This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

It's back...AVG warning of trojan clicker.fr

33 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

It seems to be running fine…for now.
Here's the HJT log
Logfile of HijackThis v1.99.1
Scan saved at 8:40:57 AM, on 8/25/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\LEXBCES.EXE
F:\WINDOWS\system32\spoolsv.exe
F:\WINDOWS\Explorer.EXE
F:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
F:\Program Files\iTunes\iTunesHelper.exe
C:\program files\support.com\bin\tgcmd.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
C:\Program Files\Lexmark X5100 Series\lxbabmon.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
F:\WINDOWS\System32\tbctray.exe
C:\PROGRA~1\AWS\WEATHE~1\WEATHER.EXE
F:\WINDOWS\system32\drivers\KodakCCS.exe
F:\Program Files\Free History Eraser\HistoryEraser.exe
F:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
F:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\MSNMES~1\msnmsgr.exe
F:\TrojanHunter 4.5\THGuard.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
F:\Program Files\MSN\MSNCoreFiles\msn6.exe
F:\Documents and Settings\Eddie\Desktop\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.findin.org/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://yahoo.sbc.com/dsl
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\en-us\msntb.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O4 - HKLM\..\Run: [tgcmd] "F:\Program Files\support.com\bin\tgcmd.exe" /server
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [iTunesHelper] "F:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MSConfig] F:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [tgcmdprovidersbc] "c:\program files\support.com\bin\tgcmd.exe" /server /startmonitor /deaf /nosystray
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Lexmark X5100 Series] "C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [TraySantaCruz] F:\WINDOWS\System32\tbctray.exe
O4 - HKLM\..\Run: [THGuard] "F:\TrojanHunter 4.5\THGuard.exe"
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\WEATHER.EXE 1
O4 - HKCU\..\Run: [SPSTEALT] "F:\Program Files\Free History Eraser\HistoryEraser.exe" /stealt
O4 - HKCU\..\Run: [Yahoo! Pager] 1
O4 - Startup: Connection Manager.lnk = F:\Program Files\SBC\Connection Manager\CManager.exe
O4 - Startup: ERUNT AutoBackup.lnk = F:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = F:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O8 - Extra context menu item: &Define - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Look Up in &Encyclopedia - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\npjpi150_08.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\npjpi150_08.dll
O9 - Extra button: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra 'Tools' menuitem: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll (file missing)
O9 - Extra button: Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - http://www.net2phone.com/ (file missing)
O9 - Extra 'Tools' menuitem: Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - http://www.net2phone.com/ (file missing)
O9 - Extra button: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra 'Tools' menuitem: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Dell Home - {08DCFC6C-B6E4-480C-95A4-FC64F37B787E} - http://www.dellnet.com (file missing) (HKCU)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O12 - Plugin for .bcf: C:\Program Files\Internet Explorer\Plugins\NPBelv32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall-beta.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200312…meInstaller.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - F:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - F:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - F:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: STOPzilla Local Service - Unknown owner - C:\Program Files\STOPzilla!\szntsvc.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe

How does it look?
Hi egates, Your hijackthis log appears to be clean. I do not see a firewall application and I urge you to install one. Find a good book to read and run Kapersky and Blacklight one more time. Please post the results from Blacklight (log that starts with fsbl….big number) and Kapersky results.
Here is Kaspersky, Blacklight, and HJT log…
do we still need to do anything about those _restore files?

KASPERSKY ONLINE SCANNER REPORT
Saturday, August 26, 2006 9:15:01 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 26/08/2006
Kaspersky Anti-Virus database records: 205593


Scan Settings
Scan using the following antivirus database standard
Scan Archives true
Scan Mail Bases true

Scan Target My Computer
A:\
C:\
D:\
E:\
F:\

Scan Statistics
Total number of scanned objects 218556
Number of viruses found 9
Number of infected objects 63 / 0
Number of suspicious objects 6
Duration of the scan process 08:21:26

Infected Object Name Virus Name Last Action
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

C:\Program Files\Kodak\Kodak EasyShare software\Catalog\EasyShare.me Object is locked skipped

C:\Program Files\Kodak\Kodak EasyShare software\Catalog\EasyShare.mm Object is locked skipped

C:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP529\A0023419.exe Infected: Trojan.Win32.Krepper.ab skipped

C:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP542\A0025311.exe Infected: Trojan-Downloader.Win32.Swizzor.fg skipped

C:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP542\A0025322.exe Infected: Trojan-Downloader.Win32.Swizzor.bw skipped

C:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP542\A0025323.exe Infected: Trojan-Downloader.Win32.Swizzor.fg skipped

C:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP542\A0025324.exe Infected: Trojan.Win32.Krepper.ab skipped

C:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP542\A0025325.exe Infected: Trojan-Downloader.Win32.Swizzor.br skipped

C:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP542\A0025326.exe Infected: Trojan-Downloader.Win32.Swizzor.br skipped

C:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP542\A0025327.exe Infected: Trojan-Downloader.Win32.Swizzor.bn skipped

C:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP542\A0025328.exe Infected: Trojan-Downloader.Win32.Swizzor.br skipped

C:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP542\A0025329.exe Infected: Trojan-Downloader.Win32.Swizzor.br skipped

C:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP542\A0025330.exe Infected: Trojan-Downloader.Win32.Swizzor.bn skipped

C:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP542\A0025331.exe Infected: Trojan-Downloader.Win32.Swizzor.bn skipped

C:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP545\change.log Object is locked skipped

F:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped

F:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped

F:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped

F:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped

F:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SecondThoughtSTCLoader2.zip/stcloader.exe Suspicious: Password-protected-EXE skipped

F:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SecondThoughtSTCLoader2.zip ZIP: suspicious - 1 skipped

F:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\TIBS2.zip/125439.exe Suspicious: Password-protected-EXE skipped

F:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\TIBS2.zip ZIP: suspicious - 1 skipped

F:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\TIBS6.zip/125439.exe Suspicious: Password-protected-EXE skipped

F:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\TIBS6.zip ZIP: suspicious - 1 skipped

F:\Documents and Settings\Eddie\.housecall\Quarantine\migksftl.exe.bac_a02848 Infected: Trojan.Win32.Krepper.ab skipped

F:\Documents and Settings\Eddie\Application Data\AVG7\Log\emc.log Object is locked skipped

F:\Documents and Settings\Eddie\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

F:\Documents and Settings\Eddie\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

F:\Documents and Settings\Eddie\Application Data\Musicmatch\Jukebox\mmjbaltlog.txt Object is locked skipped

F:\Documents and Settings\Eddie\Application Data\Musicmatch\Jukebox\mmjblog.txt Object is locked skipped

F:\Documents and Settings\Eddie\Application Data\Musicmatch\MIM\Database\Default.ldb Object is locked skipped

F:\Documents and Settings\Eddie\Application Data\Musicmatch\MIM\Database\Default.mdb Object is locked skipped

F:\Documents and Settings\Eddie\Application Data\Sun\Java\Deployment\log\plugin150_08.trace Object is locked skipped

F:\Documents and Settings\Eddie\Cookies\index.dat Object is locked skipped

F:\Documents and Settings\Eddie\Local Settings\History\History.IE5\index.dat Object is locked skipped

F:\Documents and Settings\Eddie\Local Settings\Temp\Cookies\index.dat Object is locked skipped

F:\Documents and Settings\Eddie\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped

F:\Documents and Settings\Eddie\Local Settings\Temp\hpotdd015.log Object is locked skipped

F:\Documents and Settings\Eddie\Local Settings\Temp\hsperfdata_Eddie\3656 Object is locked skipped

F:\Documents and Settings\Eddie\Local Settings\Temp\JETD667.tmp Object is locked skipped

F:\Documents and Settings\Eddie\Local Settings\Temp\msn3656.fdr Object is locked skipped

F:\Documents and Settings\Eddie\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

F:\Documents and Settings\Eddie\Local Settings\Temp\~DFA889.tmp Object is locked skipped

F:\Documents and Settings\Eddie\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

F:\Documents and Settings\Eddie\ntuser.dat Object is locked skipped

F:\Documents and Settings\Eddie\ntuser.dat.LOG Object is locked skipped

F:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

F:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

F:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped

F:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped

F:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

F:\Documents and Settings\LocalService\ntuser.dat Object is locked skipped

F:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

F:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

F:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

F:\Documents and Settings\NetworkService\ntuser.dat Object is locked skipped

F:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

F:\Program Files\MSN\MSNCoreFiles\market.mar Object is locked skipped

F:\Program Files\MSN\MSNCoreFiles\market32.mar Object is locked skipped

F:\Program Files\MSN\MSNCoreFiles\themedef32.mar Object is locked skipped

F:\Program Files\MSN\MSNCoreFiles\ui.mar Object is locked skipped

F:\Program Files\PeerGuardian2\history.db Object is locked skipped

F:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP528\A0021973.exe Infected: Trojan.Win32.Small.fb skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP528\A0021974.exe Infected: Trojan.Win32.DNSChanger.ef skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP529\A0023516.exe Infected: Trojan.Win32.Small.fb skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP529\A0023517.exe Infected: Trojan.Win32.DNSChanger.ef skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP529\A0023582.exe Infected: Trojan.Win32.Small.fb skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP529\A0023583.exe Infected: Trojan.Win32.DNSChanger.ef skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP533\A0023908.exe Infected: Trojan.Win32.Small.fb skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP533\A0023909.exe Infected: Trojan.Win32.DNSChanger.ef skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024429.exe Infected: Trojan.Win32.Small.fb skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024430.exe Infected: Trojan.Win32.DNSChanger.ef skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024443.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024444.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024446.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024447.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024448.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024449.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024451.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024452.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024455.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024458.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024459.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024460.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024461.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024462.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024464.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024465.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP534\A0024466.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP535\A0024477.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP535\A0024478.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP535\A0024481.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024573.exe Infected: Trojan.Win32.Small.fb skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024598.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024600.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024601.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024603.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024606.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024607.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024626.exe Infected: Trojan.Win32.Small.fb skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024628.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024629.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024630.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024631.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024632.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024633.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024634.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024635.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024636.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024637.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024638.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024639.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024640.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024641.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024642.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024643.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024644.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024645.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024646.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024647.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024648.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024649.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024650.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024651.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024652.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024653.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024654.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024655.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024656.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024657.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024658.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024659.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024660.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024661.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024662.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024663.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024664.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024665.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024666.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024667.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024668.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024669.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024670.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024671.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024672.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024673.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024674.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024675.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024676.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024677.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024678.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024679.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024680.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024681.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024682.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024683.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024684.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024685.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024686.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024687.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024688.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024689.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024690.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024691.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024692.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024693.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024694.exe Object is locked skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP537\A0024755.exe Infected: Trojan.Win32.DNSChanger.ef skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP543\A0025358.exe Infected: Trojan-Downloader.Win32.Swizzor.br skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP543\A0025359.exe Infected: Trojan-Downloader.Win32.Swizzor.br skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP543\A0025360.exe Infected: Trojan-Downloader.Win32.Swizzor.br skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP543\A0025361.exe Infected: Trojan-Downloader.Win32.Swizzor.br skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP543\A0025362.exe Infected: Trojan-Downloader.Win32.Swizzor.fg skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP543\A0025363.exe Infected: Trojan-Downloader.Win32.Swizzor.bn skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP543\A0025364.exe Infected: Trojan-Downloader.Win32.Swizzor.bn skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP543\A0025365.exe Infected: Trojan-Downloader.Win32.Swizzor.bn skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP543\A0025366.exe Infected: Trojan-Downloader.Win32.Swizzor.fg skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP543\A0025367.exe Infected: Trojan.Win32.Krepper.ab skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP543\A0025368.exe Infected: Trojan-Downloader.Win32.Swizzor.bw skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP544\A0025369.exe Infected: Trojan.Win32.Small.fb skipped

F:\System Volume Information\_restore{BA715CBB-0A8D-452F-A410-C63BC86D3434}\RP545\change.log Object is locked skipped

F:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

F:\WINDOWS\fffd0eff_{4FB9B3DC-E454-40F8-A6AC-7D85218BF41D}.tmp:ropaup:$DATA/data0001.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped

F:\WINDOWS\fffd0eff_{4FB9B3DC-E454-40F8-A6AC-7D85218BF41D}.tmp:ropaup:$DATA/data0002.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped

F:\WINDOWS\fffd0eff_{4FB9B3DC-E454-40F8-A6AC-7D85218BF41D}.tmp:ropaup:$DATA/data0003.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped

F:\WINDOWS\fffd0eff_{4FB9B3DC-E454-40F8-A6AC-7D85218BF41D}.tmp:ropaup:$DATA/data0004.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped

F:\WINDOWS\fffd0eff_{4FB9B3DC-E454-40F8-A6AC-7D85218BF41D}.tmp:ropaup:$DATA/data0005.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped

F:\WINDOWS\fffd0eff_{4FB9B3DC-E454-40F8-A6AC-7D85218BF41D}.tmp:ropaup:$DATA Embedded HTML: infected - 5 skipped

F:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped

F:\WINDOWS\KB823559.log:qmtix:$DATA/data0001.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped

F:\WINDOWS\KB823559.log:qmtix:$DATA/data0002.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped

F:\WINDOWS\KB823559.log:qmtix:$DATA/data0003.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped

F:\WINDOWS\KB823559.log:qmtix:$DATA/data0004.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped

F:\WINDOWS\KB823559.log:qmtix:$DATA/data0005.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped

F:\WINDOWS\KB823559.log:qmtix:$DATA Embedded HTML: infected - 5 skipped

F:\WINDOWS\SchedLgU.Txt Object is locked skipped

F:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped

F:\WINDOWS\Sti_Trace.log Object is locked skipped

F:\WINDOWS\SYSTEM32\config\AppEvent.Evt Object is locked skipped

F:\WINDOWS\SYSTEM32\config\DEFAULT Object is locked skipped

F:\WINDOWS\SYSTEM32\config\default.LOG Object is locked skipped

F:\WINDOWS\SYSTEM32\config\SAM Object is locked skipped

F:\WINDOWS\SYSTEM32\config\SAM.LOG Object is locked skipped

F:\WINDOWS\SYSTEM32\config\SecEvent.Evt Object is locked skipped

F:\WINDOWS\SYSTEM32\config\SECURITY Object is locked skipped

F:\WINDOWS\SYSTEM32\config\SECURITY.LOG Object is locked skipped

F:\WINDOWS\SYSTEM32\config\SOFTWARE Object is locked skipped

F:\WINDOWS\SYSTEM32\config\software.LOG Object is locked skipped

F:\WINDOWS\SYSTEM32\config\SysEvent.Evt Object is locked skipped

F:\WINDOWS\SYSTEM32\config\SYSTEM Object is locked skipped

F:\WINDOWS\SYSTEM32\config\system.LOG Object is locked skipped

F:\WINDOWS\SYSTEM32\dmloq.exe.tcf Infected: Trojan.Win32.Small.fb skipped

F:\WINDOWS\SYSTEM32\h323log.txt Object is locked skipped

F:\WINDOWS\SYSTEM32\wbem\Repository\FS\INDEX.BTR Object is locked skipped

F:\WINDOWS\SYSTEM32\wbem\Repository\FS\INDEX.MAP Object is locked skipped

F:\WINDOWS\SYSTEM32\wbem\Repository\FS\MAPPING.VER Object is locked skipped

F:\WINDOWS\SYSTEM32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped

F:\WINDOWS\SYSTEM32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped

F:\WINDOWS\SYSTEM32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped

F:\WINDOWS\SYSTEM32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

F:\WINDOWS\VideoSetup.exe:ucxkt:$DATA/data0001.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped

F:\WINDOWS\VideoSetup.exe:ucxkt:$DATA/data0002.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped

F:\WINDOWS\VideoSetup.exe:ucxkt:$DATA/data0003.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped

F:\WINDOWS\VideoSetup.exe:ucxkt:$DATA/data0004.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped

F:\WINDOWS\VideoSetup.exe:ucxkt:$DATA/data0005.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped

F:\WINDOWS\VideoSetup.exe:ucxkt:$DATA Embedded HTML: infected - 5 skipped

F:\WINDOWS\wiadebug.log Object is locked skipped

F:\WINDOWS\wiaservc.log Object is locked skipped

F:\WINDOWS\wininit.tmp:qssrku:$DATA/data0001.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped

F:\WINDOWS\wininit.tmp:qssrku:$DATA/data0002.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped

F:\WINDOWS\wininit.tmp:qssrku:$DATA/data0003.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped

F:\WINDOWS\wininit.tmp:qssrku:$DATA/data0004.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped

F:\WINDOWS\wininit.tmp:qssrku:$DATA/data0005.html Infected: Trojan-Downloader.Win32.WinShow.ak skipped

F:\WINDOWS\wininit.tmp:qssrku:$DATA Embedded HTML: infected - 5 skipped

Scan process completed.





08/26/06 09:17:48 [Info]: BlackLight Engine 1.0.46 initialized
08/26/06 09:17:48 [Info]: OS: 5.1 build 2600 (Service Pack 2)
08/26/06 09:17:51 [Note]: 7019 4
08/26/06 09:17:51 [Note]: 7005 0
08/26/06 09:17:57 [Note]: 7006 0
08/26/06 09:17:57 [Note]: 7011 1148
08/26/06 09:17:58 [Note]: 7026 0
08/26/06 09:17:58 [Note]: 7026 0
08/26/06 09:18:28 [Note]: FSRAW library version 1.7.1019
08/26/06 09:20:35 [Info]: Hidden file: f:\WINDOWS\VideoSetup.exe:ucxkt
08/26/06 09:20:44 [Info]: Hidden file: f:\WINDOWS\fffd0eff_{4FB9B3DC-E454-40F8-A6AC-7D85218BF41D}.tmp:ropaup
08/26/06 09:21:20 [Info]: Hidden file: f:\WINDOWS\wininit.tmp:qssrku
08/26/06 09:21:25 [Info]: Hidden file: f:\WINDOWS\KB823559.log:qmtix
08/26/06 09:43:44 [Note]: 7007 0





Logfile of HijackThis v1.99.1
Scan saved at 9:44:17 AM, on 8/26/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\LEXBCES.EXE
F:\WINDOWS\system32\spoolsv.exe
F:\WINDOWS\system32\LEXPPS.EXE
F:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
F:\Program Files\iTunes\iTunesHelper.exe
C:\program files\support.com\bin\tgcmd.exe
C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
C:\Program Files\Lexmark X5100 Series\lxbabmon.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
F:\TrojanHunter 4.5\THGuard.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
F:\WINDOWS\System32\tbctray.exe
C:\PROGRA~1\AWS\WEATHE~1\WEATHER.EXE
F:\Program Files\Free History Eraser\HistoryEraser.exe
C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mim.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
F:\WINDOWS\system32\drivers\KodakCCS.exe
F:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
F:\WINDOWS\system32\wscntfy.exe
F:\Program Files\MSN\MSNCoreFiles\msn6.exe
C:\PROGRA~1\MSNMES~1\msnmsgr.exe
F:\Program Files\PeerGuardian2\pg2.exe
C:\PROGRA~1\Grisoft\AVG7\avgw.exe
F:\Documents and Settings\Eddie\Desktop\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.findin.org/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://yahoo.sbc.com/dsl
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\en-us\msntb.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O4 - HKLM\..\Run: [tgcmd] "F:\Program Files\support.com\bin\tgcmd.exe" /server
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [iTunesHelper] "F:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MSConfig] F:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [tgcmdprovidersbc] "c:\program files\support.com\bin\tgcmd.exe" /server /startmonitor /deaf /nosystray
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Lexmark X5100 Series] "C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [THGuard] "F:\TrojanHunter 4.5\THGuard.exe"
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [TraySantaCruz] F:\WINDOWS\System32\tbctray.exe
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\WEATHER.EXE 1
O4 - HKCU\..\Run: [SPSTEALT] "F:\Program Files\Free History Eraser\HistoryEraser.exe" /stealt
O4 - HKCU\..\Run: [Yahoo! Pager] 1
O4 - HKCU\..\Run: [PeerGuardian] F:\Program Files\PeerGuardian2\pg2.exe
O4 - Startup: Connection Manager.lnk = F:\Program Files\SBC\Connection Manager\CManager.exe
O4 - Startup: ERUNT AutoBackup.lnk = F:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = F:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O8 - Extra context menu item: &Define - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Look Up in &Encyclopedia - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\npjpi150_08.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\npjpi150_08.dll
O9 - Extra button: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra 'Tools' menuitem: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll (file missing)
O9 - Extra button: Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - http://www.net2phone.com/ (file missing)
O9 - Extra 'Tools' menuitem: Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - http://www.net2phone.com/ (file missing)
O9 - Extra button: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra 'Tools' menuitem: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Dell Home - {08DCFC6C-B6E4-480C-95A4-FC64F37B787E} - http://www.dellnet.com (file missing) (HKCU)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O12 - Plugin for .bcf: C:\Program Files\Internet Explorer\Plugins\NPBelv32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall-beta.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200312…meInstaller.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - F:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - F:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - F:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: STOPzilla Local Service - Unknown owner - C:\Program Files\STOPzilla!\szntsvc.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
Hey egates, Don't worry about the _restore files. We will get to those. It is interesting that Trojan Hunter did not delete those files that Kapersky and Blacklight detected. I will prepare a fix. I thank you for being patient. My goal is to get a clean Blacklight log and a Kapersky log with just infected _restore files. Then the rest will be a snap.
Hi egates,

Let's do this:

Please download The Avenger by Swandog46 to the Desktop.
Click on Avenger.zip to open the file
Then, extract avenger.exe to the Desktop

Next, copy all the blue text below to the Clipboard by highlighting it and pressing Ctrl+C:

Files to delete:
F:\WINDOWS\fffd0eff_{4FB9B3DC-E454-40F8-A6AC-7D85218BF41D}.tmp:ropaup
F:\WINDOWS\KB823559.log:qmtix
F:\WINDOWS\SYSTEM32\dmloq.exe.tcf
F:\WINDOWS\VideoSetup.exe:ucxkt
F:\WINDOWS\wininit.tmp:qssrku


Start The Avenger program by clicking its icon on the Desktop.
Under: Script file to execute, select: Input Script Manually
Now click on the Magnifying Glass icon
It opens a new window titled: View/edit script
Paste the text copied to clipboard into this window by pressing Ctrl+V.
Click Done

Next, click on the Green Light to begin the execution of the script
Answer Yes twice when prompted.

The Avenger automatically does following:
Restarts the computer.
On reboot, briefly opens a black command window on the Desktop. This is normal.

After the restart, it creates a log that opens with the results of Avenger’s actions.
This log is located at C:\avenger.txt

Please provide C:\avenger.txt in your reply.
Logfile of The Avenger version 1, by Swandog46 Running from registry key: \Registry\Machine\System\CurrentControlSet\Services\vchqecks ******************* Script file located at: \??\F:\tghuwhwn.txt Script file opened successfully. Script file read successfully Backups directory opened successfully at F:\Avenger ******************* Beginning to process script file: Could not delete file F:\WINDOWS\fffd0eff_{4FB9B3DC-E454-40F8-A6AC-7D85218BF41D}.tmp:ropaup Deletion of file F:\WINDOWS\fffd0eff_{4FB9B3DC-E454-40F8-A6AC-7D85218BF41D}.tmp:ropaup failed! Could not process line: F:\WINDOWS\fffd0eff_{4FB9B3DC-E454-40F8-A6AC-7D85218BF41D}.tmp:ropaup Status: 0xc0000033 Could not delete file F:\WINDOWS\KB823559.log:qmtix Deletion of file F:\WINDOWS\KB823559.log:qmtix failed! Could not process line: F:\WINDOWS\KB823559.log:qmtix Status: 0xc0000033 File F:\WINDOWS\SYSTEM32\dmloq.exe.tcf deleted successfully. Could not delete file F:\WINDOWS\VideoSetup.exe:ucxkt Deletion of file F:\WINDOWS\VideoSetup.exe:ucxkt failed! Could not process line: F:\WINDOWS\VideoSetup.exe:ucxkt Status: 0xc0000033 Could not delete file F:\WINDOWS\wininit.tmp:qssrku Deletion of file F:\WINDOWS\wininit.tmp:qssrku failed! Could not process line: F:\WINDOWS\wininit.tmp:qssrku Status: 0xc0000033 Completed script processing. ******************* Finished! Terminate.
Hi egates, Please ignore what I posted. I am obtaining some expert help. Will get back to you. If you already did the stuff please post the results.
Hi egates,

Please do the following:

STEP 1.
======
AboutBuster
  • Download AboutBuster.
    AboutBuster
  • Unzip AboutBuster in an own folder such as C:\AboutBuster.
  • Start AboutBuster.exe. Click OK, Update, Check For Update and download the updates if present.
  • Start Aboutbuster and let it scan. When the scan is done and you choose exit, it will automatically create a log in the same folder where aboutbuster is in.
  • Please post the results.
oops…I checked the post this morning on my way out the door and left it up on the screen. when i got home a few minutes ago, i went ahead with the new avenger script. it rebooted and i logged back in and came back to post the results when i saw the above "ignore what i posted" post. hope everything's ok, anyway here's the second avenger report Logfile of The Avenger version 1, by Swandog46 Running from registry key: \Registry\Machine\System\CurrentControlSet\Services\yfdqeflh ******************* Script file located at: \??\F:\WINDOWS\system32\ujuvjugc.txt Script file opened successfully. Script file read successfully Backups directory opened successfully at F:\Avenger ******************* Beginning to process script file: File F:\WINDOWS\fffd0eff_{4FB9B3DC-E454-40F8-A6AC-7D85218BF41D}.tmp deleted successfully. File F:\WINDOWS\KB823559.log deleted successfully. File F:\WINDOWS\VideoSetup.exe deleted successfully. File F:\WINDOWS\wininit.tmp deleted successfully. Completed script processing. ******************* Finished! Terminate. i'll start the aboutBuster thing now
Here's the ab log contents (I followed its instructions and ran it in safemode, twice) AboutBuster 6.05 Scan started on [8/27/2006] at [5:25:14 PM] ————————————————————- Internet Explorer Instances Terminated! HomeSearch Service stopped if present ————————————————————- Removed Stream! F:\WINDOWS\fffd0a45_{03F70877-44ED-476B-9764-CE686C4058A7}.tmp:vtaxjp Removed Stream! F:\WINDOWS\fffd0d85_{9DADD548-4861-405F-A07A-6B5011A9DBFE}.tmp:gmdifc Removed Stream! F:\WINDOWS\fffd0ea1_{0A7FF1A9-3A79-42A5-B2DF-C4CDAD4EAA73}.tmp:znwvam Removed Stream! F:\WINDOWS\fffd153b_{B60424C8-80ED-4539-97D0-CA872F304190}.tmp:odwyqt Removed Stream! F:\WINDOWS\fffd15ef_{3C1855FD-7504-4ECE-A577-E67AEF362EAD}.tmp:yeplse Removed Stream! F:\WINDOWS\fffd1669_{B76738CF-05A4-48FB-87DE-9F81393B12E3}.tmp:rfiqno Removed Stream! F:\WINDOWS\fffd5b13_{89B330BF-DBF7-443A-8B89-61123D79095B}.tmp:mfoyow Removed Stream! F:\WINDOWS\fffd5e17_{225C3B35-C674-4D6E-9766-6915C41ED191}.tmp:fgzdig Removed Stream! F:\WINDOWS\fffd5ea5_{0A8B6C49-C7A0-4D86-A6A8-95C6D03DAAD7}.tmp:xhrqlr Removed Stream! F:\WINDOWS\fffe8717_{76C46E6B-5829-492C-9C9D-FBBB74C3A204}.tmp:hmtgzv Removed Stream! F:\WINDOWS\fffe887d_{2403D314-6F5B-4A6B-9171-BCA75B9324CA}.tmp:smmtbx Removed Stream! F:\WINDOWS\fffe8961_{D1C7E37A-325D-4CC2-867A-C0E5858D8B14}.tmp:kneyvi Removed Stream! F:\WINDOWS\fffecc05_{B08C81B2-D1FA-4792-ABCB-20542AB68B55}.tmp:luecal Removed Stream! F:\WINDOWS\fffecc05_{EAA764F5-86BD-424A-BF80-EE0BD675406C}.tmp:rshulb Removed Stream! F:\WINDOWS\fffeccc1_{482832CB-D91A-4E55-B276-FD1BE1803940}.tmp:dvxhcw Removed Stream! F:\WINDOWS\fffecd13_{83BE2CE2-5991-442B-A197-E4474C55E36B}.tmp:jtzafl Removed Stream! F:\WINDOWS\fffece3f_{A5C8B62A-7272-4F47-8625-B6932D623EFC}.tmp:wwhmwg Removed Stream! F:\WINDOWS\fffece3f_{D64FA804-26D6-472E-9E8E-1EE8073701CF}.tmp:cusnhw Removed Stream! F:\WINDOWS\IsUn040a.exe:nsykg Removed Stream! F:\WINDOWS\JAUTOEXP.INI:gtiyi Removed Stream! F:\WINDOWS\KB810217.log:ymbdd Removed Stream! F:\WINDOWS\Mpcwin01.ini:ntmder Removed Stream! F:\WINDOWS\mpgcom.dll:fteigc Removed Stream! F:\WINDOWS\MSBATCH.INF:yupoae Removed Stream! F:\WINDOWS\PATCH.EXE:bwssi Removed Stream! F:\WINDOWS\PCFRIEND.INI:uxdfk Removed Stream! F:\WINDOWS\Photos.dll:myvle Removed Stream! F:\WINDOWS\Plus!.bmp:rnxzgk Removed Stream! F:\WINDOWS\Prairie Wind.bmp:kopebu Removed Stream! F:\WINDOWS\puzzle.bmp:cparvx Removed Stream! F:\WINDOWS\ssdpcache.txt:ssphiz Removed Stream! F:\WINDOWS\Straw Mat.bmp:dtaafm ————————————————————- Removed File! : F:\WINDOWS\bxwig.dat Removed File! : F:\WINDOWS\lnkmu.log Removed File! : F:\WINDOWS\n_cusnhw.dat Removed File! : F:\WINDOWS\n_muoyks.txt Removed File! : F:\WINDOWS\n_snjttz.dat Removed File! : F:\WINDOWS\n_vfmfse.log Removed File! : F:\WINDOWS\n_xhrqlr.dat Removed File! : F:\WINDOWS\n_zbbbeg.dat Removed File! : F:\WINDOWS\pmxnu.dat Removed File! : F:\WINDOWS\qmmzy.txt Removed File! : F:\WINDOWS\rpkyw.dat Removed File! : F:\WINDOWS\wjrwr.txt Removed File! : F:\WINDOWS\system32\bbusr.txt Removed File! : F:\WINDOWS\system32\ccemm.txt Removed File! : F:\WINDOWS\system32\dfdee.dat Removed File! : F:\WINDOWS\system32\jiwzv.txt Removed File! : F:\WINDOWS\system32\linsv.dat Removed File! : F:\WINDOWS\system32\ncitv.log Removed File! : F:\WINDOWS\system32\tyxmg.log Removed File! : F:\WINDOWS\system32\uhuxn.txt Removed File! : F:\WINDOWS\system32\xgbqg.log ————————————————————- Removed Temp Files Internet Explorer Settings Reset! ————————————————————- Scan was COMPLETED SUCCESSFULLY at 5:39:33 PM AboutBuster 6.05 Scan started on [8/27/2006] at [5:41:28 PM] ————————————————————- Internet Explorer Instances Terminated! HomeSearch Service stopped if present ————————————————————- No Ads Found! ————————————————————- No Files Found! ————————————————————- Scan was COMPLETED SUCCESSFULLY at 5:43:46 PM
08/27/06 21:46:08 [Info]: BlackLight Engine 1.0.46 initialized 08/27/06 21:46:08 [Info]: OS: 5.1 build 2600 (Service Pack 2) 08/27/06 21:46:08 [Note]: 7019 4 08/27/06 21:46:08 [Note]: 7005 0 08/27/06 21:46:13 [Note]: 7006 0 08/27/06 21:46:13 [Note]: 7011 996 08/27/06 21:46:14 [Note]: 7026 0 08/27/06 21:46:14 [Note]: 7026 0 08/27/06 21:46:25 [Note]: FSRAW library version 1.7.1019 08/27/06 21:50:56 [Note]: 7007 0

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI