This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] A Lovely Computer in Distress

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi there…
I have been experiencing pop-ups for quite a while now and would much appreciate some help to get rid of them. This is the first time I've posted on this forum. It's probably worth mentioning that I did have Kazaa installed at one point but removed it using the method in this tutorial: http://www.pchell.com/support/kazaa.shtml
It didn't really work all too well because I can still see fragments of the p2p networking and bulldog every now and again. There's one entry in hiJackThis I'm particularly suspecious of (though I'm speaking out of my depth here) which I have highlighted in red in the entry.

Thanks for any help


My HijackThis Log:

Logfile of HijackThis v1.99.1
Scan saved at 13:32:15, on 07/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\AvidSDMService.exe
C:\Program Files\Kontiki\KService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Tablet.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\WTablet\TabUserW.exe
C:\WINDOWS\system32\Tablet.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Kontiki\KHost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\NETGEAR\WPN111\wpn111.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
X:\Junk\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: NETGEAR WPN111 Smart Wizard.lnk = ?
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Avid SDM Service (AvidSDMService) - Avid Technology, Inc. - C:\WINDOWS\system32\AvidSDMService.exe
O23 - Service: Avid Startup (AvidStartup) - Unknown owner - C:\WINDOWS\system32\AvidStartup.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Common Files\Sonic Shared\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Common Files\Sonic Shared\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
_________________________________
Welcome to the Forums.

The fixes we will use are specific to your problems and should only be used for this issue on this machine.

Please only use this topic to reply to. Do not start another thread.
If any other issues arise let me know.
The process is not instant. Please continue to review my answers until I tell you your machine is clear. Absence of symptoms does not mean that everything is clear. So lets do this to the end!
  • All hijackthis logs I ask for should be done in normal mode ( not safe mode)
  • These logs should be done last after you have followed my instructions in the previous post.


Please if you decide to seek help at another forum let us know. There is a shortage of helpers and tying 2 of us up is a waste of time.
If you have any questions about any advice given here please STOP and ask!


______________________
Rename Hijackthis.exe:
Right click on hijackthis.exe and choose rename:
Rename it to noname:




____________________
Please download VundoFix.exe to your desktop.
Double-click VundoFix.exe to run it.
Click the Scan for Vundo button.
Once it's done scanning, click the Remove Vundo button.
You will receive a prompt asking if you want to remove the files, click YES
Once you click yes, your desktop will go blank as it starts removing Vundo.
When completed, it will prompt that it will shutdown your computer, click OK.
Turn your computer back on.
Please post the contents of C:\vundofix.txt and a new HiJackThis log.


_________________________
In your next reply I would like to see:
  • A new HJT log
  • The report from VundoFix
Hi there,

Thanks for the quick response - i really appreciate what you guys are doing.

I did everything you told me to. The vundo scan didn't show any infections so it didn't prompt me to restart. But I have run a new HiJackThis (noname) and copied the VunoFix.txt for you to see. It's probably worth mentioning that there were a few other attempts at removal I tried after posting my first topic here (before your reply) which did rid me of a couple of lines in my hHiJackThis log. But the popup problem still remains.

Here are the logs:

HIJACKTHIS:
==========

Logfile of HijackThis v1.99.1
Scan saved at 16:44:29, on 08/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\AvidSDMService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Tablet.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\NETGEAR\WPN111\wpn111.exe
C:\WINDOWS\system32\WTablet\TabUserW.exe
C:\WINDOWS\system32\Tablet.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HijackThis\noname.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: NETGEAR WPN111 Smart Wizard.lnk = ?
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Avid SDM Service (AvidSDMService) - Avid Technology, Inc. - C:\WINDOWS\system32\AvidSDMService.exe
O23 - Service: Avid Startup (AvidStartup) - Unknown owner - C:\WINDOWS\system32\AvidStartup.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe

VUNDOFIX:
=========

VundoFix V6.5.10

Checking Java version…

Java version is 1.5.0.3
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.4
Old versions of java are exploitable and should be removed.

Scan started at 16:35:19 08/11/2007

Listing files found while scanning….

No infected files were found.


Beginning removal…

VundoFix V6.5.10

Checking Java version…

Java version is 1.5.0.3
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.4
Old versions of java are exploitable and should be removed.

Scan started at 16:37:41 08/11/2007

Listing files found while scanning….

No infected files were found.


Beginning removal…

=====================

Thanks again for the help,
Jack
Strange .. The type of infection I thought you have hides certain lines from us. I didn't see any of those lines and assumed you had a vundo infection. Renaming HJT let's us see those lines. Apparently I may have assumed wrong. :blush:

__________________________




______________________________

Download and install CCleaner from here


If you use either the Firefox or Mozilla browsers, the box to uncheck for Cookies is on the Applications tab, under Firefox/Mozilla.
  • Set Cookie Retention.
    Click on the Options block on the left, then choose Cookies.
    Under the Cookies to delete pane, highlight any cookies you would like to retain permanently (those companies or sites with which you regularly visit or do business), and click the right arrow > to move them to the Cookies to keep pane.
  • Reset Temp File Removal for Regular Use.
    Click on the Options block on the left. Select the Advanced button.
    Check "Only delete files in Windows Temp folders older than 48 hours".


    Now run the program and click on Run Cleaner
    ( Do not use the Registry function to clean anything with this program. Having anything auto clean your regisrty is risky).

AVG Anti-Spyware:
________________________________________
Download the trial version of AVG Anti-Spyware from here and install it. When the program has been installed, and you click the Finish button, AVG Anti-Spyware will open. Do not run a scan yet.

If the program does not automatically update itself during installation, or you are unsure whether it has done so, please do the following:
  • Click the Update icon at the top and under Manual Update click the Start update button.
  • The program will either update or inform you that no update was available.
  • It is essential that you get the update - keep trying until successful. (Note: If you have problems getting the update, you can download an installer for the full database from here (save it on your desktop). Once you have downloaded the installer, make sure that AVG Anti-Spyware is closed and then double-click on avgas-signatures-full-current.exe to install the database).



    Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
  • Open up AVG anti Malware
Please set up the program as follows:
  • Click the Shield icon at the top and under Resident shield is… click active. This should now change to inactive.
  • Click the Update icon and untick the automatic update option.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
  • Under How to act? - make sure that Quarantine is selected.
  • Under How to scan? - All checkboxes should be ticked.
  • Under Possibly unwanted software - All checkboxes should be ticked.
  • Under Reports - Select Do not automatically generate reports.
  • Under What to scan? - Select Scan every file.
Close all open windows.
  • Click on Scanner on the toolbar.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan your computer.
  • When the scan has finished, follow the instructions below:
  • Make sure that Set all elements to: shows Quarantine
  • Important: Click on the Apply all Actions button (*** This must done before saving the report ***)
  • When the program has finished, it will display the message All actions have been applied.
  • Then click the Save Scan Report button.
  • Click the Save Report as button.
  • Save the report to your Desktop.
  • Right-click the AVG Tray Icon and select Exit.
  • Reboot in normal mode.
___________________________________________




1. Download Combo fix from one of these locations.
http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply . (c:\comboFix.txt)

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall



_________________________
In your next reply I would like to see:
  • A new HJT log
  • The report from ComboFix
Hey there,

thanks again for this. It's probably worth mentioning that while the comboFix scan was running there were a few threat detects by AVG - I chose the option to 'move to vault' when each one came up. I remember them being .dll files. Here are the logs you asked for:

HIJACKTHIS:
==========

Logfile of HijackThis v1.99.1
Scan saved at 03:17:03, on 09/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\AvidSDMService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Tablet.exe
C:\WINDOWS\system32\WTablet\TabUserW.exe
C:\WINDOWS\system32\Tablet.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\NETGEAR\WPN111\wpn111.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\HijackThis\noname.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: NETGEAR WPN111 Smart Wizard.lnk = ?
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Avid SDM Service (AvidSDMService) - Avid Technology, Inc. - C:\WINDOWS\system32\AvidSDMService.exe
O23 - Service: Avid Startup (AvidStartup) - Unknown owner - C:\WINDOWS\system32\AvidStartup.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe

COMBOFIX:
==========

ComboFix 07-11-08.1 - Administrator 2007-11-09 3:13:36.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.44.1033.18.1614 [GMT 0:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\pack.epk
C:\WINDOWS\system32\holwkj.dat
c:\windows\system32\holwkj.exe
C:\WINDOWS\system32\holwkj_nav.dat
C:\WINDOWS\system32\holwkj_navps.dat
C:\WINDOWS\system32\media
C:\WINDOWS\system32\media\AvidRender.wav
C:\WINDOWS\system32\nvs2.inf

.
((((((((((((((((((((((((( Files Created from 2007-10-09 to 2007-11-09 )))))))))))))))))))))))))))))))
.

2007-11-09 03:12 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-11-09 02:22 d——– C:\Documents and Settings\Administrator\Application Data\Grisoft
2007-11-09 02:21 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-11-08 16:35 d——– C:\VundoFix Backups
2007-11-07 16:10 d——– C:\Program Files\Lavasoft
2007-11-07 12:32 d——– C:\Program Files\jv16 PowerTools 2007
2007-11-07 12:32 23 –ahs—- C:\WINDOWS\system32\febddcdadca_r.dll
2007-11-06 13:26 d——– C:\Program Files\Native Instruments
2007-11-02 01:22 d——– C:\Program Files\Kontiki
2007-11-02 01:22 d——– C:\Program Files\Channel4
2007-11-02 01:21 d——– C:\Documents and Settings\All Users\Application Data\Channel4
2007-10-26 04:33 584,192 —–c— C:\WINDOWS\system32\dllcache\rpcrt4.dll
2007-10-25 23:45 d——– C:\Program Files\iTunes

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-09 03:10 ——— d—–w C:\Documents and Settings\Administrator\Application Data\WTablet
2007-11-09 02:25 ——— d—–w C:\Documents and Settings\Administrator\Application Data\uTorrent
2007-11-09 02:03 ——— d—–w C:\Documents and Settings\Administrator\Application Data\AVG7
2007-11-08 14:31 ——— d—–w C:\Documents and Settings\LocalService\Application Data\WTablet
2007-11-07 17:23 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-11-07 16:31 ——— d—–w C:\Documents and Settings\All Users\Application Data\Kontiki
2007-11-07 16:09 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2007-11-07 15:59 ——— d—–w C:\Program Files\Steam
2007-11-07 15:56 ——— d—–w C:\Program Files\Nokia
2007-11-07 15:56 ——— d—–w C:\Program Files\Common Files\PCSuite
2007-11-07 15:56 ——— d—–w C:\Documents and Settings\All Users\Application Data\Downloaded Installations
2007-11-07 13:15 ——— d—–w C:\Program Files\CCleaner
2007-11-07 12:25 ——— d—–w C:\Program Files\GoldWave
2007-11-07 12:22 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-11-07 12:21 ——— d—–w C:\Program Files\BitLord
2007-10-26 02:18 ——— d—–w C:\Documents and Settings\Administrator\Application Data\dvdcss
2007-10-25 23:45 ——— d—–w C:\Program Files\iPod
2007-10-21 21:35 47,104 —-a-w C:\WINDOWS\system32\KMVIDC32.DLL
2007-10-12 09:54 ——— d—–w C:\Program Files\VirtualDJ
2007-09-29 01:48 ——— d—–w C:\Program Files\Winamp
2007-09-20 02:41 ——— d—–w C:\Program Files\InterActual
2007-09-20 02:14 ——— d—–w C:\Program Files\Roxio
2007-09-20 02:14 ——— d—–w C:\Program Files\Common Files\SureThing Shared
2007-09-20 02:14 ——— d—–w C:\Program Files\Common Files\Sonic Shared
2007-09-20 02:09 ——— d—–w C:\Program Files\Common Files\Roxio Shared
2007-09-20 02:07 ——— d—–w C:\Documents and Settings\All Users\Application Data\Roxio
2007-09-20 02:06 ——— d—–w C:\Program Files\DivX
2007-09-20 01:57 ——— d—–w C:\Program Files\MixVibesPro6DEMO
2007-09-14 14:14 ——— d—–w C:\Program Files\Apple Software Update
2007-09-14 11:41 ——— d—–w C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-09-13 01:13 ——— d—–w C:\Program Files\MSN Messenger
2007-09-13 01:09 ——— d—–w C:\Program Files\Microsoft.NET
2007-09-13 01:09 ——— d—–w C:\Program Files\Microsoft Works
2007-09-09 19:00 ——— d—–w C:\Documents and Settings\Administrator\Application Data\Apple Computer
2007-08-21 06:15 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-02-19 12:08 87,608 —-a-w C:\Documents and Settings\Administrator\Application Data\ezpinst.exe
2007-02-19 12:08 47,360 —-a-w C:\Documents and Settings\Administrator\Application Data\pcouffin.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 12:22]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-10-26 07:40]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-10-23 09:16]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-05-30 12:30]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2006-07-06 16:23:40]
NETGEAR WPN111 Smart Wizard.lnk - C:\Program Files\NETGEAR\WPN111\wpn111.exe [2006-09-08 14:03:56]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
"C:\Program Files\Steam\Steam.exe" -silent

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ose"=3 (0x3)
"Macromedia Licensing Service"=3 (0x3)
"iPod Service"=3 (0x3)
"IDriverT"=3 (0x3)
"Creative Service for CDROM Access"=2 (0x2)
"AvidStartup"=2 (0x2)
"AvidSDMService"=2 (0x2)
"Adobe LM Service"=3 (0x3)

R1 c2scsi;c2scsi;C:\WINDOWS\system32\drivers\c2scsi.sys
R1 DLARTL_M;DLARTL_M;C:\WINDOWS\system32\Drivers\DLARTL_M.SYS
R2 PfDetNT;PfDetNT;\??\C:\WINDOWS\System32\drivers\PfModNT.sys
R3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;\??\C:\WINDOWS\system32\DNINDIS5.SYS
R3 wacommousefilter;Wacom Mouse Filter Driver;C:\WINDOWS\system32\DRIVERS\wacommousefilter.sys
R3 wacomvhid;Wacom Virtual Hid Driver;C:\WINDOWS\system32\DRIVERS\wacomvhid.sys
R3 WPN111;Wireless USB 2.0 Adapter with RangeMax Service;C:\WINDOWS\system32\DRIVERS\WPN111.sys
S0 DigiFilter;DigiFilter;C:\WINDOWS\system32\drivers\DigiFilt.sys
S3 NMRKUSBA;Numark USB2 WDM;C:\WINDOWS\system32\drivers\nmrkusba.sys
S3 NMRKUSBU;Numark USB2 driver;C:\WINDOWS\system32\Drivers\nmrkusbu.sys
S3 SaiH8000;SaiH8000;C:\WINDOWS\system32\DRIVERS\SaiH8000.sys
S3 SetupNTGLM7X;SetupNTGLM7X;\??\D:\NTGLM7X.sys

*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2007-10-29 23:30:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
.
**************************************************************************

catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-09 03:15:41
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-09 3:16:13
.
— E O F —


ALSO THE REPORT FILE FOR THE SAFEMODE AVG SCAN JUST IN CASE:
===========================================================

———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 03:08:21 09/11/2007

+ Scan result:



HKLM\SOFTWARE\Classes\ADM25.ADM25 -> Adware.Altnet : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\ADM25.ADM25\CurVer -> Adware.Altnet : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\ADM4.ADM4 -> Adware.Altnet : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\ADM4.ADM4\CurVer -> Adware.Altnet : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\AppID\Altnet Signing Module.EXE -> Adware.Altnet : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\AppID\adm.EXE -> Adware.Altnet : Cleaned with backup (quarantined).
C:\WINDOWS\system32\AdCache -> Adware.Cydoor : Cleaned with backup (quarantined).
C:\Program Files\Common Files\Real\WeatherBug\MiniBugTransporter.dll -> Adware.Minibug : Cleaned with backup (quarantined).
C:\WINDOWS\system32\clipboard.exe -> Trojan.Small : Cleaned with backup (quarantined).


::Report end


Thanks for all the help. Where do these trojans come from?
Jack
They come from sites you visit that have code in them to infect a machine without your knowledge.
Downloading files and music is a great way to catch some of them. Once installed some of the files are designed to continue dowloading other bad files.

_____________________________________________
I see you have some torrent programs. Please do not use those programs untill we have you clean. And after that think about not using them at all.
The programs themselves are OK. But the files you download will be infected



_____________________________
Submit a file to Jotti
Please go here : http://virusscan.jotti.org/
On top of the page there is a field to add the filepath, copy and paste these filepaths: 1 at a time.


C:\WINDOWS\system32\febddcdadca_r.dll


Then hit Submit
The scan will take a while before the result comes up so please be patient.
Then copy the result and post it here in this thread.

If Jotti's service load is too high, you can use the following scanner instead:
http://www.virustotal.com/xhtml/index_en.html

________________________________



Please download Navilog1 by IL-MAFIOSO: from this link.
http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe
* Double click on navilog1.exe to install it on your computer.
* When the installation is complete, the tool will start automatically.
* If it doesn't start automatically, please double click on Navilog1 shortcut on your desktop to run it.
* Press E for English from the language Menu.
* Type 1 in the next Menu to select Search and press Enter.
* Wait for the Scan to finish (It may take a reasonable amount of time)
* Press any key as requested .
* A new document will be produced: fixnavi.txt.
* Please copy/paste the contents of this report in your next reply.
The report is also saved in the root of the directory, "%SystemDrive%\fixnavi.txt". (usually C:\fixnavi.txt)




_________________________
In your next reply I would like to see:
  • A new HJT log
  • The report from NAVILOG
  • The report from Jottis
Hey

Jotti's Log:
======

Last file scanned at least one scanner reported something about: 478bd7331d6aefb80d7f282471486223 (MD5: 478bd7331d6aefb80d7f282471486223, size: 67072 bytes), detected by:

Scanner Malware name
A-Squared X
AntiVir TR/Drop.Maran.CJ.2
ArcaVir Trojan.Psw.Maran.Ff
Avast Win32:Maran-AC
AVG Antivirus PSW.Generic4.KEW
BitDefender Generic.PWS.Maran.4B0AE63A
ClamAV Trojan.Spy-4219
CPsecure X
Dr.Web Trojan.PWS.Maran
F-Prot Antivirus W32/Trojan.ATII
F-Secure Anti-Virus Trojan-PSW.Win32.Maran.ff
Fortinet SPY/MARAN
Kaspersky Anti-Virus Trojan-PSW.Win32.Maran.ff
NOD32 Win32/PSW.Maran.FF
Norman Virus Control W32/Lineage.AXPW
Panda Antivirus X
Rising Antivirus Trojan.PSW.RoOnline.a
Sophos Antivirus Troj/Maran-Gen
VirusBuster X
VBA32 Trojan-PSW.Win32.Maran.ff

Navi Log Report:
=============

Search Navipromo version 3.3.5 began on 09/11/2007 at 12:49:09.98

!!! Warning, this report may include legitimate files/programs !!!
!!! Post this report on the forum you are being helped !!!
!!! Don't continue with removal unless instructed by an authorized helper !!!
Fix running from C:\Program Files\navilog1
Updated on 08.11.2007 at 18h00 by IL-MAFIOSO

Microsoft Windows XP [Version 5.1.2600]
Version Internet Explorer : 6.0.2900.2180

Done in normal mode

*** Searching for installed Software ***




*** Search folders in C:\WINDOWS ***



*** Search folders in C:\Program Files ***



*** Search folders in C:\Documents and Settings\All Users\Application Data ***




*** Search folders in C:\Documents and Settings\Administrator\Application Data ***


*** Search folders in C:\DOCUME~1\ALLUSE~1\STARTM~1\PROGRAMS ***


*** Search with Catchme-rootkit/stealth malware detector by gmer ***
for more info : http://www.gmer.net

No file found in :

- C:\WINDOWS\system32
- C:\DOCUME~1\ADMINI~1\LOCALS~1\APPLIC~1



*** Search with GenericNaviSearch ***
!!! Possibility of legitimate files in the result !!!
!!! Must always be checked before manually deleting !!!

* Scan in C:\WINDOWS\system32 *

* Scan in C:\DOCUME~1\ADMINI~1\LOCALS~1\APPLIC~1 *



*** Search files ***




*** Search specific Registry keys ***


*** Complementary Search ***
(Search specific files)

1)Search known files:

2)Heuristic Search :



3)Certificates Search :

Egroup certificate not found !


*** Search completed on 09/11/2007 at 12:49:43.53 ***

NEW HIJACK THIS LOG
===================

Logfile of HijackThis v1.99.1
Scan saved at 12:53:00, on 09/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\AvidSDMService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Tablet.exe
C:\WINDOWS\system32\WTablet\TabUserW.exe
C:\WINDOWS\system32\Tablet.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\NETGEAR\WPN111\wpn111.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HijackThis\noname.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: NETGEAR WPN111 Smart Wizard.lnk = ?
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Avid SDM Service (AvidSDMService) - Avid Technology, Inc. - C:\WINDOWS\system32\AvidSDMService.exe
O23 - Service: Avid Startup (AvidStartup) - Unknown owner - C:\WINDOWS\system32\AvidStartup.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe


Ceers,
Jack
I searched for the said file in system32 and it wasn't there. I also went to folder options and checked 'show hidden files' and then searched, still no avail. I did have this problem when I was browsing for the file in the Jotti's scan so I just pasted the directory you gave me ( C:\WINDOWS\system32\febddcdadca_r.dll) straight into the search bar before submitting it. I assumed that it must have found the file because it gave me the scan results. I've also tried a whole search of the file on drive C:\ using windows explorer search. Is it avoiding being found or have I somehow already deleted it with one of these scanning programmes? Cheers, Jack
Nope it's just very well hidden from us.
Heres a way for me to be sure.

________________________________________
Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\system32\febddcdadca_r.dll



Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:ComboFix.txt which I will need in your next reply.

____________________________


_________________________
In your next reply I would like to see:
  • A new HJT log
  • The report from ComboFix
  • Have things improved yet ?
  • Any more pop ups ?
ComboFix2
==========

ComboFix 07-11-08.1 - Administrator 2007-11-09 3:13:36.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.44.1033.18.1614 [GMT 0:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\pack.epk
C:\WINDOWS\system32\holwkj.dat
c:\windows\system32\holwkj.exe
C:\WINDOWS\system32\holwkj_nav.dat
C:\WINDOWS\system32\holwkj_navps.dat
C:\WINDOWS\system32\media
C:\WINDOWS\system32\media\AvidRender.wav
C:\WINDOWS\system32\nvs2.inf

.
((((((((((((((((((((((((( Files Created from 2007-10-09 to 2007-11-09 )))))))))))))))))))))))))))))))
.

2007-11-09 03:12 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-11-09 02:22 d——– C:\Documents and Settings\Administrator\Application Data\Grisoft
2007-11-09 02:21 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-11-08 16:35 d——– C:\VundoFix Backups
2007-11-07 16:10 d——– C:\Program Files\Lavasoft
2007-11-07 12:32 d——– C:\Program Files\jv16 PowerTools 2007
2007-11-07 12:32 23 –ahs—- C:\WINDOWS\system32\febddcdadca_r.dll
2007-11-06 13:26 d——– C:\Program Files\Native Instruments
2007-11-02 01:22 d——– C:\Program Files\Kontiki
2007-11-02 01:22 d——– C:\Program Files\Channel4
2007-11-02 01:21 d——– C:\Documents and Settings\All Users\Application Data\Channel4
2007-10-26 04:33 584,192 —–c— C:\WINDOWS\system32\dllcache\rpcrt4.dll
2007-10-25 23:45 d——– C:\Program Files\iTunes

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-09 03:10 ——— d—–w C:\Documents and Settings\Administrator\Application Data\WTablet
2007-11-09 02:25 ——— d—–w C:\Documents and Settings\Administrator\Application Data\uTorrent
2007-11-09 02:03 ——— d—–w C:\Documents and Settings\Administrator\Application Data\AVG7
2007-11-08 14:31 ——— d—–w C:\Documents and Settings\LocalService\Application Data\WTablet
2007-11-07 17:23 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-11-07 16:31 ——— d—–w C:\Documents and Settings\All Users\Application Data\Kontiki
2007-11-07 16:09 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2007-11-07 15:59 ——— d—–w C:\Program Files\Steam
2007-11-07 15:56 ——— d—–w C:\Program Files\Nokia
2007-11-07 15:56 ——— d—–w C:\Program Files\Common Files\PCSuite
2007-11-07 15:56 ——— d—–w C:\Documents and Settings\All Users\Application Data\Downloaded Installations
2007-11-07 13:15 ——— d—–w C:\Program Files\CCleaner
2007-11-07 12:25 ——— d—–w C:\Program Files\GoldWave
2007-11-07 12:22 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-11-07 12:21 ——— d—–w C:\Program Files\BitLord
2007-10-26 02:18 ——— d—–w C:\Documents and Settings\Administrator\Application Data\dvdcss
2007-10-25 23:45 ——— d—–w C:\Program Files\iPod
2007-10-21 21:35 47,104 —-a-w C:\WINDOWS\system32\KMVIDC32.DLL
2007-10-12 09:54 ——— d—–w C:\Program Files\VirtualDJ
2007-09-29 01:48 ——— d—–w C:\Program Files\Winamp
2007-09-20 02:41 ——— d—–w C:\Program Files\InterActual
2007-09-20 02:14 ——— d—–w C:\Program Files\Roxio
2007-09-20 02:14 ——— d—–w C:\Program Files\Common Files\SureThing Shared
2007-09-20 02:14 ——— d—–w C:\Program Files\Common Files\Sonic Shared
2007-09-20 02:09 ——— d—–w C:\Program Files\Common Files\Roxio Shared
2007-09-20 02:07 ——— d—–w C:\Documents and Settings\All Users\Application Data\Roxio
2007-09-20 02:06 ——— d—–w C:\Program Files\DivX
2007-09-20 01:57 ——— d—–w C:\Program Files\MixVibesPro6DEMO
2007-09-14 14:14 ——— d—–w C:\Program Files\Apple Software Update
2007-09-14 11:41 ——— d—–w C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-09-13 01:13 ——— d—–w C:\Program Files\MSN Messenger
2007-09-13 01:09 ——— d—–w C:\Program Files\Microsoft.NET
2007-09-13 01:09 ——— d—–w C:\Program Files\Microsoft Works
2007-09-09 19:00 ——— d—–w C:\Documents and Settings\Administrator\Application Data\Apple Computer
2007-08-21 06:15 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-02-19 12:08 87,608 —-a-w C:\Documents and Settings\Administrator\Application Data\ezpinst.exe
2007-02-19 12:08 47,360 —-a-w C:\Documents and Settings\Administrator\Application Data\pcouffin.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 12:22]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-10-26 07:40]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-10-23 09:16]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-05-30 12:30]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2006-07-06 16:23:40]
NETGEAR WPN111 Smart Wizard.lnk - C:\Program Files\NETGEAR\WPN111\wpn111.exe [2006-09-08 14:03:56]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
"C:\Program Files\Steam\Steam.exe" -silent

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ose"=3 (0x3)
"Macromedia Licensing Service"=3 (0x3)
"iPod Service"=3 (0x3)
"IDriverT"=3 (0x3)
"Creative Service for CDROM Access"=2 (0x2)
"AvidStartup"=2 (0x2)
"AvidSDMService"=2 (0x2)
"Adobe LM Service"=3 (0x3)

R1 c2scsi;c2scsi;C:\WINDOWS\system32\drivers\c2scsi.sys
R1 DLARTL_M;DLARTL_M;C:\WINDOWS\system32\Drivers\DLARTL_M.SYS
R2 PfDetNT;PfDetNT;\??\C:\WINDOWS\System32\drivers\PfModNT.sys
R3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;\??\C:\WINDOWS\system32\DNINDIS5.SYS
R3 wacommousefilter;Wacom Mouse Filter Driver;C:\WINDOWS\system32\DRIVERS\wacommousefilter.sys
R3 wacomvhid;Wacom Virtual Hid Driver;C:\WINDOWS\system32\DRIVERS\wacomvhid.sys
R3 WPN111;Wireless USB 2.0 Adapter with RangeMax Service;C:\WINDOWS\system32\DRIVERS\WPN111.sys
S0 DigiFilter;DigiFilter;C:\WINDOWS\system32\drivers\DigiFilt.sys
S3 NMRKUSBA;Numark USB2 WDM;C:\WINDOWS\system32\drivers\nmrkusba.sys
S3 NMRKUSBU;Numark USB2 driver;C:\WINDOWS\system32\Drivers\nmrkusbu.sys
S3 SaiH8000;SaiH8000;C:\WINDOWS\system32\DRIVERS\SaiH8000.sys
S3 SetupNTGLM7X;SetupNTGLM7X;\??\D:\NTGLM7X.sys

*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2007-10-29 23:30:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
.
**************************************************************************

catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-09 03:15:41
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-09 3:16:13
.
— E O F —

HIJACKTHIS
==========

Logfile of HijackThis v1.99.1
Scan saved at 16:09:53, on 09/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\AvidSDMService.exe
C:\Program Files\Kontiki\KService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Tablet.exe
C:\WINDOWS\system32\WTablet\TabUserW.exe
C:\WINDOWS\system32\Tablet.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\NETGEAR\WPN111\wpn111.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HijackThis\noname.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [4oD] "C:\Program Files\Kontiki\KHost.exe" -all
O4 - HKCU\..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: NETGEAR WPN111 Smart Wizard.lnk = ?
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Avid SDM Service (AvidSDMService) - Avid Technology, Inc. - C:\WINDOWS\system32\AvidSDMService.exe
O23 - Service: Avid Startup (AvidStartup) - Unknown owner - C:\WINDOWS\system32\AvidStartup.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe

==============
– It's worth noting that a threat was detected by AVG during the ComboFix scan (the same as yesterday's: vpspjjeHER.dll). I've put it in the vault. Also, the computer restarted automatically (which it didn't seem to do during the last ComboFix scan).

– There has been a slight improvement in the popups actually. I can't say I've noticed any today.

I have to say, all this stuff is intriguing the hell out of me: if you have a spare minute could you give me a brief description of what we're actually doing here? Specifically combo fix, and how a file like febddcdadca_r.dll manages to hide itself from me. It would be interesting to learn something from this experience.

Thanks again for all this help,
Jack
Something didn't go correctly with combo last fix.
Please reread my intructions for getting rid of that file.

Be sure to use note pad and not word pad for the file.
clcik start/run and type in notepad
Click OK.





________________________________________
Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\system32\febddcdadca_r.dll



Save this as CFScript.txt, in the same location as ComboFix.exe ( your desktop)


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:ComboFix.txt which I will need in your next reply.
Sorry, perhaps it was because ComboFix had been moved from the desktop.
Here is the new log (the same threat was found during this scan as the last, but there was no windows restart)
==========

ComboFix 07-11-08.1 - Administrator 2007-11-09 17:23:05.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1611 [GMT 0:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Administrator\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\WINDOWS\system32\febddcdadca_r.dll
.

((((((((((((((((((((((((( Files Created from 2007-10-09 to 2007-11-09 )))))))))))))))))))))))))))))))
.

2007-11-09 12:47 d——– C:\Program Files\Navilog1
2007-11-09 03:12 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-11-09 02:22 d——– C:\Documents and Settings\Administrator\Application Data\Grisoft
2007-11-09 02:21 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-11-08 16:35 d——– C:\VundoFix Backups
2007-11-07 16:10 d——– C:\Program Files\Lavasoft
2007-11-07 12:32 d——– C:\Program Files\jv16 PowerTools 2007
2007-11-06 13:26 d——– C:\Program Files\Native Instruments
2007-11-02 01:22 d——– C:\Program Files\Kontiki
2007-11-02 01:22 d——– C:\Program Files\Channel4
2007-11-02 01:21 d——– C:\Documents and Settings\All Users\Application Data\Channel4
2007-10-26 04:33 584,192 —–c— C:\WINDOWS\system32\dllcache\rpcrt4.dll
2007-10-25 23:45 d——– C:\Program Files\iTunes

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-09 17:24 ——— d—–w C:\Documents and Settings\All Users\Application Data\Kontiki
2007-11-09 16:04 ——— d—–w C:\Documents and Settings\Administrator\Application Data\WTablet
2007-11-09 16:04 ——— d—–w C:\Documents and Settings\Administrator\Application Data\AVG7
2007-11-09 12:49 ——— d—–w C:\Documents and Settings\Administrator\Application Data\uTorrent
2007-11-08 14:31 ——— d—–w C:\Documents and Settings\LocalService\Application Data\WTablet
2007-11-07 17:23 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-11-07 16:09 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2007-11-07 15:59 ——— d—–w C:\Program Files\Steam
2007-11-07 15:56 ——— d—–w C:\Program Files\Nokia
2007-11-07 15:56 ——— d—–w C:\Program Files\Common Files\PCSuite
2007-11-07 15:56 ——— d—–w C:\Documents and Settings\All Users\Application Data\Downloaded Installations
2007-11-07 13:15 ——— d—–w C:\Program Files\CCleaner
2007-11-07 12:25 ——— d—–w C:\Program Files\GoldWave
2007-11-07 12:22 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-11-07 12:21 ——— d—–w C:\Program Files\BitLord
2007-10-26 02:18 ——— d—–w C:\Documents and Settings\Administrator\Application Data\dvdcss
2007-10-25 23:45 ——— d—–w C:\Program Files\iPod
2007-10-21 21:35 47,104 —-a-w C:\WINDOWS\system32\KMVIDC32.DLL
2007-10-12 09:54 ——— d—–w C:\Program Files\VirtualDJ
2007-09-29 01:48 ——— d—–w C:\Program Files\Winamp
2007-09-20 02:41 ——— d—–w C:\Program Files\InterActual
2007-09-20 02:14 ——— d—–w C:\Program Files\Roxio
2007-09-20 02:14 ——— d—–w C:\Program Files\Common Files\SureThing Shared
2007-09-20 02:14 ——— d—–w C:\Program Files\Common Files\Sonic Shared
2007-09-20 02:09 ——— d—–w C:\Program Files\Common Files\Roxio Shared
2007-09-20 02:07 ——— d—–w C:\Documents and Settings\All Users\Application Data\Roxio
2007-09-20 02:06 ——— d—–w C:\Program Files\DivX
2007-09-20 01:57 ——— d—–w C:\Program Files\MixVibesPro6DEMO
2007-09-14 14:14 ——— d—–w C:\Program Files\Apple Software Update
2007-09-14 11:41 ——— d—–w C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-09-13 01:13 ——— d—–w C:\Program Files\MSN Messenger
2007-09-13 01:09 ——— d—–w C:\Program Files\Microsoft.NET
2007-09-13 01:09 ——— d—–w C:\Program Files\Microsoft Works
2007-09-09 19:00 ——— d—–w C:\Documents and Settings\Administrator\Application Data\Apple Computer
2007-08-21 06:15 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-02-19 12:08 87,608 —-a-w C:\Documents and Settings\Administrator\Application Data\ezpinst.exe
2007-02-19 12:08 47,360 —-a-w C:\Documents and Settings\Administrator\Application Data\pcouffin.sys
.

((((((((((((((((((((((((((((( snapshot@2007-11-09_ 3.15.46.34 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-11-09 16:04:34 16,384 —-atw C:\WINDOWS\TEMP\Perflib_Perfdata_1f4.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 12:22]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-10-26 07:40]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-10-23 09:16]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-05-30 12:30]
"4oD"="C:\Program Files\Kontiki\KHost.exe" [2007-04-23 11:23]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"kdx"="C:\Program Files\Kontiki\KHost.exe" [2007-04-23 11:23]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2006-07-06 16:23:40]
NETGEAR WPN111 Smart Wizard.lnk - C:\Program Files\NETGEAR\WPN111\wpn111.exe [2006-09-08 14:03:56]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
"C:\Program Files\Steam\Steam.exe" -silent

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ose"=3 (0x3)
"Macromedia Licensing Service"=3 (0x3)
"iPod Service"=3 (0x3)
"IDriverT"=3 (0x3)
"Creative Service for CDROM Access"=2 (0x2)
"AvidStartup"=2 (0x2)
"AvidSDMService"=2 (0x2)
"Adobe LM Service"=3 (0x3)

R1 c2scsi;c2scsi;C:\WINDOWS\system32\drivers\c2scsi.sys
R1 DLARTL_M;DLARTL_M;C:\WINDOWS\system32\Drivers\DLARTL_M.SYS
R2 PfDetNT;PfDetNT;\??\C:\WINDOWS\System32\drivers\PfModNT.sys
R3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;\??\C:\WINDOWS\system32\DNINDIS5.SYS
R3 wacommousefilter;Wacom Mouse Filter Driver;C:\WINDOWS\system32\DRIVERS\wacommousefilter.sys
R3 wacomvhid;Wacom Virtual Hid Driver;C:\WINDOWS\system32\DRIVERS\wacomvhid.sys
R3 WPN111;Wireless USB 2.0 Adapter with RangeMax Service;C:\WINDOWS\system32\DRIVERS\WPN111.sys
S0 DigiFilter;DigiFilter;C:\WINDOWS\system32\drivers\DigiFilt.sys
S3 NMRKUSBA;Numark USB2 WDM;C:\WINDOWS\system32\drivers\nmrkusba.sys
S3 NMRKUSBU;Numark USB2 driver;C:\WINDOWS\system32\Drivers\nmrkusbu.sys
S3 SaiH8000;SaiH8000;C:\WINDOWS\system32\DRIVERS\SaiH8000.sys
S3 SetupNTGLM7X;SetupNTGLM7X;\??\D:\NTGLM7X.sys

.
Contents of the 'Scheduled Tasks' folder
"2007-10-29 23:30:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
.
**************************************************************************

catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-09 17:24:51
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-09 17:25:23
C:\ComboFix2.txt … 2007-11-09 16:05
C:\ComboFix3.txt … 2007-11-09 03:16
.
— E O F —
I asked about the AVG poping up during the scan.
Seems some malware may be trying to recreate itself as combo removes it.


Please do this.

disconnect from the internet completely:
(Pull the plug !)





Disable real time protection in AVG anti virus
_______________________
* run the AVGAnti-Virus
* click on the Launch AVG Control Center option
* double-click on the AVG Resident Shield component
* disable the option Turn on AVG Resident Shield protection
* save these settings using the OK button






I'm pretty sure this file is gone but want to be sure.
________________________________________
Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\system32\febddcdadca_r.dll



Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:ComboFix.txt which I will need in your next reply.






Reconnect to the internet.
_________________________________
Please do an online scan with Kaspersky Online Scanner
Click on Kaspersky Online Scanner
You will be promted to install an ActiveX component from Kaspersky, Click Yes.
The program will launch and then start to download the latest definition files.
Once the scanner is installed and the definitions downloaded, click Next.
Now click on Scan Settings
In the scan settings make sure that the following are selected:
Scan using the following Anti-Virus database:

Extended (If available otherwise Standard)
Scan Options:
Scan Archives
Scan Mail Bases
Click OK

Now under select a target to scan select My Computer


Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.



The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.

Now click on the Save as Text button:

Save the file to your desktop.

Copy and paste that information in your next post.


_________________________
In your next reply I would like to see:
  • A new HJT log
  • The report from ComboFix
  • The report from Kasperskys
Hey, sorry I was away for the weekend. Here are the new logs:


HIJACK THIS
==========

Logfile of HijackThis v1.99.1
Scan saved at 10:49:35, on 12/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\AvidSDMService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Kontiki\KService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Tablet.exe
C:\WINDOWS\system32\WTablet\TabUserW.exe
C:\WINDOWS\system32\Tablet.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\NETGEAR\WPN111\wpn111.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HijackThis\noname.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [4oD] "C:\Program Files\Kontiki\KHost.exe" -all
O4 - HKCU\..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: NETGEAR WPN111 Smart Wizard.lnk = ?
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Avid SDM Service (AvidSDMService) - Avid Technology, Inc. - C:\WINDOWS\system32\AvidSDMService.exe
O23 - Service: Avid Startup (AvidStartup) - Unknown owner - C:\WINDOWS\system32\AvidStartup.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe

KASPERSKY
==========

——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Monday, November 12, 2007 10:48:59 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 12/11/2007
Kaspersky Anti-Virus database records: 456632
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\
F:\
G:\
X:\

Scan Statistics:
Total number of scanned objects: 110657
Number of viruses found: 4
Number of infected objects: 11
Number of suspicious objects: 0
Duration of the scan process: 01:20:37

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Administrator\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Identities\{B6E50E5A-4406-4C68-AFEA-841E24B27EB5}\Microsoft\Outlook Express\Inbox.dbx/[From [removed]][Date Wed, 9 Nov 2005 10:31:29 +0000]/UNNAMED/rwo.zip/rwo.htm .scr Infected: Net-Worm.Win32.Mytob.bw skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Identities\{B6E50E5A-4406-4C68-AFEA-841E24B27EB5}\Microsoft\Outlook Express\Inbox.dbx/[From [removed]][Date Wed, 9 Nov 2005 10:31:29 +0000]/UNNAMED/rwo.zip Infected: Net-Worm.Win32.Mytob.bw skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Identities\{B6E50E5A-4406-4C68-AFEA-841E24B27EB5}\Microsoft\Outlook Express\Inbox.dbx/[From [removed]][Date Wed, 9 Nov 2005 10:31:29 +0000]/UNNAMED Infected: Net-Worm.Win32.Mytob.bw skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Identities\{B6E50E5A-4406-4C68-AFEA-841E24B27EB5}\Microsoft\Outlook Express\Inbox.dbx Mail MS Outlook 5: infected - 3 skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\MSHist012007111220071113\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Administrator\NTUSER.dat.LOG Object is locked skipped
C:\Documents and Settings\Administrator\UserData\index.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Kontiki\error.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Mozilla Firefox\plugins\NPNd2fn.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.o skipped
C:\Program Files\Navilog1\reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{DF162A0F-4851-431B-8DE0-1A45BD4E1680}\RP791\change.log Object is locked skipped
C:\WINDOWS\CSC\000001 Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\ODiag.evt Object is locked skipped
C:\WINDOWS\system32\config\OSession.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\dtscsi.sys Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\temp\NSIS_Install_IGB.exe/stream/data0006 Infected: not-a-virus:AdWare.Win32.NaviPromo.ao skipped
C:\WINDOWS\system32\temp\NSIS_Install_IGB.exe/stream Infected: not-a-virus:AdWare.Win32.NaviPromo.ao skipped
C:\WINDOWS\system32\temp\NSIS_Install_IGB.exe NSIS: infected - 2 skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\TEMP\Perflib_Perfdata_368.dat Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
F:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
X:\downloads\misc software\NaviLog1\Navilog1.exe/file7 Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
X:\downloads\misc software\NaviLog1\Navilog1.exe Inno: infected - 1 skipped
X:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

Scan process completed.

COMBOFIX
=========

ComboFix 07-11-08.1 - Administrator 2007-11-10 12:56:16.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1648 [GMT 0:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Administrator\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\WINDOWS\system32\febddcdadca_r.dll
.

((((((((((((((((((((((((( Files Created from 2007-10-10 to 2007-11-10 )))))))))))))))))))))))))))))))
.

2007-11-09 12:47 d——– C:\Program Files\Navilog1
2007-11-09 03:12 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-11-09 02:22 d——– C:\Documents and Settings\Administrator\Application Data\Grisoft
2007-11-09 02:21 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-11-08 16:35 d——– C:\VundoFix Backups
2007-11-07 16:10 d——– C:\Program Files\Lavasoft
2007-11-07 12:32 d——– C:\Program Files\jv16 PowerTools 2007
2007-11-06 13:26 d——– C:\Program Files\Native Instruments
2007-11-02 01:22 d——– C:\Program Files\Kontiki
2007-11-02 01:22 d——– C:\Program Files\Channel4
2007-11-02 01:21 d——– C:\Documents and Settings\All Users\Application Data\Channel4
2007-10-26 04:33 584,192 —–c— C:\WINDOWS\system32\dllcache\rpcrt4.dll
2007-10-25 23:45 d——– C:\Program Files\iTunes

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-10 12:57 ——— d—–w C:\Documents and Settings\All Users\Application Data\Kontiki
2007-11-10 12:55 ——— d—–w C:\Documents and Settings\Administrator\Application Data\uTorrent
2007-11-10 12:51 ——— d—–w C:\Documents and Settings\Administrator\Application Data\AVG7
2007-11-10 12:50 ——— d—–w C:\Documents and Settings\Administrator\Application Data\WTablet
2007-11-09 17:28 ——— d—–w C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-08 14:31 ——— d—–w C:\Documents and Settings\LocalService\Application Data\WTablet
2007-11-07 17:23 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-11-07 16:09 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2007-11-07 15:59 ——— d—–w C:\Program Files\Steam
2007-11-07 15:56 ——— d—–w C:\Program Files\Nokia
2007-11-07 15:56 ——— d—–w C:\Program Files\Common Files\PCSuite
2007-11-07 15:56 ——— d—–w C:\Documents and Settings\All Users\Application Data\Downloaded Installations
2007-11-07 13:15 ——— d—–w C:\Program Files\CCleaner
2007-11-07 12:25 ——— d—–w C:\Program Files\GoldWave
2007-11-07 12:22 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-11-07 12:21 ——— d—–w C:\Program Files\BitLord
2007-10-26 02:18 ——— d—–w C:\Documents and Settings\Administrator\Application Data\dvdcss
2007-10-25 23:45 ——— d—–w C:\Program Files\iPod
2007-10-21 21:35 47,104 —-a-w C:\WINDOWS\system32\KMVIDC32.DLL
2007-10-12 09:54 ——— d—–w C:\Program Files\VirtualDJ
2007-09-29 01:48 ——— d—–w C:\Program Files\Winamp
2007-09-20 02:41 ——— d—–w C:\Program Files\InterActual
2007-09-20 02:14 ——— d—–w C:\Program Files\Roxio
2007-09-20 02:14 ——— d—–w C:\Program Files\Common Files\SureThing Shared
2007-09-20 02:14 ——— d—–w C:\Program Files\Common Files\Sonic Shared
2007-09-20 02:09 ——— d—–w C:\Program Files\Common Files\Roxio Shared
2007-09-20 02:07 ——— d—–w C:\Documents and Settings\All Users\Application Data\Roxio
2007-09-20 02:06 ——— d—–w C:\Program Files\DivX
2007-09-20 01:57 ——— d—–w C:\Program Files\MixVibesPro6DEMO
2007-09-14 14:14 ——— d—–w C:\Program Files\Apple Software Update
2007-09-14 11:41 ——— d—–w C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-09-13 01:13 ——— d—–w C:\Program Files\MSN Messenger
2007-09-13 01:09 ——— d—–w C:\Program Files\Microsoft.NET
2007-09-13 01:09 ——— d—–w C:\Program Files\Microsoft Works
2007-08-21 06:15 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-02-19 12:08 87,608 —-a-w C:\Documents and Settings\Administrator\Application Data\ezpinst.exe
2007-02-19 12:08 47,360 —-a-w C:\Documents and Settings\Administrator\Application Data\pcouffin.sys
.

((((((((((((((((((((((((((((( snapshot@2007-11-09_ 3.15.46.34 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-11-10 12:50:53 16,384 —-atw C:\WINDOWS\TEMP\Perflib_Perfdata_384.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 12:22]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-10-26 07:40]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-10-23 09:16]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-11-09 17:28]
"4oD"="C:\Program Files\Kontiki\KHost.exe" [2007-04-23 11:23]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"kdx"="C:\Program Files\Kontiki\KHost.exe" [2007-04-23 11:23]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2006-07-06 16:23:40]
NETGEAR WPN111 Smart Wizard.lnk - C:\Program Files\NETGEAR\WPN111\wpn111.exe [2006-09-08 14:03:56]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
"C:\Program Files\Steam\Steam.exe" -silent

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ose"=3 (0x3)
"Macromedia Licensing Service"=3 (0x3)
"iPod Service"=3 (0x3)
"IDriverT"=3 (0x3)
"Creative Service for CDROM Access"=2 (0x2)
"AvidStartup"=2 (0x2)
"AvidSDMService"=2 (0x2)
"Adobe LM Service"=3 (0x3)

R1 c2scsi;c2scsi;C:\WINDOWS\system32\drivers\c2scsi.sys
R1 DLARTL_M;DLARTL_M;C:\WINDOWS\system32\Drivers\DLARTL_M.SYS
R2 PfDetNT;PfDetNT;\??\C:\WINDOWS\System32\drivers\PfModNT.sys
R3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;\??\C:\WINDOWS\system32\DNINDIS5.SYS
R3 wacommousefilter;Wacom Mouse Filter Driver;C:\WINDOWS\system32\DRIVERS\wacommousefilter.sys
R3 wacomvhid;Wacom Virtual Hid Driver;C:\WINDOWS\system32\DRIVERS\wacomvhid.sys
S0 DigiFilter;DigiFilter;C:\WINDOWS\system32\drivers\DigiFilt.sys
S3 NMRKUSBA;Numark USB2 WDM;C:\WINDOWS\system32\drivers\nmrkusba.sys
S3 NMRKUSBU;Numark USB2 driver;C:\WINDOWS\system32\Drivers\nmrkusbu.sys
S3 SaiH8000;SaiH8000;C:\WINDOWS\system32\DRIVERS\SaiH8000.sys
S3 SetupNTGLM7X;SetupNTGLM7X;\??\D:\NTGLM7X.sys
S3 WPN111;Wireless USB 2.0 Adapter with RangeMax Service;C:\WINDOWS\system32\DRIVERS\WPN111.sys

.
Contents of the 'Scheduled Tasks' folder
"2007-10-29 23:30:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
.
**************************************************************************

catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-10 12:58:15
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-10 12:58:50
C:\ComboFix2.txt … 2007-11-09 23:00
C:\ComboFix3.txt … 2007-11-09 17:25
.
— E O F —


Jack

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI