Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93104 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

[Resolved] Trojan.tiny.e, Worm.brontok, Downloader Agent, And Tro


  • This topic is locked This topic is locked
13 replies to this topic

#1 Unforgiven

Unforgiven

    Authentic Member

  • Authentic Member
  • PipPip
  • 39 posts

Posted 08 September 2007 - 07:08 AM

hey my comps quite heavily infested by

downloader agent
trojan.tiny.e
trojan.shipup.a
worm.brontok


Dont know which others



Heres my HJT log


Logfile of HijackThis v1.99.1
Scan saved at 6:47:47 PM, on 9/8/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Free Download Manager\fdm.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\system32\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\sol.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\HJT\Hijackthis\HijackThis.exe

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe, explorer.exe
O1 - Hosts: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
O1 - Hosts: "http://www.w3.org/TR...ml4/loose.dtd">
O1 - Hosts: <html>
O1 - Hosts: <head>
O1 - Hosts: <script LANGUAGE="JavaScript">
O1 - Hosts: <!--
O1 - Hosts: if (window != top)
O1 - Hosts: top.location.href = location.href;
O1 - Hosts: // -->
O1 - Hosts: </script>
O1 - Hosts: <title>Site Unavailable</title>
O1 - Hosts: <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
O1 - Hosts: <style type="text/css">
O1 - Hosts: body{text-align:center;}
O1 - Hosts: .geohead {font-family:Verdana, Arial, Helvetica, sans-serif; font-size:10px;width:750px;margin:10px 0 10px 0;height:35px;}
O1 - Hosts: .geohead #geologo {width:270px;display:block; float:left; }
O1 - Hosts: .geohead #rightside {width:480px;display:block; float:right;border-bottom:1px solid #999999; height:27px;}
O1 - Hosts: .geohead #rightside #welcome {width:50%;display:block; float:left; text-align:left;}
O1 - Hosts: .geohead #rightside #wlinks {width:50%;display:block; float:right; text-align:right;}
O1 - Hosts: .ftr { margin:0px; color:#404040; font:x-small Arial,sans-serif; text-align:center; width:750px;}
O1 - Hosts: .bodywrap{display:block;height:470px;}
O1 - Hosts: .bodycnt{width:510px; display:block; float:left; background-color:#EEE9F5; height:auto; text-align:left; font-family:Arial, Helvetica, sans-serif;font-size:13px; color:#000000; padding:20px 20px 35px 20px;}
O1 - Hosts: .title { font-family:Arial, Helvetica, sans-serif; font-weight:bold; font-size:24px; color:#7C56A9}
O1 - Hosts: .adcnt{width:172px; display:block; float:right; text-align:left;cursor:pointer;cursor:hand;}
O1 - Hosts: .adcnt td {text-align:left;}
O1 - Hosts: .adsubt{font-size:10px; font-family:verdana; font-weight:bold; color:#b4b4b4; cursor:default;margin-top:5px;}
O1 - Hosts: .ybadge { font-family: Verdana, Arial, Helvetica, sans-serif; font-size:10px; color: #666666; margin-top:10px;}
O1 - Hosts: .ybadge img {margin-top:6px;}
O1 - Hosts: .adtable {font-family:Verdana, Arial, Helvetica, sans-serif; font-size:10px;border: 1px solid #d6dbe7; background-color:#eff7ff; padding:3px; margin-bottom:10px; width:172px;}
O1 - Hosts: .adttl{font-weight:bold;margin-bottom:3px;}
O1 - Hosts: .addescr{color:#6b6b6b; margin-bottom:3px;}
O1 - Hosts: .adlink a {color:#008200; text-decoration:none;}
O1 - Hosts: </style>
O1 - Hosts: </head>
O1 - Hosts: <body>
O1 - Hosts: <!-- following code added by server. PLEASE REMOVE -->
O1 - Hosts: <!-- preceding code added by server. PLEASE REMOVE -->
O1 - Hosts: <div id="maincnt">
O1 - Hosts: <div class="geohead"><div id="geologo"><a href="http://geocities.yah...yahoo.com"><img height=33 alt="Yahoo! GeoCities" src="http://us.i1.yimg.co...a/ma_geo_1.gif" width=259 border=0></a></div>
O1 - Hosts: <div id="rightside"><div id="wlinks"><a href="http://geocities.yah....com">GeoCities Home</a> - <a href="http://www.yahoo.com">Yahoo!</a> - <a href="http://help.yahoo.co...>Help</a></div>
O1 - Hosts: </div></div>
O1 - Hosts: <div class="bodywrap">
O1 - Hosts: <div class="bodycnt">
O1 - Hosts: <div class="title">Sorry, this GeoCities site is currently unavailable.</div>
O1 - Hosts: <p>The GeoCities web site you were trying to view has temporarily exceeded its data transfer limit. Please try again later. </p>
O1 - Hosts: <p>Are you the site owner?
O1 - Hosts: Avoid service interruptions in the future by increasing your data transfer limit!
O1 - Hosts: <a href="http://help.yahoo.co...ansfer-05.html" target="_blank">Find out how.</a> </p>
O1 - Hosts: <p><a href="http://help.yahoo.co.../geo/transfer/" target="_blank">Learn more about data transfer.</a></p>
O1 - Hosts: </div>
O1 - Hosts: <div class="adcnt">
O1 - Hosts: <a target="_top" href="http://geocities.yah...yahoo.com"><img src="http://us.i1.yimg.co...ast_small2.gif" alt="Yahoo! GeoCities" border="0" height="15" hspace="0" vspace="0" width="141"></a>
O1 - Hosts: <div class="adsubt">SPONSORED LINKS</div>
O1 - Hosts: <!--<table width="172" border="0" bgcolor="#FFFFFF" class="adtable"><tr><td align=left>-->
O1 - Hosts: <div class="adtable">
O1 - Hosts: <div class="adttl" title="Reliable plans include domain &amp; 24x7 support."><a href="http://pa.yahoo.com/...com/webhosting" target="_blank">Yahoo! Web Hosting<br>
O1 - Hosts: $25 Setup Waived</a></div>
O1 - Hosts: <div class="addescr" title="Reliable plans include domain &amp; 24x7 support.">Reliable plans include domain &amp; 24x7 support.</div>
O1 - Hosts: <div class="adlink" title="Reliable plans include domain &amp; 24x7 support."><a href="http://pa.yahoo.com/...com/webhosting" target="_blank">webhosting.yahoo.com</a></div>
O1 - Hosts: </div>
O1 - Hosts: <div class="adtable">
O1 - Hosts: <div class="adttl" title="Reliable plans include domain &amp; 24x7 support."><a href="http://pa.yahoo.com/...o.com/domains/" target="_blank">Domain Names from Yahoo! only $9.95/yr</a></div>
O1 - Hosts: <div class="addescr" title="Includes starter web page, email & domain forwarding, 24x7 support.">Includes starter web page, email & domain forwarding, 24x7 support.</div>
O1 - Hosts: <div class="adlink" title="Includes starter web page, email & domain forwarding, 24x7 support."><a href="http://pa.yahoo.com/...o.com/domains/" target="_blank">domains.yahoo.com</a></div>
O1 - Hosts: </div>
O1 - Hosts: <div class="adtable">
O1 - Hosts: <div class="adttl" title="Setup fee waived. Up to 10 emails, SpamGuard, forwarding & virus scanning."><a href="http://pa.yahoo.com/...yahoo.com/mail" target="_blank">Yahoo! Business Email<br> Domain Included</a></div>
O1 - Hosts: <div class="addescr" title="Setup fee waived. Up to 10 emails, SpamGuard, forwarding & virus scanning.">Setup fee waived. Up to 10 emails, SpamGuard, forwarding &amp; virus scanning.</div>
O1 - Hosts: <div class="adlink" title="Setup fee waived. Up to 10 emails, SpamGuard, forwarding & virus scanning."><a href="http://pa.yahoo.com/...yahoo.com/mail" target="_blank">smallbusiness.yahoo.com</a></div>
O1 - Hosts: </div>
O1 - Hosts: <div class="adtable">
O1 - Hosts: <div class="adttl" title="$50 setup fee waived. A reliable ecommerce plan, 24x7 support."><a href="http://pa.yahoo.com/...o.com/merchant" target="_blank">Ecommerce from Yahoo!<br> 1 Month Free</a></div>
O1 - Hosts: <div class="addescr" title="$50 setup fee waived. A reliable ecommerce plan, 24x7 support.">$50 setup fee waived. A reliable ecommerce plan, 24x7 support.</div>
O1 - Hosts: <div class="adlink" title="$50 setup fee waived. A reliable ecommerce plan, 24x7 support."><a href="http://pa.yahoo.com/...o.com/merchant" target="_blank">smallbusiness.yahoo.com</a></div>
O1 - Hosts: </div>
O1 - Hosts: <div class="ybadge">
O1 - Hosts: Get your own web site at <br><a target="_top" href="http://geocities.yah...ahoo.com">Yahoo! GeoCities</a>
O1 - Hosts: <a href="http://smallbusiness...om/webhosting/" target="_top"><img src="http://us.i1.yimg.co...dby_purp_2.gif" alt="Hosted by Yahoo! Web Hosting" align="middle" border="0" height="31" width="88"></a>
O1 - Hosts: </div>
O1 - Hosts: </div>
O1 - Hosts: </div>
O1 - Hosts: <div class=ftr>
O1 - Hosts: <hr size=1 width=100%>
O1 - Hosts: Copyright &copy;
O1 - Hosts: 2005 Yahoo! Inc. All rights reserved<br>
O1 - Hosts: <a href="http://privacy.yahoo...s/geo/">Privacy Policy</a>
O1 - Hosts: - <a href="http://docs.yahoo.co...html">Copyright Policy</a>
O1 - Hosts: - <a href="http://docs.yahoo.co...>Guidelines</a>
O1 - Hosts: - <a href="http://docs.yahoo.co...rms.html">Terms of Service</a>
O1 - Hosts: - <a href="http://help.yahoo.co.../geo/">Help</a>
O1 - Hosts: </div>
O1 - Hosts: </div>
O1 - Hosts: </body>
O1 - Hosts: </html>
O1 - Hosts: <!-- text below generated by server. PLEASE REMOVE --></object></layer></div></span></style></noscript></table></script></applet>
O1 - Hosts: <IMG SRC="http://geo.yahoo.com...29482&f=us-w66" ALT=1 WIDTH=1 HEIGHT=1>
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdmcks.dll
O2 - BHO: AL2Spy Class - {DC200356-0864-4F66-8964-5D43A19300F5} - C:\WINDOWS\AUTOLO~1\AL2DLL.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [outlook] C:\Program Files\outlook\outlook.exe /auto
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [spoo1sv.exe] C:\WINDOWS\system32\spoo1sv.exe
O4 - HKLM\..\Run: [Barsaka] explorer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Free Download Manager] C:\Program Files\Free Download Manager\fdm.exe -autorun
O4 - HKCU\..\Run: [ares] "C:\Program Files\ARES\Ares.exe" -h
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - HKCU\..\Run: [Tok-Cirrhatus] "C:\Documents and Settings\Happy Dog\Local Settings\Application Data\smss.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Kodak EasyShare software.lnk.disabled
O4 - Global Startup: Kodak software updater.lnk.disabled
O4 - Global Startup: Picture Package Menu.lnk = ?
O4 - Global Startup: Picture Package VCD Maker.lnk = ?
O4 - Global Startup: Post-itŪ Software Notes Lite.lnk.disabled
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xport to Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.snapfish....fishActivia.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebo...otoUploader.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.shockwave...ploader_v10.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1DEA7153-B1F7-4EAC-85E8-2FEB1AA81D60}: NameServer = 203.187.192.12,203.187.192.15
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe






Plz help

Thanks !

Edited by Unforgiven, 08 September 2007 - 07:20 AM.

    Advertisements

Register to Remove


#2 Simon V.

Simon V.

    MRU Emeritus

  • Authentic Member
  • PipPipPipPip
  • 897 posts

Posted 08 September 2007 - 10:14 AM

  • Hello, and welcome to the forum.

    My name is Simon V., and I'll be glad to help you with your computer problems.

    HijackThis logs can take some time to research, so please be patient with me. I know that you need your computer working as quickly as possible, and I will work hard to help see that happens.
    I am currently looking over your log. As I am a trainee, everything that I post to you must be checked by an Admin or Moderator. Thus, there may be a tiny bit of a delay between posts, but it shouldn't be too long. I will post back shortly with a potential fix.

    Please be patient and I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.


#3 Simon V.

Simon V.

    MRU Emeritus

  • Authentic Member
  • PipPipPipPip
  • 897 posts

Posted 10 September 2007 - 08:19 AM

  • Identity Theft
  • I'm afraid I have unpleasant news for you. You have a Very Dangerous infection on this machine.
    The infection is delivered by BackDoor-DJB, and a few other nasties.
    It allows outsiders COMPLETE access to every keystroke, account, and password you use while on this machine, and complete access to any other data present...

    IF this computer has been used for any kind of important data, my best recommendation is to disconnect from the internet, reformat the entire drive and re-install your operating system and applications.

    We can likely clean the infected files off the computer, and if you wish we will attempt to do so, but we cannot be sure that the infection didn't do something to your system to reduce the system security. In that instance, even after removal of the infection, you could be subject to another attack or takeover as soon as you re-connect to the internet.

    The decision whether to reformat or not should be based on:
  • The use of the computer - this is the primary factor in the decision whether to reformat and re-install, or just disinfect.
  • The variety of malware - this influences the decision on whether to re-format and re-install, or just disinfect. IN THIS CASE we have a backdoor worm, the worst kind.
If the computer has been used for any important data, you are strongly advised to do the following, immediately:
  • Disconnect the infected computer from the internet and from any networked computers until the computer can be cleaned.
  • Back up all important data on the machine. Do not back up any Applications (programs). Those should be re-installed from the original source CDs or websites.
  • If you have ever used this computer for shopping, banking, or any transactions relating to your financial well being:
    Call all of your banks, credit card companies, and financial institutions, informing them that you may be a victim of identity theft, and to put a watch on your accounts or change all your account numbers.
  • From a clean computer, change ALL your online passwords -- for ISP login, email, banks, financial accounts, PayPal, eBay, online companies, and any online forums or groups you belong to.
  • DO NOT change passwords or do any transactions while using the infected computer because the attacker will get the new password and transaction information.
  • Take any other steps you think appropriate for an attempted identity theft.
While you are deciding whether to reformat and re-install, this can be a useful link.

Please let me know what you decide.


#4 Unforgiven

Unforgiven

    Authentic Member

  • Authentic Member
  • PipPip
  • 39 posts

Posted 12 September 2007 - 01:55 AM

Hi Simon, Thats bad news, but not the worst. This is a spare computer in my office, and mostly used for personal surfing, storing pictures and videos. I have not used it for any credit card details or online payments, there are some documents which have my bank account number, but nothing which will allow anyone to have any access (as I dont do any banking online) I will change all my passwords from a clean computer, for all forums,emails, etc. that I can think of today itself and stop accessing anything from this computer other than for this forum. So I think we'll go with the disinfection. Looking to hear from you soon. Thanks aj

#5 Simon V.

Simon V.

    MRU Emeritus

  • Authentic Member
  • PipPipPipPip
  • 897 posts

Posted 12 September 2007 - 08:49 AM

  • Hi :)

    SDFix
  • Please download SDFix and save it to your Desktop.

    Double click SDFix.exe and it will extract the files to %systemdrive%
    (Drive that contains the Windows Directory, typically C:\SDFix)
    • Print these instructions or copy them to Notepad and save it to your desktop, as you won't be able to access internet in Safe Mode.
    • Please reboot into Safe Mode. To do this, go to Start>Turn off Computer, and select Restart. Rapidly tap F8 just before Windows starts to load. In the menu that appears, select Safe Mode (Without Networking)

      Once in Safe Mode, do the following:
    • Open the extracted SDFix folder and double click RunThis.bat to start the script.
    • Type Y to begin the cleanup process.
    • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to reboot.
    • Press any key and it will restart the PC.
    • When the PC restarts the fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
    • Once the desktop icons load, the SDFix report will open on screen and also save into the SDFix folder as Report.txt
      (Report.txt will also be copied to clipboard ready for posting back on the forum).
    ComboFix
  • Please download Combofix from one of the links below:

    http://download.blee...Bs/ComboFix.exe
    http://www.techsuppo...Bs/ComboFix.exe
  • Double-click combofix.exe and follow the prompts.
    • When finished, it shall produce a log for you. Save it to a convenient location.
    Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

    Report Back
  • Please post the reports from SDFix and Combofix, along with a new HijackThis log in your next reply.


#6 Unforgiven

Unforgiven

    Authentic Member

  • Authentic Member
  • PipPip
  • 39 posts

Posted 13 September 2007 - 05:40 AM

Hi Simon,

Here are all the logs


SDFIX



SDFix: Version 1.104

Run by Happy Dog on Thu 09/13/2007 at 03:46 PM

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting...


Normal Mode:
Checking Files:

Trojan Files Found:

C:\WINDOWS\system32\explorer.exe - Deleted



Removing Temp Files...

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

Remaining Services:
------------------




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\StubInstaller.exe"="C:\\StubInstaller.exe:*:Disabled:LimeWire swarmed installer"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"="C:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe:*:Enabled:Kodak Software Updater"
"C:\\Program Files\\ARES\\Ares.exe"="C:\\Program Files\\ARES\\Ares.exe:*:Disabled:Ares"
"C:\\Program Files\\Soulseek\\slsk.exe"="C:\\Program Files\\Soulseek\\slsk.exe:*:Enabled:SoulSeek"
"C:\\Tally\\tally72.exe"="C:\\Tally\\tally72.exe:*:Enabled:tally72"
"C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"="C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe:*:Enabled:EasyShare"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
"C:\\Program Files\\SmartFTP Client\\SmartFTP.exe"="C:\\Program Files\\SmartFTP Client\\SmartFTP.exe:*:Enabled:SmartFTP Client 2.5"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

Remaining Files:
---------------

File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes:

C:\Documents and Settings\Happy Dog\NetHood\mumftp.jwt.com\Desktop.ini
C:\Documents and Settings\Happy Dog\Application Data\MBSIconPlugin6867.dll
C:\Documents and Settings\Happy Dog\Application Data\MBSQTImporterPlugin6863.dll
C:\Documents and Settings\Happy Dog\Application Data\MBSQTMovieExporterPlugin6863.dll
C:\Documents and Settings\Happy Dog\Application Data\MBSQuickTimePlugin6863.dll
C:\Documents and Settings\Happy Dog\Application Data\MBSRegistrationPlugin6867.dll
C:\Documents and Settings\Happy Dog\Application Data\rbap550.dll
C:\Documents and Settings\Happy Dog\Application Data\rbqt550.DLL
C:\Documents and Settings\Happy Dog\Templates\NT.Config`.exe
C:\WINDOWS\NT.Config`.exe
C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp
C:\Documents and Settings\Happy Dog\Local Settings\Temp\Free Download Manager\tic14D.tmp
C:\Documents and Settings\Happy Dog\Local Settings\Temp\Free Download Manager\tic16.tmp
C:\Documents and Settings\Happy Dog\Local Settings\Temp\Free Download Manager\tic163.tmp
C:\Documents and Settings\Happy Dog\Local Settings\Temp\Free Download Manager\tic166.tmp
C:\Documents and Settings\Happy Dog\Local Settings\Temp\Free Download Manager\tic19F.tmp
C:\Documents and Settings\Happy Dog\Local Settings\Temp\Free Download Manager\tic1F9.tmp
C:\Documents and Settings\Happy Dog\Local Settings\Temp\Free Download Manager\tic20E.tmp
C:\Documents and Settings\Happy Dog\Local Settings\Temp\Free Download Manager\tic210.tmp
C:\Documents and Settings\Happy Dog\Local Settings\Temp\Free Download Manager\tic220.tmp
C:\Documents and Settings\Happy Dog\Local Settings\Temp\Free Download Manager\tic243.tmp
C:\Documents and Settings\Happy Dog\Local Settings\Temp\Free Download Manager\tic272.tmp
C:\Documents and Settings\Happy Dog\Local Settings\Temp\Free Download Manager\tic41.tmp
C:\Documents and Settings\Happy Dog\Local Settings\Temp\Free Download Manager\tic42.tmp
C:\Documents and Settings\Happy Dog\Local Settings\Temp\Free Download Manager\tic4C.tmp
C:\Documents and Settings\Happy Dog\Local Settings\Temp\Free Download Manager\tic93.tmp
C:\Documents and Settings\Happy Dog\Local Settings\Temp\Free Download Manager\ticF2.tmp
C:\Documents and Settings\Happy Dog\Local Settings\Temp\Free Download Manager\ticFA.tmp
C:\Documents and Settings\Happy Dog\Local Settings\Temp\Free Download Manager\ticFC.tmp
C:\Documents and Settings\Happy Dog\Local Settings\Temp\Free Download Manager\ticFF.tmp

Finished!






COMBO FIX







ComboFix 07-09-10.6 - "Happy Dog" 2007-09-13 16:34:33.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.597 [GMT 5.5:30]
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\DOCUME~1\HAPPYD~1\APPLIC~1\MBSIconPlugin6867.dll
C:\DOCUME~1\HAPPYD~1\APPLIC~1\MBSQTImporterPlugin6863.dll
C:\DOCUME~1\HAPPYD~1\APPLIC~1\MBSQTMovieExporterPlugin6863.dll
C:\DOCUME~1\HAPPYD~1\APPLIC~1\MBSQuickTimePlugin6863.dll
C:\DOCUME~1\HAPPYD~1\APPLIC~1\MBSRegistrationPlugin6867.dll
C:\DOCUME~1\HAPPYD~1\APPLIC~1\rbap550.dll
C:\DOCUME~1\HAPPYD~1\APPLIC~1\rbqt550.DLL


((((((((((((((((((((((((( Files Created from 2007-08-13 to 2007-09-13 )))))))))))))))))))))))))))))))
.

2007-09-13 16:28 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-09-13 15:43 <DIR> d-------- C:\WINDOWS\ERUNT
2007-09-13 15:40 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Free Download Manager
2007-08-20 16:25 14 --a------ C:\WINDOWS\popcinfot.dat
2007-08-20 16:25 0 --a------ C:\WINDOWS\popcreg.dat
2007-08-20 16:25 <DIR> d-------- C:\Program Files\PopCap Games

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-13 16:35 --------- d-------- C:\DOCUME~1\HAPPYD~1\APPLIC~1\Free Download Manager
2007-09-12 16:23 --------- d-------- C:\DOCUME~1\HAPPYD~1\APPLIC~1\Canon
2007-09-12 13:33 --------- d-------- C:\DOCUME~1\HAPPYD~1\APPLIC~1\BPFTP
2007-09-12 13:31 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-09-12 13:29 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ulead Systems
2007-09-07 14:56 --------- d-------- C:\Program Files\Soulseek
2007-08-09 14:19 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\PopCap
2007-07-31 22:24 --------- d-------- C:\DOCUME~1\HAPPYD~1\APPLIC~1\Skype
2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 43352 --a------ C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll
2006-03-13 11:11:19 0 --sha-w C:\WINDOWS\NT.Config`.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.

*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2005-10-15 07:21 C:\WINDOWS\RTHDCPL.EXE]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 19:42]
"Omnipage"="C:\Program Files\ScanSoft\OmniPageSE\opware32.exe" [2002-06-03 11:38]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 13:03]
"Zone Labs Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2006-08-23 23:38]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]
"spoo1sv.exe"="C:\WINDOWS\system32\spoo1sv.exe" []
"Barsaka"="explorer.exe" [2004-08-04 06:26 C:\WINDOWS\explorer.exe]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:26]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54]
"Free Download Manager"="C:\Program Files\Free Download Manager\fdm.exe" [2006-08-21 00:24]
"ares"="C:\Program Files\ARES\Ares.exe" [2006-07-03 15:31]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45]
"BitTorrent"="C:\Program Files\BitTorrent\bittorrent.exe" []
"Tok-Cirrhatus"="C:\Documents and Settings\Happy Dog\Local Settings\Application Data\smss.exe" []

C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-03-13 12:36:19]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 11:35:26]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 04:21:22]
Kodak EasyShare software.lnk.disabled [2006-12-04 10:56:45]
Kodak software updater.lnk.disabled [2006-12-04 11:00:35]
Picture Package Menu.lnk - C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe [2006-12-25 18:58:55]
Picture Package VCD Maker.lnk - C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe [2006-12-25 18:58:52]
Post-itr Software Notes Lite.lnk.disabled [2006-10-18 15:09:02]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
"ares"="C:\Program Files\ARES\Ares.exe" -h

R1 XPROTECTOR;XPROTECTOR;\??\C:\WINDOWS\system32\drivers\Oreans.sys
R3 RMSPPPOE;WAN Miniport (PPP over Ethernet Protocol);C:\WINDOWS\system32\DRIVERS\RMSPPPOE.SYS
S3 sonypvs1;Sony Digital Imaging Video2;C:\WINDOWS\system32\DRIVERS\sonypvs1.sys


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
AutoRun\command- H:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5c9662ed-b33d-11da-b495-001320e49d03}]
AutoRun\command- RavMon.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{61f21625-f47d-11db-b6d0-00a1b0a15a24}]
AutoRun\command- H:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a56c8da0-ee35-11db-b6bd-00a1b0a15a24}]
Auto\command- H:\MicrosoftPowerPoint.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL MicrosoftPowerPoint.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dbe97ae6-5c71-11dc-b793-00a1b0a15a24}]
AutoRun\command- H:\fooool.exe
explore\Command- H:\fooool.exe
open\Command- H:\fooool.exe

.
Contents of the 'Scheduled Tasks' folder
"2007-06-24 04:31:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
"2007-09-12 11:38:00 C:\WINDOWS\Tasks\At1.job"
.
**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-13 16:37:40
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\tcpip_patcher]
"ImagePath"="\??\C:\Program Files\ARES\tcpip_patcher.sys"
.
Completion time: 2007-09-13 16:38:44 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-09-13 16:38
C:\ComboFix2.txt ... 2006-12-11 15:59
.
--- E O F ---








HJT LOG








Logfile of HijackThis v1.99.1
Scan saved at 4:40:45 PM, on 9/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Free Download Manager\fdm.exe
C:\Program Files\ARES\Ares.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe
C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\HJT\Hijackthis\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdmcks.dll
O2 - BHO: AL2Spy Class - {DC200356-0864-4F66-8964-5D43A19300F5} - C:\WINDOWS\AUTOLO~1\AL2DLL.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [spoo1sv.exe] C:\WINDOWS\system32\spoo1sv.exe
O4 - HKLM\..\Run: [Barsaka] explorer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Free Download Manager] C:\Program Files\Free Download Manager\fdm.exe -autorun
O4 - HKCU\..\Run: [ares] "C:\Program Files\ARES\Ares.exe" -h
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - HKCU\..\Run: [Tok-Cirrhatus] "C:\Documents and Settings\Happy Dog\Local Settings\Application Data\smss.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Kodak EasyShare software.lnk.disabled
O4 - Global Startup: Kodak software updater.lnk.disabled
O4 - Global Startup: Picture Package Menu.lnk = ?
O4 - Global Startup: Picture Package VCD Maker.lnk = ?
O4 - Global Startup: Post-itŪ Software Notes Lite.lnk.disabled
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xport to Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.snapfish....fishActivia.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebo...otoUploader.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.shockwave...ploader_v10.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1DEA7153-B1F7-4EAC-85E8-2FEB1AA81D60}: NameServer = 203.187.192.12,203.187.192.15
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe



Also combofix restarted the computer in the middle of its scan


Phew (for you)

Thanks

#7 Simon V.

Simon V.

    MRU Emeritus

  • Authentic Member
  • PipPipPipPip
  • 897 posts

Posted 13 September 2007 - 09:35 AM

  • Hi :)

  • Please download the Brontok Worm Removal Tool (by sUBs) to your desktop.
    • Double-click CleanX-II.exe then follow the prompts.
    • Reboot your computer. A logfile will have been created on your desktop.
    Run Kaspersky Online Scan
  • Please do an online scan with Kaspersky WebScanner

    Click on Kaspersky Online Scanner

    You will be promted to install an ActiveX component from Kaspersky, click Yes.
    • The program will launch and then begin downloading the latest definition files:
    • Once the files have been downloaded click on NEXT
    • Now click on Scan Settings
    • In the scan settings make sure that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • The program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop, and post it here, along with the CleanX log and a new HijackThis log.


#8 Unforgiven

Unforgiven

    Authentic Member

  • Authentic Member
  • PipPip
  • 39 posts

Posted 17 September 2007 - 03:11 AM

Hi

I could not get the kaspersky scan to work, ther was a problem installing the active X

Heres the Clean X log

#######################################################################

Brontok Worm Removal Tool - (Version - 06.08.14)
by sUBs

#######################################################################

Current date: Fri 09/14/2007 Current time: 13:41:11.35

=== PRE RUN ANALYSIS ===================================

......................................

C:\WINDOWS\Tasks\At1.job
C:\Documents and Settings\Happy Dog\Local Settings\Application Data\ListHost10.txt
C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Bron.tok-10-10

...............

C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Bron.tok-10-10
C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Bron.tok-10-13
C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Bron.tok-10-14
C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Bron.tok-10-15
C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Bron.tok-10-16
C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Bron.tok-10-17
C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Bron.tok-10-18
C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Bron.tok-10-19
C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Bron.tok-10-20
C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Bron.tok-10-21
C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Bron.tok-10-22
C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Bron.tok-10-23
C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Bron.tok-10-24
C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Bron.tok-10-25
C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Bron.tok-10-27
C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Bron.tok-10-29
C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Bron.tok-10-3
C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Bron.tok-10-30
C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Bron.tok-10-31
C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Bron.tok-10-4
C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Bron.tok-10-5
C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Bron.tok-10-6
C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Bron.tok-10-7
C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Bron.tok-10-8
C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Bron.tok-10-9
C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok
C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Ok-SendMail-Bron-tok
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\aabs@ab.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\aartisinha@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\ABBAS@VERYPRODUCTION.COM.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\abedins@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\abeer.chakravarty@batesasia.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\abhi@rediff.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\accounts@travelorg.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\adbur@del3.vsnl.net.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\ADDRkadosh_shalom@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\ADDRlavs_m@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\ADDRlamiya@vmcreatives.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\ADDRnadeznas@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\ADDRnehasumitran@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\ADDRnidhimakhija1@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\ADDRradhika_sinha@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\ADDRrequestnotification@heliumexchange.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\ADDRvikram@vmcreatives.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\ADDRvikram@vmccreatives.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\advantage@interfacecom.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\advice@indastro.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\af.dsouza@cflpharma.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\a.gupta@ocs-india.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\ailgen@vsnl.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\ajay@happydog.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\ajaymakhija@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\ajeetdoshi@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\akapoor@fcbulka.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\akshat.pandya@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\akshay_bhagat@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\alamara@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\alang01@comcast.net.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\alaniswu628@msn.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\alex@hammerfilms91.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\alishka.anand@lowemail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\alok.agrawal@batesasia.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\alpajob@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\amb.bom1@sm1.sprintrpg.ems.vsnl.net.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\ameetparikh@mtnl.net.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\ameetparik@mtnl.net.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\ameetparikh@mtnk.net.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\amit.nasta@kotak.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\amitvnasta@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\amsleonardo@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\Anamika.Gupta@Pfizer.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\andrew@redwolf-asia.com.my.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\andrew@aplusfilm.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\anex@indiantelevision.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\anirban82@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\anita@travelorg.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\anki_t@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\anthemdl@nda.vsnl.net.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\anurag.hira@batesasia.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\anzak@joyridefilms.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\aparnashekar@rediffmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\arjunsathe@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\arparikh@bom4.vsnl.net.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\arparikh@vsnl.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\arrow.comp@xtzyra.co.nz.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\arsaeva@mail.ru.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\asha@travelorg.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\asha.shetty@sampark.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\ashok.vidyasagar@batesasia.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\asnanisuresh@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\asnanisuresh@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\asq.us@ericsson.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\attractions@maxi-trampoline.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\aytcllc@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\a_waris13@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\baaltod@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\babas.lucas@laposte.net.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\bane@ayvarfilms.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\bankule@aol.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\banokusev@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\beez_560@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\belarajan@sampark.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\bgstech@vsnl.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\bharat_00007@rediffmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\bhaumikvora@hsbc.co.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\bhaveshcool@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\bobshetty@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\bombaybomb@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\bounce@webmail32.rediffmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\brijeshchandrasingh@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\bsancheti@kpmg.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\buddhism@kalachakranet.org.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\c71vette@verizon.net.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\careers@sagemindia.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\camya17@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\canco@bom3.vsnl.net.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\capone_ad@rediffmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\career@rasasiperfumes.ae.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\career@akrutiestate.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\careers@akrutiestate.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\careers@arutiestate.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\Ccdutcher@aol.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\centrepoint@fcbulka.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\chadhakush@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\charissacherry@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\charsets@apple.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\chermainel@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\clb@vsnl.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\clouise@worldbank.org.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\coolshaz54@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\corporate.communications@perceptholdings.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\cstllittle@prodigy.net.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\customer.care@icicibank.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\darrace@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\DARSH74@GMAIL.COM.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\david@megginson.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\del@crayonad.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\delawarekennels12@mchsi.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\DeltaDonn08@aol.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dheeraj.sinha@batesasia.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\diak84@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\Dickerson007@aol.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dishant84@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\divya@happydog.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\divyarbatra@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@adinterax.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@112.2o7.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@112.2o7.net.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@247realmedia.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@2o7.net.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@about.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@accsatoruism.112.2o7.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@accsatoruism.112.2o7.net.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@ads.addynamix.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@adbrite.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@ads.pointroll.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@adtech.de.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@boldchat.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@bs.serving-sys.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@com.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@cs.sexcounter.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@ercva.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@franklintempleton.122.2o7.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@franklintempleton.122.2o7.net.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@gettyimages.122.2o7.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@gettyimages.122.2o7.net.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@hotlog.ru.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@insightexpressai.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@kontera.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@live365.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@livenation.122.2o7.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@livenation.122.2o7.net.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@lonelyplanet.112.2o7.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@lonelyplanet.112.2o7.net.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@metacafe.122.2o7.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@msnportal.112.2o7.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@msnportal.112.2o7.net.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@multiply.112.2o7.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@multiply.112.2o7.net.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@questionmarket.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@rambler.ru.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@rainbowmedia.122.2o7.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@rc2corp.112.2o7.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@revsci.net.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@realmedia.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@rotator.adjuggler.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@rocku.adbureau.net.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@serving-sys.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@search.live.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@snapfish.112.2o7.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@tacoda.net.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@tickle.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@tribalfusion.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@tripod.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@travelcomau.112.2o7.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@travelcomau.112.2o7.net.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@videoegg.adbureau.net.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@vodafonees.122.2o7.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@vodafonees.122.2o7.net.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@yousendit.112.2o7.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\dog@yousendit.112.2o7.net.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\donations@slsknet.org.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\ds.bose@mudra.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\eksyapim@sinekol.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\emirates@bmew.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\equusads@excite.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\equus.del@sm1.sprintrpg.ems.vsnl.net.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\eric@humanfactors.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\esmech@esmech.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\essess@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\event@exotiqueproductions.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\everest@mumbai.eicl.net.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\feyha.lokhandwala@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\fhead@giasmd01.vsnl.net.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\fhead@vsnl.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\flaviasodder@hsbc.co.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\futech@bom2.vsnl.net.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\futurebadrock9@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\GANESH.SHYAM@STUPIDANDIDIOT.COM.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\gargi@bom2.vsnl.net.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\gautam.shroff@rediffmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\gautamshroff@rediffmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\gayatri_tampi@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\gc2004@lycos.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\geetanjalijhala@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\getahead@rediff.co.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\GODU@lundbeck.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\gorw@gmx.de.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\graphisads@graphisads.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\gurmeetbalki@rediffmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\guru@khakani.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\hairsite@aol.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\hd139@aol.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\heidia@lowebull.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\hello@southwest-productions.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\help@winzyrar.de.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\helpdesk@icicidirect.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\henna@ptd.net.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\hitesh.bhatt@wipro.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\hjagwani@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\hjagwani@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\homie.fr@wanadoo.fr.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\hr001@rediffmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\hr@bhansalisteel.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\hr@hhpharma.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\hrd@goldenswan.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\hrd@jasperinternational.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\hrd@sulphurmills.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\h.souza@cflpharma.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\ibwbom@bom4.vsnl.net.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\imageads@bom2.vsnl.net.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\infodelhi@vfs-usa.co.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\infogames@maxi-trampoline.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\infokolkata@vfs-usa.co.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\infomumbai@vfs-usa.co.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\jagdishraj11@rediffmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\jdjaggs26@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\jeetu@c2info.net.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\jessica@hammerfilms91.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\jidsa786@stream.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\jobs@astutebposolutions.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\jobsmum@opiglobal.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\joe@work.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\johnryan85@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\Jules56763@aol.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\juliagulia21@aol.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\juliet.curtis@lowebull.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\jumpere85@verizon.net.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\jutturkar@rediffmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\jyoti111@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\jyotika.k@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\kadam.mahendra@rediffmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\kadosh_shalom@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\kamerad@bir.vsnl.net.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\kamlesh@cm99.net.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\kapoor@kapoorimpex.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\kaprisa@vsnl.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\karanthakkar@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\karl.bharucha@lowemail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\karlbharucha@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\kartik_lilani@rediffmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\kaushik.desai@edelcap.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\kevin@eastwestmovers.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\kiran@sampark.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\Kmadliak@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\koolkoks@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\ksbbdof@md3.vsnl.net.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\kshahsky@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\kunal.lala@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\lamiya@vmcreatives.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\lams21@rediffmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\lavs_m@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\lindsey@alumni.caltech.edu.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\lyndenzuzarte@hsbc.co.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\maabozell_bng@maabozell.co.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\madhwanijyoti@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\mahatma_bapu@nonviolence.heaven.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\mahendra_bhatia@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\mail@dirs-n-dops.de.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\maiurisold@comcast.net.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\manager@loweindia.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\manisha.awasthi@hutchindia.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\manoj28s52mehta@rediffmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\manoj30s54mehta@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\manoj30s54mehta@indiatimes.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\manoj30s54mehta1@indiatimes.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\manoj.acc@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\manoj.tapadia@lowemail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\manojtapadia@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\manosh.mukherjee@batesasia.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\marc.fd@libertysurf.fr.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\mary@home.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\maverick_aj@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\mca@mantraonline.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\mca@vsnl.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\mdmaxroy@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\mehezabin@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\mehulparekh@hsbc.co.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\membranic@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\mercuryhealth@hathway.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\mercuryhealth@vsnl.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\mf@onthanet.net.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\mike.khanna@jwt.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\mlich@razyr.cz.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\mmipl@giaspn01.vsnl.net.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\mofab@verizon.net.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\mohammed.khan@batesasia.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\monikkoticha@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\MOSTAFA@EGYPTPRODUCERS.COM.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\moulismadras@vsnl.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\mqxawaax@facebookmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\mrsabachau@peoplepc.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\msccomm@vsnl.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\mspss@gto.net.om.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\mts@lebanon-online.com.lb.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\mumbaijobs@flemingo-intl.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\myaccount@sharekhan.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\mystiquemalini@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\nadeznas@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\name_surname@mccann.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\nandinie@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\nasco@yemen.net.ye.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\neel1980in@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\nehasumitran@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\nehasumitran@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\nehhaa@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\newtekmarketing@rediffmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\nickyramnani@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\nicole@moonlighting.co.za.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\nicolemadon@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\nidhimakhija1@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\nupurg7@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\n_gurl777@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\obt.query@makemytrip.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\ok@vjmmedia.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\oliver.gu@qazyst.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\order@rarzy.com.tw.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\palraj8@rediff.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\palraj8@yaho.co.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\palraj8@rediffmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\patpu@singnet.com.sg.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\payal_85@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\peng1983127@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\percept@perceptindia.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\perceptric@indiatimes.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\pers@ho.jlmorison.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\philip@goodgate.tv.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\piyali16@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\posies86@verizon.net.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\pranks7@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\prime@seasons1.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\prithvirajb@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\privacy@agloco.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\priyasewani@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\priyu_soni@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\psc@hknet.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\purab.kohli@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\purniad@ad1.vsnl.net.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\pw@ftp.host.net.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\quadpune@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\rabane@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\radhika_sinha@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\rajeev.raja@batesasia.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\rajesh_goradia16@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\rajiv_shah71@rediffmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\raju.ghajini@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\rajvishroff@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\ramads@satyam.net.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\ramesh@e-locations.tv.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\ramseghal@contractadvertising.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\ram_r5@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\randeg@alum.rpi.edu.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\ranjit.talreja@intecbilling.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\ranjit.talreja@vgsl.co.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\ranjitkt_2004@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\raph@raph.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\r.arora@mudra.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\rashtriya_del@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\rasvaibhav@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\recruitment@khatthotal.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\recruitment@khatthotel.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\reference@maxi-trampoline.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\requestnotification@heliumexchange.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\resume@alokind.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\resumes@in.abnamro.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\Rfburo@aol.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\richadani@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\rinaldidesigns@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\rishmasingh@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\ritu_roy@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\RIYATRAVELS@VSNL.COM.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\riyaz_amlani@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\r.kagdada@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\rksbbdo@md3.vsnl.net.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\rkswamy@md2.vsnl.net.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\rlopes@tci.co.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\rohaniscool@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\roni@oceanfilms.com.br.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\ross@grinfinity.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\ruchi17@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\saina@21cn.net.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\sajil3@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\salonilakhani13@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\sam@madisonindia.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\sampsancheti@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\sanders_sms@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\sanjay.syal@talk21.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\sanjeebpatra@hsbc.co.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\saranya.roy@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\sasiadscbe@smb.sprintrpg.ems.vsnl.net.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\saurabh@happydog.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\sax@megginson.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\scoopsnalittlemore@carbonpower.net.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\screte@mtnl.net.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\sglobal@del2.vsnl.net.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\shabanadev@rediffmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\shabananavani@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\shaban_mithani@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\shah_siddharth@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\shamadalal@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\shancyn@ptd.net.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\shantanumukherji@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\sharmilasingh@hsbc.co.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\sheilarajmahtani@rediffmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\shikhamahajan@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\shivani.kulkarni@cflpharma.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\shoa_aio@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\shrnco@vsnl.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\shwetanjali@happydog.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\shyamtalreja@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\sidwas@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\sign@indastro.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\simos@greenolivefilms.gr.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\simsonsview@espnstar.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\singapore.citibankonline@citi.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\skapahi@msn.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\smartshop@moneycontrol.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\sonia@controlling.Priministerindia.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\soporte@winzyrar.com.es.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\soumitra.patnekar@contractadvertising.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\sprinky669@aol.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\ssehgal1977@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\ssomani@maproind.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\star@happydog.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\starfernandes@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\star.happydog@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\stirfried24@rediffmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\Stokerpoker@aol.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\sudha.sumitran@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\sueann@redwolf-asia.com.my.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\suezq_911@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\sunil.colourpencils@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\suryakiran@forindia.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\Talk@Rs.1.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\tandon_rashmi@rediffmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\Tasticfun@aol.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\television@vsnl.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\tempo@pisem.net.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\thevina18@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\tin_returns@nsdl.co.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\tkyik@yikkohteo.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\trbarry@trbarry.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\trikaya@tgindia.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\trilokmahadevia@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\triton@bom2.vsnl.net.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\u003c694cb7f60708141249q93d0ac7se35657bc24535e4b@mail.gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\u003csanjay.syal@talk21.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\u003cvicckeygoswami@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\uce@ftc.gov.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\ushakaal@del3.vsnl.net.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\vc.vasudeo@cflpharma.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\vicckeygoswami@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\vikram@vmcreatives.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\vikram@vmccreatives.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\virtualexorcist@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\virtual_exorcist@hotmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\vishal.talsania@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\vivek0305@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\vivek637@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\vmcrocks@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\vsbby@bom4.vsnl.net.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\waterbabyisha@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\Wilsonvillebill@aol.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\winrar@diana.dti.nezy.jp.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\yft42oy@facebookmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\yogient@bom5.vsnl.net.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\yolan@netvigator.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\zeeshan.mukhi@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\zen@publicisindia.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\_tasklist_divya@happydog.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\_upro_b.venky@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\_upro_alpa.jobalia@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\_upro_alishka.anand@lowemail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\_upro_noreply@wobs.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\_upro_ajay@happydog.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\_upro_Alpa_Jobalia@ind.dyr.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\_upro_manoj28s52mehta@rediffmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\_upro_invitation@whereareyounow.net.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\_upro_janani.ravichandran@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\_upro_virtualexorcist@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\_upro_geetanjalijhala@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\_upro_nehasumitran@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\_upro_dilippatne.patne@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\_upro_soumitrapatnekar@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\_upro_invite@facebook.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\_upro_staffan@tiaraholdings.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\_upro_emailkaps@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\_upro_juhishekhar@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\_upro_Campaigns@monster.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\_upro_upasana.keswani@agilisys.co.uk.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\_upro_divya@happydog.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\_upro_doctor@dictionary.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\_upro_alibaba@email.alibaba.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\_upro_tagged@taggedmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\_upro_invitations@shelfari.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\_upro_star@happydog.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\_upro_fred54g@hotmail.fr.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\_upro_umeta@ms48.hinet.net.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\_upro_prahalad@emirates.net.ae.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\_upro_harsh540@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\_upro_ajay_gurnani@indiainfo.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\_upro_18101258919626943417@mail.orkut.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\_upro_star.happydog@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\_upro_bappapics@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\_upro_alishkaanand@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\_upro_enigma.filmproductions@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\_upro_mileagestatement@jp.jetairways.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\_upro_invites@travbuddy.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\_upro_ajaymakhija@gmail.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\_upro_ameetparikh@mtnl.net.in.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\_upro_hr@imageil.com.ini"
"C:\Documents and Settings\Happy Dog\Local Settings\Application Data\Loc.Mail.Bron.Tok\_upro_ujala20@hotmail.com.ini"


=== POST RUN ANALYSIS ==================================



NOTE
The post-run analysis portion should be empty. If it's not, reboot and run the tool a second time.

======================================================




HJT LOG



Logfile of HijackThis v1.99.1
Scan saved at 2:38:26 PM, on 9/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Free Download Manager\fdm.exe
C:\Program Files\ARES\Ares.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Common Files\Symantec Shared\NMain.exe
C:\PROGRA~1\NORTON~1\navw32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\HJT\Hijackthis\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdmcks.dll
O2 - BHO: AL2Spy Class - {DC200356-0864-4F66-8964-5D43A19300F5} - C:\WINDOWS\AUTOLO~1\AL2DLL.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [spoo1sv.exe] C:\WINDOWS\system32\spoo1sv.exe
O4 - HKLM\..\Run: [Barsaka] explorer.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Free Download Manager] C:\Program Files\Free Download Manager\fdm.exe -autorun
O4 - HKCU\..\Run: [ares] "C:\Program Files\ARES\Ares.exe" -h
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Kodak EasyShare software.lnk.disabled
O4 - Global Startup: Kodak software updater.lnk.disabled
O4 - Global Startup: Picture Package Menu.lnk = ?
O4 - Global Startup: Picture Package VCD Maker.lnk = ?
O4 - Global Startup: Post-itŪ Software Notes Lite.lnk.disabled
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xport to Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.snapfish....fishActivia.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebo...otoUploader.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.shockwave...ploader_v10.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1DEA7153-B1F7-4EAC-85E8-2FEB1AA81D60}: NameServer = 203.187.192.12,203.187.192.15
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe




Thanks

Aj

#9 Simon V.

Simon V.

    MRU Emeritus

  • Authentic Member
  • PipPipPipPip
  • 897 posts

Posted 17 September 2007 - 09:19 AM

  • Hi :)

    P2P Warning
  • I understand that downloading music and other files may be important to you; however, the P2P programs that you are using to do that, even if they are not infected with malware, will bring malware into your system. Therefore, the chances of you becoming infected again are very high. This obviously can result in disabling your computer and could even lead to someone stealing sensitive personal data from your computer. Beyond the inconvenience this causes you, these programs also tend to use your computer as a server to spread more infection all over the internet, so your computer becomes a part of the malware problem.

    Remember that no matter how clean the program you're using for Peer-to-Peer filesharing may be, it offers no guarantees regarding the cleanliness of files you may choose to download. All files available via P2P filesharing carry a high risk, particularly those that offer you illegitimate methods of using legitimate software programs without paying for them. Any program or file that offers you the ability to access non-freeware programs at no cost, e.g., pirated software and/or cracks/key generators for gaining access to legitimate software, is 100% guaranteed to contain malware.

    Here is some information that looks at the rates of infection:

    http://www.benedelman.org/spyware/p2p/

    With that being said, I recommend that you remove the following P2P program(s):

    Ares
    BitTorrent


    Combofix
  • Open Notepad, and copy/paste the text in the quotebox below into it:

    File::
    
    C:\WINDOWS\explorer.exe
    C:\Documents and Settings\Happy Dog\Local Settings\Application Data\smss.exe
    H:\fooool.exe
    
    Registry::
    
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "spoo1sv.exe"=-
    "Barsaka"=-
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Tok-Cirrhatus"=-
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dbe97ae6-5c71-11dc-b793-00a1b0a15a24}]
  • Save this as "CFScript".

    Posted Image
  • Referring to the picture above, drag CFScript into ComboFix.exe.
  • It will create a log. Be sure to save it to a convenient location.

    F-Secure Online Scan
  • Note: You will need to use Internet explorer for this scan.
  • Go here to run an online scan from F-Secure.
  • Click on Start scanning.
  • This will open a new internet explorer window.
  • It will require an activex control, please install it.
  • Click Accept.
  • Click Full System Scan.
  • It will now download the scanner, this may take a while, please be patient.
  • It will then start scanning, wait for the scan to finish.
  • Click Automatic cleaning (recommended).
  • Wait for it finish the cleaning process.
  • Click show report.
  • This will open up a window with the results of the scan, copy and paste those results as a reply to this topic, along with the Combofix log and a new HijackThis log. Also tell me how everything is working.


#10 Unforgiven

Unforgiven

    Authentic Member

  • Authentic Member
  • PipPip
  • 39 posts

Posted 20 September 2007 - 05:56 AM

Hi,

Ive deleted Ares and Bit Torrent
I have a problem with the Fsecure scan as well, it gets to the downloading components
but keeps resetting, Ive tried it -5-6 times now, and it takes a whle gets to 17mb out of 28mb and
then asks me to retry.


The Combofix log is



ComboFix 07-09-10.6 - "Happy Dog" 2007-09-20 16:38:19.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.520 [GMT 5.5:30]
* Created a new restore point

FILE::
C:\Documents and Settings\Happy Dog\Local Settings\Application Data\smss.exe
H:\fooool.exe
.

((((((((((((((((((((((((( Files Created from 2007-08-20 to 2007-09-20 )))))))))))))))))))))))))))))))
.

2007-09-20 14:38 <DIR> d-------- C:\WINDOWS\LastGood
2007-09-14 17:42 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
2007-09-14 15:19 <DIR> d-------- C:\Program Files\Homestead
2007-09-14 14:16 <DIR> d-------- C:\Program Files\SymNetDrv
2007-09-14 13:38 4,608 --a------ C:\WINDOWS\system32\drivers\symlcbrd.sys
2007-09-14 13:38 <DIR> d-------- C:\Program Files\Norton AntiVirus
2007-09-14 13:37 91,904 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2007-09-14 13:37 124,016 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-09-14 13:37 <DIR> d-------- C:\Program Files\Symantec
2007-09-14 13:37 <DIR> d-------- C:\DOCUME~1\HAPPYD~1\APPLIC~1\Symantec
2007-09-13 16:28 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-09-13 15:43 <DIR> d-------- C:\WINDOWS\ERUNT
2007-09-13 15:40 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Free Download Manager
2007-08-20 16:25 14 --a------ C:\WINDOWS\popcinfot.dat
2007-08-20 16:25 0 --a------ C:\WINDOWS\popcreg.dat
2007-08-20 16:25 <DIR> d-------- C:\Program Files\PopCap Games

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-20 16:37 --------- d-------- C:\DOCUME~1\HAPPYD~1\APPLIC~1\Free Download Manager
2007-09-19 15:28 --------- d-------- C:\DOCUME~1\HAPPYD~1\APPLIC~1\Canon
2007-09-18 12:24 --------- d-------- C:\Program Files\Common Files\Symantec Shared
2007-09-14 13:53 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
2007-09-12 13:33 --------- d-------- C:\DOCUME~1\HAPPYD~1\APPLIC~1\BPFTP
2007-09-12 13:31 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-09-12 13:29 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ulead Systems
2007-09-07 14:56 --------- d-------- C:\Program Files\Soulseek
2007-08-09 14:19 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\PopCap
2007-07-31 22:24 --------- d-------- C:\DOCUME~1\HAPPYD~1\APPLIC~1\Skype
2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 43352 --a------ C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll
2006-03-13 11:11:19 0 --sha-w C:\WINDOWS\NT.Config`.exe
.

((((((((((((((((((((((((((((( snapshot_2007-09-13_163823.43 )))))))))))))))))))))))))))))))))))))))))
.
----a-w 500,120 2007-05-07 11:08:46 C:\WINDOWS\Downloaded Program Files\daas_s.dll
----a-w 192,920 2007-05-07 11:09:00 C:\WINDOWS\Downloaded Program Files\fsauc.dll
----a-w 254,360 2007-05-07 11:09:24 C:\WINDOWS\Downloaded Program Files\fscax.dll
----a-r 10,134 2007-09-14 08:09:03 C:\WINDOWS\Installer\{77772678-817F-4401-9301-ED1D01A8DA56}\ARPPRODUCTICON.exe
----a-w 466,944 2006-07-25 12:33:42 C:\WINDOWS\system32\capicom.dll
----a-w 517,848 2007-03-28 13:11:32 C:\WINDOWS\system32\SymNeti.dll
----a-w 132,824 2007-03-28 13:11:28 C:\WINDOWS\system32\SymRedir.dll
----a-w 11,480 2007-03-28 13:11:12 C:\WINDOWS\system32\drivers\symdns.sys
----a-w 171,928 2007-03-28 13:11:14 C:\WINDOWS\system32\drivers\symfw.sys
----a-w 37,016 2007-03-28 13:11:20 C:\WINDOWS\system32\drivers\symids.sys
----a-w 47,192 2007-03-28 13:11:18 C:\WINDOWS\system32\drivers\symndis.sys
----a-w 18,904 2007-03-28 13:11:24 C:\WINDOWS\system32\drivers\symredrv.sys
----a-w 266,552 2007-03-28 13:11:26 C:\WINDOWS\system32\drivers\symtdi.sys
----a-w 213,048 2005-05-24 05:57:16 C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
----a-w 94,208 2007-09-07 05:59:00 C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
----a-w 946,176 2007-09-07 05:59:00 C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
.
----a-w 466,944 2005-03-31 12:02:24 C:\WINDOWS\system32\capicom.dll
-c--a-w 213,048 2005-05-16 14:04:48 C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
----a-w 65,536 2006-03-20 07:47:24 C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
-c--a-w 798,720 2006-03-20 07:47:20 C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.

*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2005-10-15 07:21 C:\WINDOWS\RTHDCPL.EXE]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 19:42]
"Omnipage"="C:\Program Files\ScanSoft\OmniPageSE\opware32.exe" [2002-06-03 11:38]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 13:03]
"Zone Labs Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2006-08-23 23:38]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 17:32]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2007-09-14 14:16]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:26]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54]
"Free Download Manager"="C:\Program Files\Free Download Manager\fdm.exe" [2006-08-21 00:24]
"ares"="C:\Program Files\ARES\Ares.exe" []
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45]
"BitTorrent"="C:\Program Files\BitTorrent\bittorrent.exe" []

C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-03-13 12:36:19]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 11:35:26]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 04:21:22]
Kodak EasyShare software.lnk.disabled [2006-12-04 10:56:45]
Kodak software updater.lnk.disabled [2006-12-04 11:00:35]
Picture Package Menu.lnk - C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe [2006-12-25 18:58:55]
Picture Package VCD Maker.lnk - C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe [2006-12-25 18:58:52]
Post-itr Software Notes Lite.lnk.disabled [2006-10-18 15:09:02]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
"ares"="C:\Program Files\ARES\Ares.exe" -h

R1 XPROTECTOR;XPROTECTOR;\??\C:\WINDOWS\system32\drivers\Oreans.sys
R3 RMSPPPOE;WAN Miniport (PPP over Ethernet Protocol);C:\WINDOWS\system32\DRIVERS\RMSPPPOE.SYS
S3 sonypvs1;Sony Digital Imaging Video2;C:\WINDOWS\system32\DRIVERS\sonypvs1.sys


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
AutoRun\command- H:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5c9662ed-b33d-11da-b495-001320e49d03}]
AutoRun\command- RavMon.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{61f21625-f47d-11db-b6d0-00a1b0a15a24}]
AutoRun\command- H:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a56c8da0-ee35-11db-b6bd-00a1b0a15a24}]
Auto\command- H:\MicrosoftPowerPoint.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL MicrosoftPowerPoint.exe

.
Contents of the 'Scheduled Tasks' folder
"2007-06-24 04:31:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
"2007-09-14 08:28:22 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - Happy Dog.job"
- C:\PROGRA~1\NORTON~1\Navw32.exe
.
**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-20 16:39:56
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-09-20 16:40:37
C:\ComboFix-quarantined-files.txt ... 2007-09-20 16:40
C:\ComboFix2.txt ... 2007-09-13 16:38
C:\ComboFix3.txt ... 2006-12-11 15:59
.
--- E O F ---



HJT log



Logfile of HijackThis v1.99.1
Scan saved at 5:22:25 PM, on 9/20/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Free Download Manager\fdm.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Norton AntiVirus\OPScan.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\HJT\Hijackthis\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdmcks.dll
O2 - BHO: AL2Spy Class - {DC200356-0864-4F66-8964-5D43A19300F5} - C:\WINDOWS\AUTOLO~1\AL2DLL.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Free Download Manager] C:\Program Files\Free Download Manager\fdm.exe -autorun
O4 - HKCU\..\Run: [ares] "C:\Program Files\ARES\Ares.exe" -h
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Kodak EasyShare software.lnk.disabled
O4 - Global Startup: Kodak software updater.lnk.disabled
O4 - Global Startup: Picture Package Menu.lnk = ?
O4 - Global Startup: Picture Package VCD Maker.lnk = ?
O4 - Global Startup: Post-itŪ Software Notes Lite.lnk.disabled
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xport to Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-sec...m/ols/fscax.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.snapfish....fishActivia.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebo...otoUploader.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.shockwave...ploader_v10.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1DEA7153-B1F7-4EAC-85E8-2FEB1AA81D60}: NameServer = 203.187.192.12,203.187.192.15
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe




Thanks

#11 Simon V.

Simon V.

    MRU Emeritus

  • Authentic Member
  • PipPipPipPip
  • 897 posts

Posted 20 September 2007 - 11:43 AM

  • Hi :)

    That’s looking better.

  • Does your Norton installation have a Firewall? Please tell me in your next reply.

    Fix Entries with HijackThis
  • Open HijackThis, perform a scan and put a check next to the following items (if present):

    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.shockwave...ploader_v10.cab

    Close all programs except HijackThis and click on Fix checked.

    ATF Cleaner
  • Please download ATF Cleaner.

    Double-click on ATF-Cleaner.exe to start the program.
    Under the Main tab, put a check next to 'Select All'.
    Click the 'Empty Selected' button. (Note: if you select cookies, automated login at forums and sites will be disabled. If you do not want this, uncheck 'Cookies')

    If you use the Firefox browser:
    Click on Firefox at the top and put a check next to 'Select All'.
    If you would like to keep your saved passwords, click No at the prompt.
    Click the 'Empty Selected' button. (Note: if you select cookies, automated login at forums and sites will be disabled. If you do not want this, uncheck 'Cookies').

    If you use the Opera browser:
    Click on Opera at the top and put a check next to 'Select All'.
    If you would like to keep your saved passwords, click No at the prompt.
    Click the 'Empty Selected' button. (Note: if you select cookies, automated login at forums and sites will be disabled. If you do not want this, uncheck 'Cookies')

    AVG Anti-Spyware
  • Please download and install AVG Anti-Spyware.

    After the installation, open AVG Anti-Spyware and do the following:
  • Under 'Status', click on Change state, next to 'Resident shield' (this will change from Active to Inactive)
  • Under the 'Update' tab, click on 'Start update'.
  • Under 'Scanner', click on the 'Settings' tab:
  • Under 'How to act?', click on 'Recommended actions', and select Quarantine.
  • Under 'Reports', select 'Do not automatically generate reports'.
Close AVG Anti-Spyware. Do not let it scan yet.

Safe Mode

[*]Print these instructions or copy them to Notepad and save it to your desktop, as you won't be able to access internet in Safe Mode.

[*]Please reboot into Safe Mode. To do this, go to Start>Turn off Computer, and select Restart. Rapidly tap F8 just before Windows starts to load. In the menu that appears, select Safe Mode (Without Networking)

AVG Anti-Spyware

[*]Please open AVG Anti-Spyware.
  • Click on the 'Scan' tab.
  • Click on 'Complete System Scan' to start the scan process.
  • After the scan, do the following:Important: Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
  • Make sure that Set all elements to: shows Quarantine (1), if not, click on the link and select 'Quarantine' from the popup menu. (2)
  • At the bottom of the window click on the Apply all Actions button. (3)
  • When done, click the 'Save Report' (4) button, and save the file to your desktop.
Posted Image.

[*]Reboot into Normal Mode.

Update Java

[*]Your Java software is out of date. Follow these instructions to update it:
  • Go to Start and click on Control Panel, then double-click on Add or Remove Programs.
  • Search for previously installed versions of Java (J2SE Runtime Environment), and remove it. It should have this icon next to it: Posted Image
  • Then download and install Java Runtime Environment Version 6u2.
Report Back

[*]Please post the report from AVG Anti-Spyware, along with a new HijackThis log in your next reply. Also tell me how everything is working, and answer my question about Norton.
[/list]

#12 Unforgiven

Unforgiven

    Authentic Member

  • Authentic Member
  • PipPip
  • 39 posts

Posted 21 September 2007 - 05:03 AM

Hi

No I dont have norton firewall, but zone alarm firewall.
Comp is working fine, earlier my download speed had gone really low, but now its back to high
AVG found traces of all the big viruses again tho.

Heres the AVG log

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 3:40:47 PM 9/21/2007

+ Scan result:



C:\System Volume Information\_restore{85E1D03A-A684-4D97-AD5B-9C49F076514C}\RP420\A0157775.exe -> Trojan.ShipUp.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{85E1D03A-A684-4D97-AD5B-9C49F076514C}\RP420\A0157776.exe -> Trojan.ShipUp.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{85E1D03A-A684-4D97-AD5B-9C49F076514C}\RP420\A0157777.exe -> Trojan.ShipUp.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{85E1D03A-A684-4D97-AD5B-9C49F076514C}\RP420\A0157744.exe -> Trojan.Tiny.e : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{85E1D03A-A684-4D97-AD5B-9C49F076514C}\RP427\A0159198.exe -> Trojan.Tiny.e : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{85E1D03A-A684-4D97-AD5B-9C49F076514C}\RP427\A0159204.exe -> Trojan.Tiny.e : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{85E1D03A-A684-4D97-AD5B-9C49F076514C}\RP420\A0157745.exe -> Worm.Brontok.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{85E1D03A-A684-4D97-AD5B-9C49F076514C}\RP420\A0157746.exe -> Worm.Brontok.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{85E1D03A-A684-4D97-AD5B-9C49F076514C}\RP420\A0157747.exe -> Worm.Brontok.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{85E1D03A-A684-4D97-AD5B-9C49F076514C}\RP420\A0157748.exe -> Worm.Brontok.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{85E1D03A-A684-4D97-AD5B-9C49F076514C}\RP420\A0157749.exe -> Worm.Brontok.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{85E1D03A-A684-4D97-AD5B-9C49F076514C}\RP420\A0157750.exe -> Worm.Brontok.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{85E1D03A-A684-4D97-AD5B-9C49F076514C}\RP420\A0157751.pif -> Worm.Brontok.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{85E1D03A-A684-4D97-AD5B-9C49F076514C}\RP420\A0157752.com -> Worm.Brontok.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{85E1D03A-A684-4D97-AD5B-9C49F076514C}\RP420\A0157753.scr -> Worm.Brontok.a : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{85E1D03A-A684-4D97-AD5B-9C49F076514C}\RP420\A0157754.exe -> Worm.Brontok.a : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{85E1D03A-A684-4D97-AD5B-9C49F076514C}\RP420\A0157755.exe -> Worm.Brontok.a : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{85E1D03A-A684-4D97-AD5B-9C49F076514C}\RP420\A0157756.exe -> Worm.Brontok.a : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{85E1D03A-A684-4D97-AD5B-9C49F076514C}\RP420\A0157757.exe -> Worm.Brontok.a : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{85E1D03A-A684-4D97-AD5B-9C49F076514C}\RP420\A0157758.exe -> Worm.Brontok.a : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{85E1D03A-A684-4D97-AD5B-9C49F076514C}\RP420\A0157759.exe -> Worm.Brontok.a : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{85E1D03A-A684-4D97-AD5B-9C49F076514C}\RP420\A0157760.exe -> Worm.Brontok.a : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{85E1D03A-A684-4D97-AD5B-9C49F076514C}\RP420\A0157761.exe -> Worm.Brontok.a : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{85E1D03A-A684-4D97-AD5B-9C49F076514C}\RP420\A0157762.exe -> Worm.Brontok.a : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{85E1D03A-A684-4D97-AD5B-9C49F076514C}\RP420\A0157763.exe -> Worm.Brontok.a : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{85E1D03A-A684-4D97-AD5B-9C49F076514C}\RP420\A0157764.exe -> Worm.Brontok.a : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{85E1D03A-A684-4D97-AD5B-9C49F076514C}\RP420\A0157765.exe -> Worm.Brontok.a : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{85E1D03A-A684-4D97-AD5B-9C49F076514C}\RP420\A0157766.exe -> Worm.Brontok.a : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{85E1D03A-A684-4D97-AD5B-9C49F076514C}\RP420\A0157767.exe -> Worm.Brontok.a : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{85E1D03A-A684-4D97-AD5B-9C49F076514C}\RP420\A0157768.exe -> Worm.Brontok.a : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{85E1D03A-A684-4D97-AD5B-9C49F076514C}\RP420\A0157769.exe -> Worm.Brontok.a : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{85E1D03A-A684-4D97-AD5B-9C49F076514C}\RP420\A0157770.exe -> Worm.Brontok.a : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{85E1D03A-A684-4D97-AD5B-9C49F076514C}\RP420\A0157771.exe -> Worm.Brontok.a : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{85E1D03A-A684-4D97-AD5B-9C49F076514C}\RP420\A0157772.exe -> Worm.Brontok.a : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{85E1D03A-A684-4D97-AD5B-9C49F076514C}\RP420\A0157773.exe -> Worm.Brontok.a : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{85E1D03A-A684-4D97-AD5B-9C49F076514C}\RP420\A0157774.exe -> Worm.Brontok.a : Cleaned with backup (quarantined).


::Report end





HJT log



Logfile of HijackThis v1.99.1
Scan saved at 4:18:39 PM, on 9/21/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Free Download Manager\fdm.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\msiexec.exe
C:\HJT\Hijackthis\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdmcks.dll
O2 - BHO: AL2Spy Class - {DC200356-0864-4F66-8964-5D43A19300F5} - C:\WINDOWS\AUTOLO~1\AL2DLL.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Free Download Manager] C:\Program Files\Free Download Manager\fdm.exe -autorun
O4 - HKCU\..\Run: [ares] "C:\Program Files\ARES\Ares.exe" -h
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Kodak EasyShare software.lnk.disabled
O4 - Global Startup: Kodak software updater.lnk.disabled
O4 - Global Startup: Picture Package Menu.lnk = ?
O4 - Global Startup: Picture Package VCD Maker.lnk = ?
O4 - Global Startup: Post-itŪ Software Notes Lite.lnk.disabled
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xport to Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.snapfish....fishActivia.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebo...otoUploader.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1DEA7153-B1F7-4EAC-85E8-2FEB1AA81D60}: NameServer = 203.187.192.12,203.187.192.15
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe





Thanks!
aj

#13 Simon V.

Simon V.

    MRU Emeritus

  • Authentic Member
  • PipPipPipPip
  • 897 posts

Posted 22 September 2007 - 04:16 AM

  • Hi :)

    Fix Entries with HijackThis
  • Open HijackThis, perform a scan and put a check next to the following items (if present):

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    Close all programs except HijackThis and click on Fix checked.

    Prevention
  • Congratulations, your log looks clean. Please advise of any problems you are still experiencing, or follow these simple steps to keep your computer clean in the future:
    • Delete Tools - You can now delete the following files/folders:
      • Combofix.exe, C:\qoobox\, and all the logs it has created (C:\ComboFix.txt, C:\ComboFix2.txt, etc.)
      • SDFix.exe, C:\SDFix\
      • CleanX-II.exe
    • Disable and Enable System Restore - If you are using Windows ME or XP then you should disable and re-enable system restore to make sure there are no infected files found in a restore point.
      • Turn off System Restore.
      • On the desktop, right-click My Computer
      • Click Properties
      • Click the System Restore tab
      • Check Turn off System Restore
      • Click Apply, and then click OK
      • Reboot.
      • Turn on System Restore.
      • On the desktop, right-click My Computer
      • Click Properties
      • Click the System Restore tab
      • Uncheck Turn off System Restore
      • Click Apply, and then click OK
      NOTE: only do this ONCE, NOT on a regular basis!
    • Make your Internet Explorer more secure
      • From within Internet Explorer click on the Tools menu and then click on Options.
      • Click once on the Security tab.
      • Click once on the Internet icon so it becomes highlighted.
      • Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt.
      • Change the Download unsigned ActiveX controls to Disable.
      • Change the Initialise and script ActiveX controls not marked as safe to Disable.
      • Change the Installation of desktop items to Prompt.
      • Change the Launching programs and files in an IFRAME to Prompt.
      • Change the Navigate sub-frames across different domains to Prompt.
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Update your Anti-Virus Software - It is very imprtant that you update your Anti-Virus software at least once a week (even more if you wish). If you do not update your Anti-Virus software then it will not be able to catch any of the new variants that may come out.
  • Visit Microsoft's Update Site Frequently - It is important that you visit http://update.microsoft.com/ regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
  • Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option.
    This will provide real-time spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an anti virus software. A tutorial on installing & using this product can be found here:
    Instructions for - Spybot S & D and Ad-aware
  • Install Ad-Aware - Install and download Ad-Aware. You should also scan your computer with the program on a regular basis just as you would an anti virus software in conjunction with Spybot. A tutorial on installing & using this product can be found here:
    Instructions for - Spybot S & D and Ad-aware
  • Install SpywareBlaster - SpywareBlaster will add a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs. An article on anti-malware products with links for this program and others can be found here:
    Computer Safety on line - Anti-Malware
  • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.

    Follow this list and your potential for being infected again will reduce dramatically.
  • Stand Up and Be Counted!

    Please take the time to tell us what you would like to be done about the people who are behind all the problems you have had. We can only get something done about this if the people that we help, like you, are prepared to complain. We have a dedicated forum for collecting these complaints Malware Complaints, you have to be registered to post after registering just find your country room and register your complaint.
    The infection you had was the Brontok worm.


#14 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 24 September 2007 - 05:47 PM

Since this issue appears to be resolved ... this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 

Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users