 06:15:04

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Roger Littin\Application Data\Mozilla\Firefox\Profiles\wvdp5n84.Default User\cert8.db Object is locked skipped
C:\Documents and Settings\Roger Littin\Application Data\Mozilla\Firefox\Profiles\wvdp5n84.Default User\flashgot.log Object is locked skipped
C:\Documents and Settings\Roger Littin\Application Data\Mozilla\Firefox\Profiles\wvdp5n84.Default User\formhistory.dat Object is locked skipped
C:\Documents and Settings\Roger Littin\Application Data\Mozilla\Firefox\Profiles\wvdp5n84.Default User\GoogleToolbarData\googlesafebrowsing.db Object is locked skipped
C:\Documents and Settings\Roger Littin\Application Data\Mozilla\Firefox\Profiles\wvdp5n84.Default User\history.dat Object is locked skipped
C:\Documents and Settings\Roger Littin\Application Data\Mozilla\Firefox\Profiles\wvdp5n84.Default User\key3.db Object is locked skipped
C:\Documents and Settings\Roger Littin\Application Data\Mozilla\Firefox\Profiles\wvdp5n84.Default User\parent.lock Object is locked skipped
C:\Documents and Settings\Roger Littin\Application Data\Mozilla\Firefox\Profiles\wvdp5n84.Default User\search.sqlite Object is locked skipped
C:\Documents and Settings\Roger Littin\Application Data\Mozilla\Firefox\Profiles\wvdp5n84.Default User\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Roger Littin\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Roger Littin\Local Settings\Application Data\Identities\{58ACB84F-D5EB-49F6-A67B-38C42072CC73}\Microsoft\Outlook Express\Deleted Items.dbx/[From "Halifax" <anti-fraud.ref.num13992956853499@halifax.co.uk>][Date Sat, 05 Feb 2005 07:21:44 -0100]/UNNAMED/html Infected: Trojan-Spy.HTML.Bankfraud.hs skipped
C:\Documents and Settings\Roger Littin\Local Settings\Application Data\Identities\{58ACB84F-D5EB-49F6-A67B-38C42072CC73}\Microsoft\Outlook Express\Deleted Items.dbx/[From "Halifax" <anti-fraud.ref.num13992956853499@halifax.co.uk>][Date Sat, 05 Feb 2005 07:21:44 -0100]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.hs skipped
C:\Documents and Settings\Roger Littin\Local Settings\Application Data\Identities\{58ACB84F-D5EB-49F6-A67B-38C42072CC73}\Microsoft\Outlook Express\Deleted Items.dbx/[From "Regions Bank Customer Service Center" <customer@regions.com>][Date Sun, 06 Feb 2005 08:25:51 +0600]/html Infected: Trojan-Spy.HTML.Bankfraud.cm skipped
C:\Documents and Settings\Roger Littin\Local Settings\Application Data\Identities\{58ACB84F-D5EB-49F6-A67B-38C42072CC73}\Microsoft\Outlook Express\Deleted Items.dbx Mail MS Outlook 5: infected - 3 skipped
C:\Documents and Settings\Roger Littin\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\Roger Littin\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Roger Littin\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Roger Littin\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Roger Littin\Local Settings\Temp\hsperfdata_Roger Littin\4032 Object is locked skipped
C:\Documents and Settings\Roger Littin\Local Settings\Temp\Temporary Directory 1 for kf151.zip\keyfinder.exe/data.rar/officekey.exe Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
C:\Documents and Settings\Roger Littin\Local Settings\Temp\Temporary Directory 1 for kf151.zip\keyfinder.exe/data.rar Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
C:\Documents and Settings\Roger Littin\Local Settings\Temp\Temporary Directory 1 for kf151.zip\keyfinder.exe RarSFX: infected - 2 skipped
C:\Documents and Settings\Roger Littin\Local Settings\Temp\~DF231F.tmp Object is locked skipped
C:\Documents and Settings\Roger Littin\Local Settings\Temp\~DFDC6E.tmp Object is locked skipped
C:\Documents and Settings\Roger Littin\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Roger Littin\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Roger Littin\My Documents\Eclipse\.metadata\.lock Object is locked skipped
C:\Documents and Settings\Roger Littin\My Documents\Eclipse\.metadata\.plugins\org.asdt.wizards\asdtWizards.log Object is locked skipped
C:\Documents and Settings\Roger Littin\My Documents\kf151.zip/keyfinder.exe/data.rar/officekey.exe Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
C:\Documents and Settings\Roger Littin\My Documents\kf151.zip/keyfinder.exe/data.rar Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
C:\Documents and Settings\Roger Littin\My Documents\kf151.zip/keyfinder.exe Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
C:\Documents and Settings\Roger Littin\My Documents\kf151.zip ZIP: infected - 3 skipped
C:\Documents and Settings\Roger Littin\My Documents\My Downloads\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Roger Littin\My Documents\My Downloads\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Roger Littin\My Documents\My Downloads\SmitfraudFix.exe RarSFX: infected - 2 skipped
C:\Documents and Settings\Roger Littin\ntuser.dat Object is locked skipped
C:\Documents and Settings\Roger Littin\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\report\Resident protection.txt Object is locked skipped
C:\Program Files\FlashGet\ads\cache434\B_434_0_1_549500.htm Infected: Exploit.HTML.IframeBof skipped
C:\Program Files\Mozilla Firefox\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Program Files\MySQL\MySQL Server 4.1\data\ibdata1 Object is locked skipped
C:\Program Files\MySQL\MySQL Server 4.1\data\ib_logfile0 Object is locked skipped
C:\Program Files\MySQL\MySQL Server 4.1\data\ib_logfile1 Object is locked skipped
C:\Program Files\MySQL\MySQL Server 4.1\data\roger.err Object is locked skipped
C:\Program Files\MySQL\MySQL Server 5.0\data\ibdata1 Object is locked skipped
C:\Program Files\MySQL\MySQL Server 5.0\data\ib_logfile0 Object is locked skipped
C:\Program Files\MySQL\MySQL Server 5.0\data\ib_logfile1 Object is locked skipped
C:\Program Files\MySQL\MySQL Server 5.0\data\roger.err Object is locked skipped
C:\Program Files\Sawmill 7\LogAnalysisInfo\IPC\MasterProcessLock.568 Object is locked skipped
C:\Program Files\Sawmill 7\ServiceOutput.txt Object is locked skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\cuoevjga.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\qoobox\Quarantine\catchme2007-12-15_142312.67.zip/awtqpnm.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bhw skipped
C:\qoobox\Quarantine\catchme2007-12-15_142312.67.zip ZIP: infected - 1 skipped
C:\RECYCLER\NPROTECT\00150012.box Object is locked skipped
C:\RECYCLER\NPROTECT\00150013.HTM Object is locked skipped
C:\RECYCLER\NPROTECT\00150016.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150017.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150018.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150019.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150020.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150021.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150022.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150024.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150025.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150027.box Object is locked skipped
C:\RECYCLER\NPROTECT\00150029.box Object is locked skipped
C:\RECYCLER\NPROTECT\00150030.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150032.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150033.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150035.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150036.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150037.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150039.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150040.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150041.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150043.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150044.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150045.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150047.box Object is locked skipped
C:\RECYCLER\NPROTECT\00150049.dat Object is locked skipped
C:\RECYCLER\NPROTECT\00150050.dat Object is locked skipped
C:\RECYCLER\NPROTECT\00150082.box Object is locked skipped
C:\RECYCLER\NPROTECT\00150085.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150086.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150087.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150089.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150090.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150091.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150092.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150093.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150094.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150095.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150098.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150100.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150101.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150103.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150104.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150105.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150106.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150108.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150109.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150111.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150112.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150114.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150115.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150116.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150117.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150118.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150119.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150121.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150122.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150124.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150125.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150127.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150128.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150129.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150131.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150132.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150134.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150135.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150136.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150137.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150138.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150139.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150140.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150141.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150142.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150144.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150145.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150146.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150147.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150149.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150150.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150151.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150153.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150154.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150155.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150157.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150158.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150159.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150160.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150162.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150164.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150165.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150166.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150168.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150169.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150170.box Object is locked skipped
C:\RECYCLER\NPROTECT\00150172.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150176.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150177.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150178.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150179.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150181.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150182.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150184.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150185.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150186.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150188.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150189.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150190.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150191.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150195.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150197.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150200.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150201.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150202.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150203.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150204.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150206.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150209.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150220.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150221.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150222.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150224.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150225.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150227.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150230.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150232.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150234.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150235.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150236.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150237.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150239.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150240.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150241.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150243.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150244.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150246.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150247.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150248.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150251.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150252.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150253.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150255.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150256.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150258.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150260.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150262.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150263.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150264.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150265.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150266.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150267.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150269.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150271.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150272.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150280.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150281.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150283.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150284.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150285.MOZ Object is locked skipped
 
Page 2

C:\RECYCLER\NPROTECT\00150286.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150287.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150289.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150291.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150292.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150293.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150295.box Object is locked skipped
C:\RECYCLER\NPROTECT\00150296.box Object is locked skipped
C:\RECYCLER\NPROTECT\00150299.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150300.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150306.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150308.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150309.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150310.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150312.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150313.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150314.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150315.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150317.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150318.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150321.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150322.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150337.wpl Object is locked skipped
C:\RECYCLER\NPROTECT\00150338.XML Object is locked skipped
C:\RECYCLER\NPROTECT\00150341.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150343.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150344.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150346.box Object is locked skipped
C:\RECYCLER\NPROTECT\00150477.dat Object is locked skipped
C:\RECYCLER\NPROTECT\00150478.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150481.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150482.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150493.box Object is locked skipped
C:\RECYCLER\NPROTECT\00150498.HTM Object is locked skipped
C:\RECYCLER\NPROTECT\00150503.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150520.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150521.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150522.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150524.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150525.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150526.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150528.box Object is locked skipped
C:\RECYCLER\NPROTECT\00150529.box Object is locked skipped
C:\RECYCLER\NPROTECT\00150533.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150534.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150535.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150537.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150541.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150544.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150545.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150546.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150548.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150613.DIC Object is locked skipped
C:\RECYCLER\NPROTECT\00150617.LNK Object is locked skipped
C:\RECYCLER\NPROTECT\00150618.LNK Object is locked skipped
C:\RECYCLER\NPROTECT\00150626.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150627.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150629.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150630.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150632.box Object is locked skipped
C:\RECYCLER\NPROTECT\00150635.DIC Object is locked skipped
C:\RECYCLER\NPROTECT\00150639.LNK Object is locked skipped
C:\RECYCLER\NPROTECT\00150640.LNK Object is locked skipped
C:\RECYCLER\NPROTECT\00150643.PST Object is locked skipped
C:\RECYCLER\NPROTECT\00150644.PST Object is locked skipped
C:\RECYCLER\NPROTECT\00150672.box Object is locked skipped
C:\RECYCLER\NPROTECT\00150675.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150678.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150681.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150682.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150684.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150685.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150686.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150692.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150694.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150697.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150701.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150703.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150705.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150710.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150715.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150717.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150719.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150721.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150722.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150725.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150726.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150727.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150728.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150731.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150732.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150733.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150747.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150751.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150752.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150757.XML Object is locked skipped
C:\RECYCLER\NPROTECT\00150758.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150762.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150768.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150776.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150777.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150778.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150781.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150783.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150784.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150786.box Object is locked skipped
C:\RECYCLER\NPROTECT\00150809.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150815.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150816.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150817.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150818.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150819.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150820.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150821.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150822.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150823.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150824.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150825.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150826.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150829.box Object is locked skipped
C:\RECYCLER\NPROTECT\00150833.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150835.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150836.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150837.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150838.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150869.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150873.xml Object is locked skipped
C:\RECYCLER\NPROTECT\00150874.xml Object is locked skipped
C:\RECYCLER\NPROTECT\00150875.xml Object is locked skipped
C:\RECYCLER\NPROTECT\00150876.xml Object is locked skipped
C:\RECYCLER\NPROTECT\00150877.xml Object is locked skipped
C:\RECYCLER\NPROTECT\00150878.xml Object is locked skipped
C:\RECYCLER\NPROTECT\00150879.xml Object is locked skipped
C:\RECYCLER\NPROTECT\00150880.xml Object is locked skipped
C:\RECYCLER\NPROTECT\00150881.xml Object is locked skipped
C:\RECYCLER\NPROTECT\00150883.xml Object is locked skipped
C:\RECYCLER\NPROTECT\00150884.xml Object is locked skipped
C:\RECYCLER\NPROTECT\00150894.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150895.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150897.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150898.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150900.box Object is locked skipped
C:\RECYCLER\NPROTECT\00150902.xml Object is locked skipped
C:\RECYCLER\NPROTECT\00150931.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150932.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150933.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150934.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150935.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150936.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150937.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150938.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150940.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150941.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150942.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150943.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150944.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150945.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150946.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150947.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150948.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150949.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150950.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00150974.xml Object is locked skipped
C:\RECYCLER\NPROTECT\00150976.xml Object is locked skipped
C:\RECYCLER\NPROTECT\00150977.xml Object is locked skipped
C:\RECYCLER\NPROTECT\00150978.xml Object is locked skipped
C:\RECYCLER\NPROTECT\00150980.xml Object is locked skipped
C:\RECYCLER\NPROTECT\00150982.box Object is locked skipped
C:\RECYCLER\NPROTECT\00150985.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00150986.xml Object is locked skipped
C:\RECYCLER\NPROTECT\00151012.xml Object is locked skipped
C:\RECYCLER\NPROTECT\00151015.dat Object is locked skipped
C:\RECYCLER\NPROTECT\00151016.dat Object is locked skipped
C:\RECYCLER\NPROTECT\00151021.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151022.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151023.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151024.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151026.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151027.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151028.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151030.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151033.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151034.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151035.box Object is locked skipped
C:\RECYCLER\NPROTECT\00151037.xml Object is locked skipped
C:\RECYCLER\NPROTECT\00151053.dat Object is locked skipped
C:\RECYCLER\NPROTECT\00151054.box Object is locked skipped
C:\RECYCLER\NPROTECT\00151056.HTM Object is locked skipped
C:\RECYCLER\NPROTECT\00151065.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151066.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151067.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151068.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151070.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151071.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151073.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151074.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151075.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151076.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151078.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151079.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151080.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151081.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151082.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151084.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151085.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151087.box Object is locked skipped
C:\RECYCLER\NPROTECT\00151358.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151359.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151360.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151361.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151362.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151363.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151364.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151365.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151366.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151367.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151368.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151369.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151371.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151372.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151373.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151374.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151375.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151376.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151386.box Object is locked skipped
C:\RECYCLER\NPROTECT\00151395.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151396.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151401.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151402.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151408.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151412.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151414.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151415.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151417.box Object is locked skipped
C:\RECYCLER\NPROTECT\00151418.box Object is locked skipped
C:\RECYCLER\NPROTECT\00151421.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151422.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151424.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151427.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151428.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151429.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151430.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151431.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151432.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151433.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151434.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151436.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151437.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151438.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151439.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151440.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151441.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151443.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151444.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151445.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151446.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151447.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151448.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151450.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151451.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151452.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151453.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151454.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151457.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151459.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151461.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151462.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151463.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151464.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151466.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151467.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151470.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151472.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151473.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151475.box Object is locked skipped
C:\RECYCLER\NPROTECT\00151495.box Object is locked skipped
C:\RECYCLER\NPROTECT\00151500.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151501.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151517.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151518.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151521.wpl Object is locked skipped
C:\RECYCLER\NPROTECT\00151522.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151524.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151525.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151527.box Object is locked skipped
C:\RECYCLER\NPROTECT\00151548.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151549.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151550.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151551.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151552.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151553.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151554.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151555.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151556.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151557.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151558.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151559.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151560.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151561.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151562.TXT Object is locked skipped
 
Page 3

C:\RECYCLER\NPROTECT\00151563.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151564.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151565.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151566.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151567.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151568.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151569.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151570.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151571.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151572.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151573.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151574.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151575.TXT Object is locked skipped
C:\RECYCLER\NPROTECT\00151577.box Object is locked skipped
C:\RECYCLER\NPROTECT\00151580.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151582.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151583.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151587.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151589.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151591.XML Object is locked skipped
C:\RECYCLER\NPROTECT\00151594.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151595.XML Object is locked skipped
C:\RECYCLER\NPROTECT\00151598.XML Object is locked skipped
C:\RECYCLER\NPROTECT\00151601.XML Object is locked skipped
C:\RECYCLER\NPROTECT\00151604.XML Object is locked skipped
C:\RECYCLER\NPROTECT\00151608.XML Object is locked skipped
C:\RECYCLER\NPROTECT\00151611.XML Object is locked skipped
C:\RECYCLER\NPROTECT\00151614.XML Object is locked skipped
C:\RECYCLER\NPROTECT\00151617.XML Object is locked skipped
C:\RECYCLER\NPROTECT\00151620.XML Object is locked skipped
C:\RECYCLER\NPROTECT\00151622.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151623.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151625.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151626.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151627.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151628.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151630.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151631.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151632.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151633.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151634.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151636.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151638.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151639.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151642.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151644.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151645.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151646.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151648.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151649.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151650.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151652.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151653.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151654.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151656.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151657.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151659.box Object is locked skipped
C:\RECYCLER\NPROTECT\00151662.LNK Object is locked skipped
C:\RECYCLER\NPROTECT\00151663.LNK Object is locked skipped
C:\RECYCLER\NPROTECT\00151665.LNK Object is locked skipped
C:\RECYCLER\NPROTECT\00151666.LNK Object is locked skipped
C:\RECYCLER\NPROTECT\00151669.lnk Object is locked skipped
C:\RECYCLER\NPROTECT\00151671.LNK Object is locked skipped
C:\RECYCLER\NPROTECT\00151705.box Object is locked skipped
C:\RECYCLER\NPROTECT\00151710.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151725.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151727.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151728.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151730.box Object is locked skipped
C:\RECYCLER\NPROTECT\00151747.box Object is locked skipped
C:\RECYCLER\NPROTECT\00151764.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151766.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151767.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151768.box Object is locked skipped
C:\RECYCLER\NPROTECT\00151794.box Object is locked skipped
C:\RECYCLER\NPROTECT\00151821.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151823.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151825.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151827.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151828.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151829.box Object is locked skipped
C:\RECYCLER\NPROTECT\00151875.box Object is locked skipped
C:\RECYCLER\NPROTECT\00151885.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151919.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151921.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151922.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151923.box Object is locked skipped
C:\RECYCLER\NPROTECT\00151924.box Object is locked skipped
C:\RECYCLER\NPROTECT\00151930.dat Object is locked skipped
C:\RECYCLER\NPROTECT\00151931.dat Object is locked skipped
C:\RECYCLER\NPROTECT\00151933.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151935.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151936.MOZ Object is locked skipped
C:\RECYCLER\NPROTECT\00151937.box Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP978\A0214647.exe Infected: Trojan.Win32.Agent.cro skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP980\A0215803.exe Infected: not-a-virus:AdWare.Win32.RK.a skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP982\A0217774.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP982\A0218753.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP983\A0219847.exe Infected: not-a-virus:AdWare.Win32.RK.a skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP983\A0219851.dll Infected: not-a-virus:AdWare.Win32.RK.a skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP985\A0220034.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP985\A0220037.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP985\A0220038.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP985\A0220039.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP985\A0220041.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP985\A0220042.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ao skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP985\A0220044.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP986\A0220972.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP986\A0221091.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP987\A0221847.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bjc skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP987\A0221862.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bhw skipped
C:\System Volume Information\_restore{9D8C69CE-71D0-4067-B0F9-27580402459F}\RP987\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Internet Logs\fwdbglog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped
C:\WINDOWS\Internet Logs\ROGER.ldb Object is locked skipped
C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edbtmp.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\atapi.sys Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox.dat Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox.idx Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\spool\notepad.exe/stream/data0002 Infected: Trojan-Clicker.Win32.Agent.iq skipped
C:\WINDOWS\system32\spool\notepad.exe/stream Infected: Trojan-Clicker.Win32.Agent.iq skipped
C:\WINDOWS\system32\spool\notepad.exe NSIS: infected - 2 skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\ib2 Object is locked skipped
C:\WINDOWS\Temp\ib3 Object is locked skipped
C:\WINDOWS\Temp\ib4 Object is locked skipped
C:\WINDOWS\Temp\ib5 Object is locked skipped
C:\WINDOWS\Temp\ib6 Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_70c.dat Object is locked skipped
C:\WINDOWS\Temp\ZLT05b92.TMP Object is locked skipped
C:\WINDOWS\Temp\ZLT06e8f.TMP Object is locked skipped
C:\WINDOWS\Temp\_avast4_\Webshlock.txt Object is locked skipped
C:\WINDOWS\TempFile Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\recovered\Documents\Outlook\outlook.pst/Personal Folders/Inbox/16 Oct 2002 17:48 from Belinda Edwards:Bulletin.html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
D:\recovered\Documents\Outlook\outlook.pst/Personal Folders/Inbox/20 Mar 2003 21:41 from Sue Hayden:Can't remember if I sent this?.html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
D:\recovered\Documents\Outlook\outlook.pst/Personal Folders/Inbox/03 Jun 2003 00:36 from David Mayers:Updated: Vantico Classificat.html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
D:\recovered\Documents\Outlook\outlook.pst Mail MS Mail: suspicious - 3 skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
F:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

Scan process completed.
 
And Fresh HJT Log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:24:37, on 16/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\crypserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\MySQL\MySQL Server 4.1\bin\mysqld-nt.exe
C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
C:\Program Files\Sawmill 7\SawmillService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sawmill 7\SawmillCL.exe
C:\Program Files\Sawmill 7\SawmillCL.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\V0230Mon.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\JGsoft\EditPadPro6\EditPadPro.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.fluidmd.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
N3 - Netscape 7: # Mozilla User Preferences

/* Do not edit this file.
*
* If you make changes to this file while the browser is running,
* the changes will be overwritten when the browser exits.
*
* To make a manual change to preferences, you can visit the URL about:config
* For more information, see http://www.mozilla.org/unix/customizing.html#prefs
*/

user_pref("browser.activation.checkedNNFlag", true);
user_pref("browser.bookmarks.added_static_root", true);
user_pref("browser.cache.disk.parent_directory", "C:\\DOCUMENTS AND SETTINGS\\ROGER LITTIN\\APPLICATION DATA\\Mozilla\\Profiles\\default\\7n1juq48.slt");
user_pref("browser.download.dir", "C:\\Documents and Settings\\Roger Littin\\My Documents");
user_pref("browser.search.defaultengine", "engine://C%3A%5CPROGRA%7E1%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src");
user_pref("browser.startup.homepage_override.mstone", "rv:1.7.2");
user_pref("browser.tabs.forceHide", true);
user_pref("browser.turbo.showDialog", false);
user_pref("dom.disabl
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: IE DevToolbar BHO - {CC7E636D-39AA-49b6-B511-65413DA137A1} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Developer Toolbar - {CC962137-2E78-4f94-975E-FC0C07DBD78F} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [V0230Mon.exe] C:\WINDOWS\system32\V0230Mon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\RunServices: [SchedulingAgent] C:\WINDOWS\system32\mstask.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Program Files\VisualRoute\vrie.dll
O9 - Extra 'Tools' menuitem: VisualRoute Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Program Files\VisualRoute\vrie.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: IE Developer Toolbar - {48FFE35F-36D9-44bd-A6CC-1D34414EAC0D} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O9 - Extra button: Europa Casino - {4C826F10-D34B-4ba8-B609-1FB8C6482A05} - C:\Casino\Europa Casino\casino.exe (file missing)
O9 - Extra 'Tools' menuitem: Europa Casino - {4C826F10-D34B-4ba8-B609-1FB8C6482A05} - C:\Casino\Europa Casino\casino.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\flashget.exe
O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra 'Tools' menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .ocx: C:\Program Files\Opera\PLUGINS\NPFgc1.dll
O12 - Plugin for .ps: C:\Program Files\Opera\PLUGINS\NPFgc1.dll
O12 - Plugin for .tar: C:\Program Files\Opera\PLUGINS\NPFgc1.dll
O12 - Plugin for .zip: C:\Program Files\Opera\PLUGINS\NPFgc1.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.tiscali.co.uk/
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1108071541436
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
O16 - DPF: {E5ABEB00-B357-4884-9949-77B2C71A7EE3} (BoardCtl Class) - http://www.intel.com/design/motherbd/boardid/BoardID.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: Flash Media Server (FMS) (FMS) - Macromedia, Inc. - C:\Program Files\Macromedia\Flash Media Server 2\FMSMaster.exe
O23 - Service: Flash Media Administration Server (FMSAdmin) - Macromedia, Inc. - C:\Program Files\Macromedia\Flash Media Server 2\FMSAdmin.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: MySQL41 - Unknown owner - C:\Program.exe (file missing)
O23 - Service: MySQL5 - Unknown owner - C:\Program.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sawmill - Unknown owner - C:\Program Files\Sawmill 7\SawmillService.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Wowza Media Server Pro (WowzaMediaServerPro) - Unknown owner - C:\Program Files\Wowza Media Systems\Wowza Media Server Pro\bin\wrapper.exe

--
End of file - 11690 bytes
 
Hi

As for nprotect folders, see here

Empty deleted items in Outlook and delete this:

D:\recovered\Documents\Outlook\outlook.pst

Delete also these:

C:\Documents and Settings\Roger Littin\Local Settings\Temp\Temporary Directory 1 for kf151.zip
C:\Documents and Settings\Roger Littin\My Documents\kf151.zip
C:\WINDOWS\system32\spool\notepad.exe

And empty this folder:

C:\qoobox\Quarantine\

Empty Recycle Bin.

Re-scan with kaspersky.

Post:

- a fresh HijackThis log
- kaspersky report
 
I don't know if this is related.

Internet explorer seems to have forgotten what it is supposed to do with files that are not web pages. Instead of downloading them it tries to open them in a new window. I have to right click the link and save as but this sometimes doesn't work if the link goes to a download script.
 
Back
Top