Page 1 of 2 12 LastLast
Results 1 to 10 of 12
  1. #1
    Member
    Join Date
    Dec 2007
    Posts
    23
    Points
    0

    Default Win32.Agent.pz Virus Help

    My computer is restarting constantly and I'm only able to get it to work some what fine is in safe mode. I was Zone Alarm virus scan in the safe mode. It found the virus and tried to quarantine it but it only made things worst. Now zone alarm is not working. I ran Hijackthis and here is my report:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 1:25:54 PM, on 12/2/2007
    Platform: Windows XP (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2600.0000)
    Boot mode: Safe mode

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
    C:\Program Files\Microsoft Office\Office\WINWORD.EXE
    C:\WINDOWS\msagent\AgentSvr.exe
    C:\Documents and Settings\Ellis Christian\My Documents\New Folder (2)\HiJackThis.exe
    C:\WINDOWS\System32\wbem\wmiprvse.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - Default URLSearchHook is missing
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\System32\makehm.exe,C:\WINDOWS\System32\ntos.exe,
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: metaspinner GmbH - {E9E027BF-C3F3-4022-8F6B-8F6D39A59684} - C:\PROGRA~1\PRICEP~1\PRICEP~1\IEBUTT~1.DLL
    O3 - Toolbar: Protection Bar - {31615D5C-5126-448A-818A-A7CDFEE85A9B} - C:\Program Files\Video ActiveX Access\iesbpl.dll (file missing)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
    O4 - HKCU\..\Run: [userinit] C:\WINDOWS\System32\ntos.exe
    O4 - HKUS\S-1-5-18\..\Run: [userinit] C:\WINDOWS\System32\ntos.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [userinit] C:\WINDOWS\System32\ntos.exe (User 'Default user')
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
    O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
    O9 - Extra button: Pricepirates 3 - {350F4DA2-3886-4BB8-A1A8-D7F57B56DFFF} - C:\Program Files\Pricepirates\Pricepirates\preispiraten3ie.exe
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O12 - Plugin for .xfd: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
    O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://www.lizardtech.com/download/f...trol_en_US.cab
    O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/mini...ansporter.cab?
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/S...in/AvSniff.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by122fd.bay122.hotmail.msn.co...s/MsnPUpld.cab
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.johannrain-softwareentwic...an8/oscan8.cab
    O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/...toUploader.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab
    O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://www.servicehonda.com/TSWeb/msrdp.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
    O16 - DPF: {AF2E62B6-F9E1-4D4F-A10A-9DC8E6DCBCC0} (VideoEgg ActiveX Loader) - http://update.videoegg.com/Install/W...gPublisher.exe
    O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/.../installer.exe
    O23 - Service: AshampooDefragService - - C:\Program Files\Ashampoo\Ashampoo Magical Defrag\bin\aDefragService.exe
    O23 - Service: FCI - Unknown owner - C:\WINDOWS\System32\svchost.exe:ext.exe
    O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: PictureTaker - LANovation - C:\WINDOWS\System32\PCTKRNT.SYS
    O23 - Service: Xpress Mail Personal Edition Service (SevenConnectionService) - Unknown owner - C:\Program Files\Xpress Mail\Personal Edition\ConnectionService.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

    --
    End of file - 6384 bytes

  2. #2
    Member
    Join Date
    Dec 2007
    Posts
    23
    Points
    0

    Default Did I do something wrong?

    Did I do something wrong? Why would no one help me? Can some one please let me know if I did somehting wrong or did I broke some rule I overlooked.


    Ellis

  3. #3
    Member steamwiz's Avatar
    Join Date
    Sep 2003
    Location
    Yorkshire U.K.
    Posts
    14,022
    Points
    2335

    Default

    Hi

    You have a seriously compromised computer, if it is an option for you to reformat & reinstall, then I suggest you do just that ...

    You have a backdoor Trojan ... Troj/Bckdr-QJH

    O23 - Service: FCI - Unknown owner - C:\WINDOWS\System32\svchost.exe:ext.exe

    This infection is an Alternate Data Stream file attached to the legitimate C:\Windows\System32\svchost.exe file. Do not attempt to delete the svchost.exe file as Windows will not operate correctly without it.

    Troj/Bckdr-QJH includes functionality to access the internet and communicate with a remote server via HTTP.

    There is no way of knowing what a hacker may have done, or had access to on your computer ...

    -
    Should you decide to try to clean your computer ...


    1. Download SDFix and save it to your Desktop.

    http://downloads.andymanchesta.com/R...ools/SDFix.exe

    2. Double click SDFix.exe and it will extract the files to %systemdrive%
    (Drive that contains the Windows Directory, typically C:\SDFix)

    3. Reboot into Safe Mode`:-

    Reboot into >>>safe mode

    4. Once in safemode - Start HijackThis, close all open windows leaving only HijackThis running. Place a check against :-



    R3 - Default URLSearchHook is missing

    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\System32\makehm.exe,C:\WINDOWS\System32\ntos.exe,

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    O3 - Toolbar: Protection Bar - {31615D5C-5126-448A-818A-A7CDFEE85A9B} - C:\Program Files\Video ActiveX Access\iesbpl.dll (file missing)

    O4 - HKCU\..\Run: [userinit] C:\WINDOWS\System32\ntos.exe
    O4 - HKUS\S-1-5-18\..\Run: [userinit] C:\WINDOWS\System32\ntos.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [userinit] C:\WINDOWS\System32\ntos.exe (User 'Default user')

    O23 - Service: FCI - Unknown owner - C:\WINDOWS\System32\svchost.exe:ext.exe


    5. Click on Fix Checked when finished and exit HijackThis.

    Make sure your Internet Explorer is closed when you click Fix Checked.

    6. Open the extracted SDFix folder and double click RunThis.bat to start the script.
    Type Y to begin the cleanup process.

    It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
    Press any Key and it will restart the PC.

    When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.

    Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).

    Finally paste the contents of the Report.txt back on the forum...

    THEN ...

    Download Superantispyware.

    http://www.superantispyware.com/

    Once downloaded and installed update the definitions
    and then run a full system scan quarantine what it finds!

    * Double-click SUPERAntiSypware.exe and use the default settings for installation.
    * An icon will be created on your desktop. Double-click that icon to launch the program.
    * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here.)

    http://www.superantispyware.com/definitions.html

    * Under "Configuration and Preferences", click the Preferences button.
    * Click the Scanning Control tab.
    * Under Scanner Options make sure the following are checked (leave all others unchecked):
    o Close browsers before scanning.
    o Scan for tracking cookies.
    o Terminate memory threats before quarantining.
    * Click the "Close" button to leave the control center screen.
    * Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
    * On the left, make sure you check C:\Fixed Drive.
    * On the right, under "Complete Scan", choose Perform Complete Scan.
    * Click "Next" to start the scan. Please be patient while it scans your computer.
    * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
    * Make sure everything has a checkmark next to it and click "Next".
    * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
    * If asked if you want to reboot, click "Yes".
    * To retrieve the removal information after reboot, launch SUPERAntispyware again.
    o Click Preferences, then click the Statistics/Logs tab.
    o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    o Please copy and paste the Scan Log results in your next reply.
    * Click Close to exit the program.

    THEN ...

    Please download Combofix: http://download.bleepingcomputer.com...a/ComboFix.exe
    and save to the desktop.

    1. Double click on combo.exe & follow the prompts.
    2. When finished, it will produce a logfile located at C:\ComboFix.txt.
    3. Post the contents of that log in your next reply with a new hijackthis log.

    Notes:
    * Do not mouseclick combofix's window while it is running. That may cause your system to stall/hang.
    * Disable script blocking if you have NAV installed so it will not interfere with the fix. Trojan Hunter has been reported to detect combofix as Worm.Qiv.100.

    Please remember to post :-

    1. Report.txt (SDFix)
    2. SUPERAntiSpyware Scan Log
    3. C:\ComboFix.txt
    4. a new hijackthis log.( run after everything else)

    steam
    Look here for Ways to keep your computer safe
    M'SOFT MVP -Windows Security 2004/8 .member ASAP -

  4. #4
    Member
    Join Date
    Dec 2007
    Posts
    23
    Points
    0

    Default SDFIX Report

    Here is the report.




    SDFix: Version 1.116

    Run by Administrator on Mon 12/03/2007 at 09:38 PM

    Microsoft Windows XP [Version 5.1.2600]

    Running From: C:\DOCUME~1\ADMINI~1\MYDOCU~1\fix\SDFix

    Safe Mode:
    Checking Services:

    Name:
    FCI
    protect
    SysLibrary

    Path:
    C:\WINDOWS\System32\svchost.exe:ext.exe
    System32\drivers\protect.sys
    \??\C:\WINDOWS\System32\DefLib.sys

    FCI - Deleted
    protect - Deleted
    SysLibrary - Deleted



    Restoring Windows Registry Values
    Restoring Windows Default Hosts File

    Rebooting...


    Normal Mode:
    Checking Files:

    Trojan Files Found:

    C:\18D.TMP - Deleted
    C:\18F.TMP - Deleted
    C:\195.TMP - Deleted
    C:\19B.TMP - Deleted
    C:\19D.TMP - Deleted
    C:\19F.TMP - Deleted
    C:\1A1.TMP - Deleted
    C:\1A3.TMP - Deleted
    C:\1A5.TMP - Deleted
    C:\SDFIX.EXE - Deleted
    C:\WINDOWS\PART0100.DAT - Deleted
    C:\WINDOWS\system32\ntos.exe - Deleted
    C:\WINDOWS\system32\wsnpoem\audio.dll - Deleted
    C:\WINDOWS\system32\wsnpoem\video.dll - Deleted



    Folder C:\WINDOWS\system32\wsnpoem - Removed

    Removing Temp Files...

    ADS Check:

    C:\WINDOWS
    No streams found.

    C:\WINDOWS\system32
    No streams found.

    C:\WINDOWS\system32\svchost.exe
    : ADS Found!

    svchost.exe: deleted 24576 bytes in 1 streams.

    Checking for remaining Streams

    C:\WINDOWS\system32\svchost.exe
    No streams found.

    C:\WINDOWS\system32\ntoskrnl.exe
    No streams found.



    Final Check:

    catchme 0.3.1262.1 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2007-12-03 22:01:11
    Windows 5.1.2600 NTFS

    scanning hidden processes ...

    IPC error: 2 The system cannot find the file specified.
    scanning hidden services & system hive ...

    scanning hidden registry entries ...

    scanning hidden files ...

    C:\Documents and Settings\Ellis Christian\Local Settings\Temporary Internet Files\Content.IE5\G92J0X6F\002-1702244-6276014[1].: 88665 bytes hidden from API
    C:\Documents and Settings\Ellis Christian\Local Settings\Temporary Internet Files\Content.IE5\I9EYUDT5\ebay[1].: 64148 bytes hidden from API
    C:\Documents and Settings\Ellis Christian\Local Settings\Temporary Internet Files\Content.IE5\O7OXAR4T\104-4548039-1575116[1].: 106535 bytes hidden from API
    C:\Documents and Settings\Ellis Christian\Local Settings\Temporary Internet Files\Content.IE5\OX2NCH2N\104-7250829-7158300[1].: 170212 bytes hidden from API
    C:\Documents and Settings\Ellis Christian\Local Settings\Temporary Internet Files\Content.IE5\U9ED4KC1\105-9341274-5192426[1].: 66444 bytes hidden from API
    C:\Documents and Settings\Ellis Christian\Local Settings\Temporary Internet Files\Content.IE5\WXAN05MF\002-1702244-6276014[1].: 150440 bytes hidden from API

    scan completed successfully
    hidden processes: 0
    hidden services: 0
    hidden files: 6


    Remaining Services:
    ------------------



    Authorized Application Key Export:

    Remaining Files:
    ---------------

    File Backups: - C:\DOCUME~1\ADMINI~1\MYDOCU~1\fix\SDFix\backups\backups.zip

    Files with Hidden Attributes:

    Sat 3 Dec 2005 114,597 A..H. --- "C:\WINDOWS\system32\AManUtl3.dll"
    Sun 5 Nov 2006 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
    Wed 6 Sep 2006 27,648 ...H. --- "C:\Documents and Settings\Ellis Christian\Desktop\~WRL0221.tmp"
    Tue 5 Sep 2006 22,016 ...H. --- "C:\Documents and Settings\Ellis Christian\My Documents\~WRL0001.tmp"
    Sun 11 Feb 2007 22,528 ...H. --- "C:\Documents and Settings\Ellis Christian\My Documents\~WRL0278.tmp"
    Thu 26 Oct 2006 210,944 ...H. --- "C:\Documents and Settings\Ellis Christian\My Documents\~WRL0617.tmp"
    Sun 11 Feb 2007 22,528 ...H. --- "C:\Documents and Settings\Ellis Christian\My Documents\~WRL0832.tmp"
    Fri 21 Jul 2006 37,376 ...H. --- "C:\Documents and Settings\Ellis Christian\My Documents\~WRL1279.tmp"
    Thu 12 Oct 2006 20,992 ...H. --- "C:\Documents and Settings\Ellis Christian\My Documents\~WRL2046.tmp"
    Thu 26 Oct 2006 208,896 ...H. --- "C:\Documents and Settings\Ellis Christian\My Documents\~WRL2379.tmp"
    Wed 25 Oct 2006 208,384 ...H. --- "C:\Documents and Settings\Ellis Christian\My Documents\~WRL2484.tmp"
    Sun 11 Feb 2007 22,016 ...H. --- "C:\Documents and Settings\Ellis Christian\My Documents\~WRL2626.tmp"
    Sun 11 Feb 2007 22,016 ...H. --- "C:\Documents and Settings\Ellis Christian\My Documents\~WRL2678.tmp"
    Thu 26 Oct 2006 131,584 ...H. --- "C:\Documents and Settings\Ellis Christian\My Documents\~WRL3133.tmp"
    Fri 21 Jul 2006 223,744 ...H. --- "C:\Documents and Settings\Ellis Christian\My Documents\~WRL3351.tmp"
    Fri 21 Jul 2006 225,792 ...H. --- "C:\Documents and Settings\Ellis Christian\My Documents\~WRL3432.tmp"
    Sun 11 Feb 2007 23,040 ...H. --- "C:\Documents and Settings\Ellis Christian\My Documents\~WRL4039.tmp"
    Sat 10 Feb 2007 23,040 ...H. --- "C:\Documents and Settings\Ellis Christian\My Documents\Aviation Books Online\~WRL0735.tmp"
    Mon 2 Oct 2006 50,280 ...H. --- "C:\Program Files\Common Files\Adobe\ESD\DLMCleanup.exe"
    Fri 7 Jul 2006 20,480 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0003.tmp"
    Sat 1 Jul 2006 20,992 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0004.tmp"
    Thu 20 Jul 2006 22,016 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0005.tmp"
    Thu 20 Jul 2006 19,456 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0006.tmp"
    Mon 31 Jul 2006 38,400 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0007.tmp"
    Thu 28 Sep 2006 100,352 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0008.tmp"
    Thu 12 Oct 2006 22,528 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0009.tmp"
    Tue 24 Oct 2006 20,992 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0010.tmp"
    Sun 11 Feb 2007 19,968 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0011.tmp"
    Mon 12 Feb 2007 22,016 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0012.tmp"
    Wed 14 Feb 2007 19,456 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0013.tmp"
    Fri 1 Jun 2007 24,064 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0014.tmp"
    Thu 7 Jun 2007 24,064 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0015.tmp"
    Wed 20 Jun 2007 19,456 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0016.tmp"
    Fri 30 Nov 2007 19,456 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0017.tmp"
    Thu 20 Jul 2006 31,232 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0040.tmp"
    Mon 31 Jul 2006 444,416 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0059.tmp"
    Mon 31 Jul 2006 41,472 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0122.tmp"
    Thu 21 Sep 2006 20,992 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0123.tmp"
    Thu 28 Sep 2006 99,840 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0148.tmp"
    Sun 11 Feb 2007 20,992 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0218.tmp"
    Sun 11 Feb 2007 21,504 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0264.tmp"
    Tue 24 Oct 2006 20,992 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0269.tmp"
    Fri 21 Jul 2006 222,208 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0274.tmp"
    Thu 5 Oct 2006 19,968 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0276.tmp"
    Tue 25 Sep 2007 19,456 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0283.tmp"
    Thu 12 Oct 2006 21,504 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0303.tmp"
    Fri 21 Jul 2006 223,232 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0343.tmp"
    Tue 16 Oct 2007 23,040 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0345.tmp"
    Sat 1 Jul 2006 22,016 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0352.tmp"
    Sat 6 Jan 2007 22,528 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0362.tmp"
    Fri 9 Feb 2007 22,016 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0390.tmp"
    Fri 9 Feb 2007 22,528 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0399.tmp"
    Thu 21 Sep 2006 20,992 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0460.tmp"
    Sat 6 Jan 2007 23,040 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0486.tmp"
    Tue 1 Aug 2006 427,520 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0497.tmp"
    Sat 1 Jul 2006 19,456 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0516.tmp"
    Fri 5 Jan 2007 23,040 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0523.tmp"
    Sun 11 Feb 2007 20,480 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0532.tmp"
    Thu 21 Sep 2006 20,992 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0549.tmp"
    Thu 28 Sep 2006 99,328 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0555.tmp"
    Tue 24 Oct 2006 20,992 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0610.tmp"
    Fri 5 Jan 2007 23,040 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0656.tmp"
    Wed 25 Oct 2006 208,384 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0682.tmp"
    Tue 24 Oct 2006 22,016 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0691.tmp"
    Thu 26 Oct 2006 209,408 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0753.tmp"
    Thu 20 Jul 2006 34,816 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0773.tmp"
    Tue 24 Oct 2006 22,016 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0775.tmp"
    Sat 6 Jan 2007 24,064 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0777.tmp"
    Tue 16 Oct 2007 23,040 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0809.tmp"
    Sat 1 Jul 2006 20,480 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0839.tmp"
    Tue 24 Oct 2006 20,992 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0842.tmp"
    Sat 1 Jul 2006 20,480 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0851.tmp"
    Thu 20 Jul 2006 31,744 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL0963.tmp"
    Sat 6 Jan 2007 22,528 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL1049.tmp"
    Tue 1 Aug 2006 429,568 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL1085.tmp"
    Thu 20 Jul 2006 32,768 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL1090.tmp"
    Wed 25 Oct 2006 207,872 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL1094.tmp"
    Tue 16 Oct 2007 23,040 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL1115.tmp"
    Tue 24 Oct 2006 22,016 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL1164.tmp"
    Thu 5 Oct 2006 19,456 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL1188.tmp"
    Fri 9 Feb 2007 21,504 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL1195.tmp"
    Sun 11 Feb 2007 22,016 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL1216.tmp"
    Mon 31 Jul 2006 427,008 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL1222.tmp"
    Mon 31 Jul 2006 39,936 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL1248.tmp"
    Mon 31 Jul 2006 425,984 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL1256.tmp"
    Sat 1 Jul 2006 21,504 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL1257.tmp"
    Mon 22 Oct 2007 22,016 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL1258.tmp"
    Mon 11 Dec 2006 31,744 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL1263.tmp"
    Tue 1 Aug 2006 426,496 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL1273.tmp"
    Fri 21 Jul 2006 225,280 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL1295.tmp"
    Mon 31 Jul 2006 38,400 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL1361.tmp"
    Tue 16 Oct 2007 22,528 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL1364.tmp"
    Mon 31 Jul 2006 427,520 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL1391.tmp"
    Sun 25 Mar 2007 56,320 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL1414.tmp"
    Fri 1 Jun 2007 24,064 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL1439.tmp"
    Sat 1 Jul 2006 19,968 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL1448.tmp"
    Thu 21 Sep 2006 20,992 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL1495.tmp"
    Thu 28 Sep 2006 99,328 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL1537.tmp"
    Thu 21 Sep 2006 19,968 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL1633.tmp"
    Fri 21 Jul 2006 222,208 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL1646.tmp"
    Fri 21 Jul 2006 226,304 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL1651.tmp"
    Wed 25 Oct 2006 208,896 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL1692.tmp"
    Mon 31 Jul 2006 38,912 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL1699.tmp"
    Thu 21 Sep 2006 19,968 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL1701.tmp"
    Tue 24 Oct 2006 22,528 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL1757.tmp"
    Thu 28 Sep 2006 99,840 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL1817.tmp"
    Thu 7 Jun 2007 24,576 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL1849.tmp"
    Thu 31 Aug 2006 26,112 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL1904.tmp"
    Tue 1 Aug 2006 429,056 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL1967.tmp"
    Mon 11 Dec 2006 30,720 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL2006.tmp"
    Tue 24 Oct 2006 20,992 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL2045.tmp"
    Thu 21 Sep 2006 19,456 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL2047.tmp"
    Fri 21 Jul 2006 225,792 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL2051.tmp"
    Sat 1 Jul 2006 20,480 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL2080.tmp"
    Thu 20 Jul 2006 35,328 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL2094.tmp"
    Tue 24 Oct 2006 22,528 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL2106.tmp"
    Thu 31 Aug 2006 25,600 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL2165.tmp"
    Tue 24 Oct 2006 22,528 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL2177.tmp"
    Fri 9 Feb 2007 23,040 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL2179.tmp"
    Sat 1 Jul 2006 21,504 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL2200.tmp"
    Sun 11 Feb 2007 22,016 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL2362.tmp"
    Wed 25 Oct 2006 208,384 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL2368.tmp"
    Tue 24 Oct 2006 20,480 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL2382.tmp"
    Mon 11 Dec 2006 31,744 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL2520.tmp"
    Tue 16 Oct 2007 25,088 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL2570.tmp"
    Tue 16 Oct 2007 21,504 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL2576.tmp"
    Sat 1 Jul 2006 20,992 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL2613.tmp"
    Fri 21 Jul 2006 226,304 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL2617.tmp"
    Thu 20 Jul 2006 33,792 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL2658.tmp"
    Thu 21 Sep 2006 21,504 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL2679.tmp"
    Fri 21 Jul 2006 223,744 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL2693.tmp"
    Wed 25 Oct 2006 208,896 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL2807.tmp"
    Sat 1 Jul 2006 22,528 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL2856.tmp"
    Tue 24 Oct 2006 20,480 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL2899.tmp"
    Sun 25 Mar 2007 50,688 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL2903.tmp"
    Mon 31 Jul 2006 38,400 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL2915.tmp"
    Tue 24 Oct 2006 23,040 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL3008.tmp"
    Sun 11 Feb 2007 21,504 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL3011.tmp"
    Thu 8 Feb 2007 21,504 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL3037.tmp"
    Wed 25 Oct 2006 209,408 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL3046.tmp"
    Fri 5 Jan 2007 23,040 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL3048.tmp"
    Tue 1 Aug 2006 428,032 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL3052.tmp"
    Thu 21 Sep 2006 20,480 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL3191.tmp"
    Fri 5 Jan 2007 22,016 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL3198.tmp"
    Thu 20 Jul 2006 222,208 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL3221.tmp"
    Thu 28 Sep 2006 99,840 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL3224.tmp"
    Tue 24 Oct 2006 20,992 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL3231.tmp"
    Thu 31 Aug 2006 25,088 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL3232.tmp"
    Sun 11 Feb 2007 21,504 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL3325.tmp"
    Mon 31 Jul 2006 40,960 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL3329.tmp"
    Mon 31 Jul 2006 428,032 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL3349.tmp"
    Thu 26 Oct 2006 209,920 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL3429.tmp"
    Tue 24 Oct 2006 22,528 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL3438.tmp"
    Tue 25 Sep 2007 19,968 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL3461.tmp"
    Fri 5 Jan 2007 22,016 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL3474.tmp"
    Sun 11 Feb 2007 21,504 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL3499.tmp"
    Wed 25 Oct 2006 208,896 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL3515.tmp"
    Thu 26 Oct 2006 131,584 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL3567.tmp"
    Mon 31 Jul 2006 40,960 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL3588.tmp"
    Tue 24 Oct 2006 23,040 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL3608.tmp"
    Thu 26 Oct 2006 131,584 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL3628.tmp"
    Thu 20 Jul 2006 33,792 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL3630.tmp"
    Mon 31 Jul 2006 39,424 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL3638.tmp"
    Tue 24 Oct 2006 20,480 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL3658.tmp"
    Tue 24 Oct 2006 22,528 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL3693.tmp"
    Mon 31 Jul 2006 39,936 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL3701.tmp"
    Mon 11 Dec 2006 33,280 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL3760.tmp"
    Fri 5 Jan 2007 22,528 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL3833.tmp"
    Fri 21 Jul 2006 224,256 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL3834.tmp"
    Mon 31 Jul 2006 39,424 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL3875.tmp"
    Fri 21 Jul 2006 226,816 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL3886.tmp"
    Wed 25 Oct 2006 23,040 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL3949.tmp"
    Thu 18 Oct 2007 19,456 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL3960.tmp"
    Thu 31 Aug 2006 25,600 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL3978.tmp"
    Sat 1 Sep 2007 24,064 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL3984.tmp"
    Thu 21 Sep 2006 20,992 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL3997.tmp"
    Thu 26 Oct 2006 208,384 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL4015.tmp"
    Tue 1 Aug 2006 429,568 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL4046.tmp"
    Mon 11 Dec 2006 34,304 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL4067.tmp"
    Sat 6 Jan 2007 23,040 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL4071.tmp"
    Mon 11 Dec 2006 19,456 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL4084.tmp"
    Mon 31 Jul 2006 37,888 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL4092.tmp"
    Tue 1 Aug 2006 425,984 ...H. --- "C:\Documents and Settings\Ellis Christian\Application Data\Microsoft\Word\~WRL4099.tmp"
    Sun 17 Jun 2007 1,276,928 ...H. --- "C:\Documents and Settings\Ellis Christian\My Documents\Aviation Books Online\Via Viente\~WRL0002.tmp"
    Sun 5 Nov 2006 4,348 ...H. --- "C:\Documents and Settings\Ellis Christian\My Documents\My Music\License Backup\drmv1key.bak"
    Wed 23 May 2007 20 A..H. --- "C:\Documents and Settings\Ellis Christian\My Documents\My Music\License Backup\drmv1lic.bak"
    Sun 5 Nov 2006 9,656 A.SH. --- "C:\Documents and Settings\Ellis Christian\My Documents\My Music\License Backup\drmv2key.bak"
    Fri 29 Dec 2006 33,280 A..H. --- "C:\Documents and Settings\Ellis Christian\Desktop\Ellis Jr Memory Stick\JR School Stuff\ASCI 606\~WRL0200.tmp"
    Fri 29 Dec 2006 29,696 A..H. --- "C:\Documents and Settings\Ellis Christian\Desktop\Ellis Jr Memory Stick\JR School Stuff\ASCI 606\~WRL0895.tmp"
    Fri 29 Dec 2006 31,744 A..H. --- "C:\Documents and Settings\Ellis Christian\Desktop\Ellis Jr Memory Stick\JR School Stuff\ASCI 606\~WRL2778.tmp"
    Thu 7 Dec 2006 55,296 A..H. --- "C:\Documents and Settings\Ellis Christian\Desktop\Ellis Jr Memory Stick\JR School Stuff\ASCI 611\~WRL0693.tmp"
    Tue 12 Dec 2006 167,936 A..H. --- "C:\Documents and Settings\Ellis Christian\Desktop\Ellis Jr Memory Stick\JR School Stuff\ASCI 611\~WRL2472.tmp"

    Finished!

  5. #5
    Member
    Join Date
    Dec 2002
    Posts
    12,000
    Points
    1191

    Default

    Don't forget the other logs:

    2. SUPERAntiSpyware Scan Log
    3. C:\ComboFix.txt
    4. a new hijackthis log.( run after everything else)


    BG

  6. #6
    Member
    Join Date
    Dec 2007
    Posts
    23
    Points
    0

    Default Reports

    Logfile of Trend Micro HijackThis v2.0.0 (BETA)
    Scan saved at 5:45:44 PM, on 12/4/2007
    Platform: Windows XP (WinNT 5.01.2600)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Ashampoo\Ashampoo Magical Defrag\bin\aDefragService.exe
    C:\PROGRA~1\Iomega\System32\AppServices.exe
    C:\WINDOWS\System32\NMSSvc.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\AWS\WeatherBug\Weather.exe
    C:\Program Files\Microsoft ActiveSync\wcescomm.exe
    C:\PROGRA~1\MI3AA1~1\rapimgr.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\WINDOWS\System32\notepad.exe
    C:\Documents and Settings\Ellis Christian\Desktop\HiJackThis_v2.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O2 - BHO: metaspinner GmbH - {E9E027BF-C3F3-4022-8F6B-8F6D39A59684} - C:\PROGRA~1\PRICEP~1\PRICEP~1\IEBUTT~1.DLL
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
    O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
    O9 - Extra button: Pricepirates 3 - {350F4DA2-3886-4BB8-A1A8-D7F57B56DFFF} - C:\Program Files\Pricepirates\Pricepirates\preispiraten3ie.exe
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O12 - Plugin for .xfd: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
    O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://www.lizardtech.com/download/f...trol_en_US.cab
    O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/mini...ansporter.cab?
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/S...in/AvSniff.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by122fd.bay122.hotmail.msn.co...s/MsnPUpld.cab
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.johannrain-softwareentwic...an8/oscan8.cab
    O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/...toUploader.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab
    O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://www.servicehonda.com/TSWeb/msrdp.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
    O16 - DPF: {AF2E62B6-F9E1-4D4F-A10A-9DC8E6DCBCC0} (VideoEgg ActiveX Loader) - http://update.videoegg.com/Install/W...gPublisher.exe
    O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/.../installer.exe
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
    O23 - Service: AshampooDefragService - - C:\Program Files\Ashampoo\Ashampoo Magical Defrag\bin\aDefragService.exe
    O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: PictureTaker - LANovation - C:\WINDOWS\System32\PCTKRNT.SYS
    O23 - Service: Xpress Mail Personal Edition Service (SevenConnectionService) - Unknown owner - C:\Program Files\Xpress Mail\Personal Edition\ConnectionService.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

    --
    End of file - 6364 bytes





    ComboFix 07-12-02.7 - Ellis Christian 2007-12-04 7:52:49.1 - NTFSx86
    Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.122 [GMT -5:00]
    Running from: C:\Documents and Settings\Ellis Christian\Local Settings\Temporary Internet Files\Content.IE5\0LQR8LUN\ComboFix[1].exe
    * Created a new restore point
    .

    ((((((((((((((((((((((((( Files Created from 2007-11-04 to 2007-12-04 )))))))))))))))))))))))))))))))
    .

    2007-12-03 21:37 . 2007-12-03 21:37 d-------- C:\WINDOWS\SDFIX
    2007-12-03 20:55 . 2007-12-04 07:47 d-------- C:\Program Files\SUPERAntiSpyware
    2007-12-03 20:55 . 2007-12-03 20:55 d-------- C:\Documents and Settings\Ellis Christian\Application Data\SUPERAntiSpyware.com
    2007-12-03 20:55 . 2007-12-03 20:55 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
    2007-12-02 11:52 . 2007-12-04 07:56 2,567,968 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
    2007-12-02 11:52 . 2007-12-03 21:30 31,652 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
    2007-12-02 11:52 . 2007-12-04 07:57 10,528 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
    2007-12-02 11:52 . 2007-12-03 21:30 1,772 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
    2007-12-02 11:44 . 2007-12-02 11:44 d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
    2007-12-01 08:45 . 2007-12-01 08:45 d-------- C:\Program Files\MediaScouter
    2007-11-30 22:12 . 2007-11-30 22:12 52,736 --a------ C:\Documents and Settings\Ellis Christian\24631.exe
    2007-11-28 08:14 . 2007-11-28 08:14 66,048 --a------ C:\23.tmp
    2007-11-28 08:14 . 2007-11-28 08:14 1 --a------ C:\25.tmp

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2007-12-04 01:54 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
    2007-12-02 17:54 --------- d-----w C:\Program Files\Common Files\MEP
    2007-12-02 14:26 512 ----a-w C:\ScanSectorLog.dat
    2007-11-28 13:14 12,800 ----a-w C:\WINDOWS\system32\svchost.exe
    2007-11-27 07:00 --------- d-----w C:\Documents and Settings\Ellis Christian\Application Data\WeatherBug
    2007-11-14 21:05 75,248 ----a-w C:\WINDOWS\zllsputility.exe
    2007-11-14 21:05 1,086,952 ----a-w C:\WINDOWS\system32\zpeng24.dll
    2007-08-28 10:52 4,568,694 ----a-w C:\WINDOWS\Internet Logs\tvDebug.zip
    2006-12-15 00:08 334 ----a-w C:\Documents and Settings\Clementina Christian\Application Data\internaldb1942.dat
    2006-12-15 00:08 13,046 ----a-w C:\Documents and Settings\Clementina Christian\Application Data\internaldb6823.dat
    2006-12-15 00:08 0 ----a-w C:\Documents and Settings\Clementina Christian\Application Data\internaldb8600.dat
    2006-12-15 00:07 20,480 ----a-w C:\Documents and Settings\Clementina Christian\Application Data\internaldb6291.dat
    2006-12-15 00:07 0 ----a-w C:\Documents and Settings\Clementina Christian\Application Data\internaldb8673.dat
    2006-12-15 00:07 0 ----a-w C:\Documents and Settings\Clementina Christian\Application Data\internaldb3520.dat
    2006-12-15 00:07 0 ----a-w C:\Documents and Settings\Clementina Christian\Application Data\internaldb2565.dat
    2006-12-15 00:07 0 ----a-w C:\Documents and Settings\Clementina Christian\Application Data\internaldb170.dat
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Weather"="C:\Program Files\AWS\WeatherBug\Weather.exe" [2006-04-07 14:02]
    "H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-06-26 16:13]
    "SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 14:57]
    "ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-11-14 16:05]

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
    backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Ashampoo Magical Defrag.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Ashampoo Magical Defrag.lnk
    backup=C:\WINDOWS\pss\Ashampoo Magical Defrag.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Install Pending Files.LNK]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Install Pending Files.LNK
    backup=C:\WINDOWS\pss\Install Pending Files.LNKCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
    backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Xpress Mail Personal Edition.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Xpress Mail Personal Edition.lnk
    backup=C:\WINDOWS\pss\Xpress Mail Personal Edition.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Ellis Christian^Start Menu^Programs^Startup^Hotmail Popper.lnk]
    path=C:\Documents and Settings\Ellis Christian\Start Menu\Programs\Startup\Hotmail Popper.lnk
    backup=C:\WINDOWS\pss\Hotmail Popper.lnkStartup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\adstart]
    iexplore.exe http://iesettingsupdate

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Drag'n'Drop_Autolaunch]
    2003-01-30 17:17 86016 --a------ C:\Program Files\Iomega HotBurn Pro\Autolaunch.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
    2006-06-26 16:13 1207080 --a------ C:\Program Files\Microsoft ActiveSync\wcescomm.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
    2006-09-12 00:58 229952 --a------ C:\Program Files\iTunes\iTunesHelper.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\masqform.exe]
    C:\Program Files\PureEdge\Viewer 6.5\masqform.exe -RunOnce

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
    C:\Program Files\MSN Messenger\MsnMsgr.Exe /background

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
    RUNDLL32.EXE NvQTwk,NvCplDaemon initialize

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PROMon.exe]
    PROMon.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    C:\Program Files\QuickTime\qttask.exe -atboottime

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
    2005-11-10 12:03 36975 --a------ C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ToolbarInstall]
    C:\WINDOWS\mirar_distro_876088.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Tracker]
    2004-10-27 12:02 118784 --a------ C:\Program Files\MySoftware\MyInvoices\tracker.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Weather]
    C:\Program Files\AWS\WeatherBug\Weather.exe 1

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zone Labs Client]
    2007-11-14 16:05 919016 --a------ C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZoneAlarm Client]
    2007-11-14 16:05 919016 --a------ C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe

    R2 NMSSvc;Intel(R) NMS;C:\WINDOWS\System32\NMSSvc.exe
    R3 DXE201;Dynex DX-E201 CardBus PC Card;C:\WINDOWS\System32\DRIVERS\DXE201.SYS
    R3 NMSCFG;NIC Management Service Configuration Driver;\??\C:\WINDOWS\System32\drivers\NMSCFG.SYS
    S3 iscFlash;iscFlash;\??\C:\WINDOWS\SYSTEM32\DRIVERS\iscflash.sys
    S3 MhzNet;Megaherz Lan/Modem PCMCIA Device Driver;C:\WINDOWS\System32\DRIVERS\xem336n5.sys
    S3 SevenConnectionService;Xpress Mail Personal Edition Service;C:\Program Files\Xpress Mail\Personal Edition\ConnectionService.exe

    *Newly Created Service* - PROCEXP90
    .
    Contents of the 'Scheduled Tasks' folder
    "2007-12-01 01:03:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
    - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
    .
    **************************************************************************

    catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2007-12-04 07:57:42
    Windows 5.1.2600 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    Completion time: 2007-12-04 7:59:13
    .
    --- E O F ---









    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 12/04/2007 at 09:00 AM

    Application Version : 3.9.1008

    Core Rules Database Version : 3259
    Trace Rules Database Version: 1270

    Scan type : Complete Scan
    Total Scan Time : 01:00:35

    Memory items scanned : 326
    Memory threats detected : 0
    Registry items scanned : 5026
    Registry threats detected : 13
    File items scanned : 34288
    File threats detected : 12

    Trojan.Media-Codec/V3
    HKLM\Software\Classes\CLSID\{31615D5C-5126-448A-818A-A7CDFEE85A9B}
    HKCR\CLSID\{31615D5C-5126-448A-818A-A7CDFEE85A9B}
    HKCR\CLSID\{31615D5C-5126-448A-818A-A7CDFEE85A9B}
    HKCR\CLSID\{31615D5C-5126-448A-818A-A7CDFEE85A9B}\Implemented Categories
    HKCR\CLSID\{31615D5C-5126-448A-818A-A7CDFEE85A9B}\Implemented Categories\{00021493-0000-0000-C000-000000000046}
    HKCR\CLSID\{31615D5C-5126-448A-818A-A7CDFEE85A9B}\InprocServer32
    HKCR\CLSID\{31615D5C-5126-448A-818A-A7CDFEE85A9B}\InprocServer32#ThreadingModel
    C:\PROGRAM FILES\VIDEO ACTIVEX ACCESS\IESBPL.DLL
    HKLM\Software\Classes\CLSID\{B8C5186E-EC37-4889-9C2E-F73649FFB7BB}
    HKCR\CLSID\{B8C5186E-EC37-4889-9C2E-F73649FFB7BB}
    HKCR\CLSID\{B8C5186E-EC37-4889-9C2E-F73649FFB7BB}#xxx
    HKCR\CLSID\{B8C5186E-EC37-4889-9C2E-F73649FFB7BB}\InprocServer32
    HKCR\CLSID\{B8C5186E-EC37-4889-9C2E-F73649FFB7BB}\InprocServer32#ThreadingModel
    C:\PROGRAM FILES\VIDEO ACTIVEX ACCESS\IESPLG.DLL
    HKCR\CLSID\{B8C5186E-EC37-4889-9C2E-F73649FFB7BB}

    Adware.Tracking Cookie
    C:\Documents and Settings\Ellis Christian\Cookies\ellis christian@questionmarket[1].txt
    C:\Documents and Settings\Ellis Christian\Cookies\ellis christian@revsci[2].txt

    Trojan.Security Toolbar
    C:\Documents and Settings\All Users\Start Menu\Online Security Guide.url
    C:\Documents and Settings\All Users\Start Menu\Security Troubleshooting.url
    C:\Documents and Settings\All Users\Desktop\Security Troubleshooting.url
    C:\Documents and Settings\All Users\Desktop\Online Security Guide.url

    Malware.AntiVirusGolden
    C:\Program Files\AVG\AntivirusGold 4.4\AntivirusGold AntivirusGold.url
    C:\Program Files\AVG\AntivirusGold 4.4

    Browser Hijacker.Favorites
    C:\DOCUMENTS AND SETTINGS\ELLIS CHRISTIAN\FAVORITES\ONLINE SECURITY TEST.URL

    Adware.eZula/BannerRotator
    C:\WINDOWS\SYSTEM32\BRROT-UNINST.EXE
















    Sorry for the delay.

  7. #7
    Member
    Join Date
    Dec 2007
    Posts
    23
    Points
    0

    Default Reports

    Does my report look clean? My computer is working again but it takes forever to start-up and sometimes fails to shutdown. The wuauclt.exe which is a windows update element is causing an error so I'm unableto download updates. Can you guys see anyting in my log that may cause these problems?


    Elis

  8. #8
    Member steamwiz's Avatar
    Join Date
    Sep 2003
    Location
    Yorkshire U.K.
    Posts
    14,022
    Points
    2335

    Default

    HI

    NO you are not clean ...

    Please download ALL programs I ask you to run to your desktop before running them ... do not run them from the net ...


    C:\Documents and Settings\Ellis Christian\Local Settings\Temporary Internet Files\Content.IE5\0LQR8LUN\ComboFix[1].exe

    Quote Originally Posted by steamwiz
    Please download Combofix: http://download.bleepingcomputer.com/sUBs/Beta/ComboFix .exe
    and save to the desktop.
    I need you to use Combofix to remove things, but you must have it on your desktop first ...

    Once you've downloaded it, run a new scan & post the log

    steam
    Look here for Ways to keep your computer safe
    M'SOFT MVP -Windows Security 2004/8 .member ASAP -

  9. #9
    Member
    Join Date
    Dec 2007
    Posts
    23
    Points
    0

    Default Report

    Sorry, here is the report ran from my desktop. How does it look now.




    ComboFix 07-12-05.2 - Ellis Christian 2007-12-05 18:38:27.2 - NTFSx86
    Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.138 [GMT -5:00]Running from: C:\Documents and Settings\Ellis Christian\Desktop\ComboFix.exe
    * Created a new restore point
    .

    ((((((((((((((((((((((((( Files Created from 2007-11-05 to 2007-12-05 )))))))))))))))))))))))))))))))
    .

    2007-12-04 23:24 . 2007-12-04 23:24 d-------- C:\Program Files\RegCure
    2007-12-04 22:48 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuapi.dll.mui
    2007-12-04 22:47 . 2007-07-30 19:18 34,136 --a------ C:\WINDOWS\system32\wucltui.dll.mui
    2007-12-04 22:47 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui
    2007-12-04 22:47 . 2007-07-30 19:18 20,312 --a------ C:\WINDOWS\system32\wuaueng.dll.mui
    2007-12-04 22:31 . 2007-12-05 18:25 d-------- C:\Documents and Settings\Ellis Christian\Application Data\AVG7
    2007-12-04 22:30 . 2007-12-04 22:30 d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
    2007-12-04 22:29 . 2007-12-04 22:29 d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
    2007-12-04 22:29 . 2007-12-05 18:26 d-------- C:\Documents and Settings\All Users\Application Data\avg7
    2007-12-03 21:37 . 2007-12-03 21:37 d-------- C:\WINDOWS\SDFIX
    2007-12-03 20:55 . 2007-12-04 22:14 d-------- C:\Program Files\SUPERAntiSpyware
    2007-12-03 20:55 . 2007-12-03 20:55 d-------- C:\Documents and Settings\Ellis Christian\Application Data\SUPERAntiSpyware.com
    2007-12-03 20:55 . 2007-12-03 20:55 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
    2007-12-02 11:44 . 2007-12-02 11:44 d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
    2007-12-01 08:45 . 2007-12-01 08:45 d-------- C:\Program Files\MediaScouter
    2007-11-30 22:12 . 2007-11-30 22:12 52,736 --a------ C:\Documents and Settings\Ellis Christian\24631.exe
    2007-11-28 08:14 . 2007-11-28 08:14 1 --a------ C:\25.tmp

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2007-12-04 22:59 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
    2007-12-04 22:19 --------- d-----w C:\Program Files\AVG
    2007-12-04 21:15 --------- d-----w C:\Documents and Settings\Ellis Christian\Application Data\WeatherBug
    2007-12-02 17:54 --------- d-----w C:\Program Files\Common Files\MEP
    2007-12-02 14:26 512 ----a-w C:\ScanSectorLog.dat
    2007-11-28 13:14 12,800 ----a-w C:\WINDOWS\system32\svchost.exe
    2006-12-15 00:08 334 ----a-w C:\Documents and Settings\Clementina Christian\Application Data\internaldb1942.dat
    2006-12-15 00:08 13,046 ----a-w C:\Documents and Settings\Clementina Christian\Application Data\internaldb6823.dat
    2006-12-15 00:08 0 ----a-w C:\Documents and Settings\Clementina Christian\Application Data\internaldb8600.dat
    2006-12-15 00:07 20,480 ----a-w C:\Documents and Settings\Clementina Christian\Application Data\internaldb6291.dat
    2006-12-15 00:07 0 ----a-w C:\Documents and Settings\Clementina Christian\Application Data\internaldb8673.dat
    2006-12-15 00:07 0 ----a-w C:\Documents and Settings\Clementina Christian\Application Data\internaldb3520.dat
    2006-12-15 00:07 0 ----a-w C:\Documents and Settings\Clementina Christian\Application Data\internaldb2565.dat
    2006-12-15 00:07 0 ----a-w C:\Documents and Settings\Clementina Christian\Application Data\internaldb170.dat
    .

    ((((((((((((((((((((((((((((( snapshot@2007-12-04_ 7.58.01.12 )))))))))))))))))))))))))))))))))))))))))
    .
    - 2005-05-26 08:16:24 75,544 ----a-w C:\WINDOWS\system32\cdm.dll
    + 2007-07-31 00:19:20 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
    - 2007-12-04 12:52:34 262,144 ----a-w C:\WINDOWS\system32\config\systemprofile\ntuser.dat
    + 2007-12-05 23:38:24 262,144 ----a-w C:\WINDOWS\system32\config\systemprofile\ntuser.dat
    - 2005-05-26 08:16:24 75,544 -c--a-w C:\WINDOWS\system32\dllcache\cdm.dll
    + 2007-07-31 00:19:20 92,504 -c--a-w C:\WINDOWS\system32\dllcache\cdm.dll
    - 2005-05-26 08:16:30 124,184 -c--a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
    + 2007-07-31 00:19:16 53,080 -c--a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
    - 2005-05-26 08:16:30 1,343,768 -c--a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
    + 2007-07-31 00:19:42 1,712,984 -c--a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
    + 2007-12-05 03:30:01 821,856 ----a-w C:\WINDOWS\system32\drivers\avg7core.sys
    + 2007-12-05 03:30:07 4,224 ----a-w C:\WINDOWS\system32\drivers\avg7rsw.sys
    + 2007-12-05 03:30:08 27,776 ----a-w C:\WINDOWS\system32\drivers\avg7rsxp.sys
    + 2007-12-05 03:30:10 3,968 ----a-w C:\WINDOWS\system32\drivers\avgclean.sys
    + 2007-12-05 03:30:10 19,904 ----a-w C:\WINDOWS\system32\drivers\avgmfx86.sys
    - 2007-08-14 09:38:10 137,256 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
    + 2007-12-05 23:22:28 134,872 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
    + 2007-10-11 19:12:48 1,468,968 ----a-w C:\WINDOWS\system32\LegitCheckControl.DLL
    - 2006-06-08 22:19:52 5,967,776 ----a-w C:\WINDOWS\system32\MRT.exe
    + 2007-11-02 05:12:58 18,238,072 ----a-w C:\WINDOWS\system32\MRT.exe
    + 2007-07-31 00:19:36 549,720 ----a-w C:\WINDOWS\system32\SoftwareDistribution\Setup\ServiceStartup\wuapi.dll\7.0.6000.381\wuapi.dll
    + 2007-07-31 00:18:40 33,624 ----a-w C:\WINDOWS\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.0.6000.381\wups.dll
    + 2007-07-31 00:19:12 43,352 ----a-w C:\WINDOWS\system32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.0.6000.381\wups2.dll
    - 2005-05-26 08:16:30 465,176 ----a-w C:\WINDOWS\system32\wuapi.dll
    + 2007-07-31 00:19:36 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
    - 2005-05-26 08:16:30 124,184 ----a-w C:\WINDOWS\system32\wuauclt.exe
    + 2007-07-31 00:19:16 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
    - 2005-05-26 08:16:30 1,343,768 ----a-w C:\WINDOWS\system32\wuaueng.dll
    + 2007-07-31 00:19:42 1,712,984 ----a-w C:\WINDOWS\system32\wuaueng.dll
    - 2005-05-26 08:16:30 127,256 ----a-w C:\WINDOWS\system32\wucltui.dll
    + 2007-07-31 00:19:32 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
    - 2005-05-26 08:16:30 41,240 ----a-w C:\WINDOWS\system32\wups.dll
    + 2007-07-31 00:18:40 33,624 ----a-w C:\WINDOWS\system32\wups.dll
    - 2005-05-26 08:16:30 18,200 ----a-w C:\WINDOWS\system32\wups2.dll
    + 2007-07-31 00:19:12 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
    - 2005-05-26 08:16:30 173,536 ----a-w C:\WINDOWS\system32\wuweb.dll
    + 2007-07-31 00:19:46 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
    - 2007-12-04 02:50:26 4,212 ---h--w C:\WINDOWS\system32\zllictbl.dat
    + 2007-12-04 22:31:50 4,212 ---h--w C:\WINDOWS\system32\zllictbl.dat
    .
    -- Snapshot reset to current date --
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Weather"="C:\Program Files\AWS\WeatherBug\Weather.exe" [2006-04-07 14:02]
    "H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-06-26 16:13]
    "SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 14:57]
    "AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-12-04 22:29]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-04 22:29]

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
    backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Ashampoo Magical Defrag.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Ashampoo Magical Defrag.lnk
    backup=C:\WINDOWS\pss\Ashampoo Magical Defrag.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Install Pending Files.LNK]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Install Pending Files.LNK
    backup=C:\WINDOWS\pss\Install Pending Files.LNKCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
    backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Xpress Mail Personal Edition.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Xpress Mail Personal Edition.lnk
    backup=C:\WINDOWS\pss\Xpress Mail Personal Edition.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Ellis Christian^Start Menu^Programs^Startup^Hotmail Popper.lnk]
    path=C:\Documents and Settings\Ellis Christian\Start Menu\Programs\Startup\Hotmail Popper.lnk
    backup=C:\WINDOWS\pss\Hotmail Popper.lnkStartup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\adstart]
    iexplore.exe http://iesettingsupdate

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Drag'n'Drop_Autolaunch]
    2003-01-30 17:17 86016 --a------ C:\Program Files\Iomega HotBurn Pro\Autolaunch.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
    2006-06-26 16:13 1207080 --a------ C:\Program Files\Microsoft ActiveSync\wcescomm.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
    2006-09-12 00:58 229952 --a------ C:\Program Files\iTunes\iTunesHelper.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\masqform.exe]
    C:\Program Files\PureEdge\Viewer 6.5\masqform.exe -RunOnce

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
    C:\Program Files\MSN Messenger\MsnMsgr.Exe /background

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
    RUNDLL32.EXE NvQTwk,NvCplDaemon initialize

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PROMon.exe]
    PROMon.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    C:\Program Files\QuickTime\qttask.exe -atboottime

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
    2005-11-10 12:03 36975 --a------ C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ToolbarInstall]
    C:\WINDOWS\mirar_distro_876088.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Tracker]
    2004-10-27 12:02 118784 --a------ C:\Program Files\MySoftware\MyInvoices\tracker.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Weather]
    C:\Program Files\AWS\WeatherBug\Weather.exe 1

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zone Labs Client]
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZoneAlarm Client]
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe

    R2 NMSSvc;Intel(R) NMS;C:\WINDOWS\System32\NMSSvc.exe
    R3 DXE201;Dynex DX-E201 CardBus PC Card;C:\WINDOWS\System32\DRIVERS\DXE201.SYS
    R3 NMSCFG;NIC Management Service Configuration Driver;\??\C:\WINDOWS\System32\drivers\NMSCFG.SYS
    S3 iscFlash;iscFlash;\??\C:\WINDOWS\SYSTEM32\DRIVERS\iscflash.sys
    S3 MhzNet;Megaherz Lan/Modem PCMCIA Device Driver;C:\WINDOWS\System32\DRIVERS\xem336n5.sys
    S3 SevenConnectionService;Xpress Mail Personal Edition Service;C:\Program Files\Xpress Mail\Personal Edition\ConnectionService.exe

    *Newly Created Service* - NMSCFG
    .
    Contents of the 'Scheduled Tasks' folder
    "2007-12-01 01:03:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
    - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
    "2007-12-05 23:24:46 C:\WINDOWS\Tasks\RegCure Program Check.job"
    - C:\Program Files\RegCure\RegCure.exe
    "2007-12-05 04:25:15 C:\WINDOWS\Tasks\RegCure.job"
    - C:\Program Files\RegCure\RegCure.exe
    .
    **************************************************************************

    catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2007-12-05 18:40:43
    Windows 5.1.2600 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    Completion time: 2007-12-05 18:41:40
    .
    --- E O F ---

  10. #10
    Member steamwiz's Avatar
    Join Date
    Sep 2003
    Location
    Yorkshire U.K.
    Posts
    14,022
    Points
    2335

    Default

    Hi

    You are running an out-of-date version of java

    jre1.5.0 now has update _11 ... But jre1.6.0 is much faster...

    Go to add/remove programs and uninstall any earlier versions ... (in your case jre1.5.0_06)

    Then You can go here and install the latest version of Java.

    http://java.sun.com/javase/downloads/index.jsp

    Scroll down the page to 'Java Runtime Environment (JRE) 6 Update 3' and press the 'Download' button.


    Running an out-of-date version of java is an infection risk.

    THEN ...

    Open notepad and copy/paste the text in the code box below into it:
    NOTE* make sure to only highlight and copy what is inside the code box nothing out side of it.
    Also ..

    Pay particular attention to this :-

    Make sure the word File:: is on the first line of the text file you save (no blank line above it, & no space in front of it)
    Code:
    File::
    C:\Documents and Settings\Ellis Christian\24631.exe 
    C:\23.tmp 
    C:\25.tmp
    Save this as "CFScript.txt"

    Then drag the CFScript.txt into ComboFix.exe as you see in the screenshot below.


    This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.

    steam
    Look here for Ways to keep your computer safe
    M'SOFT MVP -Windows Security 2004/8 .member ASAP -

Page 1 of 2 12 LastLast