This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Various Infections, Need serious help

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I recently got infected with the trojan windownloader virus and proceeded to look for steps to remove it. I got constant popups on my taskbar saying my system was infected with worms, trojans, etc. I have since removed that (at least I think) amd then was infected with trojan vundo. symnatec removal tool cannot find it however. My ie has since stopped working, even when it is connected to the internet. Random ie windows popup, my ie settings keep changing to "Accept all cookies." Also, i cant get rid of the "online security center" and "live safety center" icons on my desktop. Please Help!

Logfile of HijackThis v1.99.1
Scan saved at 6:06:04 PM, on 11/24/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\System32\1XConfig.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\System32\basfipm.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Timothy Chow\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.com/
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [bascstray] BascsTray.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Broadcom ASF IP monitoring service v6.0.3 (BAsfIpM) - Broadcom Corp. - C:\WINDOWS\System32\basfipm.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
Hello chillin15 and welcome to the What the Tech Forums

My name is Trevuren and I will be helping you with your problem.


A. Some trojans have a way of masking their presence from the HijackThis program when they recognize the name. I think that this is the case here because there are no 02 or 020 entries visible in your log.

Please locate the following file on your desktop: HijackThis.exe
Next, right click on the file and from the popup menu that appears, choose the RENAME option and rename the file Killer.exe.

From now on, when I ask you to start HijackThis, just click on the Killer.exe file.


B. Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.



C. Download ComboFix from Here to your Desktop.
  • Double click combofix.exe and follow the prompts.
  • When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix's window while its running. That may cause it to stall


Combofix should never take more that 20 minutes including the reboot if malware is detected.

If it does, open task-manager > use the processes tab (press ctrl alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.

If that happened we want to know, and also what process you had to end.


D. Reports/Logs to post:
  • VundoFix.txt
  • ComboFix.txt
  • HijackThis log (Run after all the other tools have been run
Thanks so much for replying. I did everything you said and here are my logs.

Vundo:

VundoFix V6.6.2

Checking Java version…

Java version is 1.4.2.3
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.3
Old versions of java are exploitable and should be removed.

Scan started at 7:01:43 PM 11/24/2007

Listing files found while scanning….

C:\windows\SYSTEM32\lroyahuo.dllbox
C:\windows\SYSTEM32\vyyay.ini
C:\windows\SYSTEM32\vyyay.ini2
C:\windows\SYSTEM32\yayyv.dll

Beginning removal…

Attempting to delete C:\windows\SYSTEM32\lroyahuo.dllbox
C:\windows\SYSTEM32\lroyahuo.dllbox Has been deleted!

Attempting to delete C:\windows\SYSTEM32\vyyay.ini
C:\windows\SYSTEM32\vyyay.ini Has been deleted!

Attempting to delete C:\windows\SYSTEM32\vyyay.ini2
C:\windows\SYSTEM32\vyyay.ini2 Has been deleted!

Attempting to delete C:\windows\SYSTEM32\yayyv.dll
C:\windows\SYSTEM32\yayyv.dll Has been deleted!

Performing Repairs to the registry.
Done!

Combo:
ComboFix 07-11-19.3 - Timothy Chow 2007-11-24 19:48:32.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.155 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Administrator\Favorites\Online Security Guide.lnk
C:\Documents and Settings\All Users\Documents\_desktop.ini
C:\Documents and Settings\All Users\Documents\Adobe PDF 6.0\_desktop.ini
C:\Documents and Settings\All Users\Documents\Adobe PDF 6.0\Data\_desktop.ini
C:\Documents and Settings\All Users\Documents\Adobe PDF 6.0\Example Files\_desktop.ini
C:\Documents and Settings\All Users\Documents\Adobe PDF 6.0\Settings\_desktop.ini
C:\Documents and Settings\All Users\Documents\Adobe PDF 6.0\Startup\_desktop.ini
C:\Documents and Settings\All Users\Documents\My Music\_desktop.ini
C:\Documents and Settings\All Users\Documents\My Music\My Playlists\_desktop.ini
C:\Documents and Settings\All Users\Documents\My Music\Sample Music\_desktop.ini
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\_desktop.ini
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\0004F78E\_desktop.ini
C:\Documents and Settings\All Users\Documents\My Music\Sync Playlists\_desktop.ini
C:\Documents and Settings\All Users\Documents\My Music\Sync Playlists\0036EC41\_desktop.ini
C:\Documents and Settings\All Users\Documents\My Pictures\_desktop.ini
C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\_desktop.ini
C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\New Folder\_desktop.ini
C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\New Folder\sd\_desktop.ini
C:\Documents and Settings\All Users\Documents\My Videos\_desktop.ini
C:\Documents and Settings\Timothy Chow\Application Data\macromedia\Flash Player\#SharedObjects\FYLLBJSJ\www.broadcaster.com
C:\Documents and Settings\Timothy Chow\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
C:\Documents and Settings\Timothy Chow\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol
C:\Documents and Settings\Timothy Chow\Desktop\Live Safety Center.lnk
C:\Documents and Settings\Timothy Chow\Desktop\Online Security Guide.lnk
C:\Documents and Settings\Timothy Chow\Favorites\Online Security Guide.lnk
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\drivers\fad.sys
C:\WINDOWS\system32\pac.txt

.
((((((((((((((((((((((((( Files Created from 2007-10-25 to 2007-11-25 )))))))))))))))))))))))))))))))
.

2007-11-24 19:01 d——– C:\VundoFix Backups
2007-11-24 18:14 d——– C:\hijackthis
2007-11-24 18:05 212,849 –a—— C:\hijackthis.zip
2007-11-24 17:58 d——– C:\Program Files\Trend Micro
2007-11-20 15:08 84,544 –a—— C:\WINDOWS\SYSTEM32\ymqkscbq.dll
2007-11-19 22:11 28,672 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\CO_Mon.sys
2007-11-19 18:04 d——– C:\WINDOWS\ERUNT
2007-11-19 17:33 d——– C:\SmitfraudFix
2007-11-19 17:33 53,248 –a—— C:\WINDOWS\SYSTEM32\Process.exe
2007-11-19 17:33 51,200 –a—— C:\WINDOWS\SYSTEM32\dumphive.exe
2007-11-19 15:24 166,064 –a—— C:\FixVundo.exe
2007-11-19 15:17 0 –a—— C:\WINDOWS\nsreg.dat
2007-11-19 15:15 6,021,960 –a—— C:\Firefox Setup 2.0.0.9.exe
2007-11-19 15:13 83,008 –a—— C:\WINDOWS\SYSTEM32\smkfqxmw.dll
2007-11-19 15:05 685,772 –ahs—- C:\WINDOWS\SYSTEM32\ftxaaywv.ini
2007-11-19 13:43 d——– C:\Documents and Settings\Administrator\Application Data\Lavasoft
2007-11-18 21:44 1,208,753 –a—— C:\SDFix.exe
2007-11-18 02:10 678,229 –ahs—- C:\WINDOWS\SYSTEM32\jlhhjupn.ini
2007-11-18 02:10 84,545 –a—— C:\WINDOWS\SYSTEM32\npujhhlj.dll
2007-11-17 00:43 d——– C:\WINDOWS\SYSTEM32\rMa02yy
2007-11-17 00:43 d——– C:\Temp\abW9
2007-11-17 00:43 d——– C:\Temp
2007-11-14 20:21 d——– C:\Program Files\iTunes

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-25 00:45 ——— d—–w C:\Program Files\Symantec AntiVirus
2007-11-22 03:46 ——— d—–w C:\Program Files\DC++
2007-11-19 23:39 3,092 —-a-w C:\WINDOWS\SYSTEM32\tmp.reg
2007-11-19 20:04 84,545 —-a-w C:\WINDOWS\SYSTEM32\vwyaaxtf.dll
2007-11-19 20:00 ——— d—–w C:\Documents and Settings\Timothy Chow\Application Data\WeatherBug
2007-11-18 07:05 79,424 —-a-w C:\WINDOWS\SYSTEM32\tgiyvebe.dll
2007-11-15 01:22 ——— d—–w C:\Program Files\iPod
2007-11-15 01:19 ——— d—–w C:\Program Files\QuickTime
2007-11-06 07:00 ——— d—–w C:\Program Files\PartyGaming
2007-11-02 13:56 ——— d—–w C:\Documents and Settings\Timothy Chow\Application Data\AdobeUM
2007-10-20 04:30 ——— d—–w C:\Program Files\LimeWire
2007-10-04 04:36 25,600 —-a-w C:\WINDOWS\SYSTEM32\WS2Fix.exe
2007-09-06 04:22 289,144 —-a-w C:\WINDOWS\SYSTEM32\VCCLSID.exe
2004-09-25 01:27 56 –sh–r C:\WINDOWS\SYSTEM32\074F3A68F3.sys
2004-09-25 01:27 1,682 -csha-w C:\WINDOWS\SYSTEM32\KGyGaAvL.sys
2005-09-29 12:13 426,292 -csha-w C:\WINDOWS\SYSTEM32\klnnn.bak1
2005-10-13 14:33 337,490 -csha-w C:\WINDOWS\SYSTEM32\klnnn.bak2
2005-10-13 20:22 337,269 -csha-w C:\WINDOWS\SYSTEM32\klnnn.ini2
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CFB54076-0D5A-4B75-856B-D1932025AAF4}]
C:\WINDOWS\system32\yayyv.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56]
"Weather"="C:\Program Files\AWS\WeatherBug\Weather.exe" [2005-06-07 12:58]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-04 16:52]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nwiz"="nwiz.exe" [2004-10-26 12:01 C:\WINDOWS\SYSTEM32\nwiz.exe]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-02-02 15:32]
"bascstray"="BascsTray.exe" []
"PRONoMgr.exe"="C:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe" [2003-12-19 12:49]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2004-03-04 20:59]
"DVDSentry"="C:\WINDOWS\System32\DSentry.exe" [2002-07-17 10:18]
"AdaptecDirectCD"="C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-12-17 12:28]
"AWMON"="C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe" []
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-01-13 01:24]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe" [2005-04-13 02:48]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-11-21 16:38]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2007-03-14 18:49]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-10-19 20:16]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-02 18:36]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-04 02:56 C:\WINDOWS\SYSTEM32\rundll32.exe]

[hklm\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"= C:\Program Files\Bear Access\winba\eudora\EuShlExt.dll [ ]
C:\WINDOWS\system32\NavLogon.dll 2007-03-14 18:49 43712 C:\WINDOWS\SYSTEM32\NavLogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\nnnlk]
C:\WINDOWS\system32\nnnlk.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Sebring]
C:\WINDOWS\System32\LgNotify.dll 2004-01-13 15:17 110592 C:\WINDOWS\SYSTEM32\LgNotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wuauserv"=2 (0x2)
"ose"=3 (0x3)
"MDM"=2 (0x2)

R2 BASFND;BASFND;\??\C:\WINDOWS\system32\Drivers\BASFND.sys
R3 GTICARD;GTICARD;C:\WINDOWS\system32\DRIVERS\gticard.sys
S3 SQLAgent$MICROSOFTBCM;SQLAgent$MICROSOFTBCM;C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlagent.EXE -i MICROSOFTBCM

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6b633110-9dc3-11db-97e9-000e3527b4ac}]
\Shell\AutoRun\command - E:\wd_windows_tools\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b8645b70-cc70-11db-984f-000e3527b4ac}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Boot.exe e
\Shell\Open\command - Boot.exe e

.
Contents of the 'Scheduled Tasks' folder
"2007-11-15 01:14:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-24 19:50:38
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-24 19:51:16
.
— E O F —

HiJack:
Logfile of HijackThis v1.99.1
Scan saved at 7:54:45 PM, on 11/24/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\System32\1XConfig.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\System32\basfipm.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Timothy Chow\Desktop\hijackthis\killer.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: (no name) - {CFB54076-0D5A-4B75-856B-D1932025AAF4} - C:\WINDOWS\system32\yayyv.dll (file missing)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [bascstray] BascsTray.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: nnnlk - C:\WINDOWS\system32\nnnlk.dll (file missing)
O20 - Winlogon Notify: Sebring - C:\WINDOWS\System32\LgNotify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Broadcom ASF IP monitoring service v6.0.3 (BAsfIpM) - Broadcom Corp. - C:\WINDOWS\System32\basfipm.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

Pesky desktop icons have disappeared. Am I virus free? Also, I just have a question about th infection. I have sensitive info stored on my comp, were the infections that I have able to pull that info/or files from my computer? If you could tell me what kind of infections I had that would be great also. Also, any recommendations for future protection. I already have spybot, ad-aware, and symantec…but all of those seem useless. Thank you again!
Yes there are still infected files on your system. We will start removing these now. Nothing "appears" to be info theft threatening. Your main infection was the Vundo Trojan. If you have sensitive data on your system, you should stay away from file sharing programs in general which are notorious for increasing the risk of ending up with a contaminated system.

I need to know if this system is networked

A. Using the Add/Remove Program module in your Control Panel, please UNINSTALL the following program:

PartyPoker

Justification for this action can be found here: http://www.bleepingcomputer.com/uninstall/Cat-P.html


B. 1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.

2. Now copy/paste the entire content of the codebox below into the Notepad window:

KillAll::

File::
C:\WINDOWS\SYSTEM32\ymqkscbq.dll
C:\FixVundo.exe
C:\SDFix.exe
C:\WINDOWS\SYSTEM32\jlhhjupn.ini
C:\WINDOWS\SYSTEM32\npujhhlj.dll
C:\WINDOWS\SYSTEM32\smkfqxmw.dll
C:\WINDOWS\SYSTEM32\ftxaaywv.ini
C:\WINDOWS\SYSTEM32\vwyaaxtf.dll
C:\WINDOWS\SYSTEM32\klnnn.bak1
C:\WINDOWS\SYSTEM32\klnnn.bak2
C:\WINDOWS\SYSTEM32\klnnn.ini2
C:\WINDOWS\SYSTEM32\WS2Fix.exe
C:\WINDOWS\SYSTEM32\VCCLSID.exe
C:\WINDOWS\SYSTEM32\074F3A68F3.sys
C:\WINDOWS\SYSTEM32\tgiyvebe.dll

Folder::
C:\SmitfraudFix
C:\WINDOWS\SYSTEM32\rMa02yy
C:\Temp\abW9
C:\Program Files\PartyGaming

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CFB54076-0D5A-4B75-856B-D1932025AAF4}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"bascstray"=-
"AWMON"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\nnnlk]


3. Now physically disconnect from the internet and STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields)


4. Save the above as CFScript.txt

5. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


6. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.

6. When finished, it will produce a log. Please save that log to a Notepad File to post in your next reply along with a fresh HJT log.

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

* After you have saved the logs, restart your system to re-enable all the programs that were disabled during the running of ComboFix.

* Reconnect to the internet

* Post the following logs/Reports:
  • An answer to my question
  • ComboFix.txt
  • Fresh HijackThis log run after all the other tools have performed their cleanup.
Yes, I'm networked with my desktop.

ComboFix 07-11-19.3 - 2007-11-24 21:10:32.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.186 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Timothy Chow\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\FixVundo.exe
C:\SDFix.exe
C:\WINDOWS\SYSTEM32\074F3A68F3.sys
C:\WINDOWS\SYSTEM32\ftxaaywv.ini
C:\WINDOWS\SYSTEM32\jlhhjupn.ini
C:\WINDOWS\SYSTEM32\klnnn.bak1
C:\WINDOWS\SYSTEM32\klnnn.bak2
C:\WINDOWS\SYSTEM32\klnnn.ini2
C:\WINDOWS\SYSTEM32\npujhhlj.dll
C:\WINDOWS\SYSTEM32\smkfqxmw.dll
C:\WINDOWS\SYSTEM32\tgiyvebe.dll
C:\WINDOWS\SYSTEM32\VCCLSID.exe
C:\WINDOWS\SYSTEM32\vwyaaxtf.dll
C:\WINDOWS\SYSTEM32\WS2Fix.exe
C:\WINDOWS\SYSTEM32\ymqkscbq.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\FixVundo.exe
C:\Program Files\PartyGaming
C:\Program Files\PartyGaming\images\habeas_webseal.gif
C:\Program Files\PartyGaming\INSTALL.LOG
C:\Program Files\PartyGaming\Language\en_US\lang_pack_en_US.txt
C:\Program Files\PartyGaming\MFC42LU.DLL
C:\Program Files\PartyGaming\MSLUP60.dll
C:\Program Files\PartyGaming\MSLURT.dll
C:\Program Files\PartyGaming\PartyCasino\format.ini
C:\Program Files\PartyGaming\PartyCasino\Images\.#version.txt.1.17.2.14
C:\Program Files\PartyGaming\PartyCasino\Images\games\cardgames\blackjack\split_button.png
C:\Program Files\PartyGaming\PartyCasino\Images\games\cardgames\c95.gif
C:\Program Files\PartyGaming\PartyCasino\Images\games\cardgames\card_deck.bmp
C:\Program Files\PartyGaming\PartyCasino\Images\games\cardgames\pointer_R.gif
C:\Program Files\PartyGaming\PartyCasino\Images\games\cardgames\Rr.bmp
C:\Program Files\PartyGaming\PartyCasino\Images\games\cardgames\rules_button.jpg
C:\Program Files\PartyGaming\PartyCasino\Images\games\cashier_button.jpg
C:\Program Files\PartyGaming\PartyCasino\Images\games\exit_button.jpg
C:\Program Files\PartyGaming\PartyCasino\Images\games\game_topbar_pff.jpg
C:\Program Files\PartyGaming\PartyCasino\Images\games\gamebalance_free.jpg
C:\Program Files\PartyGaming\PartyCasino\Images\games\gamelogs_button.jpg
C:\Program Files\PartyGaming\PartyCasino\Images\games\version_button.jpg
C:\Program Files\PartyGaming\PartyCasino\Images\icon_three.gif
C:\Program Files\PartyGaming\PartyCasino\Images\icon_ticked.gif
C:\Program Files\PartyGaming\PartyCasino\Images\lhn_ani_refresh.gif
C:\Program Files\PartyGaming\PartyCasino\Images\lhn_bar_jackpot_numbers.gif
C:\Program Files\PartyGaming\PartyCasino\Images\lhn_bar_jackpot_numbers_small.gif
C:\Program Files\PartyGaming\PartyCasino\Images\loading.gif
C:\Program Files\PartyGaming\PartyCasino\Images\lobby\version.txt
C:\Program Files\PartyGaming\PartyCasino\Images\lobbyconfig.txt
C:\Program Files\PartyGaming\PartyCasino\Images\sys_icons.jpg
C:\Program Files\PartyGaming\PartyCasino\Images\system_but_bets.jpg
C:\Program Files\PartyGaming\PartyCasino\Images\system_but_bingo.jpg
C:\Program Files\PartyGaming\PartyCasino\Images\system_but_gammon.jpg
C:\Program Files\PartyGaming\PartyCasino\Images\Thumbs.db
C:\Program Files\PartyGaming\PartyCasino\Images\version.jar
C:\Program Files\PartyGaming\PartyCasino\language\allLangVersion.txt
C:\Program Files\PartyGaming\PartyCasino\language\de_DE\closewindow.html
C:\Program Files\PartyGaming\PartyCasino\language\de_DE\closewindow.swf
C:\Program Files\PartyGaming\PartyCasino\language\de_DE\images\but.bmp
C:\Program Files\PartyGaming\PartyCasino\language\de_DE\images\but_account.bmp
C:\Program Files\PartyGaming\PartyCasino\language\de_DE\images\client_top.jpg
C:\Program Files\PartyGaming\PartyCasino\language\de_DE\images\lhn_bar_jackpot.jpg
C:\Program Files\PartyGaming\PartyCasino\language\de_DE\images\lhn_bar_jackpot_numbers.jpg
C:\Program Files\PartyGaming\PartyCasino\language\de_DE\lang_pack_de_DE.txt
C:\Program Files\PartyGaming\PartyCasino\language\de_DE\PartyCasinoRes.dll
C:\Program Files\PartyGaming\PartyCasino\language\en_US\articles\6.html
C:\Program Files\PartyGaming\PartyCasino\language\en_US\closewindow.html
C:\Program Files\PartyGaming\PartyCasino\language\en_US\closewindow.swf
C:\Program Files\PartyGaming\PartyCasino\language\en_US\format.ini
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\account_but_newacocunt.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\account_button_background.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\active_popup-bottom.JPG
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\active_popup-bottomleft.gif
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\active_popup-bottomleft.JPG
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\active_popup-bottomright.gif
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\active_popup-bottomright.JPG
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\active_popup-left.JPG
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\active_popup-right.JPG
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\active_title-background.JPG
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\active_title-topleft.gif
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\active_title-topleft.JPG
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\active_title-topright.gif
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\active_title-topright.JPG
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\allversion.txt
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\but.bmp
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\but_account.bmp
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\but_skin.gif
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\but_skin_account.gif
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\client_bottom.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\client_bottom_right.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\client_gradient.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\client_lobby_left.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\client_lobby_right.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\client_top.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\connect_screen_bg.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\addplaymoney_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\aud.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\autospincancel_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\autospinoptions_background.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\autospinstart_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\balance_strip.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\but_skin.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\buyin_botbg.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\buyin_cancelbutton.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\buyin_cashierbutton.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\buyin_midbg.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\buyin_okbutton.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\buyin_topbg.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\BuyInConfig.ini
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cad.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\6_bigcardback.bmp
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\bj_check.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\bjbar_americanroulette_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\bjbar_baccarat_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\bjbar_bjbonuspairs_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\bjbar_bjhighlimit_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\bjbar_bjsingledeck_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\bjbar_boardbabe_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\bjbar_cashcruise_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\bjbar_casinowar_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\bjbar_coolbanana_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\bjbar_deuceswild_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\bjbar_europeanroulette_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\bjbar_firedrake_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\bjbar_flamingo_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\bjbar_fruitparty_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\bjbar_goannagold_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\bjbar_goldenoasis_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\bjbar_graveyardbash_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\bjbar_hotjokerpoker_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\bjbar_hotroller_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\bjbar_job_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\bjbar_junglerumble_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\bjbar_kangacash_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\bjbar_kookakeno_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\bjbar_lir_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\bjbar_logo_cover.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\bjbar_magicman_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\bjbar_mhvp_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\bjbar_paigow_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\bjbar_pc_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\bjbar_pcp_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\bjbar_piggypayback_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\bjbar_predator_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\bjbar_reddog_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\bjbar_safecrackerkeno_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\bjbar_sfw_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\bjbar_silvercity_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\bjbar_superjoker_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\bjbar_supermystic_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\bjbar_superstar_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\bjbar_sweethawaii_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\bjbar_tcp_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\bjbar_tod_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\bjbar_vegasclub_icon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\BlackJack.dll
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\blackjack.wav
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\blackjack\bj_table.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\blackjack\Config.ini
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\blackjack\pff_betinfo.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\blackjack\version.txt
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\chip_pointer_R.gif
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\chip1_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\chip100_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\chip25_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\chip5_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\chip500_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\clear_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\deal_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\double_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\hit_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\insurance.wav
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\insure_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\number_circle.gif
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\pointer_R.gif
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\push.wav
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\repeatbet_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\result_bj.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\result_bust.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\result_insure.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\result_lost.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\result_push.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\result_won.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\split.wav
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\split_button.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\stand_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\surrender_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\blackjack\version.txt
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\c0_5.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\c1.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\c10.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\c100.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\c100k.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\c10k.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\c1k.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\c2_5k.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\c25.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\c250.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\c25k.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\c5.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\c50.gif
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\c50.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\c500.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\c500k.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\c50k.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\c5k.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\c95.gif
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\Card.wav
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\card_deck.bmp
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\CardFlip.wav
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\d1.gif
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\d100.gif
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\d1000.gif
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\d1k.gif
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\d2000.gif
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\d25.gif
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\d2k.gif
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\d5.gif
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\d50.gif
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\d500.gif
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\d5000.gif
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\d5k.gif
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\FRU_6_bigcardback.bmp
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\action_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\action_button.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\action_pending_panel.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\autostand.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\away_button.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\backcard.bmp
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\bj_check.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\blackjack.wav
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\card_pointer.gif
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\card_pointer.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\check_box.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\chip_pointer.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\chip1_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\chip100_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\chip25_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\chip5_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\chip500_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\clear_button.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\CommonConfig.ini
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\deal_button.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\double_button.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\first_hand.gif
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\first_hand.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\FRU_backcard.bmp
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\game_topbar_pff.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\hit_button.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\iam_back_button.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\insurance.wav
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\last_of_all.gif
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\leave_seat_button.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\looser.rgn
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\looser_popup.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\mpbj_deck.bmp
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\MultiHandBJConfig.ini
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\MultiHandBJTrnyConfig.ini
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\multiplayerbj.dll
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\multiplayerblackjack\mpbj_table.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\multiplayerblackjack\mpbj_trny_table.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\multiplayerblackjack\sp_mpbj_table.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\multiplayerblackjack\version.txt
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\number_circle.gif
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\player_area.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\push.wav
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\repeatbet_button.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\result_bj.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\result_bust.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\result_push.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\result_won.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\sittingout_button.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\skip_button.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\split.wav
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\split_button.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\stand_button.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\steppedout_button.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\surrender_button.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\take_seat_button.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\title_tourneybuyin.gif
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\trny_player_area.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\trny_watcher_area.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\version.txt
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\watcher_area.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\winner.rgn
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\winners_closebutton.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\multiplayerbj\winners_popup.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\number_circle.gif
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\pointer_R.gif
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\rc0_5.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\rc1.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\rc10.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\rc100.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\rc100k.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\rc10k.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\rc1k.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\rc2_5k.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\rc25.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\rc250.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\rc25k.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\rc5.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\rc50.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\rc500.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\rc500k.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\rc50k.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\rc5k.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\Rr.bmp
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\rules_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cardgames\version.txt
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cashier_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cashout_midbg.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\cent_strip.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\chf.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\chips.wav
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\czk.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\dkk.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\eur.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\exit_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\format.ini
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\game_topbar_pff.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\gamebalance_free.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\gamelogs_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\gbp.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\hkd.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\huf.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\ils.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\inr.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\jpy.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\krw.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\myr.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\nok.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\nzd.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\php.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\pln.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\popup_but_cancel.gif
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\popup_but_cashier.gif
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\popup_but_ok.gif
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\popup_but_playmoney.gif
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\popup_buyin_box.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\popup_buyin_but_all.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\popup_buyin_tab.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\popup_buyin_top.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\PushBut.wav
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\ron.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\rur.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\sek.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\sgd.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\skk.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\status_dlg.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\sys_icons.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\system_but_close.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\system_but_inactive_close.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\system_but_inactive_minimise.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\system_but_minimise.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\thb.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\trny_buyin_botbg.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\try.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\twd.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\usd.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\version.txt
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\version_button.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\win.wav
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\games\zar.png
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\icon_three.gif
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\icon_ticked.gif
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\inactive_popup-bottom.JPG
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\inactive_popup-bottomleft.gif
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\inactive_popup-bottomleft.JPG
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\inactive_popup-bottomright.gif
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\inactive_popup-bottomright.JPG
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\inactive_popup-left.JPG
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\inactive_popup-right.JPG
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\inactive_title-background.JPG
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\inactive_title-left.gif
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\inactive_title-left.JPG
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\inactive_title-right.gif
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\inactive_title-right.JPG
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\jackpotwin_bg.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\lhn_account_background.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\lhn_account_divider.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\lhn_ani_refresh.gif
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\lhn_bar_jackpot.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\lhn_bar_jackpot_numbers.gif
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\lhn_bar_jackpot_numbers.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\lhn_bar_jackpot_numbers_small.gif
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\lhn_bar_news.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\lhn_but_cashout.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\lhn_but_deposit.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\lhn_but_deposit_large.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\lhn_but_options.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\lhn_but_redeem.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\lhn_but_refresh.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\lhn_but_reload_play.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\lhn_but_status.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\lhn_details_open.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\lhn_link_arrow.gif
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\lhn_tab_background.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\loading.gif
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\lobby\lobbyconfig.txt
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\lobbyconfig.txt
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\menu_01_myaccount.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\menu_02_cashier.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\menu_03_news.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\menu_04_rules.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\menu_05_tellfriend.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\menu_06_about.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\menu_07_help.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\PartyCasino.ico
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\popup_login_bottom.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\popup_login_top.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\popup_register_bottomleft.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\popup_register_top.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\skin.bmp
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\skin_account.bmp
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\sys_icons.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\system_but_bets.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\system_but_bingo.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\system_but_cashier.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\system_but_close.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\system_but_connected.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\system_but_gammon.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\system_but_inactive_close.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\system_but_inactive_minimise.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\system_but_login.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\system_but_minimise.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\system_but_poker.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\system_but_security.jpg
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\title_changevalidateemail.gif
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\title_chgpwd.gif
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\title_weak_password.gif
C:\Program Files\PartyGaming\PartyCasino\language\en_US\images\version.txt
C:\Program Files\PartyGaming\PartyCasino\language\en_US\lang_pack_en_US.txt
C:\Program Files\PartyGaming\PartyCasino\language\en_US\version.txt
C:\Program Files\PartyGaming\PartyCasino\language\es_ES\images\but.bmp
C:\Program Files\PartyGaming\PartyCasino\language\es_ES\images\but_account.bmp
C:\Program Files\PartyGaming\PartyCasino\language\es_ES\images\client_top.jpg
C:\Program Files\PartyGaming\PartyCasino\language\es_ES\images\lhn_bar_jackpot.jpg
C:\Program Files\PartyGaming\PartyCasino\language\es_ES\images\lhn_bar_jackpot_numbers.jpg
C:\Program Files\PartyGaming\PartyCasino\language\es_ES\lang_pack_es_ES.txt
C:\Program Files\PartyGaming\PartyCasino\language\version.txt
C:\Program Files\PartyGaming\PartyCasino\lobbyconfig.txt
C:\Program Files\PartyGaming\PartyCasino\pc_uninstall.bat
C:\Program Files\PartyGaming\PartyCasino\ProductVersion.txt
C:\Program Files\PartyGaming\PartyCasino\sys.ini
C:\Program Files\PartyGaming\PartyCasino\version.txt
C:\Program Files\PartyGaming\PartyGaming.RPT
C:\Program Files\PartyGaming\PartyPoker\6001145.hhf
C:\Program Files\PartyGaming\PartyPoker\Articles\1.html
C:\Program Files\PartyGaming\PartyPoker\Articles\1007.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\107.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1371.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\157.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1753.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1757.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1795.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1797.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1799.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1801.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1803.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1837.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1947.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1949.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1953.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\1955.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\205.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\225.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\227.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2329.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\233.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2333.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\235.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2445.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2455.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2487.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\257.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\2581.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\279.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\283.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\285.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\287.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\29.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\3.html
C:\Program Files\PartyGaming\PartyPoker\Articles\321.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\323.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\325.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\367.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\371.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\379.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\387.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\391.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\397.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\405.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\409.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\4255.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\451.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\453.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\457.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\467.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\525.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\533.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\539.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\541.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\593.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\595.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\597.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\607.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\6331.html
C:\Program Files\PartyGaming\PartyPoker\Articles\6333.html
C:\Program Files\PartyGaming\PartyPoker\Articles\6417.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\6427.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\6433.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\6435.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\6437.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\6459.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\6483.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\6485.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\6489.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\6495.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\6497.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\6503.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\6505.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\6511.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\6553.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\667.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\685.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\695.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\735.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\737.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\77.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\79.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\809.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\877.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\907.atc
C:\Program Files\PartyGaming\PartyPoker\Articles\97.atc
C:\Program Files\PartyGaming\PartyPoker\Images\468x60_DefaultBanner.gif
C:\Program Files\PartyGaming\PartyPoker\Images\728x90_DefaultBanner.gif
C:\Program Files\PartyGaming\PartyPoker\Images\but_joinlist_number.jpg
C:\Program Files\PartyGaming\PartyPoker\Images\but_unjoinlist_number.jpg
C:\Program Files\PartyGaming\PartyPoker\Images\buyin_popup_okbg.jpg
C:\Program Files\PartyGaming\PartyPoker\Images\Cashier_button.gif
C:\Program Files\PartyGaming\PartyPoker\Images\close_EM_button.gif
C:\Program Files\PartyGaming\PartyPoker\Images\fold_to_off.jpg
C:\Program Files\PartyGaming\PartyPoker\Images\fold_to_on.jpg
C:\Program Files\PartyGaming\PartyPoker\Images\icon_three.gif
C:\Program Files\PartyGaming\PartyPoker\Images\icon_ticked.gif
C:\Program Files\PartyGaming\PartyPoker\Images\lhn_ani_refresh.gif
C:\Program Files\PartyGaming\PartyPoker\Images\lhn_bar_jackpot_numbers_small.gif
C:\Program Files\PartyGaming\PartyPoker\Images\lhn_bar_prize.jpg
C:\Program Files\PartyGaming\PartyPoker\Images\menu_background.jpg
C:\Program Files\PartyGaming\PartyPoker\Images\Payout_background.bmp
C:\Program Files\PartyGaming\PartyPoker\Images\popup.css
C:\Program Files\PartyGaming\PartyPoker\Images\popup_logo_monster.jpg
C:\Program Files\PartyGaming\PartyPoker\Images\popup_logo_monster_buyin.jpg
C:\Program Files\PartyGaming\PartyPoker\Images\pp_logo_small.jpg
C:\Program Files\PartyGaming\PartyPoker\Images\prize_numbers.jpg
C:\Program Files\PartyGaming\PartyPoker\Images\strip.jpg
C:\Program Files\PartyGaming\PartyPoker\Images\system_but_bets.jpg
C:\Program Files\PartyGaming\PartyPoker\Images\system_but_bingo.jpg
C:\Program Files\PartyGaming\PartyPoker\Images\system_but_gammon.jpg
C:\Program Files\PartyGaming\PartyPoker\Images\t_logout.jpg
C:\Program Files\PartyGaming\PartyPoker\Images\table_jp_pin.jpg
C:\Program Files\PartyGaming\PartyPoker\Images\table_jp_pin_tacked.jpg
C:\Program Files\PartyGaming\PartyPoker\Images\table_prize_dollar.bmp
C:\Program Files\PartyGaming\PartyPoker\Images\table_prize_dollar_comma.bmp
C:\Program Files\PartyGaming\PartyPoker\Images\table_prize_label.jpg
C:\Program Files\PartyGaming\PartyPoker\Images\table_prize_pin.jpg
C:\Program Files\PartyGaming\PartyPoker\Images\table_prize_pin_tacked.jpg
C:\Program Files\PartyGaming\PartyPoker\Images\table_prize_stip_bottom.bmp
C:\Program Files\PartyGaming\PartyPoker\Images\table_prize_stip_left.bmp
C:\Program Files\PartyGaming\PartyPoker\Images\table_prize_stip_right.bmp
C:\Program Files\PartyGaming\PartyPoker\Images\table_prize_stip_top.bmp
C:\Program Files\PartyGaming\PartyPoker\Images\timer.gif
C:\Program Files\PartyGaming\PartyPoker\Images\title_add_take_money.gif
C:\Program Files\PartyGaming\PartyPoker\Images\titlebar_chip.jpg
C:\Program Files\PartyGaming\PartyPoker\Images\tree_listing_background_SB.jpg
C:\Program Files\PartyGaming\PartyPoker\Images\tree_main_background_SB.jpg
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\10285.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\10287.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\10299.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\10301.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\10303.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\10305.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\10437.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\10509.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\10511.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\10521.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\10523.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\10749.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\10751.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\10753.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\12741.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\12743.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\12763.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\12845.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\12871.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\12875.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\12879.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\12915.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\14895.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\14897.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\14899.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\16891.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\16895.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\16991.html
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\16997.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\17007.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\17049.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\17051.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\17061.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\17097.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\17099.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\17109.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\17143.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\18869.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\18871.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\18877.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\2.html
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\20891.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\20899.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\20907.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\20909.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\22873.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\22879.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\22953.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\4.html
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\54708.html
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\6331.html
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\6333.html
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\64759.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\64761.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\66983.html
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\67039.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\67041.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\8257.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\8261.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\8263.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\8265.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\8267.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\8321.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\8323.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\8325.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\8363.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\8385.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\8387.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\8391.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\8395.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\8465.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\articles\94242.atc
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\bulletin_background.jpg
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\bulletin_box_background.jpg
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\bulletin_nav_background.jpg
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\bulletin_nav_buttons.jpg
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\but_help.jpg
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\client_top.jpg
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\congratulations.gif
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\conn.gif
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\conn_lost.gif
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\connect_screen_bg.jpg
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\down_arrow.gif
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\down_arrow_o.gif
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\help_background.jpg
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\help_background_SB.jpg
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\help_but_continue.jpg
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\highcarding.gif
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\JP_Other_Popup_BG.jpg
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\lhn_bar_blackjack.jpg
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\lhn_bar_news.jpg
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\lhn_but_cashout.jpg
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\lhn_but_deposit.jpg
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\lhn_but_deposit_large.jpg
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\lhn_but_redeem.jpg
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\lhn_but_reload_play.jpg
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\lhn_but_status.jpg
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\loading.gif
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\OtherPayouts.jpg
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\out.gif
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\PayoutInfo.jpg
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\payouts.jpg
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\popup_login_bottom.jpg
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\pp_tourney_banner_default.jpg
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\SideBetClose.bmp
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\SideBetCloseBet.bmp
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\SideBetOpen.bmp
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\SideBetOpenBet.bmp
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\SideBetOpenBetNoborder.bmp
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\SidebetOpenNoborder.bmp
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\spacer.gif
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\t_shootout_grid.gif
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\tab_description.jpg
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\tab_game_info.jpg
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\tab_players.jpg
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\tab_players_right.jpg
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\tab_three_first.jpg
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\tab_three_second.jpg
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\tab_three_third.jpg
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\tab_tournament_info.jpg
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\ticker_bg.jpg
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\tourn_congrats.gif
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\tourneylobby.jpg
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\tree_but_filtercash.jpg
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\tree_but_filtershowall.jpg
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\tree_but_filtertournaments.jpg
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\up_arrow.gif
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\up_arrow_o.gif
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\images\you_win.bmp
C:\Program Files\PartyGaming\PartyPoker\Language\en_US\lang_pack_en_US.txt
C:\Program Files\PartyGaming\PartyPoker\llh.dll
C:\Program Files\PartyGaming\PartyPoker\Notes.txt
C:\Program Files\PartyGaming\PartyPoker\Sys.ini
C:\Program Files\PartyGaming\PartyPoker\Temp\art30.htm
C:\Program Files\PartyGaming\PartyPoker\tmpUpgrade\INSTALL.LOG
C:\Program Files\PartyGaming\PartyPoker\tmpUpgrade\upgradepp105-106man.exe
C:\Program Files\PartyGaming\PartyPoker\tmpUpgrade\upgradepp106-107man.exe
C:\Program Files\PartyGaming\PartyPoker\tmpUpgrade\upgradepp107-108man.exe
C:\Program Files\PartyGaming\PartyPoker\tmpUpgrade\upgradepp108-109man.exe
C:\Program Files\PartyGaming\PartyPoker\tmpUpgrade\upgradepp109-110man.exe
C:\Program Files\PartyGaming\PartyPoker\tmpUpgrade\upgradepp110-111man.exe
C:\Program Files\PartyGaming\PartyPoker\tmpUpgrade\upgradepp111-112man.exe
C:\Program Files\PartyGaming\PartyPoker\tmpUpgrade\upgradepp112-113man.exe
C:\Program Files\PartyGaming\PartyPoker\tmpUpgrade\upgradepp113-114man.exe
C:\Program Files\PartyGaming\PartyPoker\tmpUpgrade\upgradepp114-115man.exe
C:\Program Files\PartyGaming\PartyPoker\tmpUpgrade\upgradepp91-92man.exe
C:\Program Files\PartyGaming\PartyPoker\tmpUpgrade\upgradepp92-93man.exe
C:\Program Files\PartyGaming\PartyPoker\tmpUpgrade\upgradepp93-94sim.exe
C:\Program Files\PartyGaming\PartyPoker\tmpUpgrade\upgradepp94-95man.exe
C:\Program Files\PartyGaming\PartyPoker\tmpUpgrade\upgradepp95-96man.exe
C:\Program Files\PartyGaming\PartyPoker\tmpUpgrade\upgradepp96-97man.exe
C:\Program Files\PartyGaming\PartyPoker\tmpUpgrade\upgradepp97-98man.exe
C:\Program Files\PartyGaming\PartyPoker\TourneyDescription.html
C:\Program Files\PartyGaming\PartyPoker\Uninstall.exe
C:\Program Files\PartyGaming\PartyPoker\usertab.txt
C:\Program Files\PartyGaming\tmpUpgrade\INSTALL.LOG
C:\Program Files\PartyGaming\tmpUpgrade\upgradePG105-106man.exe
C:\Program Files\PartyGaming\tmpUpgrade\upgradePG106-107man.exe
C:\Program Files\PartyGaming\tmpUpgrade\upgradePG107-108man.exe
C:\Program Files\PartyGaming\tmpUpgrade\upgradePG108-109man.exe
C:\Program Files\PartyGaming\tmpUpgrade\upgradePG109-110man.exe
C:\Program Files\PartyGaming\tmpUpgrade\upgradePG110-111man.exe
C:\Program Files\PartyGaming\tmpUpgrade\upgradePG111-112man.exe
C:\Program Files\PartyGaming\tmpUpgrade\upgradePG112-113man.exe
C:\Program Files\PartyGaming\tmpUpgrade\upgradePG113-114man.exe
C:\Program Files\PartyGaming\tmpUpgrade\upgradePG115-116man.exe
C:\Program Files\PartyGaming\tmpUpgrade\upgradePG116-117man.exe
C:\Program Files\PartyGaming\tmpUpgrade\upgradePG91-92man.exe
C:\Program Files\PartyGaming\tmpUpgrade\upgradePG92-93man.exe
C:\Program Files\PartyGaming\tmpUpgrade\upgradePG93-94man.exe
C:\Program Files\PartyGaming\tmpUpgrade\upgradePG94-95man.exe
C:\Program Files\PartyGaming\tmpUpgrade\upgradePG95-96man.exe
C:\Program Files\PartyGaming\UNICOWS.DLL
C:\SDFix.exe
C:\SmitfraudFix
C:\SmitfraudFix\dumphive.exe
C:\SmitfraudFix\exit.exe
C:\SmitfraudFix\GenericRenosFix.exe
C:\SmitfraudFix\HostsChk.exe
C:\SmitfraudFix\Process.exe
C:\SmitfraudFix\Reboot.exe
C:\SmitfraudFix\restart.exe
C:\SmitfraudFix\SmitfraudFix.cmd
C:\SmitfraudFix\SmiUpdate.exe
C:\SmitfraudFix\SrchSTS.exe
C:\SmitfraudFix\swreg.exe
C:\SmitfraudFix\swsc.exe
C:\SmitfraudFix\swxcacls.exe
C:\SmitfraudFix\unzip.exe
C:\SmitfraudFix\VCCLSID.exe
C:\SmitfraudFix\WS2Fix.exe
C:\Temp\abW9
C:\WINDOWS\SYSTEM32\074F3A68F3.sys
C:\WINDOWS\SYSTEM32\ftxaaywv.ini
C:\WINDOWS\SYSTEM32\jlhhjupn.ini
C:\WINDOWS\SYSTEM32\klnnn.bak1
C:\WINDOWS\SYSTEM32\klnnn.bak2
C:\WINDOWS\SYSTEM32\klnnn.ini2
C:\WINDOWS\SYSTEM32\npujhhlj.dll
C:\WINDOWS\SYSTEM32\rMa02yy
C:\WINDOWS\SYSTEM32\smkfqxmw.dll
C:\WINDOWS\SYSTEM32\tgiyvebe.dll
C:\WINDOWS\SYSTEM32\VCCLSID.exe
C:\WINDOWS\SYSTEM32\vwyaaxtf.dll
C:\WINDOWS\SYSTEM32\WS2Fix.exe
C:\WINDOWS\SYSTEM32\ymqkscbq.dll

.
((((((((((((((((((((((((( Files Created from 2007-10-25 to 2007-11-25 )))))))))))))))))))))))))))))))
.

2007-11-24 19:01 d——– C:\VundoFix Backups
2007-11-24 18:14 d——– C:\hijackthis
2007-11-24 18:05 212,849 –a—— C:\hijackthis.zip
2007-11-24 17:58 d——– C:\Program Files\Trend Micro
2007-11-19 22:11 28,672 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\CO_Mon.sys
2007-11-19 18:04 d——– C:\WINDOWS\ERUNT
2007-11-19 17:34 3,092 –a—— C:\WINDOWS\SYSTEM32\tmp.reg
2007-11-19 17:34 0 –a—— C:\WINDOWS\SYSTEM32\tmp.txt
2007-11-19 17:33 288,417 –a—— C:\WINDOWS\SYSTEM32\SrchSTS.exe
2007-11-19 17:33 53,248 –a—— C:\WINDOWS\SYSTEM32\Process.exe
2007-11-19 17:33 51,200 –a—— C:\WINDOWS\SYSTEM32\dumphive.exe
2007-11-19 15:17 0 –a—— C:\WINDOWS\nsreg.dat
2007-11-19 15:15 6,021,960 –a—— C:\Firefox Setup 2.0.0.9.exe
2007-11-19 13:43 d——– C:\Documents and Settings\Administrator\Application Data\Lavasoft
2007-11-17 00:43 d——– C:\Temp
2007-11-14 20:21 d——– C:\Program Files\iTunes

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-25 02:16 ——— d—–w C:\Program Files\Symantec AntiVirus
2007-11-22 03:46 ——— d—–w C:\Program Files\DC++
2007-11-19 20:00 ——— d—–w C:\Documents and Settings\Timothy Chow\Application Data\WeatherBug
2007-11-15 01:22 ——— d—–w C:\Program Files\iPod
2007-11-15 01:19 ——— d—–w C:\Program Files\QuickTime
2007-11-02 13:56 ——— d—–w C:\Documents and Settings\Timothy Chow\Application Data\AdobeUM
2007-10-20 04:30 ——— d—–w C:\Program Files\LimeWire
2004-09-25 01:27 1,682 -csha-w C:\WINDOWS\SYSTEM32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((( snapshot@2007-11-24_19.50.39.48 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-11-25 02:16:31 16,384 —-atw C:\WINDOWS\Temp\Perflib_Perfdata_f8.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56]
"Weather"="C:\Program Files\AWS\WeatherBug\Weather.exe" [2005-06-07 12:58]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nwiz"="nwiz.exe" [2004-10-26 12:01 C:\WINDOWS\SYSTEM32\nwiz.exe]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-02-02 15:32]
"PRONoMgr.exe"="C:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe" [2003-12-19 12:49]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2004-03-04 20:59]
"DVDSentry"="C:\WINDOWS\System32\DSentry.exe" [2002-07-17 10:18]
"AdaptecDirectCD"="C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-12-17 12:28]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-01-13 01:24]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe" [2005-04-13 02:48]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-11-21 16:38]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2007-03-14 18:49]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-10-19 20:16]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-02 18:36]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-04 02:56 C:\WINDOWS\SYSTEM32\rundll32.exe]

[hklm\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"= C:\Program Files\Bear Access\winba\eudora\EuShlExt.dll [ ]
C:\WINDOWS\system32\NavLogon.dll 2007-03-14 18:49 43712 C:\WINDOWS\SYSTEM32\NavLogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\nnnlk]
C:\WINDOWS\system32\nnnlk.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Sebring]
C:\WINDOWS\System32\LgNotify.dll 2004-01-13 15:17 110592 C:\WINDOWS\SYSTEM32\LgNotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wuauserv"=2 (0x2)
"ose"=3 (0x3)
"MDM"=2 (0x2)

R2 BASFND;BASFND;\??\C:\WINDOWS\system32\Drivers\BASFND.sys
R3 GTICARD;GTICARD;C:\WINDOWS\system32\DRIVERS\gticard.sys
S3 SQLAgent$MICROSOFTBCM;SQLAgent$MICROSOFTBCM;C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlagent.EXE -i MICROSOFTBCM

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6b633110-9dc3-11db-97e9-000e3527b4ac}]
\Shell\AutoRun\command - E:\wd_windows_tools\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b8645b70-cc70-11db-984f-000e3527b4ac}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Boot.exe e
\Shell\Open\command - Boot.exe e

.
Contents of the 'Scheduled Tasks' folder
"2007-11-15 01:14:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-24 21:17:12
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-24 21:18:36 - machine was rebooted
C:\ComboFix2.txt … 2007-11-24 19:51
.
— E O F —

MY HIJACKTHIS LOG:

Logfile of HijackThis v1.99.1
Scan saved at 9:20:03 PM, on 11/24/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\1XConfig.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\System32\basfipm.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\Timothy Chow\Desktop\hijackthis\killer.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: nnnlk - C:\WINDOWS\system32\nnnlk.dll (file missing)
O20 - Winlogon Notify: Sebring - C:\WINDOWS\System32\LgNotify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Broadcom ASF IP monitoring service v6.0.3 (BAsfIpM) - Broadcom Corp. - C:\WINDOWS\System32\basfipm.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
A. Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. A malicious site could render Java content under older, vulnerable versions of Sun's software if the user has not removed them. Please follow these steps to remove older version Java components and update:
  • Download the latest version of Java Runtime Environment (JRE) 6 Update 3 and save it to your desktop.
  • Scroll down to where it says "Java Runtime Environment (JRE) 6u3…allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Read the License Agreement and then check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Settings > Control Panel > Add/Remove Programs, double-click on and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u3-windows-i586-p.exe to install the newest version.

Now to Clean out the Java cache:

Go into the Control Panel and double-click the Java Icon.
  • Under Temporary Internet Files, click the Delete Files button.
  • There are three options in the window to clear the cache - Leave ALL 3 Checked
    • Downloaded Applets
      Downloaded Applications
      Other Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Java Control Panel.


B. Please make sure that you can view all hidden files. Instructions on how to do this can be found here:

How to see hidden files in Windows

Please click this link–>Jotti

When the jotti page has finished loading, click the browse button and navigate to the files listed below in bold, then click Submit. You will only be able to have one file scanned at a time.

E:\wd_windows_tools\setup.exe

then submit this one for analysis:

C:\WINDOWS\system32\boot.exe

Please post back the results of the scan in your next post.

If Jotti is busy, try the same at Virustotal: http://www.virustotal.com/


C. Please RUN HijackThis
  • Click the SCAN button to produce a log.

  • Place a check mark beside each one of the following items:

    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O20 - Winlogon Notify: nnnlk - C:\WINDOWS\system32\nnnlk.dll (file missing)


  • Now with all the items selected, and all windows closed except for HJT, delete them by clicking the FIX checked button. Close the HijackThis window.

  • Reboot Your System



D. Please use the Internet Explorer browser, and do an online scan with Kaspersky Online Scanner
Click Yes, when prompted to install its ActiveX component.
(Note.. for Internet Explorer 7 users: If at any time you have trouble with the "Accept" button of the license, click on the "Zoom" tool located at the bottom right of the IE window and set the zoom to 75 %. Once the license has been accepted, reset to 100%.)
The program launches and downloads the latest definition files.
  • Once the files are downloaded click on Next
  • Click on Scan Settings and configure as follows:
    • Scan using the following Anti-Virus database:
      • Extended
    • Scan Options:Scan Archives
      Scan Mail Bases
  • Click OK and, under select a target to scan, select My Computer
When the scan is done, in the Scan is completed window (below), any infection is displayed.
There is no option to clean/disinfect, however, we need to analyze the information on the report.
[external image: Posted Image]
[external image: Posted Image]
To obtain the report:
Click on: Save Report As (above - red blinking arrow)
Next, in the Save as prompt, Save in area, select: Desktop
In the File name area, use KScan, or something similar
In Save as type, click the drop arrow and select: Text file [*.txt]
Then, click: Save
Please post the Kaspersky Online Scanner Report in your reply, along with a fresh HijackThis log
I was unable to find both of these files E:\wd_windows_tools\setup.exe C:\WINDOWS\system32\boot.exe I did find a bootok.exe, bootcfg.exe, and a bootvrfy.exe <– all of which came out to be clean by a virustotalscan. I am performing a kaspersky online scan right now, going slow though but going. I also installed Java without a prob and did the HJT fixes.
:thumbup: Kaspersky will take some time to run. It is very thorough. I would recommend that you do a search on your machine for the following file "boot.exe" to see if it appears with a different path than the one I gave you.
While doing the scan, my symnatec antivirus popped up and warned me I was infected with trojan vundo again! (This happens whenever I use IE for a prolonged period of time, I have no clue why) This interrupted my scan and I eventually had to put it to a stop. However, it did find some viruses and here is the report along with my newest HJT. I was at 45% scanned, should I try again..if I do, I think I'll just keep getting infected with vundo.

——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Saturday, November 24, 2007 11:57:42 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 25/11/2007
Kaspersky Anti-Virus database records: 465197
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\

Scan Statistics:
Total number of scanned objects: 8173
Number of viruses found: 9
Number of infected objects: 24
Number of suspicious objects: 0
Duration of the scan process: 00:19:53

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\00C40000\47C73EED.VBN Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\05480002.VBN/backups/mrofinu77.exe Infected: Trojan-Downloader.Win32.Agent.fhv skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\05480002.VBN ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\05480002.VBN CryptZ: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\05740000\477EA683.VBN Infected: Trojan-Downloader.Win32.Agent.dxj skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\05740001\477EA69A.VBN Infected: Trojan-Downloader.Win32.VB.axa skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09800000\4FBFE5FB.VBN Infected: not-a-virus:Downloader.Win32.WinFixer.au skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09900000\4FBFE7B6.VBN Infected: not-a-virus:Downloader.Win32.WinFixer.au skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09900001\4FBFE8C9.VBN Infected: not-a-virus:Downloader.Win32.WinFixer.au skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D740000.VBN Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DA00000\4FE25016.VBN Infected: not-a-virus:Downloader.Win32.WinFixer.au skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DA00001\4FE25067.VBN Infected: not-a-virus:Downloader.Win32.WinFixer.au skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DA00002\4FE250AA.VBN Infected: not-a-virus:Downloader.Win32.WinFixer.au skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DA00003\4FE250E3.VBN Infected: not-a-virus:Downloader.Win32.WinFixer.au skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DA00004\4FE250F4.VBN Infected: not-a-virus:Downloader.Win32.WinFixer.au skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DA00005\4FE25221.VBN Infected: not-a-virus:Downloader.Win32.WinFixer.au skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DA00006\4FE2529D.VBN Infected: not-a-virus:Downloader.Win32.WinFixer.au skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DA00007\4FE252AC.VBN Infected: not-a-virus:Downloader.Win32.WinFixer.au skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DA00008\4FE252E3.VBN Infected: not-a-virus:Downloader.Win32.WinFixer.au skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F480000.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.apx skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0FD00000\4FFE7FC3.VBN Infected: Trojan-Downloader.Win32.VB.bto skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0FD00001\4FFE8073.VBN Infected: Trojan-Dropper.Win32.Agent.chq skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0FD00002\4FFE81EE.VBN Infected: not-a-virus:Downloader.Win32.WinFixer.au skipped
C:\Documents and Settings\LocalService\Cookies\INDEX.DAT Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Timothy Chow\.housecall\Quarantine\052[1].htm.bac_a03104 Infected: Trojan-Downloader.JS.Phel.d skipped
C:\Documents and Settings\Timothy Chow\Cookies\INDEX.DAT Object is locked skipped

Scan was interrupted by user!


Logfile of HijackThis v1.99.1
Scan saved at 11:59:34 PM, on 11/24/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\System32\basfipm.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\WINDOWS\System32\1XConfig.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\Timothy Chow\Desktop\hijackthis\killer.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: Sebring - C:\WINDOWS\System32\LgNotify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Broadcom ASF IP monitoring service v6.0.3 (BAsfIpM) - Broadcom Corp. - C:\WINDOWS\System32\basfipm.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
Your Vundo warnings appear to be coming from your different Antivirus Quarantines.

A. Using the Add\Remove Program feature in your Control Panel, please UNINSTALL the following program:

WeatherBug


Justification for the above can be found here:

http://www.bleepingcomputer.com/uninstall/…WeatherBug.html


Here is a similar program that is clean: http://tropicdesigns.net/weatherpulse.php


B. Now DELETE the following folder with all its content (If still present):

C:\PROGRAM Files\AWS


C. Once the above is finished, please make all files visible:

To enable the viewing of Hidden files follow these steps:

1. Close all programs so that you are at your desktop.
2. Double-click on the My Computer icon.
3. Select the Tools menu and click Folder Options.
4. After the new window appears select the View tab.
5. Put a checkmark in the checkbox labeled Display the contents of system folders.
6. Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
7. Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
8. Remove the checkmark from the checkbox labeled Hide protected operating system files.
9. Press the Apply button and then the OK button and shutdown My Computer.
10. Now your computer is configured to show all hidden files.


D. Now please empty your Symantec Antivirus Quarantine. If you are not sure of how to proceed, please follow the instructions found here:

http://www.upenn.edu/computing/virus/docs/…61/navce76u.pdf

In addition, please empty this quarantine also: C:\Documents and Settings\Timothy Chow\.housecall\Quarantine


E. Once the above is completed, try running Kaspersky again and post the results.


Trevuren
This was before I deleted my backup norton items: ——————————————————————————- KASPERSKY ONLINE SCANNER REPORT Sunday, November 25, 2007 1:35:23 AM Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.98.0 Kaspersky Anti-Virus database last update: 25/11/2007 Kaspersky Anti-Virus database records: 465197 ——————————————————————————- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: C:\ D:\ Scan Statistics: Total number of scanned objects: 61570 Number of viruses found: 11 Number of infected objects: 36 Number of suspicious objects: 0 Duration of the scan process: 01:19:44 Infected Object Name / Virus Name / Last Action C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\APQ578.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.apx skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\APQ6ED.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.apx skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\APQ71D.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.apx skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\APQ725.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.apx skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\APQ727.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.apx skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\APQ729.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.apx skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\00C40000\47C73EED.VBN Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\05480002.VBN/backups/mrofinu77.exe Infected: Trojan-Downloader.Win32.Agent.fhv skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\05480002.VBN ZIP: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\05480002.VBN CryptZ: infected - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\05740000\477EA683.VBN Infected: Trojan-Downloader.Win32.Agent.dxj skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\05740001\477EA69A.VBN Infected: Trojan-Downloader.Win32.VB.axa skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09800000\4FBFE5FB.VBN Infected: not-a-virus:Downloader.Win32.WinFixer.au skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09900000\4FBFE7B6.VBN Infected: not-a-virus:Downloader.Win32.WinFixer.au skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09900001\4FBFE8C9.VBN Infected: not-a-virus:Downloader.Win32.WinFixer.au skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0D740000.VBN Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DA00000\4FE25016.VBN Infected: not-a-virus:Downloader.Win32.WinFixer.au skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DA00001\4FE25067.VBN Infected: not-a-virus:Downloader.Win32.WinFixer.au skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DA00002\4FE250AA.VBN Infected: not-a-virus:Downloader.Win32.WinFixer.au skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DA00003\4FE250E3.VBN Infected: not-a-virus:Downloader.Win32.WinFixer.au skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DA00004\4FE250F4.VBN Infected: not-a-virus:Downloader.Win32.WinFixer.au skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DA00005\4FE25221.VBN Infected: not-a-virus:Downloader.Win32.WinFixer.au skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DA00006\4FE2529D.VBN Infected: not-a-virus:Downloader.Win32.WinFixer.au skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DA00007\4FE252AC.VBN Infected: not-a-virus:Downloader.Win32.WinFixer.au skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0DA00008\4FE252E3.VBN Infected: not-a-virus:Downloader.Win32.WinFixer.au skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0F480000.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.apx skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0FD00000\4FFE7FC3.VBN Infected: Trojan-Downloader.Win32.VB.bto skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0FD00001\4FFE8073.VBN Infected: Trojan-Dropper.Win32.Agent.chq skipped C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0FD00002\4FFE81EE.VBN Infected: not-a-virus:Downloader.Win32.WinFixer.au skipped C:\Documents and Settings\LocalService\Cookies\INDEX.DAT Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\Timothy Chow\.housecall\Quarantine\052[1].htm.bac_a03104 Infected: Trojan-Downloader.JS.Phel.d skipped C:\Documents and Settings\Timothy Chow\Cookies\INDEX.DAT Object is locked skipped C:\Documents and Settings\Timothy Chow\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Timothy Chow\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Timothy Chow\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped C:\Documents and Settings\Timothy Chow\Local Settings\History\History.IE5\MSHist012007112520071126\index.dat Object is locked skipped C:\Documents and Settings\Timothy Chow\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Timothy Chow\NTUSER.DAT Object is locked skipped C:\Documents and Settings\Timothy Chow\ntuser.dat.LOG Object is locked skipped C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBConfig.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDebug.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDetect.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBNotify.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBRefr.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg2.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetDev.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetLoc.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetUsr.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMNot.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMReg.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMRSt.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStHash.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStMSI.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBValid.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPPolicy.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStart.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStop.log Object is locked skipped C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Data\master.mdf Object is locked skipped C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Data\mastlog.ldf Object is locked skipped C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Data\model.mdf Object is locked skipped C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Data\modellog.ldf Object is locked skipped C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Data\tempdb.mdf Object is locked skipped C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Data\templog.ldf Object is locked skipped C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\LOG\ERRORLOG Object is locked skipped C:\Program Files\Symantec AntiVirus\SAVRT\0012NAV~.TMP Object is locked skipped C:\Program Files\Symantec AntiVirus\SAVRT\0030NAV~.TMP Object is locked skipped C:\qoobox\Quarantine\C\SmitfraudFix\Reboot.exe.vir Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\npujhhlj.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\vwyaaxtf.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP2\A0000241.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP2\A0000257.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP2\A0000261.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP6\change.log Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\EventCache\{D319F585-7C31-4D15-B358-CD95D7A2A87E}.bin Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\SYSTEM32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\SYSTEM32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\AppEvent.Evt Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SAM Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SecEvent.Evt Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SECURITY Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SysEvent.Evt Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM Object is locked skipped C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\H323LOG.TXT Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\Temp\Perflib_Perfdata_25c.dat Object is locked skipped C:\WINDOWS\WIADEBUG.LOG Object is locked skipped C:\WINDOWS\WIASERVC.LOG Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped Scan process completed. I'm going to scan again now. Thanks for staying wih me
With your previous suggestions, the new online scan:

KASPERSKY ONLINE SCANNER REPORT
Sunday, November 25, 2007 4:07:38 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 25/11/2007
Kaspersky Anti-Virus database records: 465276
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
C:\
D:\
Scan Statistics
Total number of scanned objects 61341
Number of viruses found 3
Number of infected objects 18
Number of suspicious objects 0
Duration of the scan process 01:12:24

Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\APQ313E.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.apx skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\APQ3140.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.apx skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\APQ3142.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.apx skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\APQ3144.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.apx skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\APQ3146.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.apx skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\APQ3148.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.apx skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\APQ578.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.apx skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\APQ6ED.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.apx skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\APQ71D.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.apx skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\APQ725.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.apx skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\APQ727.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.apx skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\APQ729.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.apx skipped
C:\Documents and Settings\LocalService\Cookies\INDEX.DAT Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Timothy Chow\Cookies\INDEX.DAT Object is locked skipped
C:\Documents and Settings\Timothy Chow\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Timothy Chow\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Timothy Chow\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\Timothy Chow\Local Settings\History\History.IE5\MSHist012007112520071126\index.dat Object is locked skipped
C:\Documents and Settings\Timothy Chow\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Timothy Chow\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Timothy Chow\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBConfig.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDebug.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDetect.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBNotify.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBRefr.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg2.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetDev.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetLoc.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetUsr.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMNot.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMReg.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMRSt.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStHash.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStMSI.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBValid.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPPolicy.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStart.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStop.log Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Data\master.mdf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Data\mastlog.ldf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Data\model.mdf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Data\modellog.ldf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Data\tempdb.mdf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Data\templog.ldf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\LOG\ERRORLOG Object is locked skipped
C:\Program Files\Symantec AntiVirus\SAVRT\0012NAV~.TMP Object is locked skipped
C:\Program Files\Symantec AntiVirus\SAVRT\0030NAV~.TMP Object is locked skipped
C:\qoobox\Quarantine\C\SmitfraudFix\Reboot.exe.vir Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\npujhhlj.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\vwyaaxtf.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP2\A0000241.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP2\A0000257.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP2\A0000261.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP6\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{D319F585-7C31-4D15-B358-CD95D7A2A87E}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\SYSTEM32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\SYSTEM32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\AppEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SAM Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SecEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SysEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\H323LOG.TXT Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_25c.dat Object is locked skipped
C:\WINDOWS\WIADEBUG.LOG Object is locked skipped
C:\WINDOWS\WIASERVC.LOG Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.


After that I went on to delete:
C:\qoobox\Quarantine\C\SmitfraudFix\Reboot.exe.vir
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\npujhhlj.dll.vir
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\vwyaaxtf.dll.vir


Is the system volume info normal?
Also, a new HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 4:15:15 AM, on 11/25/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\System32\basfipm.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\1XConfig.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\Timothy Chow\Desktop\hijackthis\killer.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: Sebring - C:\WINDOWS\System32\LgNotify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Broadcom ASF IP monitoring service v6.0.3 (BAsfIpM) - Broadcom Corp. - C:\WINDOWS\System32\basfipm.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
Everything looks good. Still a few items for you to delete in your Symantec Antivirus Quarantine. Don't be concerned about what is in your System Restore Cache as that is one of the items that we clean out at the end. How is your system now running? If everything is OK, just give me the :thumbup: and we will proceed with our final cleanup procedures.
For some reason, I don't have the "Set program Access and Defaults" "Windows catalog" "Windows Update" shortcuts when I hit the start menu. (Small thing compared to what I was experiencing before) Besides that, I can finally shutdown and restart my comp without having to finally press "End program now!" lol. Thank you again. Yea, I'm ready for the final cleanup.
Congratulations, your logs look CLEAN

There are a few things you must do once you system is completely clean:

Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK


    • [external image: Posted Image]

  • When shown the disclaimer, Select "2"

The above procedure will:
  • Delete the following:
    • ComboFix and its associated files and folders.
    • VundoFix backups, if present
    • The C:\Deckard folder, if present
    • The C:_OtMoveIt folder, if present
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Reset System Restore.


Here are some tips to reduce the potential for spyware infection in the future:

1. Make sure you keep your Windows OS currentby visiting Windows update
regularly to download and install any critical updates and service packs. With out these you are leaving the backdoor open.

2. I strongly recommend installing the following applications:
  • Spywareblaster <= SpywareBlaster will prevent spyware from being installed.
  • Spywareguard <= SpywareGuard offers realtime protection from spyware installation attempts.
  • How to use Ad-Aware to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Ad-Aware.
  • How to use Spybot to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Spybot. Similar to Ad-Aware, I strongly recommend both to catch most spyware.
To protect yourself further:
  • Spyad <= IE/Spyad places over 4000 websites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (Cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • MVPS Hosts file <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your coputer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
And also see TonyKlein's good advice
So how did I get infected in the first place?

Regards,

Trevuren

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI