This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Can't erase BHO/AppInit_dll combo

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,
I have been trying to prepare my computer for SP2. In my HJT scan below, I have one of those 02/020 combos (hlnahln.dll) that I'm pretty sure is spyware or worse (can you confirm?) as it arrived along with some other trojans which I have since deleted with AVG Anti-Spyware. Previously I was running Spybot S&D and Ad-Aware regularly. Here's what I've tried to get rid of it so far:

HJT in both regular and safe mode with "delete on reboot".
Killbox - same as above.
Closing down explorer.exe and trying to delete via CMD (DOS) - I got the usual "Access is Denied" message.

Before all these attempts I have shut down System Restore.

My antivirus is McAfee VirusScan and my firewall is ZoneAlarm.

I'm not having any major problems (that I can notice anyway) except for getting the same 2 cookies a lot, but would like to get rid of it if possible. Nothing works so far, so I'm hoping one of you good folks can help.
Thanks kindly.

Logfile of HijackThis v1.99.1
Scan saved at 8:24:40 PM, on 1/25/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
E:\WINDOWS\Explorer.EXE
E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
E:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
E:\Program Files\Ahead\InCD\InCDsrv.exe
E:\WINDOWS\System32\nvsvc32.exe
E:\WINDOWS\System32\svchost.exe
E:\Program Files\Network Associates\VirusScan\VsStat.exe
E:\WINDOWS\system32\ZoneLabs\vsmon.exe
E:\Program Files\Network Associates\VirusScan\Vshwin32.exe
E:\WINDOWS\Mixer.exe
E:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
E:\Updater.exe
E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
E:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
E:\Program Files\QUICKENW\QWDLLS.EXE
E:\Program Files\Microsoft Office\Office\FINDFAST.EXE
E:\Program Files\Microsoft Office\Office\OSA.EXE
E:\Program Files\Network Associates\VirusScan\Avconsol.exe
E:\Program Files\Network Associates\VirusScan\Webscanx.exe
E:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
E:\WINDOWS\System32\wuauclt.exe
E:\Documents and Settings\Norman\My Documents\HijackThis\Halt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p…ER}&ar=home
F3 - REG:win.ini: run=
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {325F7293-F292-45EF-8AC9-464B96F79123} - E:\WINDOWS\system32\hlnahln.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - E:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE E:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [NeroFilterCheck] E:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Zone Labs Client] E:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
O4 - HKLM\..\Run: [iRiver Updater] \Updater.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - Startup: Microsoft Find Fast.lnk = E:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: MS Outlook.lnk = E:\Program Files\Microsoft Office\Office\OUTLOOK.EXE
O4 - Startup: Office Startup.lnk = E:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = E:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Monitor.lnk = E:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
O4 - Global Startup: Quicken Startup.lnk = E:\Program Files\QUICKENW\QWDLLS.EXE
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - E:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O16 - DPF: {C946EF6D-296D-4907-A6E1-ED0E8E5AF024} (LycosMail Upload Control) - http://mail.lycos.com/hanmail-ax/AttachMail.cab
O20 - Winlogon Notify: oxoplkwy - E:\WINDOWS\SYSTEM32\hlnahln.dll
O21 - SSODL: IEFilter - {B7AA8361-65B8-420D-B27D-94763E8404B9} - E:\WINDOWS\system32\IEFilter.dll (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVSync Manager (AvSynMgr) - Unknown owner - E:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
O23 - Service: InCD Helper (InCDsrv) - AHEAD Software - E:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - E:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McShield - Unknown owner - E:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
O23 - Service: MSCSPTISRV - Sony Corporation - E:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - E:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - E:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - E:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - E:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - E:\WINDOWS\system32\ZoneLabs\vsmon.exe
Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.

Download AVG Anti Rootkit© by Grisoft and save it to your desktop.
Double-click on AVG_AntiRootkit.exe to run it.
Click I Agree to agree to the EULA.
By default it will install to "C:\Program Files\GRISOFT\AVG Anti-Rootkit Beta"
Click Next to begin the installation then click Install
It will then ask you to reboot now to finish the installation.
Click Finish and your computer will reboot.
After it reboots, double-click on the AVG Anti-Rootkit Beta shortcut that is now on your desktop.
Click on the Perform in-depth search button to begin the scan.
The scan will take a while so be patient and let it complete.
When the scan is finished, click the Save result to file button.
Save the scan results to your desktop
Copy and Paste the scan results here

Post back with the vundofix log, the AVG-antispyware log and a new HijackThis log
Thanks for your reply. I downloaded and ran both Vundofix and AVG AntiRootkit as per your instructions, and unfortunately, neither one was able to find anything at all. Is there a Plan B I can try?
Please download the Killbox.
Unzip it to the desktop but do NOT run it yet.

Copy the text to a Notepad file and save it to your desktop! We will need the file later.

Then please reboot into Safe Mode by restarting your computer and pressing F8 as your computer is booting up. Then select the Safe Mode option.

Once in Safe Mode, please run Killbox.

Select "Delete on Reboot".

Open the text file with these instructions in it, and copy the file names below to the clipboard by highlighting them and pressing Control-C:

E:\WINDOWS\system32\hlnahln.dll
E:\WINDOWS\system32\IEFilter.dll

Return to Killbox, go to the File menu, and choose "Paste from Clipboard".

Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt.

If your computer does not restart automatically, please restart it manually.

Run HijackThis
Click on do a system scan only
Place a checkmark next to these lines(if still present)

F3 - REG:win.ini: run=
O2 - BHO: (no name) - {325F7293-F292-45EF-8AC9-464B96F79123} - E:\WINDOWS\system32\hlnahln.dll
O20 - Winlogon Notify: oxoplkwy - E:\WINDOWS\SYSTEM32\hlnahln.dll
O21 - SSODL: IEFilter - {B7AA8361-65B8-420D-B27D-94763E8404B9} - E:\WINDOWS\system32\IEFilter.dll (file missing)

Then close all windows except HijackThis and click Fix Checked

Go here to run an online scannner from Kaspersky.
  • Click on "Kaspersky Online Scanner"
  • A new smaller window will pop up. Press on "Accept". After reading the contents.
  • Now Kaspersky will update the anti-virus database. Let it run.
  • Click on "Next">"Scan Settings", and make sure the database is set to "extended". And check both the scan options. Then click OK.
  • Then click on "My Computer", and the scan will start.
  • Once finished, save the log as "KAV.txt" to the desktop.

Post back with the Kaspersky log and a new HijackThis log
I want to make sure I'm doing this right, so please bear with me. 1. I cannot paste both System32 files to Killbox at the same time (even with "All Files" box checked) Should I just do them separately, or am I doing something wrong? Are there certain options I need to check or uncheck? If I do them separately, do I say YES or NO (after the first one) at the "Pending Operations" prompt? 2. When I reboot after running Killbox, is it a normal reboot, or Safe Mode? 3. Do I have to turn off System Restore while I'm doing all of this? Thanks for the clarification.
Please keep system restore enabled

Let's try a slightly different method for killbox

Download killbox here:

KillBox


Unzip the folder to your desktop.

Start Killbox.exe

When it is open, enter E:\WINDOWS\system32\hlnahln.dll into the field labeled "Full path of file to delete".

Select the Delete on reboot option.

Then press the button that looks like a red circle with a white X in it.

You will get a prompt that asks you this:

All files will be deleted on reboot

Click yes to that

You will then get this prompt:

files will be removed on reboot. Do you want to reboot now?

CLICK NO

Then, repeat the process..
enter E:\WINDOWS\system32\IEFilter.dll into the field labeled "Full path of file to delete".

Select the Delete on reboot option.

Then press the button that looks like a red circle with a white X in it.

You will get a prompt that asks you this:

All files will be deleted on reboot

Click yes to that

You will then get this prompt:

files will be removed on reboot. Do you want to reboot now?

Click yes

Your computer will reboot and check to see if the file is gone.

If your computer does not restart automatically, please restart it manually.

After that please continue with the rest of the fix
OK, here are the HJT and KAS logs. Looks like Killbox could not remove the hlnahln.dll files; HJT was able to remove the F3 and O21 entries but not the original O2 and O20 ones; Kaspersky found 5 viruses and 68 infected objects (which I have not removed pending your reply).

Again, thanks for your time.

Logfile of HijackThis v1.99.1
Scan saved at 11:58:01 AM, on 1/29/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\Explorer.EXE
E:\WINDOWS\system32\spoolsv.exe
E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
E:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
E:\Program Files\Ahead\InCD\InCDsrv.exe
E:\WINDOWS\System32\nvsvc32.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\ZoneLabs\vsmon.exe
E:\WINDOWS\Mixer.exe
E:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
E:\Program Files\Network Associates\VirusScan\VsStat.exe
E:\Updater.exe
E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
E:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
E:\Program Files\QUICKENW\QWDLLS.EXE
E:\Program Files\Microsoft Office\Office\FINDFAST.EXE
E:\Program Files\Microsoft Office\Office\OSA.EXE
E:\Program Files\Network Associates\VirusScan\Vshwin32.exe
E:\Program Files\Network Associates\VirusScan\Avconsol.exe
E:\Program Files\Network Associates\VirusScan\Webscanx.exe
E:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
E:\Documents and Settings\Norman\My Documents\HijackThis\Halt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p…ER}&ar=home
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {325F7293-F292-45EF-8AC9-464B96F79123} - E:\WINDOWS\system32\hlnahln.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - E:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE E:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [NeroFilterCheck] E:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Zone Labs Client] E:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
O4 - HKLM\..\Run: [iRiver Updater] \Updater.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - Startup: Microsoft Find Fast.lnk = E:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: MS Outlook.lnk = E:\Program Files\Microsoft Office\Office\OUTLOOK.EXE
O4 - Startup: Office Startup.lnk = E:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = E:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Monitor.lnk = E:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
O4 - Global Startup: Quicken Startup.lnk = E:\Program Files\QUICKENW\QWDLLS.EXE
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - E:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O16 - DPF: {C946EF6D-296D-4907-A6E1-ED0E8E5AF024} (LycosMail Upload Control) - http://mail.lycos.com/hanmail-ax/AttachMail.cab
O20 - Winlogon Notify: oxoplkwy - E:\WINDOWS\SYSTEM32\hlnahln.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVSync Manager (AvSynMgr) - Unknown owner - E:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
O23 - Service: InCD Helper (InCDsrv) - AHEAD Software - E:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - E:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McShield - Unknown owner - E:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
O23 - Service: MSCSPTISRV - Sony Corporation - E:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - E:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - E:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - E:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - E:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - E:\WINDOWS\system32\ZoneLabs\vsmon.exe


——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Monday, January 29, 2007 1:59:33 PM
Operating System: Microsoft Windows XP Professional, Service Pack 1 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 29/01/2007
Kaspersky Anti-Virus database records: 263047
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 64223
Number of viruses found: 5
Number of infected objects: 68 / 0
Number of suspicious objects: 0
Duration of the scan process: 00:39:09

Infected Object Name / Virus Name / Last Action
E:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
E:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
E:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
E:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
E:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
E:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
E:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
E:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
E:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
E:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
E:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 f … /[From 6.43 (******) FROM_HAS_MIXED_NUMS,HTML_20_30,HTML_FONTCOLOR_BLUE,HTML_FONTCOLOR_GREEN,HTML_FONTCOLOR_RED,HTML_FONTCOLOR_UNSAFE,HTML … /[From host-148-244-86-81.b … /[From "Amadeus" <[removed]>][Date Tue, 11 Jan 2005 10:01:00 -0600]/UNNAMED Infected: Email-Worm.Win32.Bagle.eb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 f … /[From 6.43 (******) FROM_HAS_MIXED_NUMS,HTML_20_30,HTML_FONTCOLOR_BLUE,HTML_FONTCOLOR_GREEN,HTML_FONTCOLOR_RED,HTML_FONTCOLOR_UNSAFE,HTML … /[From host-148-244-86-81.block.alestra.net.mx [148.244.86.81]][Date Wed, 2 Nov 2005 09:43:39 -0500 (EST)]/UNNAMED Infected: Email-Worm.Win32.Bagle.eb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 f … /[From 6.43 (******) FROM_HAS_MIXED_NUMS,HTML_20_30,HTML_FONTCOLOR_BLUE,HTML_FONTCOLOR_GREEN,HTML_FONTCOLOR_RED,HTML_FONTCOLOR_UNSAFE,HTML_ … /[From "Shaw's E … … /[From <[removed]>][Date Mon, 24 Oct 2005 14:20:01 - .. … /text Infected: Email-Worm.Win32.Bagle.eb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 f … /[From 6.43 (******) FROM_HAS_MIXED_NUMS,HTML_20_30,HTML_FONTCOLOR_BLUE,HTML_FONTCOLOR_GREEN,HTML_FONTCOLOR_RED,HTML_FONTCOLOR_UNSAFE,HTML_ … /[From "Shaw's E … … /[From <[removed]>][Date Mon, 24 Oct 2005 14:20:01 - … /UNNAMED Infected: Email-Worm.Win32.Bagle.eb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 f … /[From 6.43 (******) FROM_HAS_MIXED_NUMS,HTML_20_30,HTML_FONTCOLOR_BLUE,HTML_FONTCOLOR_GREEN,HTML_FONTCOLOR_RED,HTML_FONTCOLOR_UNSAFE,HTML_ … /[From "Shaw's E … … /[From <[removed]>][Date Mon, 24 Oct 2005 14:20:01 -0700]/UNNAMED Infected: Email-Worm.Win32.Bagle.eb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 f … /[From 6.43 (******) FROM_HAS_MIXED_NUMS,HTML_20_30,HTML_FONTCOLOR_BLUE,HTML_FONTCOLOR_GREEN,HTML_FONTCOLOR_RED,HTML_FONTCOLOR_UNSAFE,HTML_ … /[From "Shaw's E … /[From "Wrapped C. Kenned" <[removed]>][Date Sun, 23 Oct 2005 00:15:24 -0700]/UNNAMED Infected: Email-Worm.Win32.Bagle.eb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 f … /[From 6.43 (******) FROM_HAS_MIXED_NUMS,HTML_20_30,HTML_FONTCOLOR_BLUE,HTML_FONTCOLOR_GREEN,HTML_FONTCOLOR_RED,HTML_FONTCOLOR_UNSAFE,HTML_ … /[From "Shaw's Eservice Center" <[removed]>][Date Wed, 19 Oct 2005 08:55:08 -0700 (MST … /text Infected: Email-Worm.Win32.Bagle.eb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 f … /[From 6.43 (******) FROM_HAS_MIXED_NUMS,HTML_20_30,HTML_FONTCOLOR_BLUE,HTML_FONTCOLOR_GREEN,HTML_FONTCOLOR_RED,HTML_FONTCOLOR_UNSAFE,HTML_ … /[From "Shaw's Eservice Center" <[removed]>][Date Wed, 19 Oct 2005 08:55:08 -0700 (MST)]/UNNAMED Infected: Email-Worm.Win32.Bagle.eb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 f … /[From 6.43 (******) FROM_HAS_MIXED_NUMS,HTML_20_30,HTML_FONTCOLOR_BLUE,HTML_FONTCOLOR_GREEN,HTML_FONTCOLOR_RED,HTML_FONTCOLOR_UNSAFE,HTML_FONT_BIG,HTM … … /[From "Inadmissible C. Decimation" <[removed]>][Date Tue, 18 Oct 2005 23:25:59 -0700]/UNNAMED Infected: Email-Worm.Win32.Bagle.eb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 f … /[From 6.43 (******) FROM_HAS_MIXED_NUMS,HTML_20_30,HTML_FONTCOLOR_BLUE,HTML_FONTCOLOR_GREEN,HTML_FONTCOLOR_RED,HTML_FONTCOLOR_UNSAFE,HTML_FONT_BIG,HTM … /[Fro … /[From "Sonja Velt" <[removed]>][Date Fri, 14 Oct 2005 11:59:00 -070 … /text Infected: Email-Worm.Win32.Bagle.eb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 f … /[From 6.43 (******) FROM_HAS_MIXED_NUMS,HTML_20_30,HTML_FONTCOLOR_BLUE,HTML_FONTCOLOR_GREEN,HTML_FONTCOLOR_RED,HTML_FONTCOLOR_UNSAFE,HTML_FONT_BIG,HTM … /[Fro … /[From "Sonja Velt" <[removed]>][Date Fri, 14 Oct 2005 11:59:00 -0700]/UNNAMED Infected: Email-Worm.Win32.Bagle.eb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 f … /[From 6.43 (******) FROM_HAS_MIXED_NUMS,HTML_20_30,HTML_FONTCOLOR_BLUE,HTML_FONTCOLOR_GREEN,HTML_FONTCOLOR_RED,HTML_FONTCOLOR_UNSAFE,HTML_FONT_BIG,HTM … /[Fro … /[From "Sonja Velt" <[removed]>][Date Thu, 13 Oct 2005 09:17:52 -070 … /text Infected: Email-Worm.Win32.Bagle.eb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 f … /[From 6.43 (******) FROM_HAS_MIXED_NUMS,HTML_20_30,HTML_FONTCOLOR_BLUE,HTML_FONTCOLOR_GREEN,HTML_FONTCOLOR_RED,HTML_FONTCOLOR_UNSAFE,HTML_FONT_BIG,HTM … /[Fro … /[From "Sonja Velt" <[removed]>][Date Thu, 13 Oct 2005 09:17:52 -0700]/UNNAMED Infected: Email-Worm.Win32.Bagle.eb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 f … /[From 6.43 (******) FROM_HAS_MIXED_NUMS,HTML_20_30,HTML_FONTCOLOR_BLUE,HTML_FONTCOLOR_GREEN,HTML_FONTCOLOR_RED,HTML_FONTCOLOR_UNSAFE,HTML_FONT_BIG,HTM … /[Fro … /[From "Sonja Velt" <[removed]>][Date Thu, 13 Oct 2005 08:56:35 -070 … /text Infected: Email-Worm.Win32.Bagle.eb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 f … /[From 6.43 (******) FROM_HAS_MIXED_NUMS,HTML_20_30,HTML_FONTCOLOR_BLUE,HTML_FONTCOLOR_GREEN,HTML_FONTCOLOR_RED,HTML_FONTCOLOR_UNSAFE,HTML_FONT_BIG,HTM … /[Fro … /[From "Sonja Velt" <[removed]>][Date Thu, 13 Oct 2005 08:56:35 -0700]/UNNAMED Infected: Email-Worm.Win32.Bagle.eb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 f … /[From 6.43 (******) FROM_HAS_MIXED_NUMS,HTML_20_30,HTML_FONTCOLOR_BLUE,HTML_FONTCOLOR_GREEN,HTML_FONTCOLOR_RED,HTML_FONTCOLOR_UNSAFE,HTML_FONT_BIG,HTM … /[Fro … /[From "Sonja Velt" <[removed]>][Date Thu, 13 Oct 2005 08:56:24 -070 … /text Infected: Email-Worm.Win32.Bagle.eb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 f … /[From 6.43 (******) FROM_HAS_MIXED_NUMS,HTML_20_30,HTML_FONTCOLOR_BLUE,HTML_FONTCOLOR_GREEN,HTML_FONTCOLOR_RED,HTML_FONTCOLOR_UNSAFE,HTML_FONT_BIG,HTM … /[Fro … /[From "Sonja Velt" <[removed]>][Date Thu, 13 Oct 2005 08:56:24 -0700]/UNNAMED Infected: Email-Worm.Win32.Bagle.eb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 f … /[From 6.43 (******) FROM_HAS_MIXED_NUMS,HTML_20_30,HTML_FONTCOLOR_BLUE,HTML_FONTCOLOR_GREEN,HTML_FONTCOLOR_RED,HTML_FONTCOLOR_UNSAFE,HTML_FONT_BIG,HTM … /[From "K.C. (Karen) Cameron" <[removed]>][Date Wed, 12 Oct 2005 19:25:00 -0400]/UNNAMED Infected: Email-Worm.Win32.Bagle.eb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 f … /[From 6.43 (******) FROM_HAS_MIXED_NUMS,HTML_20_30,HTML_FONTCOLOR_BLUE,HTML_FONTCOLOR_GREEN,HTML_FONTCOLOR_RED,HTML_FONTCOLOR_UNSAFE,HTML_FONT_BIG,HTML_ … /[From Mai … /[From Anne Marsh <[removed]>][Date Sat, 08 Oct 2005 12:59:12 -0700]/UNNAMED Infected: Email-Worm.Win32.Bagle.eb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 f … /[From 6.43 (******) FROM_HAS_MIXED_NUMS,HTML_20_30,HTML_FONTCOLOR_BLUE,HTML_FONTCOLOR_GREEN,HTML_FONTCOLOR_RED,HTML_FONTCOLOR_UNSAFE,HTML_FONT_BIG,HTML_ … /[From Mail Delivery Subsystem ][Date Thu, 11 Aug 2005 00:01:32 -0700 (PDT)]/UNNAMED Infected: Email-Worm.Win32.Bagle.eb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 f … /[From 6.43 (******) FROM_HAS_MIXED_NUMS,HTML_20_30,HTML_FONTCOLOR_BLUE,HTML_FONTCOLOR_GREEN,HTML_FONTCOLOR_RED,HTML_FONTCOLOR_UNSAFE,HTML_FONT_BIG,HTML_FONT_FACE_ODD .. … /[From Info <[removed]>][Date Wed, 27 Jul 2005 17:30:07 -0700]/UNNAMED Infected: Email-Worm.Win32.Bagle.eb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 f … /[From 6.43 (******) FROM_HAS_MIXED_NUMS,HTML_20_30,HTML_FONTCOLOR_BLUE,HTML_FONTCOLOR_GREEN,HTML_FONTCOLOR_RED,HTML_FONTCOLOR_UNSAFE,HTML_FONT_BIG,HTML_FONT_FACE_ODD … /[From "Chris Mullin" <[removed]>][Date Wed, 13 Jul 2005 12:30:03 -0700]/text Infected: Email-Worm.Win32.Bagle.eb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 f … /[From 6.43 (******) FROM_HAS_MIXED_NUMS,HTML_20_30,HTML_FONTCOLOR_BLUE,HTML_FONTCOLOR_GREEN,HTML_FONTCOLOR_RED,HTML_FONTCOLOR_UNSAFE,HTML_FONT_BIG,HTML_FONT_FACE_ODD … … /[From [removed]][Date Sun, 19 Jun 2005 20:23:44 -0400 (EDT)]/text Infected: Email-Worm.Win32.Bagle.eb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 f … /[From 6.43 (******) FROM_HAS_MIXED_NUMS,HTML_20_30,HTML_FONTCOLOR_BLUE,HTML_FONTCOLOR_GREEN,HTML_FONTCOLOR_RED,HTML_FONTCOLOR_UNSAFE,HTML_FONT_BIG,HTML_FONT_FACE_ODD … … /[From Anne Marsh <[removed]>][Date Fri, 03 Jun 2005 12:52:50 -0700]/text Infected: Email-Worm.Win32.Bagle.eb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 f … /[From 6.43 (******) FROM_HAS_MIXED_NUMS,HTML_20_30,HTML_FONTCOLOR_BLUE,HTML_FONTCOLOR_GREEN,HTML_FONTCOLOR_RED,HTML_FONTCOLOR_UNSAFE,HTML_FONT_BIG,HTML_FONT_FACE_ODD … /[From Sandy Branning <[removed]>][Date Wed, 25 May 2005 13:53:27 -0700]/text Infected: Email-Worm.Win32.Bagle.eb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 f … /[From 6.43 (******) FROM_HAS_MIXED_NUMS,HTML_20_30,HTML_FONTCOLOR_BLUE,HTML_FONTCOLOR_GREEN,HTML_FONTCOLOR_RED,HTML_FONTCOLOR_UNSAFE,HTML_FONT_BIG,HTML_FONT_FACE_ODD,HTML_MESSAGE,MIME_HTML_ONLY,MIME_HTML_ONLY_MULTI,NOT_ADVISOR][Date Fri, 20 May 2005 03:04: Infected: Email-Worm.Win32.Bagle.eb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 feb 2005 08:16:36 +0100]/UNNAMED/[From "Frankel Tori"<[removed]>][Date qua, 09 fev 2005 20:53:03 +0100]/UNNAMED/[From "Customer Service, … /[From fr … /[Fro … / … /[From "Administration" <[removed]>][Date Fri, 13 May 2005 12:14:44 -0700]/text Infected: Email-Worm.Win32.Bagle.eb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 feb 2005 08:16:36 +0100]/UNNAMED/[From "Frankel Tori"<[removed]>][Date qua, 09 fev 2005 20:53:03 +0100]/UNNAMED/[From "Customer Service, … /[From fr … /[Fro … / .. … /[From "Carlos" <[removed]>][Date Sun, 08 May 2005 17:28:16 -0500]/UNNAMED Infected: Email-Worm.Win32.Bagle.eb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 feb 2005 08:16:36 +0100]/UNNAMED/[From "Frankel Tori"<[removed]>][Date qua, 09 fev 2005 20:53:03 +0100]/UNNAMED/[From "Customer Service, … /[From fr … /[Fro … / .. … /[From Anne Marsh <[removed]>][Date Thu, 28 Apr 2005 14:54:33 -0700]/text Infected: Email-Worm.Win32.Bagle.eb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 feb 2005 08:16:36 +0100]/UNNAMED/[From "Frankel Tori"<[removed]>][Date qua, 09 fev 2005 20:53:03 +0100]/UNNAMED/[From "Customer Service, … /[From fr … /[Fro … / … /[ … /[From [removed]][Date Mon, 25 Apr 2005 16:17:33 -0700 (MST)]/text Infected: Email-Worm.Win32.Bagle.eb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 feb 2005 08:16:36 +0100]/UNNAMED/[From "Frankel Tori"<[removed]>][Date qua, 09 fev 2005 20:53:03 +0100]/UNNAMED/[From "Customer Service, … /[From fr … /[Fro … / … /[From "Support Team" <[removed]>][Date Sat, 16 Apr 2005 12:00:49 -0700]/text Infected: Email-Worm.Win32.Bagle.eb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 feb 2005 08:16:36 +0100]/UNNAMED/[From "Frankel Tori"<[removed]>][Date qua, 09 fev 2005 20:53:03 +0100]/UNNAMED/[From "Customer Service, … /[From fr … /[Fro … /[From Nicolle Blok <[removed]>][Date Sun, 10 Apr 2005 13:42:47 +0200]/UNNAMED Infected: Email-Worm.Win32.Bagle.eb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 feb 2005 08:16:36 +0100]/UNNAMED/[From "Frankel Tori"<[removed]>][Date qua, 09 fev 2005 20:53:03 +0100]/UNNAMED/[From "Customer Service, … /[From fr … /[Fro … /[From "Sonja Velt" <[removed]>][Date Tue, 29 Mar 2005 08:07:07 - .. … /text Infected: Email-Worm.Win32.Bagle.eb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 feb 2005 08:16:36 +0100]/UNNAMED/[From "Frankel Tori"<[removed]>][Date qua, 09 fev 2005 20:53:03 +0100]/UNNAMED/[From "Customer Service, … /[From fr … /[Fro … /[From "Sonja Velt" <[removed]>][Date Tue, 29 Mar 2005 08:07:07 - … /UNNAMED Infected: Email-Worm.Win32.Bagle.eb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 feb 2005 08:16:36 +0100]/UNNAMED/[From "Frankel Tori"<[removed]>][Date qua, 09 fev 2005 20:53:03 +0100]/UNNAMED/[From "Customer Service, … /[From fr … /[Fro … /[From "Sonja Velt" <[removed]>][Date Tue, 29 Mar 2005 08:07:07 -0800]/UNNAMED Infected: Email-Worm.Win32.Bagle.eb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 feb 2005 08:16:36 +0100]/UNNAMED/[From "Frankel Tori"<[removed]>][Date qua, 09 fev 2005 20:53:03 +0100]/UNNAMED/[From "Customer Service, … /[From fr … /[From "K. … /[From "nicolaas.velt" <[removed]>][Date Sat, 5 Mar 2005 18:54:17 +0100]/text Infected: Email-Worm.Win32.Bagle.eb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 feb 2005 08:16:36 +0100]/UNNAMED/[From "Frankel Tori"<[removed]>][Date qua, 09 fev 2005 20:53:03 +0100]/UNNAMED/[From "Customer Service, … /[From fr … /[From "K.C. (Karen) Cameron" <[removed]>][Date Sat, 19 Feb 2005 14:51:50 -0500]/UNNAMED Infected: Email-Worm.Win32.Bagle.eb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 feb 2005 08:16:36 +0100]/UNNAMED/[From "Frankel Tori"<[removed]>][Date qua, 09 fev 2005 20:53:03 +0100]/UNNAMED/[From "Customer Service, … /[From from quoted-printable … /[From Anne Marsh <[removed]>][Date Fri, 11 Feb 2005 19:58:29 -0800]/text Infected: Email-Worm.Win32.Bagle.eb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 feb 2005 08:16:36 +0100]/UNNAMED/[From "Frankel Tori"<[removed]>][Date qua, 09 fev 2005 20:53:03 +0100]/UNNAMED/[From "Customer Service, . … .. .. … /[From yolane tome E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 feb 2005 08:16:36 +0100]/UNNAMED/[From "Frankel Tori"<[removed]>][Date qua, 09 fev 2005 20:53:03 +0100]/UNNAMED/[From "Customer Service, . … .. .. … /[From yolane tome <[removed]>][Date Sun, 26 Nov 2006 16:49:04 +0000]/UNNAMED Infected: Email-Worm.Win32.Warezov.hb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 feb 2005 08:16:36 +0100]/UNNAMED/[From "Frankel Tori"<[removed]>][Date qua, 09 fev 2005 20:53:03 +0100]/UNNAMED/[From "Customer Service, . … .. … /[F … /[From "Roy Sullivan" <[removed]>][Date Sun, 25 Feb 2007 19:36:23 - .. … /text Infected: Email-Worm.Win32.Warezov.hb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 feb 2005 08:16:36 +0100]/UNNAMED/[From "Frankel Tori"<[removed]>][Date qua, 09 fev 2005 20:53:03 +0100]/UNNAMED/[From "Customer Service, . … .. … /[F … /[From "Roy Sullivan" <[removed]>][Date Sun, 25 Feb 2007 19:36:23 - … /UNNAMED Infected: Email-Worm.Win32.Warezov.hb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 feb 2005 08:16:36 +0100]/UNNAMED/[From "Frankel Tori"<[removed]>][Date qua, 09 fev 2005 20:53:03 +0100]/UNNAMED/[From "Customer Service, . … .. … /[F … /[From "Roy Sullivan" <[removed]>][Date Sun, 25 Feb 2007 19:36:23 -0120]/UNNAMED Infected: Email-Worm.Win32.Warezov.hb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 feb 2005 08:16:36 +0100]/UNNAMED/[From "Frankel Tori"<[removed]>][Date qua, 09 fev 2005 20:53:03 +0100]/UNNAMED/[From "Customer Service, . … .. … /[From … /[From "important" <[removed]>][Date Sat, 25 Nov 2006 12:14:28 +0100]/UNNAMED Infected: Email-Worm.Win32.Warezov.hb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 feb 2005 08:16:36 +0100]/UNNAMED/[From "Frankel Tori"<[removed]>][Date qua, 09 fev 2005 20:53:03 +0100]/UNNAMED/[From "Customer Service, . … .. … /[From "languages eminently" <[removed]>][Date Sat, 25 Nov 2006 12:14:28 +0100]/UNNAMED Infected: Email-Worm.Win32.Warezov.hb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 feb 2005 08:16:36 +0100]/UNNAMED/[From "Frankel Tori"<[removed]>][Date qua, 09 fev 2005 20:53:03 +0100]/UNNAMED/[From "Customer Service, . … … /[From "Caroline Joiner" <[removed]>][Date Sat, 25 Nov 2006 09:31:29 -0060]/UNNAMED Infected: Email-Worm.Win32.Warezov.hb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 feb 2005 08:16:36 +0100]/UNNAMED/[From "Frankel Tori"<[removed]>][Date qua, 09 fev 2005 20:53:03 +0100]/UNNAMED/[From "Customer Service, . … /[From "C … /[From "Adrienne Rivera" <[removed]>][Date Sat, 25 Nov 2006 05:39:25 -0480]/UNNAMED Infected: Email-Worm.Win32.Warezov.hb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 feb 2005 08:16:36 +0100]/UNNAMED/[From "Frankel Tori"<[removed]>][Date qua, 09 fev 2005 20:53:03 +0100]/UNNAMED/[From "Customer Service, . … /[From "Carter Rivas" <[removed]>][Date Fri, 24 Nov 2006 06:51:56 -0060]/UNNAMED Infected: Email-Worm.Win32.Warezov.hb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 feb 2005 08:16:36 +0100]/UNNAMED/[From "Frankel Tori"<[removed]>][Date qua, 09 fev 2005 20:53:03 +0100]/UNNAMED/[From "Customer Service, … /[From … /[F … /[From "Ina Landis" <[removed]>][Date Thu, 23 Nov 2006 12:55:34 -0060]/UNNAMED Infected: Email-Worm.Win32.Warezov.hb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 feb 2005 08:16:36 +0100]/UNNAMED/[From "Frankel Tori"<[removed]>][Date qua, 09 fev 2005 20:53:03 +0100]/UNNAMED/[From "Customer Service, … /[From … /[From "helping strategic" <[removed]>][Date Thu, 23 Nov 2006 07:11:09 -0000]/UNNAMED Infected: Email-Worm.Win32.Warezov.hb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 feb 2005 08:16:36 +0100]/UNNAMED/[From "Frankel Tori"<[removed]>][Date qua, 09 fev 2005 20:53:03 +0100]/UNNAMED/[From "Customer Service, … /[From from quoted-pr … /[From "Kimberly" <[removed]>][Date Wed, 22 Nov 2006 22:41:32 +0200]/text Infected: Email-Worm.Win32.Warezov.hb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 feb 2005 08:16:36 +0100]/UNNAMED/[From "Frankel Tori"<[removed]>][Date qua, 09 fev 2005 20:53:03 +0100]/UNNAMED/[From "Customer Service, … /[From from quoted-printable to 8bit by mail.lynx.bc.ca id j1BKH0KE035369][Date Fri, 11 Feb 2005 20:16:53 GMT]/text Infected: Email-Worm.Win32.Warezov.hb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 feb 2005 08:16:36 +0100]/UNNAMED/[From "Frankel Tori"<[removed]>][Date qua, 09 fev 2005 20:53:03 +0100]/UNNAMED/[From "Customer Service, Canada" ][Date Thu, 10 Feb 2005 18:24:08 +0100]/UNNAMED Infected: Email-Worm.Win32.Warezov.hb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 feb 2005 08:16:36 +0100]/UNNAMED/[From "Frankel Tori"<[removed]>][Date qua, 09 fev 2005 20:53:03 +0100]/UNNAMED/[From "Customer Service, Canada" ][Date Thu, 10 Feb 2005 18:24:09 +0100]/UNNAMED Infected: Email-Worm.Win32.Warezov.hb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 feb 2005 08:16:36 +0100]/UNNAMED/[From "Frankel Tori"<[removed]>][Date qua, 09 fev 2005 20:53:03 +0100]/UNNAMED/[From "Customer Service, Canada" ][Date Cz, 10 lut 2005 22:19:50 +0100]/UNNAMED Infected: Email-Worm.Win32.Warezov.hb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 feb 2005 08:16:36 +0100]/UNNAMED/[From "Frankel Tori"<[removed]>][Date qua, 09 fev 2005 20:53:03 +0100]/UNNAMED/[From "Customer Service, Canada" ][Date Cz, 10 lut 2005 22:19:49 +0100]/UNNAMED Infected: Email-Worm.Win32.Warezov.hb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 feb 2005 08:16:36 +0100]/UNNAMED/[From "Frankel Tori"<[removed]>][Date qua, 09 fev 2005 20:53:03 +0100]/UNNAMED/[From "Customer Service, Canada" ][Date Thu, 10 Feb 2005 16:18:38 +0100]/UNNAMED Infected: Email-Worm.Win32.Warezov.hb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 feb 2005 08:16:36 +0100]/UNNAMED/[From "Frankel Tori"<[removed]>][Date qua, 09 fev 2005 20:53:03 +0100]/UNNAMED/[From "Customer Service, Canada" <[removed]>][Date Thu, 10 Feb 2005 13:08:53 -0800]/UNNAMED Infected: Email-Worm.Win32.Warezov.hb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 feb 2005 08:16:36 +0100]/UNNAMED/[From "Frankel Tori"<[removed]>][Date qua, 09 fev 2005 20:53:03 +0100]/UNNAMED Infected: Email-Worm.Win32.Warezov.hb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED/[From "Glucksman Ingrid"<[removed]>][Date ma, 07 feb 2005 08:16:36 +0100]/UNNAMED Infected: Email-Worm.Win32.Warezov.hb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED/[From "Goldwyn Gina"<[removed]>][Date ma, 07 feb 2005 08:16:33 +0100]/UNNAMED Infected: Email-Worm.Win32.Warezov.hb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox/[From "Greenberg Vicki"<[removed]>][Date N, 06 lut 2005 16:38:58 +0100]/UNNAMED Infected: Email-Worm.Win32.Warezov.hb skipped
E:\Documents and Settings\Norman\Application Data\Thunderbird\Profiles\rs2qtews.Nigels Profile Jan 27_05\Mail\pop.lynx.net\Inbox Mail Berkeley mbox: infected - 62 skipped
E:\Documents and Settings\Norman\Cookies\index.dat Object is locked skipped
E:\Documents and Settings\Norman\Downloads\Cdvd.exe/stream/data0013 Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
E:\Documents and Settings\Norman\Downloads\Cdvd.exe/stream/data0014 Infected: not-a-virus:AdWare.Win32.MyWay.j skipped
E:\Documents and Settings\Norman\Downloads\Cdvd.exe/stream/data0015 Infected: not-a-virus:AdTool.Win32.WhenU.a skipped
E:\Documents and Settings\Norman\Downloads\Cdvd.exe/stream Infected: not-a-virus:AdTool.Win32.WhenU.a skipped
E:\Documents and Settings\Norman\Downloads\Cdvd.exe NSIS: infected - 4 skipped
E:\Documents and Settings\Norman\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
E:\Documents and Settings\Norman\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
E:\Documents and Settings\Norman\Local Settings\History\History.IE5\index.dat Object is locked skipped
E:\Documents and Settings\Norman\Local Settings\History\History.IE5\MSHist012007012720070128\index.dat Object is locked skipped
E:\Documents and Settings\Norman\Local Settings\History\History.IE5\MSHist012007012920070130\index.dat Object is locked skipped
E:\Documents and Settings\Norman\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
E:\Documents and Settings\Norman\ntuser.dat Object is locked skipped
E:\Documents and Settings\Norman\ntuser.dat.LOG Object is locked skipped
E:\System Volume Information\_restore{4C054834-B299-4781-B861-1EFADDD6D621}\RP3\change.log Object is locked skipped
E:\WINDOWS\Debug\oakley.log Object is locked skipped
E:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
E:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped
E:\WINDOWS\Internet Logs\NORM.ldb Object is locked skipped
E:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped
E:\WINDOWS\ModemLog_SupraMAX 56i.txt Object is locked skipped
E:\WINDOWS\SchedLgU.Txt Object is locked skipped
E:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
E:\WINDOWS\Sti_Trace.log Object is locked skipped
E:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
E:\WINDOWS\system32\config\default Object is locked skipped
E:\WINDOWS\system32\config\default.LOG Object is locked skipped
E:\WINDOWS\system32\config\SAM Object is locked skipped
E:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
E:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
E:\WINDOWS\system32\config\SECURITY Object is locked skipped
E:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
E:\WINDOWS\system32\config\software Object is locked skipped
E:\WINDOWS\system32\config\software.LOG Object is locked skipped
E:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
E:\WINDOWS\system32\config\system Object is locked skipped
E:\WINDOWS\system32\config\system.LOG Object is locked skipped
E:\WINDOWS\system32\h323log.txt Object is locked skipped
E:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
E:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
E:\WINDOWS\Temp\WebPoolFileFile Object is locked skipped
E:\WINDOWS\Temp\ZLT02ccb.TMP Object is locked skipped
E:\WINDOWS\wiadebug.log Object is locked skipped
E:\WINDOWS\wiaservc.log Object is locked skipped
E:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.
You appear to have a large number of infected e-mails, please delete all e-mails from untrusted senders

1. Download this file - combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Post back with the combofix log and a new HijackThis log
Combofix scan below, plus new HJT. Did not appear that Combofix found anything as did not reboot. Anything of help in the scan?
Thanks,

"Norman" - 07-01-30 12:04:38 Service Pack 1
ComboFix 07.01.30 - Running from: "E:\Documents and Settings\Norman\Downloads"

(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


c:\command.com


((((((((((((((((((((((((((((((( Files Created from 2006-12-30 to 2007-01-30 ))))))))))))))))))))))))))))))))))


2007-01-29 12:20 d——– E:\WINDOWS\system32\Kaspersky Lab
2007-01-27 13:08 d——– E:\VundoFix Backups
2007-01-21 11:28 d——– E:\DOCUME~1\Norman\Saves
2007-01-18 20:27 3,968 –a—— E:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-01-18 20:27 d——– E:\Program Files\Grisoft
2007-01-14 12:27 d——– E:\!KillBox
2007-01-04 14:00 95,744 –a—— E:\WINDOWS\system32\zfujrhqg.dll
2007-01-04 13:53 78,848 –a—— E:\WINDOWS\system32\dkqbaaaa.exe
2007-01-04 13:53 61,952 –a—— E:\WINDOWS\system32\hlnahln.dll
2007-01-04 13:53 61 –a—— E:\WINDOWS\system32\idhvhri.dll
2007-01-04 13:53 16,384 –a—— E:\WINDOWS\system32\mshaaaaa.exe
2007-01-04 13:53 13,824 –a—— E:\WINDOWS\system32\vtntaaaa.exe
2007-01-04 13:53 1,042 –a—— E:\WINDOWS\system32\ppfyaaaa.exe
2007-01-04 13:52 1,042 –a—— E:\WINDOWS\system32\vifsnhro.exe
2006-12-31 16:23 d——– E:\Program Files\Sfx
2006-12-31 16:23 d——– E:\Program Files\Map
2006-12-31 16:23 d——– E:\Program Files\Gfx
2006-12-31 16:23 d——– E:\Program Files\Dta
2006-12-31 16:23 d——– E:\Program Files\Anims
2006-12-31 11:31 d——– E:\DOCUME~1\ALLUSE~1\SonicStage
2006-12-31 11:24 27,255 ——— E:\WINDOWS\system32\drivers\NWWMUSB.sys
2006-12-31 11:24 11,510 ——— E:\WINDOWS\system32\drivers\VMCUSB.sys
2006-12-31 11:24 d——– E:\Program Files\Sony Corporation
2006-12-31 11:23 90,112 ——— E:\WINDOWS\snymsico.dll
2006-12-31 11:23 765,952 –a—— E:\WINDOWS\system32\CDDBUISony.dll
2006-12-31 11:23 73,728 –a—— E:\WINDOWS\system32\CddbLinkSony.dll
2006-12-31 11:23 598,016 –a—— E:\WINDOWS\system32\CDDBControlSony.dll
2006-12-31 11:23 565,248 –a—— E:\WINDOWS\system32\CddbMusicIDSony.dll
2006-12-31 11:23 38,951 ——— E:\WINDOWS\system32\drivers\NETMDUSB.sys
2006-12-31 11:23 36,679 ——— E:\WINDOWS\system32\drivers\NETMD052.sys
2006-12-31 11:23 36,232 ——— E:\WINDOWS\system32\drivers\NETMD033.sys
2006-12-31 11:23 35,319 ——— E:\WINDOWS\system32\drivers\NETMD031.sys
2006-12-31 11:23 151,552 ——— E:\WINDOWS\system32\pxwma.dll
2006-12-31 11:23 109,568 ——— E:\WINDOWS\system32\pxinsi64.exe
2006-12-31 11:23 108,544 ——— E:\WINDOWS\system32\pxcpyi64.exe
2006-12-31 11:22 d——– E:\DOCUME~1\ALLUSE~1\Application Data\Sony Corporation
2006-12-31 11:21 d——– E:\Program Files\Sony
2006-12-31 11:21 d——– E:\Program Files\Common Files\Sony Shared
2006-12-31 11:21 d——– E:\DOCUME~1\Norman\Application Data\Sony Corporation


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-01-13 11:24 ——– d——– E:\Program Files\qt2004
2007-01-07 14:45 96504 –a—— E:\Program Files\schizm.s00
2007-01-06 19:47 96504 –a—— E:\Program Files\schizm.s03
2007-01-04 17:03 96504 –a—— E:\Program Files\schizm.s02
2007-01-01 17:46 96504 –a—— E:\Program Files\schizm.s01
2006-12-31 16:56 2834 –a—— E:\Program Files\uninstall.ini
2006-12-31 16:55 328 –a—— E:\Program Files\schizm.ini
2006-12-31 16:55 28425 –a—— E:\Program Files\uninstall.cd0
2006-12-31 16:55 ——– d——– E:\Program Files\log
2006-12-31 11:24 ——– d–h—– E:\Program Files\installshield installation information
2006-12-23 14:52 ——– d——– E:\Program Files\the adventure company


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"NvCplDaemon"="RUNDLL32.EXE E:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"C-Media Mixer"="Mixer.exe /startup"
"NeroFilterCheck"="E:\\WINDOWS\\system32\\NeroCheck.exe"
"Zone Labs Client"="E:\\PROGRA~1\\ZONELA~1\\ZONEAL~1\\zlclient.exe"
"iRiver Updater"="\\Updater.exe"
"!AVG Anti-Spyware"="\"E:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\E:^Documents and Settings^All Users^Start Menu^Programs^Startup^Billminder.lnk]
"path"="E:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Billminder.lnk"
"backup"="E:\\WINDOWS\\pss\\Billminder.lnkCommon Startup"
"location"="Common Startup"
"command"="E:\\PROGRA~1\\QUICKENW\\BILLMIND.EXE "
"item"="Billminder"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="InCD"
"hkey"="HKLM"
"command"="E:\\Program Files\\Ahead\\InCD\\InCD.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="iTunesHelper"
"hkey"="HKLM"
"command"="E:\\Program Files\\iTunes\\iTunesHelper.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QAGENT]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="QAGENT"
"hkey"="HKCU"
"command"="E:\\PROGRA~1\\QUICKENW\\QAGENT.EXE"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"command"="\"E:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SsAAD.exe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SsAAD"
"hkey"="HKLM"
"command"="E:\\PROGRA~1\\Sony\\SONICS~1\\SsAAD.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{3E898EEA-FEFA-451b-ACF2-7561F94B1191}"="gkj"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\oxoplkwy

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"


[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0


Completion time: 07-01-30 12:06:44


Logfile of HijackThis v1.99.1
Scan saved at 12:21:38 PM, on 1/30/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\Explorer.EXE
E:\WINDOWS\system32\spoolsv.exe
E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
E:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
E:\Program Files\Ahead\InCD\InCDsrv.exe
E:\WINDOWS\System32\nvsvc32.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\Mixer.exe
E:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
E:\Updater.exe
E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
E:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
E:\Program Files\QUICKENW\QWDLLS.EXE
E:\Program Files\Microsoft Office\Office\FINDFAST.EXE
E:\WINDOWS\system32\ZoneLabs\vsmon.exe
E:\Program Files\Microsoft Office\Office\OSA.EXE
E:\Program Files\Network Associates\VirusScan\VsStat.exe
E:\Program Files\Network Associates\VirusScan\Vshwin32.exe
E:\Program Files\Network Associates\VirusScan\Avconsol.exe
E:\Program Files\Network Associates\VirusScan\Webscanx.exe
E:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
E:\WINDOWS\system32\NOTEPAD.EXE
E:\Program Files\internet explorer\iexplore.exe
E:\Documents and Settings\Norman\My Documents\HijackThis\Halt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {325F7293-F292-45EF-8AC9-464B96F79123} - E:\WINDOWS\system32\hlnahln.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - E:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE E:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [NeroFilterCheck] E:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Zone Labs Client] E:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
O4 - HKLM\..\Run: [iRiver Updater] \Updater.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - Startup: Microsoft Find Fast.lnk = E:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: MS Outlook.lnk = E:\Program Files\Microsoft Office\Office\OUTLOOK.EXE
O4 - Startup: Office Startup.lnk = E:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = E:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Monitor.lnk = E:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
O4 - Global Startup: Quicken Startup.lnk = E:\Program Files\QUICKENW\QWDLLS.EXE
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - E:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {C946EF6D-296D-4907-A6E1-ED0E8E5AF024} (LycosMail Upload Control) - http://mail.lycos.com/hanmail-ax/AttachMail.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6F154908-7BEA-47E6-8F64-4C87CE958E7F}: NameServer = 216.18.70.248 216.18.70.233
O17 - HKLM\System\CS1\Services\Tcpip\..\{6F154908-7BEA-47E6-8F64-4C87CE958E7F}: NameServer = 216.18.70.248 216.18.70.233
O20 - Winlogon Notify: oxoplkwy - E:\WINDOWS\SYSTEM32\hlnahln.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVSync Manager (AvSynMgr) - Unknown owner - E:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
O23 - Service: InCD Helper (InCDsrv) - AHEAD Software - E:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - E:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McShield - Unknown owner - E:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
O23 - Service: MSCSPTISRV - Sony Corporation - E:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - E:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - E:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - E:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - E:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - E:\WINDOWS\system32\ZoneLabs\vsmon.exe
Please print the instructions below.
Then reboot your computer
As soon as it starts to boot, rapidly press the f8 key.
select safe mode from the menu
If you are still unsure, see here

Run HijackThis
Click on do a system scan only
Place a checkmark next to these lines(if still present)

O2 - BHO: (no name) - {325F7293-F292-45EF-8AC9-464B96F79123} - E:\WINDOWS\system32\hlnahln.dll
O20 - Winlogon Notify: oxoplkwy - E:\WINDOWS\SYSTEM32\hlnahln.dll

Then close all windows except HijackThis and click Fix Checked

Use windows explorer to find and delete these files:

E:\WINDOWS\system32\zfujrhqg.dll
E:\WINDOWS\system32\dkqbaaaa.exe
E:\WINDOWS\system32\hlnahln.dll
E:\WINDOWS\system32\idhvhri.dll
E:\WINDOWS\system32\mshaaaaa.exe
E:\WINDOWS\system32\vtntaaaa.exe
E:\WINDOWS\system32\ppfyaaaa.exe
E:\WINDOWS\system32\vifsnhro.exe

Restart in normal mode

Download AVG Anti Rootkit© by Grisoft and save it to your desktop.
Double-click on AVG_AntiRootkit.exe to run it.
Click I Agree to agree to the EULA.
By default it will install to "C:\Program Files\GRISOFT\AVG Anti-Rootkit Beta"
Click Next to begin the installation then click Install
It will then ask you to reboot now to finish the installation.
Click Finish and your computer will reboot.
After it reboots, double-click on the AVG Anti-Rootkit Beta shortcut that is now on your desktop.
Click on the Perform in-depth search button to begin the scan.
The scan will take a while so be patient and let it complete.
When the scan is finished, click the Save result to file button.
Save the scan results to your desktop
Copy and Paste the scan results here

Post back with the AVG-antirootkit log and a new HijackThis log
HJT could not remove the 02/020 entries in safe mode (I had tried this before, think I mentioned in first log).
I was able to manually delete all but 2 of the files listed: hlnahln.dll and zfujrhqg.dll. For both of these I got message: "Cannot delete: access is denied. Make sure….file is not currently open".

On one of your previous posts you had asked me to install and run AVG Anti Rootkit, which I did and reported back that no rootkits were found. Ran it again, and same result - nada!
Also updated and ran Spybot, Ad-Aware and AVG Anti-Spyware once more - nothing found.
This is a tough one!

Logfile of HijackThis v1.99.1
Scan saved at 9:14:56 PM, on 1/30/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\Explorer.EXE
E:\WINDOWS\system32\spoolsv.exe
E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
E:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
E:\Program Files\Ahead\InCD\InCDsrv.exe
E:\WINDOWS\System32\nvsvc32.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\ZoneLabs\vsmon.exe
E:\Program Files\Network Associates\VirusScan\VsStat.exe
E:\WINDOWS\Mixer.exe
E:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
E:\Program Files\Network Associates\VirusScan\Vshwin32.exe
E:\Updater.exe
E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
E:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
E:\Program Files\QUICKENW\QWDLLS.EXE
E:\Program Files\Microsoft Office\Office\FINDFAST.EXE
E:\Program Files\Microsoft Office\Office\OSA.EXE
E:\Program Files\Network Associates\VirusScan\Avconsol.exe
E:\Program Files\Network Associates\VirusScan\Webscanx.exe
E:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
E:\Documents and Settings\Norman\My Documents\HijackThis\Halt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {325F7293-F292-45EF-8AC9-464B96F79123} - E:\WINDOWS\system32\hlnahln.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - E:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE E:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [NeroFilterCheck] E:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Zone Labs Client] E:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
O4 - HKLM\..\Run: [iRiver Updater] \Updater.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - Startup: Microsoft Find Fast.lnk = E:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: MS Outlook.lnk = E:\Program Files\Microsoft Office\Office\OUTLOOK.EXE
O4 - Startup: Office Startup.lnk = E:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = E:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Monitor.lnk = E:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
O4 - Global Startup: Quicken Startup.lnk = E:\Program Files\QUICKENW\QWDLLS.EXE
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - E:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {C946EF6D-296D-4907-A6E1-ED0E8E5AF024} (LycosMail Upload Control) - http://mail.lycos.com/hanmail-ax/AttachMail.cab
O20 - Winlogon Notify: oxoplkwy - E:\WINDOWS\SYSTEM32\hlnahln.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVSync Manager (AvSynMgr) - Unknown owner - E:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
O23 - Service: InCD Helper (InCDsrv) - AHEAD Software - E:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - E:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McShield - Unknown owner - E:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
O23 - Service: MSCSPTISRV - Sony Corporation - E:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - E:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - E:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - E:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - E:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - E:\WINDOWS\system32\ZoneLabs\vsmon.exe
1. Please download The Avenger by Swandog46 to your Desktop.
  • Click on Avenger.zip to open the file
  • Extract avenger.exe to your desktop
2. Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):

Files to delete:
E:\WINDOWS\system32\zfujrhqg.dll
E:\WINDOWS\system32\dkqbaaaa.exe
E:\WINDOWS\system32\hlnahln.dll
E:\WINDOWS\system32\idhvhri.dll
E:\WINDOWS\system32\mshaaaaa.exe
E:\WINDOWS\system32\vtntaaaa.exe
E:\WINDOWS\system32\ppfyaaaa.exe
E:\WINDOWS\system32\vifsnhro.exe


Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.


3. Now, start The Avenger program by clicking on its icon on your desktop.
  • Under "Script file to execute" choose "Input Script Manually".
  • Now click on the Magnifying Glass icon which will open a new window titled "View/edit script"
  • Paste the text copied to clipboard into this window by pressing (Ctrl+V).
  • Click Done
  • Now click on the Green Light to begin execution of the script
  • Answer "Yes" twice when prompted.
4. The Avenger will automatically do the following:
  • It will Restart your computer. ( In cases where the code to execute contains "Drivers to Unload", The Avenger will actually restart your system twice.)
  • On reboot, it will briefly open a black command window on your desktop, this is normal.
  • After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
  • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
Run HijackThis
Click on do a system scan only
Place a checkmark next to these lines(if still present)

O2 - BHO: (no name) - {325F7293-F292-45EF-8AC9-464B96F79123} - E:\WINDOWS\system32\hlnahln.dll
O20 - Winlogon Notify: oxoplkwy - E:\WINDOWS\SYSTEM32\hlnahln.dll

Then close all windows except HijackThis and click Fix Checked


5. Please copy/paste the content of c:\avenger.txt into your reply along with a fresh HJT log by using Add/Reply
I do believe you've done it, Sir Random/ Random! Avenger was able to disable the 2 files that I could not delete manually previously, and then HJT was finally able to dump them! I rebooted and the O2 and O20 lines didn't come back this time - what a relief! Thank you so much for your time and expertise! I'm very grateful to you, and to Tom for enabling this forum.
Cheers,

Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\wabwvtni

*******************

Script file located at: \??\E:\Documents and Settings\vkcquxmf.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at E:\Avenger

*******************

Beginning to process script file:

File E:\WINDOWS\system32\zfujrhqg.dll deleted successfully.


File E:\WINDOWS\system32\dkqbaaaa.exe not found!
Deletion of file E:\WINDOWS\system32\dkqbaaaa.exe failed!

Could not process line:
E:\WINDOWS\system32\dkqbaaaa.exe
Status: 0xc0000034

File E:\WINDOWS\system32\hlnahln.dll deleted successfully.


File E:\WINDOWS\system32\idhvhri.dll not found!
Deletion of file E:\WINDOWS\system32\idhvhri.dll failed!

Could not process line:
E:\WINDOWS\system32\idhvhri.dll
Status: 0xc0000034



File E:\WINDOWS\system32\mshaaaaa.exe not found!
Deletion of file E:\WINDOWS\system32\mshaaaaa.exe failed!

Could not process line:
E:\WINDOWS\system32\mshaaaaa.exe
Status: 0xc0000034



File E:\WINDOWS\system32\vtntaaaa.exe not found!
Deletion of file E:\WINDOWS\system32\vtntaaaa.exe failed!

Could not process line:
E:\WINDOWS\system32\vtntaaaa.exe
Status: 0xc0000034



File E:\WINDOWS\system32\ppfyaaaa.exe not found!
Deletion of file E:\WINDOWS\system32\ppfyaaaa.exe failed!

Could not process line:
E:\WINDOWS\system32\ppfyaaaa.exe
Status: 0xc0000034



File E:\WINDOWS\system32\vifsnhro.exe not found!
Deletion of file E:\WINDOWS\system32\vifsnhro.exe failed!

Could not process line:
E:\WINDOWS\system32\vifsnhro.exe
Status: 0xc0000034


Completed script processing.

*******************

Finished! Terminate.


Logfile of HijackThis v1.99.1
Scan saved at 9:07:42 PM, on 2/1/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\Explorer.EXE
E:\WINDOWS\system32\spoolsv.exe
E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
E:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
E:\Program Files\Ahead\InCD\InCDsrv.exe
E:\WINDOWS\System32\nvsvc32.exe
E:\WINDOWS\System32\svchost.exe
E:\Program Files\Network Associates\VirusScan\VsStat.exe
E:\WINDOWS\system32\ZoneLabs\vsmon.exe
E:\WINDOWS\Mixer.exe
E:\Program Files\Network Associates\VirusScan\Vshwin32.exe
E:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
E:\Updater.exe
E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
E:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
E:\Program Files\QUICKENW\QWDLLS.EXE
E:\Program Files\Microsoft Office\Office\FINDFAST.EXE
E:\Program Files\Microsoft Office\Office\OSA.EXE
E:\Program Files\Network Associates\VirusScan\Avconsol.exe
E:\Program Files\Network Associates\VirusScan\Webscanx.exe
E:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
E:\Program Files\internet explorer\iexplore.exe
E:\Documents and Settings\Norman\My Documents\HijackThis\Halt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - E:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE E:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [NeroFilterCheck] E:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Zone Labs Client] E:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
O4 - HKLM\..\Run: [iRiver Updater] \Updater.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - Startup: Microsoft Find Fast.lnk = E:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: MS Outlook.lnk = E:\Program Files\Microsoft Office\Office\OUTLOOK.EXE
O4 - Startup: Office Startup.lnk = E:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = E:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Monitor.lnk = E:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
O4 - Global Startup: Quicken Startup.lnk = E:\Program Files\QUICKENW\QWDLLS.EXE
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - E:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {C946EF6D-296D-4907-A6E1-ED0E8E5AF024} (LycosMail Upload Control) - http://mail.lycos.com/hanmail-ax/AttachMail.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6F154908-7BEA-47E6-8F64-4C87CE958E7F}: NameServer = 216.18.70.248 216.18.70.233
O17 - HKLM\System\CS1\Services\Tcpip\..\{6F154908-7BEA-47E6-8F64-4C87CE958E7F}: NameServer = 216.18.70.248 216.18.70.233
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVSync Manager (AvSynMgr) - Unknown owner - E:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
O23 - Service: InCD Helper (InCDsrv) - AHEAD Software - E:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - E:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McShield - Unknown owner - E:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
O23 - Service: MSCSPTISRV - Sony Corporation - E:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - E:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - E:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - E:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - E:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - E:\WINDOWS\system32\ZoneLabs\vsmon.exe
You now appear to be clean. Congratulations!

Below are some steps to follow in order to dramatically lower the chances of reinfection
You may have already implemented some of the steps below, however you should follow any steps that you have not already implemented
  • Turn off System Restore.
    On the Desktop, right-click My Computer.
    Click Properties.
    Click the System Restore tab.
    Check Turn off System Restore.
    Click Apply, and then click OK.

    Reboot.

    Turn ON System Restore.
    On the Desktop, right-click My Computer.
    Click Properties.
    Click the System Restore tab.
    UN-Check *Turn off System Restore*.
    Click Apply, and then click OK.
    NOTE: only do this ONCE,NOT on a regular basis
  • Keep your antivirus updated
  • Keep windows up to date with the latest patches


    IMPORTANT: You Need to Update Windows and Internet Explorer to protect your computer from the malware that is around on the Internet. Please go to the windows update site to get the critical updates.

    If you are running Microsoft Office, or any portion thereof, go to the Microsoft's Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.
  • Install spywareblaster
    Spyware blaster is a program that stops known malicious activex controls from installing on your computer. It works by changing settings in your registry. It makes
    kill bits
    in the registry, so that certain activex controls can't install.
    If you don't know what activex controls are, see here
    You can download SpywareBlaster here here
    Make sure to update it on a regular basis
  • Install IE-SPYAD
    Dowload and instructions located here
    Make sure to update it on a regular basis
  • Use a HOSTS file
    • Every version of windows has a hosts file as part of them.
    • In a very basic sense, they are used to locate webpages.
    • We can customize a hosts file so that it blocks certain webpages.
    • However, it can slow down certain computers.
    • This is why using a hosts file is optional!!
    Download it here. Make sure you read the instructions on how to install the hosts file. There is a good tutorial here
    If you decide to download the hosts file, the slowdown problems can usually be avoided by following these steps:
    • Click the start button (at the lower left hand corner of your screen)
    • Click run
    • In the dialog box, type services.msc
    • hit enter, then locate dns client
    • Highlight it, then double-click it.
    • On the dropdown box, change the setting from automatic to manual.
    • Click ok
  • Install and use Ad-aware & Spybot search & destroy
    Instructions are located here
    Make sure to update them on a regular basis
  • Most exploits are aimed at internet explorer, so I recommend you switch to an altenative browser
    Two good alternative browsers are
    Firefox
    Opera
    It is essential to update to the latest version of your browser, as the updates fix known security holes
  • Even if you do decide to switch to another browser, it is still a good idea to lock down Internet explorer
    This can be done by following these simple instructions:
    From within Internet Explorer click on the Tools menu and then click on Options.
    Click once on the Security tab
    Click once on the Internet icon so it becomes highlighted.
    Click once on the Custom Level button.
    Change the Download signed ActiveX controls to Prompt
    Change the Download unsigned ActiveX controls to Disable
    Change the Initialize and script ActiveX controls not marked as safe to Disable
    Change the Installation of desktop items to Prompt
    Change the Launching programs and files in an IFRAME to Prompt
    Change the Navigate sub-frames across different domains to Prompt
    Change the allow paste operations via script to Disable
    When all these settings have been made, click on the OK button.
    If it prompts you as to whether or not you want to save the settings, press the Yes button.
    Next press the Apply button and then the OK to exit the Internet Properties page.
  • Clean out you temp file on a regular basis
    I use and recommend ATF Cleaner by Attribune
    To use it, follow these instructions
    • Double-click ATF-Cleaner.exe to run the program.
    • Click Main at the top and choose Select All from the list.
    • Click the Empty Selected button.
    If you use Firefox browser:
    • Click Firefox at the top and choose Select All from the list.
    • Click the Empty Selected button.
    • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser:
    • Click Opera at the top and choose Select All from the list.
    • Click the Empty Selected button.
    • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main menu to close the program.
  • Finally I am trying to make one point very clear. It is absolutely essential to keep all of your security programs up to date
This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.


Also follow the recommendations in Tony Klein's article
So how did I get infected in the first place?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI