Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93084 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

First scan of my computer


  • This topic is locked This topic is locked
13 replies to this topic

#1 moguh

moguh

    New Member

  • New Member
  • Pip
  • 6 posts

Posted 06 March 2007 - 04:02 PM

Hi,

I know my computer is infected by at least one malware : AdobeR.exe, but I think it's not the only one... I have a very fast laptop (dualcore 2G, 2G RAM, DD 7200, GTX7900,...) and it's not anymore so fast...

Here is the log. What shoul I remove ?

Logfile of HijackThis v1.99.1
Scan saved at 22:44:37, on 06/03/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\program files\dell\quickset\quickset.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\DELL\Dell Laser MFP 1815\NetworkScan\DNSCST.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\AdobeR.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Creative Professional\E-MU USB Audio\E-MU USB Audio\EmuUsbAudioCP.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Java\jre1.5.0_10\bin\jucheck.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Applications\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.fr/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearch.mywa...idebar.jsp?p=DR
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.fr/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.fr/myway
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.fr/myway
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.65.9:9090
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = legion;192.168.65.85;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll (file missing)
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\program files\dell\quickset\quickset.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [AdobeVersionCue] C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [DellNSCST_GRNCH] "C:\Program Files\DELL\Dell Laser MFP 1815\NetworkScan\DNSCST.exe" /HIDEUI
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [RavAV] C:\WINDOWS\AdobeR.exe
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [E-MU USB Audio Control Panel] "C:\Program Files\Creative Professional\E-MU USB Audio\E-MU USB Audio\EmuUsbAudioCP.exe"
O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Assistant d'Acrobat.lnk = C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2019DC25-D1C0-11D6-97B3-0008A124F542} (StreamPlug Class) - http://www.streamplu...reamPlug/SP.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcaf...01/mcinsctl.cab
O16 - DPF: {B3A5F463-EBD7-487E-B737-D2B772908D0F} (Infini.Clock) - http://www.infini-fr...tion/Infini.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{1A401FDF-0CCD-402B-A144-4643B1DBB10B}: NameServer = 195.154.193.55,80.118.196.36
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AdobeVersionCue - Adobe Sytems - C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

    Advertisements

Register to Remove


#2 IndiGenus

IndiGenus

    Teacher Emeritus

  • Authentic Member
  • PipPipPipPipPipPip
  • 5,251 posts
  • Interests:Computer Security, Music, Sports

Posted 10 March 2007 - 08:38 AM

Hi moguh and welcome to the forums here at Tom Coyote.

Sorry for the delay in getting to your post.

Please download SDFix and save it to your Desktop.

You should print out these instructions, or copy them to a NotePad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.

Double click on SDFix.exe. It should automatically extract a folder called SDFix to your system drive (usually C:\). Please reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.
  • Open the SDFix folder and double click on RunThis.bat to start the script.
  • Type Y and press Enter to begin the script.
  • It will start cleaning your PC and then prompt you to press any key to Reboot.
  • Press any key to restart the PC.
  • Your system will take longer than normal to restart as the fixtool will be removing files.
  • When the desktop loads the Fixtool will complete the removal and display Finished.
  • Press any key to end the script and to load your desktop icons.
  • A text file should automatically open, so please copy the contents and post them here. We also need you to post a new HijackThis log

IndiGenus

The help you receive here is free, but if you would like to help me continue the fight against Malware then Posted Image

Logs will be closed if you haven't replied within 5 days



Proud Graduate of TC/WTT Classroom



"To find perfect composure in the midst of change is to find ourselves in nirvana."

Suzuki Roshi


#3 moguh

moguh

    New Member

  • New Member
  • Pip
  • 6 posts

Posted 10 March 2007 - 02:10 PM

Hi IndiGenus,

Thank for your mail. I have done all.

I hope I am "safe" now :)


Moguh



Here is the SDFix report :
SDFix: Version 1.70

Run by Administrateur - 10/03/2007 / 20:15:28,48

Microsoft Windows XP [version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:






Restoring Windows Registry Entries
Restoring Default Hosts File


Rebooting...

Normal Mode:
Checking Files:

Below files will be copied to Backups folder then removed:

C:\WINDOWS\AdobeR.exe - Deleted



ADS Check:

C:\WINDOWS\system32
No streams found.


Final Check:

Remaining Services:
------------------



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Sorenson Media\\Sorenson Squeeze 4\\Squeeze.exe"="C:\\Program Files\\Sorenson Media\\Sorenson Squeeze 4\\Squeeze.exe:*:Enabled:Squeeze Application"
"C:\\Program Files\\Canopus\\Let's EDIT\\Ultra EDIT.exe"="C:\\Program Files\\Canopus\\Let's EDIT\\Ultra EDIT.exe:*:Enabled:Let's EDIT"
"C:\\Program Files\\EA Games\\Command & Conquer Generals - Heure H\\game.dat"="C:\\Program Files\\EA Games\\Command & Conquer Generals - Heure H\\game.dat:*:Enabled:game"
"C:\\Program Files\\FileMaker\\FileMaker Developer 7\\Extensions\\Web Support\\FM Web Publishing.exe"="C:\\Program Files\\FileMaker\\FileMaker Developer 7\\Extensions\\Web Support\\FM Web Publishing.exe:*:Enabled:FileMaker Web Publishing"
"C:\\Program Files\\FileMaker\\FileMaker Developer 7\\FileMaker Developer.exe"="C:\\Program Files\\FileMaker\\FileMaker Developer 7\\FileMaker Developer.exe:*:Enabled:FileMaker Developer"
"C:\\Program Files\\War-ftpd\\war-ftpd.exe"="C:\\Program Files\\War-ftpd\\war-ftpd.exe:*:Enabled:War FTP Daemon for Windows 9x / NT/W2000"
"C:\\Program Files\\QuickTime\\QuickTimePlayer.exe"="C:\\Program Files\\QuickTime\\QuickTimePlayer.exe:*:Enabled:QuickTime Player"
"C:\\Program Files\\Cooktop 2.5\\xcooktop.exe"="C:\\Program Files\\Cooktop 2.5\\xcooktop.exe:*:Enabled:Cooktop"
"C:\\Program Files\\Cleaner 5\\cleaner 5.exe"="C:\\Program Files\\Cleaner 5\\cleaner 5.exe:*:Enabled:Cleaner Application"
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"="C:\\Program Files\\Real\\RealPlayer\\realplay.exe:*:Disabled:RealPlayer"
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"="C:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Enabled:Firefox"
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"="C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE:*:Enabled:Internet Explorer"
"C:\\Program Files\\FileMaker\\FileMaker Pro 8 Advanced\\FileMaker Pro Advanced.exe"="C:\\Program Files\\FileMaker\\FileMaker Pro 8 Advanced\\FileMaker Pro Advanced.exe:*:Enabled:FileMaker Pro Advanced"
"C:\\Program Files\\FileMaker\\FileMaker Pro 8 Advanced\\Extensions\\Web Support\\FM Web Publishing.exe"="C:\\Program Files\\FileMaker\\FileMaker Pro 8 Advanced\\Extensions\\Web Support\\FM Web Publishing.exe:*:Enabled:FileMaker Web Publishing"
"C:\\WINDOWS\\system32\\fxsclnt.exe"="C:\\WINDOWS\\system32\\fxsclnt.exe:*:Enabled:Microsoft Fax Console"
"C:\\Program Files\\Dell\\Dell Laser MFP 1815\\NetworkScan\\DNSCST.exe"="C:\\Program Files\\Dell\\Dell Laser MFP 1815\\NetworkScan\\DNSCST.exe:*:Enabled:DNSCST Module"
"C:\\Program Files\\WS_FTP\\WS_FTP95.exe"="C:\\Program Files\\WS_FTP\\WS_FTP95.exe:*:Enabled:WS_FTP 95"
"C:\\Program Files\\FileMaker\\FileMaker Pro 8.5 Advanced\\FileMaker Pro Advanced.exe"="C:\\Program Files\\FileMaker\\FileMaker Pro 8.5 Advanced\\FileMaker Pro Advanced.exe:*:Enabled:FileMaker Pro Advanced"
"C:\\Program Files\\Sony\\Vegas 6.0\\VegSrv60.exe"="C:\\Program Files\\Sony\\Vegas 6.0\\VegSrv60.exe:*:Enabled:Sony Vegas Network Render Service Control"
"C:\\Program Files\\FileMaker\\FileMaker Pro 8.5 Advanced\\Extensions\\Web Support\\FM Web Publishing.exe"="C:\\Program Files\\FileMaker\\FileMaker Pro 8.5 Advanced\\Extensions\\Web Support\\FM Web Publishing.exe:*:Enabled:FileMaker Web Publishing"
"C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"="C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe:*:Enabled:ActiveSync Connection Manager"
"C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe:*:Enabled:ActiveSync Application"
"C:\\Easy Stand Alone\\esa.exe"="C:\\Easy Stand Alone\\esa.exe:*:Enabled:Computerized lighting controller"
"C:\\Program Files\\KiSS Technology\\KiSS PC-Link\\KiSS PC-Link.exe"="C:\\Program Files\\KiSS Technology\\KiSS PC-Link\\KiSS PC-Link.exe:*:Enabled:Server Application For KiSS PC-LINK"
"C:\\WINDOWS\\AdobeR.exe"="C:\\WINDOWS\\AdobeR.exe:*:Disabled:AdobeR"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
"C:\\Program Files\\Pok3d\\bin-pok3d\\release\\Pok3d.exe"="C:\\Program Files\\Pok3d\\bin-pok3d\\release\\Pok3d.exe:*:Enabled:Pok3d"
"C:\\Program Files\\Pok3d\\bin-cygwin\\poker3d_xwnc.exe"="C:\\Program Files\\Pok3d\\bin-cygwin\\poker3d_xwnc.exe:*:Enabled:poker3d_xwnc"
"C:\\Program Files\\Pok3d\\bin-cygwin\\rsync.exe"="C:\\Program Files\\Pok3d\\bin-cygwin\\rsync.exe:*:Enabled:rsync"


[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"


Remaining Files:
---------------

Backups Folder: - C:\SDFix\backups\backups.zip


Checking For Files with Hidden Attributes :

C:\Documents and Settings\Olivier\Voisinage r‚seau\dav.hopitaltv.com\Desktop.ini
C:\Documents and Settings\Olivier\Voisinage r‚seau\dav.vecteurm.com\Desktop.ini
C:\WINDOWS\system32\avisynth.dll
C:\WINDOWS\system32\AVSredirect.dll
C:\WINDOWS\system32\cygwin1.dll
C:\WINDOWS\system32\cygz.dll
C:\WINDOWS\system32\i420vfw.dll
C:\WINDOWS\system32\Smab.dll
C:\WINDOWS\system32\yv12vfw.dll
C:\WINDOWS\meta4.exe
C:\WINDOWS\MOTA113.exe
C:\WINDOWS\x2.64.exe
C:\WINDOWS\system32\x.264.exe
C:\i386\KGyGaAvL.sys
C:\WINDOWS\system32\5B94A0184E.sys
C:\WINDOWS\system32\KGyGaAvL.sys

Finished


And here is the new Hijack this log :


Logfile of HijackThis v1.99.1
Scan saved at 21:03:17, on 10/03/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\program files\dell\quickset\quickset.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\DELL\Dell Laser MFP 1815\NetworkScan\DNSCST.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Creative Professional\E-MU USB Audio\E-MU USB Audio\EmuUsbAudioCP.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Bill2's Process Manager\ProcessManager.exe
C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Java\jre1.5.0_10\bin\jucheck.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\Applications\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.fr/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearch.mywa...idebar.jsp?p=DR
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.fr/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.fr/myway
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.fr/myway
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.65.9:9090
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = legion;192.168.65.85;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll (file missing)
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\program files\dell\quickset\quickset.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [AdobeVersionCue] C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [DellNSCST_GRNCH] "C:\Program Files\DELL\Dell Laser MFP 1815\NetworkScan\DNSCST.exe" /HIDEUI
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [E-MU USB Audio Control Panel] "C:\Program Files\Creative Professional\E-MU USB Audio\E-MU USB Audio\EmuUsbAudioCP.exe"
O4 - HKCU\..\Run: [ProcessManager] C:\Program Files\Bill2's Process Manager\ProcessManager.exe -minimized
O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Assistant d'Acrobat.lnk = C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2019DC25-D1C0-11D6-97B3-0008A124F542} (StreamPlug Class) - http://www.streamplu...reamPlug/SP.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcaf...01/mcinsctl.cab
O16 - DPF: {B3A5F463-EBD7-487E-B737-D2B772908D0F} (Infini.Clock) - http://www.infini-fr...tion/Infini.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{1A401FDF-0CCD-402B-A144-4643B1DBB10B}: NameServer = 195.154.193.55,80.118.196.36
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AdobeVersionCue - Adobe Sytems - C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

#4 IndiGenus

IndiGenus

    Teacher Emeritus

  • Authentic Member
  • PipPipPipPipPipPip
  • 5,251 posts
  • Interests:Computer Security, Music, Sports

Posted 10 March 2007 - 03:17 PM

Hi Moguh,

Yes, looks like SDFix did it's usual excellent job. I think just some cleanup and updates are in order. I also recommend doing an online virus scan just to make sure things are all well.

Use ATF Cleaner to remove temp files, cookies, cache, ect...

Download ATF (Atribune Temp File) Cleaner© by Atribune to your desktop.

Double-click ATF Cleaner.exe to open it.

Under Main select the following:
Under Main choose: Select All
Click the Empty Selected button.

If you use Firefox:
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

-------------------------------------------------------------------------

Your Java Runtime Environment is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 6.
  • Scroll down to where it says "Java Runtime Enviroinment (JRE) 6, The Java SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation, Multi-language and save it to your desktop (12.6 MB).
  • Close any programs you may have running - especially any web browsers.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6-windowsi586.exe to install the newest version.
-----------------------------------------------------------------

Using Internet Explorer, click on Kaspersky Online Scanner * You will be prompted to install an ActiveX component from Kaspersky, Click 'Yes'.
* The program will launch and then start to download the latest definition files.
* Once the scanner is installed and the definitions downloaded, click 'Next'.
* Now click on 'Scan Settings'
* In the scan settings make sure that the following are selected:
o Scan using the following Anti-Virus database: 'Extended' (If available, otherwise 'Standard')
o Scan Options: 'Scan Archives' and 'Scan Mail Bases'
* Click 'OK'
* Now under 'Select a target to scan' select 'My Computer'
* The scan will take a while, so be patient and let it run. Once the scan is complete, it will display whether your system has been infected.
* Now click on the 'Save as Text' button:
* Save the file to your desktop.
Please post the Kaspersky report and a new HijackThis log.

Dave
IndiGenus

The help you receive here is free, but if you would like to help me continue the fight against Malware then Posted Image

Logs will be closed if you haven't replied within 5 days



Proud Graduate of TC/WTT Classroom



"To find perfect composure in the midst of change is to find ourselves in nirvana."

Suzuki Roshi


#5 moguh

moguh

    New Member

  • New Member
  • Pip
  • 6 posts

Posted 10 March 2007 - 05:42 PM

Hi,


Here is the Kaspersky report and the Hijack this files.


Big thank's

Scan Statistics
Total number of scanned objects 158321
Number of viruses found 2
Number of infected objects 9 / 0
Number of suspicious objects 0
Duration of the scan process 01:37:47

Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\791576950ebfab18ffae65fe78f04804_317f7cfe-190a-4e83-b1c9-595527d33e6e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Mozilla\Firefox\Profiles\bscdknbx.default\history.dat Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Mozilla\Firefox\Profiles\bscdknbx.default\parent.lock Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\abook.mab Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\cert8.db Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Archives mail.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Archives mail.sbd\2001.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Archives mail.sbd\2002.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Archives mail.sbd\2003.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Archives mail.sbd\2004.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Archives mail.sbd\2005.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Archives mail.sbd\2006_part1.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\english.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\FilemakerPro.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Offline Inbox.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\OpenOffice.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2001.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2001.sbd\07-Jul.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2001.sbd\08-Aug.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2001.sbd\09-Sep.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2001.sbd\10-Oct.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2001.sbd\11-Nov.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2001.sbd\12-Dec.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2003.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2003.sbd\08-Aug.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2005.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2005.sbd\01-Jan.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2005.sbd\02-Feb.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2005.sbd\03-Mar.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2005.sbd\04-Apr.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2005.sbd\05-May.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2005.sbd\06-Jun.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2005.sbd\07-Jul.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2005.sbd\08-Aug.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2005.sbd\09-Sep.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2005.sbd\10-Oct.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2005.sbd\11-Nov.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2005.sbd\12-Dec.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2006.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2006.sbd\01-Jan.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2006.sbd\02-Feb.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2006.sbd\03-Mar.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2006.sbd\04-Apr.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2006.sbd\05-May-1.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2006.sbd\06-Jun-1.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2006.sbd\07-Jul-1.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2006.sbd\08-Aug-1.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2006.sbd\09-Sep-1.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2006.sbd\10-Oct-1.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2006.sbd\11-Nov-1.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2006.sbd\12-Dec-1.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2007-1.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2007-1.sbd\01-Jan.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2007-1.sbd\02-Feb.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Trash.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Travaux.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Travaux.sbd\mailing list HTV.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\VLC.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\junklog.html Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\mail.vecteurm.com\INBOX.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\mail.vecteurm.com\INBOX.sbd\Sent-1.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\mail.vecteurm.com\INBOX.sbd\Trash.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\key3.db Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\Mail\Local Folders\Junk.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\Mail\Local Folders\Kit hygiene.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\Mail\Local Folders\Sent.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\Mail\Local Folders\Templates.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\Mail\Local Folders\Trash.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\Mail\pop.gmail.com\Inbox.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\Mail\pop.gmail.com\Junk.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\Mail\pop.gmail.com\Sent.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\Mail\pop.gmail.com\Trash.msf Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\panacea.dat Object is locked skipped
C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\parent.lock Object is locked skipped
C:\Documents and Settings\Olivier\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Olivier\Local Settings\Application Data\Ahead\Nero Home\bl.db Object is locked skipped
C:\Documents and Settings\Olivier\Local Settings\Application Data\Ahead\Nero Home\bl.db-journal Object is locked skipped
C:\Documents and Settings\Olivier\Local Settings\Application Data\Ahead\Nero Home\is2.db Object is locked skipped
C:\Documents and Settings\Olivier\Local Settings\Application Data\Ahead\Nero Home\is2.db-journal Object is locked skipped
C:\Documents and Settings\Olivier\Local Settings\Application Data\Google\Google Desktop\f4d43a9eea77\dbc2e.ht1 Object is locked skipped
C:\Documents and Settings\Olivier\Local Settings\Application Data\Google\Google Desktop\f4d43a9eea77\dbdam Object is locked skipped
C:\Documents and Settings\Olivier\Local Settings\Application Data\Google\Google Desktop\f4d43a9eea77\dbdao Object is locked skipped
C:\Documents and Settings\Olivier\Local Settings\Application Data\Google\Google Desktop\f4d43a9eea77\dbeam Object is locked skipped
C:\Documents and Settings\Olivier\Local Settings\Application Data\Google\Google Desktop\f4d43a9eea77\dbeao Object is locked skipped
C:\Documents and Settings\Olivier\Local Settings\Application Data\Google\Google Desktop\f4d43a9eea77\dbm Object is locked skipped
C:\Documents and Settings\Olivier\Local Settings\Application Data\Google\Google Desktop\f4d43a9eea77\dbu2d.ht1 Object is locked skipped
C:\Documents and Settings\Olivier\Local Settings\Application Data\Google\Google Desktop\f4d43a9eea77\dbvm.cf1 Object is locked skipped
C:\Documents and Settings\Olivier\Local Settings\Application Data\Google\Google Desktop\f4d43a9eea77\dbvmh.ht1 Object is locked skipped
C:\Documents and Settings\Olivier\Local Settings\Application Data\Google\Google Desktop\f4d43a9eea77\fii.cf1 Object is locked skipped
C:\Documents and Settings\Olivier\Local Settings\Application Data\Google\Google Desktop\f4d43a9eea77\fiih.ht1 Object is locked skipped
C:\Documents and Settings\Olivier\Local Settings\Application Data\Google\Google Desktop\f4d43a9eea77\hp Object is locked skipped
C:\Documents and Settings\Olivier\Local Settings\Application Data\Google\Google Desktop\f4d43a9eea77\hpt2i.ht1 Object is locked skipped
C:\Documents and Settings\Olivier\Local Settings\Application Data\Google\Google Desktop\f4d43a9eea77\rpm.cf1 Object is locked skipped
C:\Documents and Settings\Olivier\Local Settings\Application Data\Google\Google Desktop\f4d43a9eea77\rpm1m.cf1 Object is locked skipped
C:\Documents and Settings\Olivier\Local Settings\Application Data\Google\Google Desktop\f4d43a9eea77\rpm1mh.ht1 Object is locked skipped
C:\Documents and Settings\Olivier\Local Settings\Application Data\Google\Google Desktop\f4d43a9eea77\rpmh.ht1 Object is locked skipped
C:\Documents and Settings\Olivier\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Olivier\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Olivier\Local Settings\Application Data\Mozilla\Firefox\Profiles\bscdknbx.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Olivier\Local Settings\Application Data\Mozilla\Firefox\Profiles\bscdknbx.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Olivier\Local Settings\Application Data\Mozilla\Firefox\Profiles\bscdknbx.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Olivier\Local Settings\Application Data\Mozilla\Firefox\Profiles\bscdknbx.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Olivier\Local Settings\Historique\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Olivier\Local Settings\Temp\~DF1161.tmp Object is locked skipped
C:\Documents and Settings\Olivier\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Olivier\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Olivier\ntuser.dat.LOG Object is locked skipped
C:\ftpserver\war ftp\ward165.exe/war-ftpd.exe Infected: not-a-virus:Server-FTP.Win32.PremierServer.b skipped
C:\ftpserver\war ftp\ward165.exe ZIP: infected - 1 skipped
C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\integ\avast.int Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped
C:\SDFix\backups\backups.zip/backups/AdobeR.exe Infected: Worm.Win32.RJump.a skipped
C:\SDFix\backups\backups.zip ZIP: infected - 1 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{340C3340-2EBB-4324-859A-C37E85627171}\RP352\A0069141.exe Infected: Worm.Win32.RJump.a skipped
C:\System Volume Information\_restore{340C3340-2EBB-4324-859A-C37E85627171}\RP353\A0069259.exe Infected: Worm.Win32.RJump.a skipped
C:\System Volume Information\_restore{340C3340-2EBB-4324-859A-C37E85627171}\RP356\A0069672.exe Infected: Worm.Win32.RJump.a skipped
C:\System Volume Information\_restore{340C3340-2EBB-4324-859A-C37E85627171}\RP359\A0071027.exe Infected: Worm.Win32.RJump.a skipped
C:\System Volume Information\_restore{340C3340-2EBB-4324-859A-C37E85627171}\RP359\A0071033.exe Infected: Worm.Win32.RJump.a skipped
C:\System Volume Information\_restore{340C3340-2EBB-4324-859A-C37E85627171}\RP365\change.log Object is locked skipped
C:\WINDOWS\CSC\00000001 Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{ED1C34EA-7486-428F-B356-A2DD5C88887D}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_588.dat Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.



Logfile of HijackThis v1.99.1
Scan saved at 00:37:22, on 11/03/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\stsystra.exe
C:\program files\dell\quickset\quickset.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\DELL\Dell Laser MFP 1815\NetworkScan\DNSCST.exe
C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Creative Professional\E-MU USB Audio\E-MU USB Audio\EmuUsbAudioCP.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Applications\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.fr/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearch.mywa...idebar.jsp?p=DR
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.fr/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.fr/myway
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.fr/myway
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.65.9:9090
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = legion;192.168.65.85;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll (file missing)
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\program files\dell\quickset\quickset.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [AdobeVersionCue] C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [DellNSCST_GRNCH] "C:\Program Files\DELL\Dell Laser MFP 1815\NetworkScan\DNSCST.exe" /HIDEUI
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [E-MU USB Audio Control Panel] "C:\Program Files\Creative Professional\E-MU USB Audio\E-MU USB Audio\EmuUsbAudioCP.exe"
O4 - HKCU\..\Run: [ProcessManager] C:\Program Files\Bill2's Process Manager\ProcessManager.exe -minimized
O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Assistant d'Acrobat.lnk = C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {2019DC25-D1C0-11D6-97B3-0008A124F542} (StreamPlug Class) - http://www.streamplu...reamPlug/SP.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcaf...01/mcinsctl.cab
O16 - DPF: {B3A5F463-EBD7-487E-B737-D2B772908D0F} (Infini.Clock) - http://www.infini-fr...tion/Infini.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{1A401FDF-0CCD-402B-A144-4643B1DBB10B}: NameServer = 195.154.193.55,80.118.196.36
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AdobeVersionCue - Adobe Sytems - C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

#6 IndiGenus

IndiGenus

    Teacher Emeritus

  • Authentic Member
  • PipPipPipPipPipPip
  • 5,251 posts
  • Interests:Computer Security, Music, Sports

Posted 10 March 2007 - 06:29 PM

Hi Moguh,

Not too much to be concerned about there. A couple in your restore points, which I advise you clean out (see below), a couple in your SDFix backups folder (which can be deleted), and a couple I'm not sure of. These two entries:

C:\ftpserver\war ftp\ward165.exe/war-ftpd.exe Infected: not-a-virus:Server-FTP.Win32.PremierServer.b skipped
C:\ftpserver\war ftp\ward165.exe ZIP: infected - 1 skipped

Do you know what they are?

---------------------------------------------------------------

Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: (You will lose all previous restore points which may be infected anyway).

Click Start>Help and Support>Undo changes to your computer with System Restore
Select Create A Restore Point then click Next. Give it a name it and then click Create

Click Start>Run and type Cleanmgr
Click the More Options Tab.
Click Clean Up in the System Restore section.

------------------------------------------------------------------

You can also delete SDFix now.

------------------------------------------------------------------

Let me know if you know what that file is. If you're not sure you can upload it to one of the online multi-scanners to get "other opinions".

Go to http://virusscan.jotti.org, click on Browse, and upload the following file for analysis:

C:\ftpserver\war ftp\ward165.exe/war-ftpd.exe

Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.

If Jotti is too busy you can try these.

http://www.kaspersky...anforvirus.html
http://www.virustota.../en/indexf.html
IndiGenus

The help you receive here is free, but if you would like to help me continue the fight against Malware then Posted Image

Logs will be closed if you haven't replied within 5 days



Proud Graduate of TC/WTT Classroom



"To find perfect composure in the midst of change is to find ourselves in nirvana."

Suzuki Roshi


#7 IndiGenus

IndiGenus

    Teacher Emeritus

  • Authentic Member
  • PipPipPipPipPipPip
  • 5,251 posts
  • Interests:Computer Security, Music, Sports

Posted 16 March 2007 - 07:42 AM

Hi Moguh, Do you still need help here? Please let me know. Thanks, Dave
IndiGenus

The help you receive here is free, but if you would like to help me continue the fight against Malware then Posted Image

Logs will be closed if you haven't replied within 5 days



Proud Graduate of TC/WTT Classroom



"To find perfect composure in the midst of change is to find ourselves in nirvana."

Suzuki Roshi


#8 moguh

moguh

    New Member

  • New Member
  • Pip
  • 6 posts

Posted 16 March 2007 - 08:29 AM

Hi Indigenus, Sorry to be late to answer, I was away. I have downloaded war ftp because I needed a ftp server, but it seems to be infected files. I will send it to trash. C:\ftpserver\war ftp\ward165.exe/war-ftpd.exe Infected: not-a-virus:Server-FTP.Win32.PremierServer.b skipped C:\ftpserver\war ftp\ward165.exe ZIP: infected - 1 skipped Yesterday, I get an USB key with AdobeR.exe, and I have been infected another time. How can I prevent this infection ? (Avast seems to be "out", should I go back to Kaspersky ?) Here is the result of the scan by Kaspersky : Infected Object Name Virus Name Last Action C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\791576950ebfab18ffae65fe78f04804_317f7cfe-190a-4e83-b1c9-595527d33e6e Object is locked skipped C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare Object is locked skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Mozilla\Firefox\Profiles\bscdknbx.default\history.dat Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Mozilla\Firefox\Profiles\bscdknbx.default\parent.lock Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\abook.mab Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\cert8.db Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Archives mail.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Archives mail.sbd\2001.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Archives mail.sbd\2002.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Archives mail.sbd\2003.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Archives mail.sbd\2004.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Archives mail.sbd\2005.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Archives mail.sbd\2006_part1.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\english.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\FilemakerPro.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Offline Inbox.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\OpenOffice.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2001.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2001.sbd\07-Jul.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2001.sbd\08-Aug.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2001.sbd\09-Sep.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2001.sbd\10-Oct.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2001.sbd\11-Nov.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2001.sbd\12-Dec.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2003.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2003.sbd\08-Aug.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2005.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2005.sbd\01-Jan.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2005.sbd\02-Feb.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2005.sbd\03-Mar.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2005.sbd\04-Apr.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2005.sbd\05-May.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2005.sbd\06-Jun.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2005.sbd\07-Jul.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2005.sbd\08-Aug.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2005.sbd\09-Sep.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2005.sbd\10-Oct.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2005.sbd\11-Nov.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2005.sbd\12-Dec.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2006.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2006.sbd\01-Jan.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2006.sbd\02-Feb.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2006.sbd\03-Mar.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2006.sbd\04-Apr.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2006.sbd\05-May-1.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2006.sbd\06-Jun-1.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2006.sbd\07-Jul-1.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2006.sbd\08-Aug-1.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2006.sbd\09-Sep-1.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2006.sbd\10-Oct-1.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2006.sbd\11-Nov-1.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2006.sbd\12-Dec-1.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2007-1.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2007-1.sbd\01-Jan.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Sent.sbd\2007-1.sbd\02-Feb.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Trash.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Travaux.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\Travaux.sbd\mailing list HTV.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\INBOX.sbd\VLC.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\imap.vecteurm.com\junklog.html Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\mail.vecteurm.com\INBOX.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\mail.vecteurm.com\INBOX.sbd\Sent-1.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\ImapMail\mail.vecteurm.com\INBOX.sbd\Trash.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\key3.db Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\Mail\Local Folders\Junk.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\Mail\Local Folders\Kit hygiene.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\Mail\Local Folders\Sent.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\Mail\Local Folders\Templates.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\Mail\Local Folders\Trash.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\Mail\pop.gmail.com\Inbox.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\Mail\pop.gmail.com\Junk.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\Mail\pop.gmail.com\Sent.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\Mail\pop.gmail.com\Trash.msf Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\panacea.dat Object is locked skipped C:\Documents and Settings\Olivier\Application Data\Thunderbird\Profiles\hxeyx2mu.default\parent.lock Object is locked skipped C:\Documents and Settings\Olivier\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Olivier\Local Settings\Application Data\Ahead\Nero Home\bl.db Object is locked skipped C:\Documents and Settings\Olivier\Local Settings\Application Data\Ahead\Nero Home\bl.db-journal Object is locked skipped C:\Documents and Settings\Olivier\Local Settings\Application Data\Ahead\Nero Home\is2.db Object is locked skipped C:\Documents and Settings\Olivier\Local Settings\Application Data\Ahead\Nero Home\is2.db-journal Object is locked skipped C:\Documents and Settings\Olivier\Local Settings\Application Data\Google\Google Desktop\f4d43a9eea77\dbc2e.ht1 Object is locked skipped C:\Documents and Settings\Olivier\Local Settings\Application Data\Google\Google Desktop\f4d43a9eea77\dbdam Object is locked skipped C:\Documents and Settings\Olivier\Local Settings\Application Data\Google\Google Desktop\f4d43a9eea77\dbdao Object is locked skipped C:\Documents and Settings\Olivier\Local Settings\Application Data\Google\Google Desktop\f4d43a9eea77\dbeam Object is locked skipped C:\Documents and Settings\Olivier\Local Settings\Application Data\Google\Google Desktop\f4d43a9eea77\dbeao Object is locked skipped C:\Documents and Settings\Olivier\Local Settings\Application Data\Google\Google Desktop\f4d43a9eea77\dbm Object is locked skipped C:\Documents and Settings\Olivier\Local Settings\Application Data\Google\Google Desktop\f4d43a9eea77\dbu2d.ht1 Object is locked skipped C:\Documents and Settings\Olivier\Local Settings\Application Data\Google\Google Desktop\f4d43a9eea77\dbvm.cf1 Object is locked skipped C:\Documents and Settings\Olivier\Local Settings\Application Data\Google\Google Desktop\f4d43a9eea77\dbvmh.ht1 Object is locked skipped C:\Documents and Settings\Olivier\Local Settings\Application Data\Google\Google Desktop\f4d43a9eea77\fii.cf1 Object is locked skipped C:\Documents and Settings\Olivier\Local Settings\Application Data\Google\Google Desktop\f4d43a9eea77\fiih.ht1 Object is locked skipped C:\Documents and Settings\Olivier\Local Settings\Application Data\Google\Google Desktop\f4d43a9eea77\hp Object is locked skipped C:\Documents and Settings\Olivier\Local Settings\Application Data\Google\Google Desktop\f4d43a9eea77\hpt2i.ht1 Object is locked skipped C:\Documents and Settings\Olivier\Local Settings\Application Data\Google\Google Desktop\f4d43a9eea77\rpm.cf1 Object is locked skipped C:\Documents and Settings\Olivier\Local Settings\Application Data\Google\Google Desktop\f4d43a9eea77\rpm1m.cf1 Object is locked skipped C:\Documents and Settings\Olivier\Local Settings\Application Data\Google\Google Desktop\f4d43a9eea77\rpm1mh.ht1 Object is locked skipped C:\Documents and Settings\Olivier\Local Settings\Application Data\Google\Google Desktop\f4d43a9eea77\rpmh.ht1 Object is locked skipped C:\Documents and Settings\Olivier\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Olivier\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Olivier\Local Settings\Application Data\Mozilla\Firefox\Profiles\bscdknbx.default\Cache\_CACHE_001_ Object is locked skipped C:\Documents and Settings\Olivier\Local Settings\Application Data\Mozilla\Firefox\Profiles\bscdknbx.default\Cache\_CACHE_002_ Object is locked skipped C:\Documents and Settings\Olivier\Local Settings\Application Data\Mozilla\Firefox\Profiles\bscdknbx.default\Cache\_CACHE_003_ Object is locked skipped C:\Documents and Settings\Olivier\Local Settings\Application Data\Mozilla\Firefox\Profiles\bscdknbx.default\Cache\_CACHE_MAP_ Object is locked skipped C:\Documents and Settings\Olivier\Local Settings\Historique\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Olivier\Local Settings\Temp\~DF1161.tmp Object is locked skipped C:\Documents and Settings\Olivier\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Olivier\NTUSER.DAT Object is locked skipped C:\Documents and Settings\Olivier\ntuser.dat.LOG Object is locked skipped C:\ftpserver\war ftp\ward165.exe/war-ftpd.exe Infected: not-a-virus:Server-FTP.Win32.PremierServer.b skipped C:\ftpserver\war ftp\ward165.exe ZIP: infected - 1 skipped C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped C:\Program Files\Alwil Software\Avast4\DATA\integ\avast.int Object is locked skipped C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped C:\SDFix\backups\backups.zip/backups/AdobeR.exe Infected: Worm.Win32.RJump.a skipped C:\SDFix\backups\backups.zip ZIP: infected - 1 skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{340C3340-2EBB-4324-859A-C37E85627171}\RP352\A0069141.exe Infected: Worm.Win32.RJump.a skipped C:\System Volume Information\_restore{340C3340-2EBB-4324-859A-C37E85627171}\RP353\A0069259.exe Infected: Worm.Win32.RJump.a skipped C:\System Volume Information\_restore{340C3340-2EBB-4324-859A-C37E85627171}\RP356\A0069672.exe Infected: Worm.Win32.RJump.a skipped C:\System Volume Information\_restore{340C3340-2EBB-4324-859A-C37E85627171}\RP359\A0071027.exe Infected: Worm.Win32.RJump.a skipped C:\System Volume Information\_restore{340C3340-2EBB-4324-859A-C37E85627171}\RP359\A0071033.exe Infected: Worm.Win32.RJump.a skipped C:\System Volume Information\_restore{340C3340-2EBB-4324-859A-C37E85627171}\RP365\change.log Object is locked skipped C:\WINDOWS\CSC\00000001 Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\EventCache\{ED1C34EA-7486-428F-B356-A2DD5C88887D}.bin Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\DEFAULT Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SYSTEM Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\Temp\Perflib_Perfdata_588.dat Object is locked skipped C:\WINDOWS\wiadebug.log Object is locked skipped C:\WINDOWS\wiaservc.log Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped Scan process completed.

#9 IndiGenus

IndiGenus

    Teacher Emeritus

  • Authentic Member
  • PipPipPipPipPipPip
  • 5,251 posts
  • Interests:Computer Security, Music, Sports

Posted 16 March 2007 - 09:23 AM

Yesterday, I get an USB key with AdobeR.exe,

Not sure what you mean. Is your USB drive infected?

and I have been infected another time.

When, since we cleaned up here?

How can I prevent this infection ? (Avast seems to be "out", should I go back to Kaspersky ?)

Not quite sure as infections can come from so many places. And your antivirus is only one level of protection, along with a good firewall. I typically recommend Avast or AVG because they are free. But there are more robust pay-for products. Take a look through this link for some reviews:

http://www.pcpro.co....troduction.html

Post a fresh HJT log for review to make sure all looks well.

Regards,
Dave
IndiGenus

The help you receive here is free, but if you would like to help me continue the fight against Malware then Posted Image

Logs will be closed if you haven't replied within 5 days



Proud Graduate of TC/WTT Classroom



"To find perfect composure in the midst of change is to find ourselves in nirvana."

Suzuki Roshi


#10 moguh

moguh

    New Member

  • New Member
  • Pip
  • 6 posts

Posted 16 March 2007 - 09:58 AM

[quote name='IndiGenus' date='Mar 16 2007, 04:23 PM' post='361406']
[quote]Yesterday, I get an USB key with AdobeR.exe,[/quote]
Not sure what you mean. Is your USB drive infected?

Not mine, but I had to put an infected one in my computer, and I see that something did not want to stop on it : it was adbeR.exe

Post a fresh HJT log for review to make sure all looks well.


Thanks a lot

Here is the Hijack this log :

Logfile of HijackThis v1.99.1
Scan saved at 16:53:34, on 16/03/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\stsystra.exe
C:\program files\dell\quickset\quickset.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\DELL\Dell Laser MFP 1815\NetworkScan\DNSCST.exe
C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\Program Files\Creative Professional\E-MU USB Audio\E-MU USB Audio\EmuUsbAudioCP.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Applications\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.fr/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearch.mywa...idebar.jsp?p=DR
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.fr/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.fr/myway
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.fr/myway
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.65.9:9090
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = legion;192.168.65.85;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll (file missing)
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\program files\dell\quickset\quickset.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [AdobeVersionCue] C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [DellNSCST_GRNCH] "C:\Program Files\DELL\Dell Laser MFP 1815\NetworkScan\DNSCST.exe" /HIDEUI
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [E-MU USB Audio Control Panel] "C:\Program Files\Creative Professional\E-MU USB Audio\E-MU USB Audio\EmuUsbAudioCP.exe"
O4 - HKCU\..\Run: [ProcessManager] C:\Program Files\Bill2's Process Manager\ProcessManager.exe -minimized
O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Assistant d'Acrobat.lnk = C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {2019DC25-D1C0-11D6-97B3-0008A124F542} (StreamPlug Class) - http://www.streamplu...reamPlug/SP.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcaf...01/mcinsctl.cab
O16 - DPF: {B3A5F463-EBD7-487E-B737-D2B772908D0F} (Infini.Clock) - http://www.infini-fr...tion/Infini.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{1A401FDF-0CCD-402B-A144-4643B1DBB10B}: NameServer = 195.154.193.55,80.118.196.36
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AdobeVersionCue - Adobe Sytems - C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

#11 IndiGenus

IndiGenus

    Teacher Emeritus

  • Authentic Member
  • PipPipPipPipPipPip
  • 5,251 posts
  • Interests:Computer Security, Music, Sports

Posted 16 March 2007 - 10:58 AM

Not mine, but I had to put an infected one in my computer, and I see that something did not want to stop on it : it was adbeR.exe

Yikes :o did you know it was infected? That particular infection will spread quickly and easily. I don't see any evidence that the problem came back in your log though.

Some cleanup with HJT:

Run HijackThis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearch.mywa...idebar.jsp?p=DR
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll (file missing)

Then close all windows except this one and press Fix checked.

Let me know if you need any more help and how things are running.

Dave
IndiGenus

The help you receive here is free, but if you would like to help me continue the fight against Malware then Posted Image

Logs will be closed if you haven't replied within 5 days



Proud Graduate of TC/WTT Classroom



"To find perfect composure in the midst of change is to find ourselves in nirvana."

Suzuki Roshi


#12 moguh

moguh

    New Member

  • New Member
  • Pip
  • 6 posts

Posted 16 March 2007 - 11:11 AM

Not mine, but I had to put an infected one in my computer, and I see that something did not want to stop on it : it was adbeR.exe

Yikes :o did you know it was infected? That particular infection will spread quickly and easily. I don't see any evidence that the problem came back in your log though.


I did not know before insertion that the usb key was infected

I have made the Hijack cleanup. I will uninstall Nero because there are too many processes belonging to it, and I think my computer should be faster at startup.


Thank you for your help !

#13 IndiGenus

IndiGenus

    Teacher Emeritus

  • Authentic Member
  • PipPipPipPipPipPip
  • 5,251 posts
  • Interests:Computer Security, Music, Sports

Posted 19 March 2007 - 12:43 PM

Hi moguh,

In addition to updating and running your current protection you may want to consider some of these free tools:

Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly or set your computer to receive automatic updates. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

Install Spybot - Search and Destroy - Spybot: Search And Destroy with its TeaTimer option. This will provide realtime spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an antivirus software.
A tutorial on installing & using this product can be found here:
Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers

Install Ad-Aware - Ad-Aware SE You should also scan your computer with program on a regular basis just as you would an antivirus software in conjunction with Spybot.
A tutorial on installing & using this product can be found here:
Using Ad-aware to remove Spyware, Malware, & Hijackers from Your Computer

Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.
A tutorial on installing & using this product can be found here:
Using SpywareBlaster to protect your computer from Spyware and Malware

Install SpywareGuard - SpywareGuard provides a real-time protection solution against spyware that is a great addition to SpywareBlaster's protection method.
A tutorial on installing & using this product can be found here:
Using SpywareGuard to protect your computer from Spyware and Malware

Update all of your Anti-Malware programs regularly - Make sure you update all the programs I have listed and the ones you are currently running regularly. Without regular updates you Will Not be protected when new malicious programs are released.

Here is a great link to a post here on securing your PC after an attack.
http://forums.tomcoy...mp;#entry257163

Follow this list and your potential for being infected again will reduce dramatically.

Glad I was able to help.

Dave
IndiGenus

The help you receive here is free, but if you would like to help me continue the fight against Malware then Posted Image

Logs will be closed if you haven't replied within 5 days



Proud Graduate of TC/WTT Classroom



"To find perfect composure in the midst of change is to find ourselves in nirvana."

Suzuki Roshi


#14 IndiGenus

IndiGenus

    Teacher Emeritus

  • Authentic Member
  • PipPipPipPipPipPip
  • 5,251 posts
  • Interests:Computer Security, Music, Sports

Posted 26 March 2007 - 12:23 PM

Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoy...showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php
IndiGenus

The help you receive here is free, but if you would like to help me continue the fight against Malware then Posted Image

Logs will be closed if you haven't replied within 5 days



Proud Graduate of TC/WTT Classroom



"To find perfect composure in the midst of change is to find ourselves in nirvana."

Suzuki Roshi

Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users