This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Does everything look ok here?

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.1
Scan saved at 11:29:01 PM, on 9/3/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\DVD Shrink\DVD Shrink 3.2.exe
C:\Program Files\Trillian\trillian.exe
C:\Documents and Settings\Dustin\Desktop\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1157167141843
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1157172167953
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe



StartupList report, 9/3/2006, 11:29:22 PM
StartupList version: 1.52.2
Started from : C:\Documents and Settings\Dustin\Desktop\HijackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
* Using default options
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\DVD Shrink\DVD Shrink 3.2.exe
C:\Program Files\Trillian\trillian.exe
C:\Documents and Settings\Dustin\Desktop\HijackThis.exe

————————————————–

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

BCMSMMSG = BCMSMMSG.exe
NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
itype = "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
MISAggregator =
nwiz = nwiz.exe /install
NvMediaCenter = RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
NeroFilterCheck = C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

SpybotSD TeaTimer = C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

————————————————–

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINDOWS\System32\logon.scr
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*

————————————————–


Enumerating Browser Helper Objects:

(no name) - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
(no name) - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll - {53707962-6F74-2D53-2644-206D7942484F}
(no name) - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
(no name) - c:\program files\google\googletoolbar2.dll - {AA58ED58-01DD-4d91-8333-CF10577473F7}

————————————————–

Enumerating Download Program Files:

[WUWebControl Class]
InProcServer32 = C:\WINDOWS\System32\wuweb.dll
CODEBASE = http://update.microsoft.com/windowsupdate/…b?1157167141843

[MUWebControl Class]
InProcServer32 = C:\WINDOWS\System32\muweb.dll
CODEBASE = http://update.microsoft.com/microsoftupdat…b?1157172167953

————————————————–

Enumerating Windows NT logon/logoff scripts:
*No scripts set to run*

Windows NT checkdisk command:
BootExecute = autocheck autochk *

Windows NT 'Wininit.ini':
PendingFileRenameOperations: C:\DOCUME~1\Dustin\LOCALS~1\Temp\NeroSearchTrayHook_{F15FBC17-856D-470F-A625-F9F18B232305}.dll


————————————————–

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\System32\webcheck.dll
SysTray: C:\WINDOWS\System32\stobject.dll

————————————————–
End of report, 4,738 bytes
Report generated in 0.016 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only


Thanks!
Thanks for sending your information. We are sorry for the delay in responding. The volunteers here are swamped and unfortunately not all logs get answered as quickly as we'd like.

Have you followed the suggestions in this topic ?
http://forums.tomcoyote.org/index.php?showtopic=57813

When you have done so, please post the logs requested, into this topic and I will assist you.

Please provide a description of the problem.

Please do not edit your Hijack This log. We need to see the entire logfile, with no revisions. If anything is disabled using MSCONFIG, please enable all, before scanning with Hijack This.


Please use the [external image: Posted Image] button to reply.
Cant get rid of these

Backdoor.IRCBot.dd

Dropper.VB.lu




Logfile of HijackThis v1.99.1
Scan saved at 1:30:04 AM, on 9/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Dustin\Desktop\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MPFTray] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1157167141843
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1157172167953
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe



———————————————————
ewido anti-spyware - Scan Report
———————————————————

+ Created at: 1:14:20 AM 9/10/2006

+ Scan result:



C:\Documents and Settings\Dustin\Desktop\Downloads\_\A1 Website Download v1.0.7.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\A1Monitor v7.0.0.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\ASCII Generator.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Acronis True Image 9.1 Enterprise Server.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Active SMART.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Ad Muncher v4.7.26039 BETA.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Advanced Windows Optimizer v.5.1.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\AdventNet Wifi Manager 4.5.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Age of Pirates Caribbean Tales.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Ahead NeroLinux v2.1.0.1.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Alliance Future Combat.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Amethyst DWG-2-PDF v2.01.01.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Amor SWF to Video Converter v.2.3.9.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Andrew Bird - Fingerlings.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Animation Workshop v2.0.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Any DVD 6.0.1.1.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\AoA Advanced X Video Converter v.4.5.1.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Armin Van Buuren - A State Of Trance 225.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Ashampoo Magic Defrag 1.10.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Atomix Virtual DJ 4.0.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\AutoRun Design Specialty v6.0.6.5.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Axialis IconWorkshop 6.01.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Axialis Screen Saver Producer 3.63.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Bad Boys II.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Beerfest 2006 CAM Xvid.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Better Than Ezra - Before The Robots.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Black and White 2 and Battle of the Gods iSO.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Bob Dylan - Love and Theft.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Bob Dylan - World Gone Wrong.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Body of Evidence DVDRip Xvid.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\CD Wave Editor v1.95.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Car Tycoon.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\ChrisTV Online 2.00.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Classroom Spy Professional v1.1.4.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\CleanerZoomer Professional v.3.51d.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\ClipCache Pro v.3.0.33.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\ClockWatch Server v.3.1.2.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\ComputerTime 1.0.1.11.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Crank (2006).rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\CuteFTP Pro v8.0.2.08.22.2006.5.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\CuteFTP Pro v8.0.2.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Dark Fall.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Darkstar One iSO.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Desktop Calendar Reminder v1.59.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Desktop Icon Toy v.1.2.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Desktop Tray Clock v2.3.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Diablo.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\DigitByte MIDI to WAV Maker 2.01834.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Driver Genius 2006 6.1.2518.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Durutti Column - Sex & Death.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\EZPlay Audio Player 2.0.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Error Doctor 2006.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\F.E.A.R. iSO.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\FTP Now v2.6.47.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Face On Body ver. 2.1.3.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\FairBot v.1.6 UPDATED DATECODE 083106.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Fallen LordsCondemnation iSO.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Final Fantasy VIII iSO.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Ford Street Racing.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Formula One 2006 PS2 iSO.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\GTA Liberty City Stories PS2 iSO.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Global Mapper v8.00.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Golden FTP Server Pro 2.70.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Halo Combat Evolved.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Harry Potter and the Chamber of Secrets.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Harry Potter and the Prisoner of Azkaban.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Hellogoodbye - Hellogoodbye (EP).rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Hitman 3 Contracts.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Hot Tamale (2006) DVDRip XviD.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Image Optimizer 5.10 Pro.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Internet Download Manager 5.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Invisible Browsing 5.0.52.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\J Dilla aka Jay Dee - Donuts.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Jack Johnson - In Between Dreams.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\KLS Backup 2006 Professional.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Keep Your Distance DVDRip Xvid.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Kingdia CD Extractor 3.0.0.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Kingdia DVD Audio Ripper 3.0.0.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Kingdia DVD Ripper 3.0.0.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Laurent Wolf - In The Club Vol. 1.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Lego Star Wars 2 The Original Trilogy.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Loose Change 2 - True story about 9 11 DVDRip Xvid.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\M-Audio Pro Sessions Vol.25.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\MAGIX Movies2go e-version v1.0.1.10.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\MacroMachine v3.1.7.0.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Magic Photo Editor 3.0.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Magic Photo Editor v3.0.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Mario Forever.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Martin Solveig - Hedonist.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Martin Solveig - Suite.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\McAfee 8.0 Full Bundle Pack.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Miami Vice TC DVDR-DREAMLiGHT.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Mission Impossible 3 TS Xvid-MaVen.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Monster House TC Xvid-PUKKA.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\My Notes Keeper 1.6.605.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\NHL 2006 iSO.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\NOD32 v.2.51.28.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\NXPowerLite v.2.3.1 Standard Edition.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\NXPowerLite v2.3.1 SE.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\NetConceal Anonymizer v.4.6.051.02.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\NetLimiter 2.0.81 Pro.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Norton Antivirus 2006.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Operational Art of War III-DEViANCE iSO.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\PC Privacy Software Spam Sweeper v3.3.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\PC Privacy Software Wiper Wizard v2.8.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\PC Repairs Gold Pack 21 in 1.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\PDF2Word 2006.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\PDF2Word v2.0.08.29.2006.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\PS FileRenamer v2.56.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\PassMark BurnInTest Pro 5.1.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\PassMark BurnInTest Pro v5.1.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Perfect Ace 2-RELOADED iSO.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\PhotoFiltre Studio v.8.0.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Photolightning v4.3.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Plato DVD to MP3 Ripper v4.4.7.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Power DVD 7 Deluxe.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\PowerUp XP Platinum 2.20 SE.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Print Manager Plus v.6.0.0.112.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Private Parts DVDRip Xvid.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\RapGet Fix 1.11.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Recover My Files v3.98.5061.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Rilo Kiley - More Adventurous.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Slither (2006).rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Snakes on a Plane TS Xvid.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Snappy Fax v.3.74.1.1.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\SolSuite 2006 6.9 Full.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Sothink DVD Ripper v1.1.60817.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Sothink iPod Video Converter v.1.1.60822.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Speed Up My PC 2.04.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Spy Professional V1.1.4.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Spyware Doctor 4.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Stardock Aquarium Desktop 2006.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\StatAssist v.2.0.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Stephen King Hearts in Atlantis 2001 DVDRip Xvid.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Super Cleaner 2.84.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Super Email Sender v.2.78.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Super Utilities Pro 6.21.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Superman Returns TS Xvid.maVen.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\SwiftDog RamSmash v1.94 2006.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\SwiftDog.NetScream v1.94 2006.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Switch Plus 1.05.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\System Cleaner 5.52.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Tears for Fears - The Seeds of Love.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\The Bat Professional v.3.85.02.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\The Bat v3.85.02.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\The Bravery - The Bravery.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\The Breed LiMiTED DVDRip XviD-ZN.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\The Cassandra Crossing 1976 DVDRip Xvid.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\The Clash - London Calling.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\The Da Vinci Code iSO.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\The Hulk.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\The Illusionist.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\The Lake House (2006).rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\The Wicker Man.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Themselves - Them.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Tiny Personal Firewall Pro 6.5.126.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Total Annihilation Battle Tactics iSO.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\TrackMania Sunrise iSO.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\TrojanHunter v.4.6 Build 928.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Tune Up Utilities v2006.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Turbo FTP v5.00.540.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\TurboFTP v5.00.540.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Ulead VideoStudio 10 Plus.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\User Bar Generator 2.2.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\VA - Different Sessions of Movie Music Vol. 1.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\VA - Songs of Jimmie Rodgers A Tribute.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Video Vision Plus 7.2.32.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Video Vision Plus v7.2.31.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\VideoGrabber v.1.0.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Voxengo Analogflux Suite VST v1.5.1.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\VueScan Pro v8.3.63.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\VueScan Professional v8.3.36.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\WinHex v13.2.SR-10.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\WinX DVD Ripper v.3.6.30.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Winamp MegaPack 2006.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Winenhance Clean Registry v3.1.0.0.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\WiseDesktop 1.2.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\World of Warcraft iSO.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\XRayz Software ClipCache Pro v3.0.33.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\XoftSpySE v4.29.xx.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\ZD Soft Video Recorder v1.0.3.0.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Zeallsoft Fun Morph v3.3.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Zylom Bookworm v.1.30.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\n00zn00zn00zn00z.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\WINDOWS\system32\p2pnetworking.exe -> Backdoor.IRCBot.dd : No action taken.
C:\t.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\svchost.exe -> Dropper.VB.lu : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Anfibia Desktop Orbiter v4.1.2.exe -> Dropper.VB.lu : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Aston 1.9.1.exe -> Dropper.VB.lu : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Avast Pro v4.7.exe -> Dropper.VB.lu : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\BSP Popup Shield v5.0.0.0.exe -> Dropper.VB.lu : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Backup To DVD CD v5.1.exe -> Dropper.VB.lu : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\BitSpirit 3.2.1.100.exe -> Dropper.VB.lu : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Blindwrite 6.0.exe -> Dropper.VB.lu : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Browserbob 4 Professional v4.1.3.0.exe -> Dropper.VB.lu : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Clip Plus 4.1.exe -> Dropper.VB.lu : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\CounterSpy 1.5.82.exe -> Dropper.VB.lu : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Dark Basic Professional v1.062.exe -> Dropper.VB.lu : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\DeepBurner Pro 1.8.0.225.exe -> Dropper.VB.lu : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\DivX 6.3.1 Beta 1.exe -> Dropper.VB.lu : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Download Accelerator Plus 8.1.3.0.exe -> Dropper.VB.lu : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Dvd Decrypter v3.5.4.0.exe -> Dropper.VB.lu : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Eudora 7.1.0.6 Beta.exe -> Dropper.VB.lu : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Exacttrend Web Log Explorer v3.1.exe -> Dropper.VB.lu : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\FileLocator Pro 3.1.exe -> Dropper.VB.lu : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Folder Lock 5.5.7.exe -> Dropper.VB.lu : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Force Vision v3.35.exe -> Dropper.VB.lu : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\FunPhotor v4.5.exe -> Dropper.VB.lu : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\GameGain v2.8.7.exe -> Dropper.VB.lu : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Hide Window Hotkey v2.5.exe -> Dropper.VB.lu : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Kaemsoft Screeny v1.6.0.0.exe -> Dropper.VB.lu : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Kerio MailServer 6.2.1 Build 1663.exe -> Dropper.VB.lu : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\KoolMoves v5.2.5.exe -> Dropper.VB.lu : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Movie Label 2007 2.0.exe -> Dropper.VB.lu : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\NOD32 2.51.28.exe -> Dropper.VB.lu : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Nero CD-DVD Speed 4.60.exe -> Dropper.VB.lu : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Nod32 AntiVirus 2.51.27.exe -> Dropper.VB.lu : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\PhotoRescue Pro v3.9.146.exe -> Dropper.VB.lu : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Photoplorer v2.05c.exe -> Dropper.VB.lu : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Spyware Doctor 4.0.0.2613.exe -> Dropper.VB.lu : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Spyware Scrapper v2.1.exe -> Dropper.VB.lu : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\TVU Player 2.2.0.exe -> Dropper.VB.lu : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Task Catcher v1.0.0.2.exe -> Dropper.VB.lu : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Ultra QuickTime Converter v1.0.2.exe -> Dropper.VB.lu : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Vista Transformation Pack 5.5.exe -> Dropper.VB.lu : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\Web Page Maker v2.2.exe -> Dropper.VB.lu : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\WinASO Registry Optimizer 2.7.exe -> Dropper.VB.lu : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\WinAntiVirus Pro 2007 3.0.257.1.exe -> Dropper.VB.lu : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\XP Tools 5.99.exe -> Dropper.VB.lu : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\XP Tools v5.99.exe -> Dropper.VB.lu : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\mIRC v6.2.exe -> Dropper.VB.lu : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\nLite 1.0.1 Beta.exe -> Dropper.VB.lu : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\pdfFactory Pro 3.01.exe -> Dropper.VB.lu : No action taken.
C:\Documents and Settings\Dustin\Desktop\Downloads\_\xzxzxzxzxzxz.exe -> Dropper.VB.lu : No action taken.
C:\RECYCLER\S-1-5-21-448539723-1547161642-839522115-1004\Dc32\T-233472-Madden 07 PC DVD ISO - Crack And Cd Key.exe -> Dropper.VB.lu : No action taken.
:mozilla.9:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.247realmedia : No action taken.
:mozilla.108:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.10:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.11:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.12:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.13:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.14:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.15:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.16:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.17:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.18:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.19:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.203:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.20:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.21:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.22:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.23:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.258:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.270:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.301:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.305:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.95:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.38:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.39:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.40:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.41:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.53:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Addynamix : No action taken.
:mozilla.54:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Addynamix : No action taken.
:mozilla.523:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Adjuggler : No action taken.
:mozilla.524:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Adjuggler : No action taken.
:mozilla.525:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Adjuggler : No action taken.
:mozilla.526:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Adjuggler : No action taken.
:mozilla.527:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Adjuggler : No action taken.
:mozilla.44:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Admarketplace : No action taken.
:mozilla.45:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Admarketplace : No action taken.
:mozilla.46:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Admarketplace : No action taken.
:mozilla.515:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.52:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.60:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Adtech : No action taken.
:mozilla.61:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Adtech : No action taken.
:mozilla.104:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Clickbank : No action taken.
:mozilla.116:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Com : No action taken.
:mozilla.156:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.157:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.158:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.159:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.160:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.161:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.162:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.163:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.164:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.165:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.166:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.167:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.168:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.169:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.170:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.202:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Findwhat : No action taken.
:mozilla.583:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.584:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.531:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Liveperson : No action taken.
:mozilla.532:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Liveperson : No action taken.
:mozilla.533:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Liveperson : No action taken.
:mozilla.534:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Liveperson : No action taken.
:mozilla.299:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Overture : No action taken.
:mozilla.300:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Overture : No action taken.
:mozilla.311:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Overture : No action taken.
:mozilla.55:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.56:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.57:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.58:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.59:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.314:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Questionmarket : No action taken.
:mozilla.315:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Questionmarket : No action taken.
:mozilla.316:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Questionmarket : No action taken.
:mozilla.553:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Realtracker : No action taken.
:mozilla.189:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Ru4 : No action taken.
:mozilla.190:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Ru4 : No action taken.
:mozilla.191:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Ru4 : No action taken.
:mozilla.192:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Ru4 : No action taken.
:mozilla.47:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Specificclick : No action taken.
:mozilla.48:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Specificclick : No action taken.
:mozilla.49:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Specificclick : No action taken.
:mozilla.50:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Specificclick : No action taken.
:mozilla.51:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Specificclick : No action taken.
:mozilla.377:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.378:C:\Documents and Settings\Dustin\Application Data\Mozilla\Firefox\Profiles\33d46koh.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.388:C:\Documents and Settings\Dustin\Application Data\Mozilla\F
Hi TonyJimmy:

Please print, or copy and paste this text into a Notepad file and place it on your desktop, to review as you work. Please proceed with this fix in the order provided below.

Cant get rid of these

Backdoor.IRCBot.dd

Dropper.VB.lu


Thanks for the input and the Ewido log. That explains a lot about why you requested assistance.

The problem likely lies in the way Ewido is being set up and ran. Please try the following, exactally as it shows below. If this is not done, the fix will fail.


First, lets do a bit of cleaning, to make the Ewido report managable.

Clean your Cache and Cookies in IE:
  • Close all instances of Outlook Express and Internet Explorer
  • Go to Control Panel > Internet Options > General tab
  • Click the "Delete Cookies" button
  • Next to it, Click the "Delete Files" button
  • When prompted, place a check in: "Delete all offline content", click OK
Clean your Cache and Cookies in Firefox (In case you also have Firefox installed):
  • Go to Tools > Options.
  • Click Privacy in the menu on the left side of the Options window.
  • Click the Clear button located to the right of each option (History, Cookies, Cache).
  • Click OK to close the Options window
    Alternatively, you can clear all information stored while browsing by clicking Clear All.
    A confirmation dialog box will be shown before clearing the information.
Clean other Temporary files + Recycle bin
  • Go to start > run and type: cleanmgr and click ok.
  • Let it scan your system for files to remove.
  • Make sure Temporary Files, Temporary Internet Files, and Recycle Bin are the only things checked.
  • Press OK to remove them.

    Please Note: This is a new version of Ewido Anti-Malware. It has a new set of setup and running instructions. Please delete any other versions and use the setup and usage directions shown below.

    Download ewido anti-spyware from HERE and save that file to your desktop.
    This is a 30 day trial of the program
  • Once you have downloaded ewido anti-spyware, locate the icon on the desktop and double-click it to launch the set up program.
  • Once the setup is complete you will need run ewido and update the definition files.
  • On the main screen select the icon "Update" then select the "Update now" link.
  • Next select the "Start Update" button, the update will start and a progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
  • Under "Reports"
  • Select "Automatically generate report after every scan"
  • Un-Select "Only if threats were found"
Close ewido anti-spyware, Do Not run a scan at this time.

Reboot your computer into SafeMode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight SafeMode then hit enter.
IMPORTANT: Do not open any other windows or programs while ewido is scanning, it may interfere with the scanning proccess:
  • Lauch ewido-anti-spyware by double-clicking the icon on your desktop.
  • Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
  • ewido will now begin the scanning process, be patient this may take a little time.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all actions"
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the screen and save it to a text file on your system (make sure to remember where you saved that file, this is important). I suggest saving it to your desktop.
Close ewido and reboot your system back into Normal Mode.

Then, please run Hijack This again. Scan and copy the log and post it into this topic, along with the Ewido report.

Please advise if any problems remain.

Please use the [external image: Posted Image] button to reply.
Logfile of HijackThis v1.99.1
Scan saved at 3:50:17 PM, on 9/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Dustin\Desktop\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MPFTray] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1157167141843
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1157172167953
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe




Nothing showed up in the ewido scan
Hi TonyJimmy:

Please print, or copy and paste this text into a Notepad file and place it on your desktop, to review as you work. Please proceed with this fix in the order provided below.


Nothing showed up in the ewido scan


That's what I like to see after Ewido is ran.

Not much left to do now. Just some leftovers to remove and some Protection Programs to download and install. Looking good.


Disable TeaTimer:
Please disable TeaTimer as it may hinder the removal of some entries. You can re-enable it after you're clean.To disable TeaTimer:
  • Run Spybot-S&D
  • Go to the Mode menu , and make sure "Advanced Mode " is selected
  • On the left hand side, choose Tools -> Resident
  • Uncheck "Resident TeaTimer " and OK any prompts
  • Restart your computer.
After all of the fixes are complete it is very important that you enable TeaTimer again.

Disable Ewido:
Please disable Ewido, as it may interfere with the fix.
To disable Ewido:
From the system tray:
  • Right-click the system tray icon and uncheck real time protection.
    or From within Ewido -
  • Under 'Your security status', if the real time protection is active, deactivate it by clicking 'real time protection' until the status says 'inactive'.
Once your log is clean you can re-enable Ewido.

Next:
Close all windows and browsers, leaving only HijackThis running.

Place a check beside each of these entries listed below, if still present.

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)

Click on Fix Checked when finished and exit HijackThis.


Updating Java
  • Download the latest version of Java Runtime Environment (JRE) 5.0 Update 8.
  • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-1_5_0_08-windowsi586-p.exe to install the newest version.
Your Hijack This logfile looks to be clean.
If there are no problems, please be sure to use the link to see TonyKlein's good advice (below). Those Protection programs offered free, are some of the best available.


One of the best features of Windows XP is the System Restore option, however if Malware infects a computer with this operating system the Malware can be backed up in the System Restore folder. Therefore, clearing the restore points is necessary after a virus removal.

To reset your restore points, please note that you will need to log into your computer with an account which has full administrator access. You will know if the account has administrator access because you will be able to see the System Restore tab. If the tab is missing, you are logged in under a limited account.

(winXP)

1. Turn off System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

2. Reboot.

3. Turn ON System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check *Turn off System Restore*.
Click Apply, and then click OK.

* Clean your Cache and Cookies in IE:
Close all instances of Outlook Express and Internet Explorer
Go to Control Panel > Internet Options > General tab
Click the "Delete Cookies" button
Next to it, Click the "Delete Files" button
When prompted, place a check in: "Delete all offline content", click OK

* Clean your Cache and Cookies in Firefox (In case you also have Firefox installed):
Go to Tools > Options.
Click Privacy in the menu on the left side of the Options window.
Click the Clear button located to the right of each option (History, Cookies, Cache).
Click OK to close the Options window
Alternatively, you can clear all information stored while browsing by clicking Clear All.
A confirmation dialog box will be shown before clearing the information.

* Clean other Temporary files + Recycle bin

Go to start > run and type: cleanmgr and click ok.
Let it scan your system for files to remove.
Make sure Temporary Files, Temporary Internet Files, and Recycle Bin are the only things checked.
Press OK to remove them.

Also, see TonyKlein's good advice and highly recommended FREE PROTECTION PROGRAMS. A must for all PC users.
http://forums.spywareinfo.com/index.php?showtopic=60955
So how did I get infected in the first place?

Safe surfing. :wavey:
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI