Welcome, Guest. Please Login or Register.
Search
Members
Login
Register
   Mischel Internet Security Forum
   Malware
   Adware, Browser Hijackers and other Malware
(Moderators: Helena, Gavin_Coe, Magnus)
   Please Help - HijackThis Scan log
« Previous topic | Next topic »
Pages: 1 2  Reply Reply  Notify of replies Notify of replies   Send Topic Send Topic   Print Print
   Author  Topic: Please Help - HijackThis Scan log  (Read 3229 times)
GodsSoldier
Newbie
*





   


Posts: 15
Please Help - HijackThis Scan log
« on: May 23rd, 2008, 6:58pm »
Quote Quote  Modify Modify

How bad is it? Thank you very much for your help!
 
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:54:02 PM, on 5/23/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
 
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\McAfee\MBK\MBackMonitor.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\SnoopFreeSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Anonymizer\Anonymizer Software\AnonASW\AnonAswSvc.exe
C:\Program Files\Anonymizer\Anonymizer Software\Common\AnonMgmtSvc.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe
C:\WINDOWS\SnoopFreeUI.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\HP\digital imaging\bin\hpqtra08.exe
C:\Program Files\Nikon\NkView6\NkvMon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\REGEDIT.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\RegCure\RegCure.exe
C:\WINDOWS\system32\wuauclt.exe
 
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo. com/ext/search/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo. com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo. com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.comcast.net
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo. com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
F2 - REG:system.ini: UserInit=c:\windows\system32\userinit.exe
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {99C92EED-01D9-420A-9BA1-D3AC9B57D71F} - (no file)
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Video - {F856BB9E-855B-498D-883E-3509C550A031} - C:\WINDOWS\korad.dll (file missing)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [xclzreq] c:\windows\system32\xzrcser.exe r
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [ndZ] C:\windows\temp\ndZ.exe
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe"
O4 - HKLM\..\Run: [jgqemc] C:\WINDOWS\System32\jjcvhsmm.exe
O4 - HKLM\..\Run: [irznlKCax] C:\documents and settings\flaca\local settings\temp\irznlKCax.exe
O4 - HKLM\..\Run: [ibecdbv8] C:\WINDOWS\system32\ibecdbv8.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [Dell AIO Printer A960] "C:\Program Files\Dell AIO Printer A960\dlbfbmgr.exe"
O4 - HKLM\..\Run: [defghijklm] C:\WINDOWS\System32\defghijklm.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [McAfee Backup] C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
O4 - HKLM\..\Run: [MBkLogOnHook] C:\Program Files\McAfee\MBK\LogOnHook.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [Adobe Version Cue CS2] "C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe"
O4 - HKLM\..\Run: [SnoopFreeUI] SnoopFreeUI.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [tgcmd] C:\Program Files\Support.com\bin\tgcmd.exe /server /startmonitor /deaf
O4 - HKLM\..\Run: [AIMPro] "C:\Program Files\AIM\AIM Pro\aimpro.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Active Desktop Calendar] C:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.EXE 1
O4 - HKCU\..\RunOnce: [DelayShred] "c:\program files\mcafee\mshr\ShrCL.EXE" /P7 /q C:\DOCUME~1\Flaca\LOCALS~1\Temp\TEMPOR~1\Content.SH! C:\DOCUME~1\Flaca\LOCALS~1\Temp\TEMPOR~1.SH! C:\DOCUME~1\Flaca\LOCALS~1\Temp\HSPERF~1.SH! C:\DOCUME~1\Flaca\LOCALS~1\Temp\History\History.IE5\MSE813~1.SH! C:\DOCUME~1\Flaca\LOCALS~1\Temp\History\History.SH! C:\DOCUME~1\Flaca\LOCALS~1\Temp\History.SH! C:\DOCUME~1\Flaca\LOCALS~1\Temp\Cookies.SH!
O4 - HKCU\..\RunOnce: [CheckNetworkConnection] "C:\Program Files\Support.com\providerComcast\desktopdoctor.exe" /flow /flow=diagnosenetwork /trayclick=true /haveconfirmedwiring=true /haverenewed=true /haverestartedmodem=true /onrestart=true /havehealed=true /issuenumber=f32e3517-f0f7-44fb-abc7-08febf233be5
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: FriendFinder Messenger.lnk = C:\Program Files\FriendFinder Messenger\FriendFinder Messenger.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\digital imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} -  
O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {7CCAD6DD-DD0B-440B-91FF-7670F5AADC21} - http://playgames.comcast.net/online2/mahjong_escape_ancient_japan/SpinTo pGamesLauncher.cab
O16 - DPF: {809A6301-7B40-4436-A02C-87B8D3D7D9E3} (ZPA_DMNO Object) - http://zone.msn.com/bingame/zpagames/zpa_dmno.cab55579.cab
O16 - DPF: {97B79133-88F0-45F0-8D57-0F2EF27D9C66} -  
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5245/mcfscan.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (file missing)
O20 - Winlogon Notify: entrsv - C:\WINDOWS\inf\entrsv.dll (file missing)
O20 - Winlogon Notify: lvruvhux - lvruvhux.dll (file missing)
O20 - Winlogon Notify: vvfnmsop - vvfnmsop.dll (file missing)
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS2 - Adobe Systems Incorporated - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
O23 - Service: Anonymizer Anti-Spyware Service (AnonAswSvc) - Anonymizer - C:\Program Files\Anonymizer\Anonymizer Software\AnonASW\AnonAswSvc.exe
O23 - Service: Anonymizer Management Service (AnonMgmtSvc) - Anonymizer - C:\Program Files\Anonymizer\Anonymizer Software\Common\AnonMgmtSvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: Snoop Free Service (SnoopFreeSvc) - Unknown owner - C:\WINDOWS\System32\SnoopFreeSvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
 
--
End of file - 18611 bytes
IP Logged
siliconman01
Global Moderator
*****



Trojans! Chew 'em Up, Spit 'em Out...

   


Gender: male
Posts: 7358
Re: Please Help - HijackThis Scan log
« Reply #1 on: May 24th, 2008, 11:30am »
Quote Quote  Modify Modify

Welcome to the forum GodsSoldier,  Cheesy
 
There are some infections showing up.  Please do this:
 
1.  Run another Hijackthis scan.
 
2.  When the scan is completed, place a check mark next to the following items.  BE SURE that these are the only items checked.
 
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
 
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
 
O2 - BHO: (no name) - {99C92EED-01D9-420A-9BA1-D3AC9B57D71F} - (no file)
 
O2 - BHO: Video - {F856BB9E-855B-498D-883E-3509C550A031} - C:\WINDOWS\korad.dll (file missing)
 
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
 
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
 
O20 - Winlogon Notify: entrsv - C:\WINDOWS\inf\entrsv.dll (file missing)
 
O20 - Winlogon Notify: lvruvhux - lvruvhux.dll (file missing)
 
O20 - Winlogon Notify: vvfnmsop - vvfnmsop.dll (file missing)

 
3.  Close your Browser window
 
4.  Then click on Fix Checked located at the bottom left of the HJT window.  Confirm that you want these items fixed and let HJT fix them.
 
5.  Close HiJackthis and immediately reboot.
 
After you reboot, please do the following:
 
1.  Go to the link below and download program Combofix.exe and save it on your desktop.  
   
http://download.bleepingcomputer.com/sUBs/ComboFix.exe  
   
2.  Temporarily de-activate all your security programs EXCEPT your software firewall.  
   
3.  Close down as many programs as you can (programs in the Notification Tray-  next to the clock).  
   
4.  Close your browser.  
   
5.  Double click on Combofix.exe to execute it and follow the instructions.  
   
Please note, that once you start ComboFix you should not click anywhere on the ComboFix window as it can cause the program to stall. In fact, when ComboFix is running, do not touch your computer at all and just take a break as it may take a while for it to complete.
   
-  When Combofix.exe is finished, it will save a log on your system.    
   
6.  Post the Combofix log back here    
   
7.  Run Hijackthis and post the new HiJackthis scan log back here.
IP Logged

______
TrojanHunter V5.5.1002...No. 1 AT in my Book and on my Box(es)! Windows 7 x64 Professional on a Dell XPS 410, 8 gbyte RAM, dual WD VelociRaptors, dual 24" UltraSharp FPD monitors, Logitech 5.1 Surround Sound; Windows 7 x86 Professional on a Dell Vostro 220s, 4 gbyte RAM, dual WD VelociRaptors. Common: router, cable modem.
GodsSoldier
Newbie
*





   


Posts: 15
Re: Please Help - HijackThis Scan log
« Reply #2 on: May 24th, 2008, 12:55pm »
Quote Quote  Modify Modify

Thank You! Grin
 
I did all that already, I actually read some posts and did all of that.  How do programs like friend finder get on my machine that I never download? I have noticed some stuff in the log I have never even used. Are these all hackers Angry and should i look out for them in the future?
 
It says my post is too long I am posting separately I hope that is ok.
 
Here is beginning of combolog:
 
ComboFix 08-05-21.3 - Flaca 2008-05-24 13:25:30.3 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.563 [GMT -4:00]
Running from: C:\Documents and Settings\Flaca\Desktop\ComboFix.exe
 
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
 
(((((((((((((((((((((((((   Files Created from 2008-04-24 to 2008-05-24  )))))))))))))))))))))))))))))))
.
 
2008-05-24 12:45 . 2008-05-24 13:23
54,156
--ah-----
C:\WINDOWS\QTFont.qfn
2008-05-24 12:45 . 2008-05-24 12:45
1,409
--a------
C:\WINDOWS\QTFont.for
2008-05-24 12:30 . 2008-05-24 12:30
<DIR>
d--------
C:\Program Files\PC Drivers HeadQuarters
2008-05-24 12:30 . 2008-05-24 12:30
<DIR>
d--------
C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
2008-05-24 01:03 . 2008-05-24 01:03
<DIR>
d--------
C:\Documents and Settings\Flaca\Application Data\cerasus.media
2008-05-24 01:03 . 2008-05-24 01:03
<DIR>
d--------
C:\Documents and Settings\All Users\Application Data\cerasus.media
2008-05-24 00:58 . 2008-05-24 01:45
<DIR>
d--------
C:\Program Files\Chill
2008-05-23 21:32 . 2008-05-23 21:32
<DIR>
d--------
C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-05-23 20:37 . 2008-05-23 20:38
<DIR>
d--------
C:\Program Files\CCleaner
2008-05-23 19:33 . 2008-05-23 20:55
<DIR>
d--------
C:\Program Files\TrojanHunter 5.0
2008-05-21 21:11 . 2008-05-21 21:11
<DIR>
d--------
C:\Program Files\Common Files\Wise Installation Wizard
2008-05-20 17:49 . 2008-05-20 17:49
<DIR>
d--------
C:\Documents and Settings\All Users\Application Data\{9E97B640-FCFE-4900-B18A-72FAE662D6B7}
2008-05-20 17:48 . 2007-10-08 14:04
939,368
--a------
C:\WINDOWS\SYSTEM32\flash.ocx
2008-05-20 17:00 . 2000-03-23 12:50
446,464
-ra------
C:\WINDOWS\SYSTEM32\hhactivex.dll
2008-05-20 17:00 . 1999-05-07 13:24
414,944
--a------
C:\WINDOWS\SYSTEM32\COMCT332.OCX
2008-05-20 17:00 . 1998-11-10 10:46
328,480
--a------
C:\WINDOWS\SYSTEM32\ssa3d30.ocx
2008-05-20 17:00 . 2002-01-08 17:00
176,128
--a------
C:\WINDOWS\SYSTEM32\RcdScan.dll
2008-05-20 17:00 . 1998-09-24 12:03
171,967
--a------
C:\WINDOWS\SYSTEM32\Odbcjet.hlp
2008-05-20 17:00 . 1998-06-17 23:00
89,360
--a------
C:\WINDOWS\SYSTEM32\VB5DB.DLL
2008-05-20 17:00 . 1998-09-24 12:03
7,348
--a------
C:\WINDOWS\SYSTEM32\Odbcjet.cnt
2008-05-20 12:22 . 2008-05-20 12:22
<DIR>
d--------
C:\WINDOWS\SYSTEM32\Migration
2008-05-20 11:50 . 2008-05-20 11:50
<DIR>
d--------
C:\Program Files\RegCure
2008-05-19 18:53 . 2008-05-19 18:53
221,184
--a------
C:\WINDOWS\SnoopFreeUI.exe
2008-05-19 18:53 . 2008-05-19 18:53
90,112
--a------
C:\WINDOWS\SYSTEM32\SnoopFreeSvc.exe
2008-05-19 18:53 . 2008-05-19 18:53
45,056
--a------
C:\WINDOWS\SnoopFreeDll.dll
2008-05-19 18:53 . 2008-05-19 18:53
9,472
--a------
C:\WINDOWS\SYSTEM32\DRIVERS\SnopFree.sys
2008-05-16 11:58 . 2008-05-16 11:58
12,632
--a------
C:\WINDOWS\SYSTEM32\lsdelete.exe
2008-04-29 11:20 . 2008-04-29 11:20
15,648
--a------
C:\WINDOWS\SYSTEM32\DRIVERS\NSDriver.sys
2008-04-29 11:19 . 2008-04-29 11:19
15,648
--a------
C:\WINDOWS\SYSTEM32\DRIVERS\Awrtrd.sys
2008-04-29 11:19 . 2008-04-29 11:19
12,960
--a------
C:\WINDOWS\SYSTEM32\DRIVERS\Awrtpd.sys
 
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-24 16:31
---------
d--h--w
C:\Program Files\InstallShield Installation Information
2008-05-24 05:52
---------
d---a-w
C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-24 04:58
---------
d-----w
C:\Program Files\Common Files\Oberon Media
2008-05-24 01:05
---------
d-----w
C:\Program Files\Spybot - Search & Destroy
2008-05-24 01:04
---------
d-----w
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-24 00:56
---------
d-----w
C:\Program Files\Trapware Corporation
2008-05-24 00:37
---------
d-----w
C:\Program Files\Yahoo!
2008-05-24 00:05
---------
d-----w
C:\Program Files\Google
2008-05-22 01:12
---------
d-----w
C:\Program Files\Lavasoft
2008-05-22 01:12
---------
d-----w
C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-20 16:24
---------
d-----w
C:\Documents and Settings\All Users\Application Data\avg7
2008-05-20 16:11
---------
d-----w
C:\Program Files\Real
2008-05-20 16:11
---------
d-----w
C:\Documents and Settings\Flaca\Application Data\Move Networks
2008-05-17 13:05
---------
d-----w
C:\Documents and Settings\Flaca\Application Data\AdobeUM
2008-05-04 20:45
---------
d-----w
C:\Program Files\XoftSpySE
2008-04-27 19:07
---------
d-----w
C:\Program Files\Common Files\Adobe
2008-04-22 02:38
---------
d-----w
C:\Documents and Settings\All Users\Application Data\HPSSUPPLY
2008-04-21 19:23
---------
d-----w
C:\Program Files\VirtualDJ
2008-04-21 18:36
---------
d-----w
C:\Program Files\McAfee
2008-04-21 17:26
---------
d-----w
C:\Documents and Settings\Flaca\Application Data\AVG7
2008-04-20 22:05
---------
d-----w
C:\Documents and Settings\LocalService\Application Data\AVG7
2008-04-20 18:36
---------
d-----w
C:\Program Files\Viewpoint
2008-04-17 23:30
---------
d-----w
C:\Program Files\Trend Micro
2008-04-17 20:07
---------
d-----w
C:\Program Files\RegistryFix
2008-04-16 02:40
---------
d-----w
C:\Program Files\MSECache
2008-04-04 00:17
---------
d-----w
C:\Program Files\iTunes
2008-04-04 00:17
---------
d-----w
C:\Program Files\iPod
2008-04-04 00:13
---------
d-----w
C:\Program Files\QuickTime
2008-03-27 08:12
151,583
----a-w
C:\WINDOWS\SYSTEM32\msjint40.dll
2008-03-19 09:47
1,845,248
----a-w
C:\WINDOWS\SYSTEM32\win32k.sys
2008-03-01 13:06
826,368
----a-w
C:\WINDOWS\SYSTEM32\wininet.dll
2008-02-25 20:18
0
----a-w
C:\WINDOWS\Fonts\AeroOutline.tt
2008-02-25 20:18
0
----a-w
C:\WINDOWS\Fonts\AeroLight.tt
2008-02-25 20:18
0
----a-w
C:\WINDOWS\Fonts\AeroExtended.tt
2008-02-25 20:18
0
----a-w
C:\WINDOWS\Fonts\AeroCondensed.tt
2008-02-25 20:18
0
----a-w
C:\WINDOWS\Fonts\Aero.tt
2008-02-25 20:17
82
----a-w
C:\WINDOWS\Fonts\._.DS_Store
2007-02-03 17:20
974,268
--sha-w
C:\WINDOWS\INF\vsrtne.ini2
2006-07-15 02:39
10,752
--sha-w
C:\Program Files\Thumbs.db
2005-09-02 00:06
186
----a-w
C:\Program Files\seven.reg
2005-07-30 00:00
664,654
----a-w
C:\Program Files\screen_03.exe
2005-07-29 23:59
967,234
----a-w
C:\Program Files\screen_04.exe
2005-07-29 23:58
683,024
----a-w
C:\Program Files\screen_02.exe
2005-07-29 23:56
664,203
----a-w
C:\Program Files\screen_01.exe
2005-07-25 19:24
1,782,960
----a-w
C:\Program Files\tmas-web-scan.exe
2005-03-09 21:44
4,970
----a-w
C:\Program Files\SEvEN.nfo
2005-03-09 21:41
174
----a-w
C:\Program Files\seven.dat
2005-03-09 21:14
49,152
----a-w
C:\Program Files\snd3d.dll
2005-03-09 21:14
32,768
----a-w
C:\Program Files\snd3d_fmod.dll
2005-03-09 21:14
193,772
----a-w
C:\Program Files\splashscreen.jpg
2005-03-09 21:14
176,128
----a-w
C:\Program Files\ui2.dll
2005-03-09 21:14
16,255,227
----a-w
C:\Program Files\data.mjz
2004-12-09 03:06
893,252
----a-r
C:\Program Files\What's New in 6_0.pdf
2004-12-09 03:06
632,550
----a-r
C:\Program Files\Contacting Quark.pdf
2004-12-09 03:06
509,570
----a-r
C:\Program Files\Demo ReadMe.pdf
2004-12-09 03:06
152,053
----a-r
C:\Program Files\License Agreement.pdf
2004-12-09 03:06
1,082,258
----a-r
C:\Program Files\Guide to QXP Addendum.pdf
2004-12-09 03:05
474,353
----a-r
C:\Program Files\Updater ReadMe.pdf
2004-12-04 00:03
50,665,546
----a-r
C:\Program Files\Data1.cab
2004-12-04 00:03
4,188,160
----a-r
C:\Program Files\QuarkXPress 6.5 Demo.msi
2004-08-18 19:01
2,931,712
---ha-w
C:\Program Files\BOOTIMG.BIN
2004-08-18 19:00
2,048
---ha-w
C:\Program Files\BOOTCAT.BIN
2004-08-18 13:34
2,740
----a-w
C:\Program Files\INSTOPTS.DAT
2004-08-18 13:09
577,024
----a-w
C:\Program Files\SCRBLOCK.MSI
2004-08-18 13:09
204,997
----a-w
C:\Program Files\DEFRULES.DAT
2004-08-18 13:09
2,182,656
----a-w
C:\Program Files\IWP.MSI
2004-08-18 13:08
556,032
----a-w
C:\Program Files\PARENT.MSI
2004-08-18 13:08
100,864
----a-w
C:\Program Files\MSREDIST.MSI
2004-08-18 13:08
1,132,544
----a-w
C:\Program Files\SYMLT.MSI
2004-08-18 13:08
1,121,280
----a-w
C:\Program Files\NAV.MSI
2004-08-18 12:54
1,475,072
----a-w
C:\Program Files\DISK3.IMG
2004-08-18 12:51
1,475,072
----a-w
C:\Program Files\DISK2.IMG
2004-08-18 12:49
1,475,072
----a-w
C:\Program Files\DISK1.IMG
2004-08-18 12:44
99,456
----a-w
C:\Program Files\APWCMD9X.DLL
2004-08-18 12:20
110
----a-w
C:\Program Files\VERSION.DAT
2004-08-18 03:36
87,192
----a-w
C:\Program Files\SYMLTCOM.DLL
2004-08-18 03:36
74,904
----a-w
C:\Program Files\LTCHKRES.DLL
2004-08-18 03:36
656,536
----a-w
C:\Program Files\SYMUIHLP.DLL
2004-08-18 03:36
324,760
----a-w
C:\Program Files\SYMUIAX2.OCX
2004-08-18 03:36
226,456
----a-w
C:\Program Files\ACTRES.DLL
2004-08-18 03:36
22,168
----a-w
C:\Program Files\LRSEND.EXE
2004-08-18 03:36
169,112
----a-w
C:\Program Files\SLTCHK01.DLL
2004-08-18 03:36
169,112
----a-w
C:\Program Files\DJSALERT.DLL
2004-08-18 03:36
148,632
----a-w
C:\Program Files\SYMLCUI.DLL
2004-08-18 03:36
140,440
----a-w
C:\Program Files\SYMBBAAX.OCX
2004-08-18 03:36
132,248
----a-w
C:\Program Files\CFGWIZ.EXE
2004-08-18 03:22
9,728
----a-w
C:\Program Files\UNIN.DLL
2004-08-18 03:22
9,728
----a-w
C:\Program Files\SYMHELP.DLL
2004-08-18 03:22
9,728
----a-w
C:\Program Files\SUPT_CPD.DLL
2004-08-18 03:22
9,728
----a-w
C:\Program Files\OPTIONS.DLL
2004-08-18 03:22
9,728
----a-w
C:\Program Files\MONITOR.DLL
2004-08-18 03:22
9,728
----a-w
C:\Program Files\LU_SUB.DLL
2004-08-18 03:22
3,832
----a-w
C:\Program Files\CFGWIZ.TLB
2004-08-18 03:22
112,640
----a-w
C:\Program Files\HELP.MSI
2004-08-18 03:21
9,728
----a-w
C:\Program Files\NAV_001.DLL
2004-08-18 03:21
9,728
----a-w
C:\Program Files\LU_PC.DLL
2004-08-18 03:21
9,728
----a-w
C:\Program Files\LU_MODE.DLL
2004-08-18 03:21
9,728
----a-w
C:\Program Files\LU_FAQ.DLL
2004-08-18 03:21
9,728
----a-w
C:\Program Files\LU_004.DLL
2004-08-18 03:21
9,728
----a-w
C:\Program Files\LU_003.DLL
2007-02-03 17:20
974,268
--sha-w
C:\WINDOWS\INF\vsrtne.ini2
.
 
(((((((((((((((((((((((((((((   snapshot@2008-05-23_21.54.18.28   )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-05-24 16:30:44
184,320
----a-w
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\DriversHQ.DriverDet#\3ca8 c7d362d7a3675c344c1579b30005\DriversHQ.DriverDetective.Common.ni.dll
+ 2008-05-24 16:30:26
2,236,416
----a-w
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\DriversHQ.DriverDet#\44eb d042ef56bf4c9ca617adb1942a74\DriversHQ.DriverDetective.Client.ni.exe
+ 2008-05-24 16:30:45
57,856
----a-w
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\DriversHQ.DriverDet#\ad84 0beeac4cf221d79b894e731a52a5\DriversHQ.DriverDetective.ExceptionLogging. ni.dll
+ 2008-05-24 16:30:37
225,280
----a-w
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\DriversHQ.DriverDet#\c533 129262205686976f2d05d3fc89e9\DriversHQ.DriverDetective.Client.Communicat ion.ni.dll
+ 2008-05-24 16:30:45
249,856
----a-w
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Applicati#\9b29 f77352782e25520051e9a2165ccd\Microsoft.ApplicationBlocks.Updater.ni.dll
+ 2008-05-24 16:30:53
2,441,216
----a-w
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\b3b62fe 820b416515420a6ec17b247c3\Microsoft.JScript.ni.dll
+ 2008-05-24 16:30:55
167,936
----a-w
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Practices#\264a 02da4ba71b8ad3bc5c65d21f535a\Microsoft.Practices.EnterpriseLibrary.Secur ity.Cryptography.ni.dll
+ 2008-05-24 16:30:54
356,352
----a-w
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Practices#\7752 f8cfb86957944f4882ace6f996c2\Microsoft.Practices.ObjectBuilder.ni.dll
+ 2008-05-24 16:30:47
368,640
----a-w
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Practices#\ea85 63fc0a0c59330ab878a2f428a3f6\Microsoft.Practices.EnterpriseLibrary.Commo n.ni.dll
+ 2008-05-24 16:30:37
17,920
----a-w
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualC\cd07306 94ba5927a6efd32129783e1b4\Microsoft.VisualC.ni.dll
+ 2008-05-24 16:30:53
77,824
----a-w
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\e674ba75a51 4e00b26329e212da938e0\Microsoft.Vsa.ni.dll
+ 2008-05-24 16:30:35
163,840
----a-w
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\c466 25ea87db53ccf6194fe17ee05c19\System.Configuration.Install.ni.dll
+ 2008-05-24 16:30:43
1,183,744
----a-w
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Data.OracleC#\1abd b47765d0696a2fc0a1095bac0249\System.Data.OracleClient.ni.dll
+ 2008-05-24 16:30:33
2,756,608
----a-w
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\e59504 af41afab5e04681af951d9b302\System.Data.SqlXml.ni.dll
+ 2008-05-24 16:30:49
1,064,960
----a-w
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Management\29c7192 327cf3999961560bf3a3995c6\System.Management.ni.dll
+ 2008-05-24 16:30:40
815,104
----a-w
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\0898f6c1de8cb89413d206e3d6a3ce1d\System.Runtime.Remoting.ni.dll
+ 2008-05-24 16:30:35
339,968
----a-w
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\1f5c f8178029f5b959a9af75cb8cfedb\System.Runtime.Serialization.Formatters.Soa p.ni.dll
+ 2008-05-24 16:30:56
139,264
----a-w
C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\XPBurnComponent\1fcfda856 b6a110ed833efa1ec27e647\XPBurnComponent.ni.dll
- 2008-05-24 01:40:46
2,048
--s-a-w
C:\WINDOWS\BOOTSTAT.DAT
+ 2008-05-24 17:23:32
2,048
--s-a-w
C:\WINDOWS\BOOTSTAT.DAT
+ 2008-05-24 16:30:07
26,694
----a-r
C:\WINDOWS\Installer\{621C02EA-AAFF-4026-A903-165D59529A16}\ARPPRODUCTIC ON.exe
+ 2008-05-24 16:30:07
69,632
----a-r
C:\WINDOWS\Installer\{621C02EA-AAFF-4026-A903-165D59529A16}\DriversHQ.Dr iverDe_212B77217E284373BD0AA155B0932A89.exe
+ 2008-05-24 16:30:07
69,632
----a-r
C:\WINDOWS\Installer\{621C02EA-AAFF-4026-A903-165D59529A16}\DriversHQ.Dr iverDe_212B77217E284373BD0AA155B0932A89_1.exe
.
(((((((((((((((((((((((((((((((((((((((((((((   AWF   ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
----a-w      278,528 2005-05-14 04:20:50  C:\Program Files\iTunes\bak\iTunesHelper.exe
----a-w      267,048 2008-03-30 14:36:40  C:\Program Files\iTunes\iTunesHelper.exe
 
----a-w  98,304 2005-07-25 23:01:09  C:\Program Files\QuickTime\bak\qttask.exe
----a-w      413,696 2008-03-29 03:37:20  C:\Program Files\QuickTime\QTTask.exe
 
----a-w  13,312 2003-07-16 16:20:13  C:\WINDOWS\SYSTEM32\bak\ctfmon.exe
----a-w  15,360 2004-08-04 05:56:50  C:\WINDOWS\SYSTEM32\ctfmon.exe
 
----a-w      172,032 2004-04-06 10:28:46  C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\bak\hpztsb11.exe
 
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown  
REGEDIT4
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Weather"="C:\PROGRA~1\AWS\WEATHE~1\Weather.exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56 15360]
"Active Desktop Calendar"="C:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe" [ ]
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"DelayShred"="c:\program files\mcafee\mshr\ShrCL.exe" [2007-01-17 19:02 95784]
"CheckNetworkConnection"="C:\Program Files\Support.com\providerComcast\desktopdoctor.exe" [ ]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"xclzreq"="c:\windows\system32\xzrcser.exe" [ ]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-04 18:24 28672 C:\WINDOWS\SYSTEM32\Ati2mdxx.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [ ]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe" [2008-04-23 02:08 483328]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 02:01 110592]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-01-26 17:20 185896]
"SM1BG"="C:\WINDOWS\SM1BG.EXE" [ ]
"ShStatEXE"="C:\Program Files\Network Associates\VirusScan\SHSTAT.exe" [ ]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [ ]
"McAfeeUpdaterUI"="C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" [ ]
"jgqemc"="C:\WINDOWS\System32\jjcvhsmm.exe" [ ]
"irznlKCax"="C:\documents and settings\flaca\local settings\temp\irznlKCax.exe" [ ]
"ibecdbv8"="C:\WINDOWS\system32\ibecdbv8.exe" [ ]
"DVDSentry"="C:\WINDOWS\System32\DSentry.exe" [2003-08-13 12:27 28672]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2003-08-06 03:04 114741]
"Dell AIO Printer A960"="C:\Program Files\Dell AIO Printer A960\dlbfbmgr.exe" [ ]
"defghijklm"="C:\WINDOWS\System32\defghijklm.exe" [ ]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [ ]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 20:51 39792]
"McAfee Backup"="C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe" [2007-01-16 14:59 4838952]
"MBkLogOnHook"="C:\Program Files\McAfee\MBK\LogOnHook.exe" [2007-01-08 12:22 20480]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 11:09 63712]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 22:34 49152]
"SnoopFreeUI"="SnoopFreeUI.exe" [2008-05-19 18:53 221184 C:\WINDOWS\SnoopFreeUI.exe]
"tgcmd"="C:\Program Files\Support.com\bin\tgcmd.exe" [ ]
"BJCFD"="C:\Program Files\BroadJump\Client Foundation\CFD.exe" [ ]
"AIMPro"="C:\Program Files\AIM\AIM Pro\aimpro.exe" [ ]
"Adobe Version Cue CS2"="C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe" [2005-04-04 18:58 856064]
 
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\System32\ctfmon.exe" [2004-08-04 01:56 15360]
 
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-04 01:56 53760 C:\WINDOWS\SYSTEM32\narrator.exe]
"tscuninstall"="C:\WINDOWS\system32\tscupgrd.exe" [2004-08-04 01:59 44544]
 
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.e xe [2007-10-16 18:20:26 25214]
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2003-02-17 23:25:57 110592]
 
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSACM.MSNAUDIO"= msnaudio.acm
"SENTINEL"= snti386.dll
"VIDC.JDCT"= jl_jdct.drv
 
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
IP Logged
GodsSoldier
Newbie
*





   


Posts: 15
Re: Please Help - HijackThis Scan log
« Reply #3 on: May 24th, 2008, 12:58pm »
Quote Quote  Modify Modify

combolog cont:
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\2LRX2W83X2T3MQ]
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\4kOc]
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\6gxNuiUtt]
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\defghijklm]
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EbatesMoeMoneyMaker0]
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ibecdbv8]
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\irznlKCax]
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\jgqemc]
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ndZ]
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Rxagik]
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\satmat]
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SM1BG]
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TBPS]
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Win Server Updt]
 
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
 
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
 
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
 
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Anonymizer\\Anonymizer Software\\common\\AnonProxy.exe"=
"C:\\Program Files\\Adobe\\Adobe Version Cue CS2\\bin\\VersionCueCS2.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\McAfee\\MBK\\McAfeeDataBackup.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
 
R2 AnonAswSvc;Anonymizer Anti-Spyware Service;"C:\Program Files\Anonymizer\Anonymizer Software\AnonASW\AnonAswSvc.exe"  [2007-10-22 05:12]
R2 AnonMgmtSvc;Anonymizer Management Service;"C:\Program Files\Anonymizer\Anonymizer Software\Common\AnonMgmtSvc.exe"  [2007-10-22 05:12]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 17:38]
S3 JL2005C;Dual Mode Camera;C:\WINDOWS\system32\Drivers\jl2005c.sys []
S3 USB_RNDIS_XP;Westell WireSpeed Dual Connect Modem;C:\WINDOWS\system32\DRIVERS\usb8023.sys [2004-08-04 00:04]
 
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12
REG_MULTI_SZ    
Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt
REG_MULTI_SZ    
hpqcxs08 hpqddsvc
 
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\##192.168.1.10#c$#Deploy#Office_2003]
\Shell\AutoRun\command - Z:\SETUP.EXE /AUTORUN
\Shell\configure\command - Z:\SETUP.EXE
\Shell\install\command - Z:\SETUP.EXE
 
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
 
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{908d84df-91d8-11db-911b-000cf193dd71}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
 
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d8364dca-0eab-11dc-925e-000cf193dd71}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
 
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-05-24 17:00:01 C:\WINDOWS\Tasks\AF2C9B4E90A3120E.job"
- c:\progra~1\hecktr~1\Bendantiobj.exe
"2008-05-23 22:10:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-04-15 05:02:30 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe'
"2008-03-01 06:00:33 C:\WINDOWS\Tasks\McQcTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe
"2008-05-20 22:00:00 C:\WINDOWS\Tasks\Pareto UNS.job"
- C:\Program Files\Common Files\ParetoLogic\UUS\UUS.dll\Pareto_Update.exe
"2008-05-24 17:23:40 C:\WINDOWS\Tasks\RegCure Program Check.job"
- C:\Program Files\RegCure\RegCure.exe
"2008-05-20 15:51:10 C:\WINDOWS\Tasks\RegCure.job"
- C:\Program Files\RegCure\RegCure.exe
.
************************************************************************ **
 
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-24 13:31:46
Windows 5.1.2600 Service Pack 2 NTFS
 
scanning hidden processes ...  
 
scanning hidden autostart entries ...
 
scanning hidden files ...  
 
scan completed successfully
hidden files: 0
 
************************************************************************ **
.
--------------------- DLLs Loaded Under Running Processes ---------------------
 
PROCESS: C:\WINDOWS\explorer.exe
-> C:\WINDOWS\SnoopFreeDll.dll
.
Completion time: 2008-05-24 13:35:51
ComboFix-quarantined-files.txt  2008-05-24 17:35:36
ComboFix2.txt  2008-05-24 01:54:48
 
Pre-Run: 14,050,951,168 bytes free
Post-Run: 14,042,021,888 bytes free
 
324
--- E O F ---
2008-05-17 18:23:33
IP Logged
GodsSoldier
Newbie
*





   


Posts: 15
Re: Please Help - HijackThis Scan log
« Reply #4 on: May 24th, 2008, 12:58pm »
Quote Quote  Modify Modify

Hijack This (thanks again!):
 
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:44:27 PM, on 5/24/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
 
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\McAfee\MBK\MBackMonitor.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\SnoopFreeSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Anonymizer\Anonymizer Software\AnonASW\AnonAswSvc.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Program Files\Anonymizer\Anonymizer Software\Common\AnonMgmtSvc.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\SnoopFreeUI.exe
C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\digital imaging\bin\hpqtra08.exe
C:\Program Files\Nikon\NkView6\NkvMon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\notepad.exe
C:\WINDOWS\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
 
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo. com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo. com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [xclzreq] c:\windows\system32\xzrcser.exe r
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe"
O4 - HKLM\..\Run: [jgqemc] C:\WINDOWS\System32\jjcvhsmm.exe
O4 - HKLM\..\Run: [irznlKCax] C:\documents and settings\flaca\local settings\temp\irznlKCax.exe
O4 - HKLM\..\Run: [ibecdbv8] C:\WINDOWS\system32\ibecdbv8.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [Dell AIO Printer A960] "C:\Program Files\Dell AIO Printer A960\dlbfbmgr.exe"
O4 - HKLM\..\Run: [defghijklm] C:\WINDOWS\System32\defghijklm.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [McAfee Backup] C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
O4 - HKLM\..\Run: [MBkLogOnHook] C:\Program Files\McAfee\MBK\LogOnHook.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SnoopFreeUI] SnoopFreeUI.exe
O4 - HKLM\..\Run: [tgcmd] C:\Program Files\Support.com\bin\tgcmd.exe /server /startmonitor /deaf
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [AIMPro] "C:\Program Files\AIM\AIM Pro\aimpro.exe"
O4 - HKLM\..\Run: [Adobe Version Cue CS2] "C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe"
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.EXE 1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Active Desktop Calendar] C:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe
O4 - HKCU\..\RunOnce: [DelayShred] "c:\program files\mcafee\mshr\ShrCL.EXE" /P7 /q C:\DOCUME~1\Flaca\LOCALS~1\Temp\TEMPOR~1\Content.SH! C:\DOCUME~1\Flaca\LOCALS~1\Temp\TEMPOR~1.SH! C:\DOCUME~1\Flaca\LOCALS~1\Temp\HSPERF~1.SH! C:\DOCUME~1\Flaca\LOCALS~1\Temp\History\History.IE5\MSE813~1.SH! C:\DOCUME~1\Flaca\LOCALS~1\Temp\History\History.SH! C:\DOCUME~1\Flaca\LOCALS~1\Temp\History.SH! C:\DOCUME~1\Flaca\LOCALS~1\Temp\Cookies.SH!
O4 - HKCU\..\RunOnce: [CheckNetworkConnection] "C:\Program Files\Support.com\providerComcast\desktopdoctor.exe" /flow /flow=diagnosenetwork /trayclick=true /haveconfirmedwiring=true /haverenewed=true /haverestartedmodem=true /onrestart=true /havehealed=true /issuenumber=f32e3517-f0f7-44fb-abc7-08febf233be5
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\digital imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} -  
O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {7CCAD6DD-DD0B-440B-91FF-7670F5AADC21} - http://playgames.comcast.net/online2/mahjong_escape_ancient_japan/SpinTo pGamesLauncher.cab
O16 - DPF: {809A6301-7B40-4436-A02C-87B8D3D7D9E3} (ZPA_DMNO Object) - http://zone.msn.com/bingame/zpagames/zpa_dmno.cab55579.cab
O16 - DPF: {97B79133-88F0-45F0-8D57-0F2EF27D9C66} -  
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5245/mcfscan.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (file missing)
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS2 - Adobe Systems Incorporated - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
O23 - Service: Anonymizer Anti-Spyware Service (AnonAswSvc) - Anonymizer - C:\Program Files\Anonymizer\Anonymizer Software\AnonASW\AnonAswSvc.exe
O23 - Service: Anonymizer Management Service (AnonMgmtSvc) - Anonymizer - C:\Program Files\Anonymizer\Anonymizer Software\Common\AnonMgmtSvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Snoop Free Service (SnoopFreeSvc) - Unknown owner - C:\WINDOWS\System32\SnoopFreeSvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
 
--
End of file - 16155 bytes
IP Logged
siliconman01
Global Moderator
*****



Trojans! Chew 'em Up, Spit 'em Out...

   


Gender: male
Posts: 7358
Re: Please Help - HijackThis Scan log
« Reply #5 on: May 24th, 2008, 2:27pm »
Quote Quote  Modify Modify

Okay, now please do this:
 
1.  Download/install the Trial version of TrojanHunter.  The download link is at the top of this forum page.
 
2.  Because the Trial version does not activate LiveUpdate, go to the link below and manually update the TH rulesets to the latest version.
 
http://www.misec.net/trojanhunter/updating/
 
3.  Go the link below and download/install the Free version of SuperAntiSpyware.
 
http://www.SuperAntiSpyware.com
 
4.  Be sure to update to the latest definitions during the installation of SuperAntiSpyware.
 
(The Free version of SAS requires manually updating the core and trace definitions.  The link for this is below)
 
http://www.superantispyware.com/definitions.html
 
The bottom of the above webpage tells you how to install these updates.
 
5.  Once you get both of these two programs installed and updated, reboot your computer in SAFE MODE.
 
6.  Run a Full System scan of your computer with TrojanHunter.  Let it quarantine what it finds.  After TH has completed its scan and has completed the quarantining, reboot your computer again back into SAFE MODE.
 
7.  Run a Complete Scan of your system with SuperAntiSpyware.  Let it quarantine what it finds.
 
8.  When SAS has completed, reboot your computer back into Normal Mode.
 
9.  Post the log for the TrojanHunter scan.  It is located in C:\Program Files\TrojanHunter 5.0\Scan Reports.
 
10.  Post the log for the SuperAntispyware scan.  You can get the scan log by opening SuperAntiSpyware to the main window, clicking on Preferences, and then selecting the Statistics/Logs tab.  
 
11.  Post a NEW Hijackthis log.
IP Logged

______
TrojanHunter V5.5.1002...No. 1 AT in my Book and on my Box(es)! Windows 7 x64 Professional on a Dell XPS 410, 8 gbyte RAM, dual WD VelociRaptors, dual 24" UltraSharp FPD monitors, Logitech 5.1 Surround Sound; Windows 7 x86 Professional on a Dell Vostro 220s, 4 gbyte RAM, dual WD VelociRaptors. Common: router, cable modem.
GodsSoldier
Newbie
*





   


Posts: 15
Re: Please Help - HijackThis Scan log
« Reply #6 on: May 24th, 2008, 7:45pm »
Quote Quote  Modify Modify

Thanks. Wink Log for the TrojanHunter scan:
 
TrojanHunter Scan Report - Saved 2008-05-24 18:27
 
Error: Directory not found: A:\
Error: Directory not found: A:\
Found trojan file: C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP200\A006337 2.exe (TrojanDownloader.Peregar.115)
Error: Directory not found: D:\
Error: Directory not found: D:\
Error: Directory not found: E:\
Error: Directory not found: E:\
Quarantined file C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP200\A006337 2.exe
 
Log for the SuperAntispyware scan:
 
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
 
Generated 05/24/2008 at 08:19 PM
 
Application Version : 4.1.1046
 
Core Rules Database Version : 3468
Trace Rules Database Version: 1459
 
Scan type  : Complete Scan
Total Scan Time : 01:46:02
 
Memory items scanned : 158
Memory threats detected   : 0
Registry items scanned    : 6610
Registry threats detected : 0
File items scanned   : 30270
File threats detected     : 0
 
NEW Hijackthis log:
 
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:30:31 PM, on 5/24/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
 
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\McAfee\MBK\MBackMonitor.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\SnoopFreeSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Anonymizer\Anonymizer Software\AnonASW\AnonAswSvc.exe
C:\Program Files\Anonymizer\Anonymizer Software\Common\AnonMgmtSvc.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\SnoopFreeUI.exe
C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe
C:\Program Files\TrojanHunter 5.0\THGuard.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\digital imaging\bin\hpqtra08.exe
C:\Program Files\Nikon\NkView6\NkvMon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Windows NT\Accessories\WORDPAD.EXE
C:\WINDOWS\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
 
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo. com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo. com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [xclzreq] c:\windows\system32\xzrcser.exe r
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe"
O4 - HKLM\..\Run: [jgqemc] C:\WINDOWS\System32\jjcvhsmm.exe
O4 - HKLM\..\Run: [irznlKCax] C:\documents and settings\flaca\local settings\temp\irznlKCax.exe
O4 - HKLM\..\Run: [ibecdbv8] C:\WINDOWS\system32\ibecdbv8.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [Dell AIO Printer A960] "C:\Program Files\Dell AIO Printer A960\dlbfbmgr.exe"
O4 - HKLM\..\Run: [defghijklm] C:\WINDOWS\System32\defghijklm.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [McAfee Backup] C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
O4 - HKLM\..\Run: [MBkLogOnHook] C:\Program Files\McAfee\MBK\LogOnHook.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SnoopFreeUI] SnoopFreeUI.exe
O4 - HKLM\..\Run: [tgcmd] C:\Program Files\Support.com\bin\tgcmd.exe /server /startmonitor /deaf
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [AIMPro] "C:\Program Files\AIM\AIM Pro\aimpro.exe"
O4 - HKLM\..\Run: [Adobe Version Cue CS2] "C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe"
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 5.0\THGuard.exe"
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.EXE 1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Active Desktop Calendar] C:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\RunOnce: [DelayShred] "c:\program files\mcafee\mshr\ShrCL.EXE" /P7 /q C:\DOCUME~1\Flaca\LOCALS~1\Temp\TEMPOR~1\Content.SH! C:\DOCUME~1\Flaca\LOCALS~1\Temp\TEMPOR~1.SH! C:\DOCUME~1\Flaca\LOCALS~1\Temp\HSPERF~1.SH! C:\DOCUME~1\Flaca\LOCALS~1\Temp\History\History.IE5\MSE813~1.SH! C:\DOCUME~1\Flaca\LOCALS~1\Temp\History\History.SH! C:\DOCUME~1\Flaca\LOCALS~1\Temp\History.SH! C:\DOCUME~1\Flaca\LOCALS~1\Temp\Cookies.SH!
O4 - HKCU\..\RunOnce: [CheckNetworkConnection] "C:\Program Files\Support.com\providerComcast\desktopdoctor.exe" /flow /flow=diagnosenetwork /trayclick=true /haveconfirmedwiring=true /haverenewed=true /haverestartedmodem=true /onrestart=true /havehealed=true /issuenumber=f32e3517-f0f7-44fb-abc7-08febf233be5
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\digital imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} -  
O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {7CCAD6DD-DD0B-440B-91FF-7670F5AADC21} - http://playgames.comcast.net/online2/mahjong_escape_ancient_japan/SpinTo pGamesLauncher.cab
O16 - DPF: {809A6301-7B40-4436-A02C-87B8D3D7D9E3} (ZPA_DMNO Object) - http://zone.msn.com/bingame/zpagames/zpa_dmno.cab55579.cab
O16 - DPF: {97B79133-88F0-45F0-8D57-0F2EF27D9C66} -  
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5245/mcfscan.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (file missing)
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS2 - Adobe Systems Incorporated - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
O23 - Service: Anonymizer Anti-Spyware Service (AnonAswSvc) - Anonymizer - C:\Program Files\Anonymizer\Anonymizer Software\AnonASW\AnonAswSvc.exe
O23 - Service: Anonymizer Management Service (AnonMgmtSvc) - Anonymizer - C:\Program Files\Anonymizer\Anonymizer Software\Common\AnonMgmtSvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Snoop Free Service (SnoopFreeSvc) - Unknown owner - C:\WINDOWS\System32\SnoopFreeSvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
 
--
End of file - 16627 bytes[/b]
IP Logged
siliconman01
Global Moderator
*****



Trojans! Chew 'em Up, Spit 'em Out...

   


Gender: male
Posts: 7358
Re: Please Help - HijackThis Scan log
« Reply #7 on: May 25th, 2008, 12:45am »
Quote Quote  Modify Modify

Okay, now please do the following:
 
1.  Run another HJT scan.
 
2.  When the scan is completed, place a check mark in the box next to the following items.  
 
O4 - HKLM\..\Run: [xclzreq] c:\windows\system32\xzrcser.exe r
 
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
 
O4 - HKLM\..\Run: [jgqemc] C:\WINDOWS\System32\jjcvhsmm.exe
 
O4 - HKLM\..\Run: [irznlKCax] C:\documents and settings\flaca\local settings\temp\irznlKCax.exe
 
O4 - HKLM\..\Run: [ibecdbv8] C:\WINDOWS\system32\ibecdbv8.exe
 
O4 - HKLM\..\Run: [defghijklm] C:\WINDOWS\System32\defghijklm.exe
 
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
 
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
 
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
 
O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab

 
3.  Close your browser
 
4.  Click on Fix Checked located in the lower left corner of the HJT Window.  Confirm that you want HJT to fix these items and let it fix them.
 
5.  Close HJT and immediately reboot.
 
Following the reboot, please do the following
 
1.  Remove Combofix.exe from your desktop  
  
2.  Remove the folder named Qoobox from C:\.  It is the Quarantine folder of Combofix.  
  
3.  Remove the Combofix log file from your system.  
 
4.  Empty your trash can/recycle bin
 
5.  Clean out your System Volume Information folder per the procedure in the link below.
 
http://www.misec.net/forum/board/FAQ/1139255588
 
6.  Your Java is out-of-date.  Please update to the latest build 6 of Java.
 
-  Go to START>Control Panel>Java
-  Select the Update tab
-  Click on Update Now and update.
 
IF the Java cpl does not find the update to install, do the following:
 
-  Go to the link below and download Java Runtime Environment (JRE) 6 Update 6.  Save it on your desktop.
 
http://java.sun.com/javase/downloads/index.jsp
 
-  Double click on the desktop icon for the downloaded Java update and run the Java installer.
 
After the above update is completed, remove all older versions of Java from your system.
 
-  Go to Control Panel>Add or Remove Programs
 
-  Uninstall all older versions of Java from your system.
 
7.  Run a Remote Scan using Kaspersky at the link below.
 
http://www.kaspersky.com/virusscanner
 
-  Use Internet Explorer to access the above website.  Kaspersky needs to download/install an ActiveX component.  Please let it do so.
 
-  Before running the scan, disable all your security programs Except your software firewall.  Be sure that McAfee anti-virus is disabled.
 
-  Close down as many programs as you can (the ones with icons next to the clock in your task bar).
 
-  BE SURE to run a full system scan (all disks) using the Kaspersky Remote Scanner.
 
NOTE that Kaspersky will not quarantine anything malicious that it finds; however, it will tell us if further work is needed for cleaning your system.
 
7.  Post the Kaspersky scan log.
 
8.  Post a new Hijackthis log.
 
NOTE:
 
Should you happen to loose internet connectivity during this cleaning, please open SuperAntiSpyware to the main window.
 
-  Click on Preferences
 
-  Select the Repairs tab
 
-  Click on "Repair broken Network Connection (Winsock LSP Chain) and let it fix Winsock.  
« Last Edit: May 25th, 2008, 12:58am by siliconman01 » IP Logged

______
TrojanHunter V5.5.1002...No. 1 AT in my Book and on my Box(es)! Windows 7 x64 Professional on a Dell XPS 410, 8 gbyte RAM, dual WD VelociRaptors, dual 24" UltraSharp FPD monitors, Logitech 5.1 Surround Sound; Windows 7 x86 Professional on a Dell Vostro 220s, 4 gbyte RAM, dual WD VelociRaptors. Common: router, cable modem.
GodsSoldier
Newbie
*





   


Posts: 15
Re: Please Help - HijackThis Scan log
« Reply #8 on: May 25th, 2008, 2:17pm »
Quote Quote  Modify Modify

Thanks.- Log too long, here we go in parts:
 
KASPERSKY ONLINE SCANNER REPORT  
Sunday, May 25, 2008 3:04:56 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 25/05/2008
Kaspersky Anti-Virus database records: 800216
 
Scan Settings
Scan using the following antivirus database
extended
Scan Archives
true
Scan Mail Bases
true
 
Scan Target
My Computer
A:\
C:\
D:\
E:\  
 
Scan Statistics
Total number of scanned objects
128282
Number of viruses found
1
Number of infected objects
0
Number of suspicious objects
2
Duration of the scan process
01:42:36
 
Infected Object Name
Virus Name
Last Action
C:\Documents and Settings\All Users\Application Data\MailFrontier\reginfo.xml  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\McAfee\MNA\NAData  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\McAfee\MPF\data\log.edb  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\McAfee\MPF\data\logout.edb  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\Events.dat  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\{A24ADB58-906D-43F3-9D8D-F25482086E25}.log  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\{C392FA0A-A8E0-4404-90AA-D2D96CBCE120}.log  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\McUsers.dat  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Data\TFRE.tmp  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Logs\OAS.Log  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\000d9ed55f27b3b07757935ed7025545_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\00c0004f625071e80455d08f484f92d5_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\00e2786e0247ee681bc76c8778b0ec87_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\00eb8e641082dd6cecd51b06c44d9e03_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\016375d79b6fae766c6cf129b1956e21_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0346b7c269791b99150d93957aef5dde_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0378bb139c7192a4cf2e64e5a7847976_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\03bd9a475ec6fab1310409fff9516f82_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0493e7e7e9acdef2590ba3d27ed34563_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\054b02a83ea96c01b9153455c342bfa8_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\059172a91e93c72682919ae7aeff2d59_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\07a2aeaf705e670a64dee134895e0b37_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\07a9a282fed4f5b83fc48a2cbaa32e69_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0890ed057c18d3e8c188f13ed084d5f1_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\08f0ec01a7a74cea5dd419d89b4f821c_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\090c6aa4236fe82acdad00436b921f8a_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0ad1a4fd9c6db45703931ebe1659fbc5_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0b7c39e95066b7e78fd9f75d2e4cfafd_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0c3773b41092cafaa5219427e2da2519_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0d2ef8f9db41e0a30c7207e06a6fe23a_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0d83999493fd1e81603651350efb6f29_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0e406c623bb67f1125786383382c5fd0_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0ed8489c8b40258f9e448d06e25c799f_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0f071110c34c18ead81887bec7aa3219_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped
IP Logged
GodsSoldier
Newbie
*





   


Posts: 15
Re: Please Help - HijackThis Scan log
« Reply #9 on: May 25th, 2008, 2:20pm »
Quote Quote  Modify Modify

Kaspersky log Cont:
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0f4ac64897bd355296e53ffae5ea725d_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1004a72b4e6e828d96715962f9594431_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\10f912b375bdb9cced2f9f1118c85e5c_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\11496b6309dae740dfce978cc332c0b3_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1176c8f8fe3125b0dbd3170b1c2b3d95_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\122afb1a9c03fb03be4021f31e99b721_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\128b0ca2179bd5c697798e3c73634e31_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\12d3675361d8e987839e7dc23380302b_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\13097cb10e7c1a8e346b4a5cd3aa60cb_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\13283d5d5412799cb9bd3ea28201eb73_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\134658f83e44bb3dd9d9aff78bc967d4_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\13503d916943241ff08e2dd6995ba19b_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\139912429df5ef197de5d20366c05013_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\13e18c0046963871e722216c7e40e0f4_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\146497921829c8fa979206940ec205ff_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\14b94cdaff81dc5219f4d3fc375980b6_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\15c0476c447c79e10eb537125eda103b_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1618612bacba29bc77b95fb5f31b58ba_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1634af2ecd8bc6c97e793a20222e6d82_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\16e2d8c659f2744c58faee8559369231_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\17103ea3d67249cbbc106a691d4e9563_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1720b18166db4c947f5deb3b69a7c750_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\17884a4f936cd3f553ffec979df0afeb_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1807769c8bfd61505d0cff8a24fde5a7_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\182e5a84a4bce620c3d637dde7bf25bd_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\18f1a981fab0b74f7643453050439941_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\19c5457d4cefad06c0592c8f1061f4d5_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1a814d3e94dad34cf18e7ba25c519766_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1c759a2da8de7d96bac63c9d3a9f9bd2_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1ce9070a96b1e4caab4ee5de8f2aa231_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1d9868493df5d84227adad8e08cc2f92_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1dc56e8fe5da82328450cde324e0da50_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1dd0813c0fd6a7ffe8e99a09104b8023_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1e2f582588194bef3571cb149389f2bc_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1eba4f304477309d78bd95760f667972_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\202cf5a76e35cc3d162c868f0f1a098d_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\21c4f69be471a883c29c2e3c595c39a9_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2338dd1e43b4557922f0e17fefb1b9e2_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2345790d16ad69d6ed5dabfeada73153_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\23c4738b2a886fbcdfaa69b0602f7548_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\244b0c046d8b382044c715fa5436cd71_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\24d5d519e408254c94b6843a699085f8_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\24e3de558926ef4c8afbe327740c3ab2_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\25a0a217d5c971b7d4fb2c17bd9855fa_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\26fd1fbe611575aa27145aa6dda64147_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\285b2b7137f51e9ab6b4b0eebf6183ce_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\28a5a2c370bf2b000c4b8fb0949171cd_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\28fb38ed177a343ba2bd16bf175c62b8_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\29333faba5844d0503871af76ae3a44b_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2957e52d6d5bfbe6d1d3d25b01b2f01d_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2a495759c9e4f20f3406f6359002abb3_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2a54b9e221ec01f270f30e5cc9e68596_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2aad4da8686b28fe5b44b9f5ea93f2d0_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2c031957747508c74c89bbb122f79703_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2cdee6cae6e3c822a34ff2a998f12b6d_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2d4e166ed66fd8396f0642ee192dfe5d_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2d53097780c7aa6e716208a25b7b16df_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2dbc6d95a7c29fe33430c1d680edb90f_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2eb49faa4be21c9f2cc82881398b52dd_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2ef11c652390c0ca8d345ea337716d0e_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2f0f644834523b81999a9f87b3c5e2c9_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2f2863d61596b7d711bf7d7f8a5163f3_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2f944178901e5bdb4c8f787dffa5ffea_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3063c5635e78b9a2d2f472635176c77b_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\30cd61932844e4397e4c54c3e89e3815_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
IP Logged
GodsSoldier
Newbie
*





   


Posts: 15
Re: Please Help - HijackThis Scan log
« Reply #10 on: May 25th, 2008, 2:25pm »
Quote Quote  Modify Modify

Kaspersky log Cont:
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3148c9b9772a8cbe6e518ff4fd89d4b7_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\319c1bdfbc727c1cd1e93a9e238bbad4_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\321b0df052fe725f12461c09441de689_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\32c3f2a5f408817aaf0865490e003930_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3387e432622915a070034b76dff3c01b_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\340419ded0d086aed153cc48f6f0af61_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3443f22f0712b805f8bd4b2f307f2b95_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\344accd3964694abc8e72a75df15974e_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\34ef8f4b0d31c1663996ffe605d64fb3_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\34f091d7df47f1ffce129df1c85b82e3_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\35038878c2bdd7ba8b9f34ef00595320_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\363b2475f4904b8d8520560232c216ed_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3643675f48d3286243d5133d0cc18c57_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\36fc70a361e2c728598e86c63e0d63d0_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3888640e2e42fe58ed42e9e01ce33cdb_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\38a3bd5f6312b04ea5f9d693e2a0aeb1_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\39577c2d2c6b7a73768f748837b00a49_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3b61b6f2b3543a89ae2a309d07b4c3ff_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3be0f42157ef9caf3144c92bb4b4cc9c_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3d0f8871f48e48b1da0184657537bd50_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3ddaccc820e5b99eecc895f8c8d8e273_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3e02cb9761b5146467f71fc24f278897_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3eac53dfe8e47b5da30501c9fb2d667a_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3f8276170711f0d9108b8ea96928ce2d_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3f8c64eb39d7c0e193e06839909e44a1_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\40c82ae7e700f1b2421eac3098eda028_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4105a53831f744ad7f6ec757aaf97905_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\416ef78a8cd4e52f52d3ab18078e5949_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\436154747b05519c96314e029a08e618_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\438d711572e94474667765fe01852111_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4446b36af59ec62016be2509e7bc71e6_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\45d6b77f96a62c15ec6882aa9949aa40_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\46e9f9ac5df184b3c5c19112b14bf356_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\46f426250d87380e7931bc6de3873b3e_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4707432ef82c97cca78ace6fe40f8529_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\470b69ac506ce902b7bea7ad324349f0_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\470fb14ddcf791a165e675b956165789_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\48369bdffd8712e30f86d274dc6151dd_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\483b245bc1b3e83ec00413747e7f5253_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4882408d3879fcc2c4179db30202e55f_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\493dee21064d869ebfc0fb23d0856bd8_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4abbd2e64d073dc0ce6772dcf1ee1aa4_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4ad2cb4371ed26139d9a09c57a515908_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4c3cdce92929cf0d98922d8bcb97c496_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4ea9ff5ce42493fb0705a77bf55423b2_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4f0a1be87a94551b46e67fe9ffd42420_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4fab893329d6581aa9f4bb4bc09273fe_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4ffe40680183847c7ce3ad071417389e_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5198d6f43d31c996ae2f8e7a5bcf0037_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\51be6faa0ac9c97190c1ab4d4cfb18c1_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\51ea277c65330c2f0961c952634944e8_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\53a0da84380bbca60e4563375c2a965a_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\53fdee3659406cd630509d7d85e03269_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\54c21553699b3fd157a843ec4872c713_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5599128b249b1e2e22c5206ae98dd745_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\559f791716313c0c40ef55e75a0d45f6_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\55e7f521242cf73453c9b19856877949_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\576fe83700657da7b7ab126bbb02e81a_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\57c5c7c1acb2216fc274170e94506cc3_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\58059f21e879f43dc6413979145bc41a_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\581a54cdcf6524f704597c92fb29e9ea_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5833105702e6e752dc9f219d9ad504c8_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\59197e286378b846a718f870968f15fc_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5979fd4ef47e49887520b173616f50e2_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5a6d48219d590fab4713eb914f21c28d_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5bac6dcb8d851b93c0c84de93caa77d0_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5bba7e7519dce210b87e3c7d728f61b7_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5c2506b2f1090fb84a713af6138e4158_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5d2b9d64b31acc5ab883be9cff888feb_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5e3b54a343896af1111d9d14e60321ee_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5ee2c76cebffee85a8c9e8588e715b2b_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5fb914b9814c45cc1041901ec6189b0d_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\61ea0217a75bfaa80da071d7e6f79e0f_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\61fa937069251c2d6e79e1d40abc2bc7_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\621518ce22dffa9fbec9b02811ef589a_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\625fdbc913cc1b059655a70b8fd4d5d8_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\630d7bf0a4093c170919bc02e0ca61d5_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6335fac63259a01ec4ce86545817d1cb_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\637de8d2b696e86294fa7fb299f069df_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\63c3134166899462b58f3c4973b39a6e_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\64ea55b142f7a6c2ee6b862e5ee4f707_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\65ddcca94bb86e2602a8c16ea52ab2e4_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\65e1af2e2a463a2aef267798e013ff35_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6640c50e7ee00fe81c3e6d6a33d00162_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\673f4bcd681a3c0bcd454ca29a452631_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\67f755fb70bfec7bdd662549798f3fbd_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\68400226b2ba3fbf42a3c76113f4336b_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\68d96181a6f9fcbe17afac934d4958d5_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\690f6c6d73735cd5d8b50284c3b8fe38_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6ae03072c6d0c3a67166772e32145fab_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6b06427b34bde3b4f0a34a0cceb4c6b6_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6b941190639f250c002d1456edd2992f_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6bc6ee777f6bd6a3a9a7999f62395490_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6d02fc878bab5de9276279a96c846e8e_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6d521bb3fa58f174b85707b388fe3b6c_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6d88762fa59c78463aec989df06d3363_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6ec0b9b2f55d9a9642cee96476719739_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6ee6d1543774257c3eb8fff9a5d2edb2_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6f02a9d1a45179c6d8874dde8f347aa9_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6fe5ef96801a2ded417e0e4d3e3e5058_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\701264550757669ea27eb29fd55e6deb_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\70489ae9e32ae295be0db0c37ef78142_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\70cafc5258e14f9c8d221f759f913dd5_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped
IP Logged
GodsSoldier
Newbie
*





   


Posts: 15
Re: Please Help - HijackThis Scan log
« Reply #11 on: May 25th, 2008, 2:28pm »
Quote Quote  Modify Modify

Kaspersky log Cont:
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\71e402a4909b4bd5e9c6b040a464b432_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\720f1c6191dc7a55f7c1bb25a048b6b0_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7259a23db38e20afe08735029caf74af_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\728bce0fa1b69121af5b7fd3883bbe2e_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\731ae4d84eb2974de70704dee523bd1b_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7348a2e1a4366c872e5b02f462a13e41_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\742fb0f2cbf43954634a5a2fb448f711_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\748dd266e5c2f9492f5bff01077bb37e_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\753c608bc1f357258b2355d2d578a79c_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\75992919e6203274ce7207c51aac726b_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\76880a51494faf638e8a9859ca88215f_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\771f15fefbf9a334dbce44587c1cb4e8_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\77d2ef56ee2cb4cabb64ff1e923c7392_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\77fd86da4ccab30e9df713baec3e9571_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\78887d561bc50ffb36225db982d74ec1_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\78b64bdda66723d17eadf8911609d244_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\791b83fd7982f037a9f8cdec8e375b35_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\793045958dcfd9d824ea4e2eccdf96d6_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\79526734ee22717ba049be95570556a9_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7a2d3c2046cdc9d0c726d80459a2d41f_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7ab2e250efeb3bc24b8cbf6dce08d30a_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7adfa34b6b3ad3ed81fbbd0ef513cfc6_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7d24344b694f5d53f643369a8efa7a44_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7d2a5724589cecd5b6e5c3355f37933e_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7d4fd9df9e700cf396f12c53232f7b37_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7d5df00d06ff6a405625c0520f787c29_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7ecfabd8418283dbc05c43d177137109_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7ecfaff493d9f1a23a05c7eaf1baf6b7_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7edddb72e96c6b861743c40c3a12847d_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7f9a08b17b6b302a5305eaca325563f1_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7fd3762e0790c02e52eab94e125908d1_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\804ae0cb5b3ef300a12df3b4f2090c14_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\804af850875ec86c2f06bb9ae21faba4_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\806527c94cfe5267e4d280712fbe83c8_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\814306e398466fe1043190e4d28c7adb_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8466091eac033077611ffc96b6fcba21_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8480634b8f9b205d078682880b236aa3_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\864511e31c5ba105fe39ca2e74f56f4c_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\867cfc9fce02c82b2555aace5f2102ad_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\869f31004252605b4542baa5d98b56ba_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\86a6209b5a5b2d185ef9e8f1bb9f6569_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\86eeb1111bebd12a15b50a0e8a24493f_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\86f9b7f8d5234effd990fc403d529699_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8731cae841e178637bdc8746bba74510_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\877abf5c9d365ce63e07227235c05ef2_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\87f74d183a86c9e69f39742130ecdab7_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\88b27f2647825dfd1a338f6cad3f33a7_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\88f3f0a245e756bbc73c7d332d1d786d_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\89582946b9c73f868254f872a1208e9f_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8aa50442022a1bf709c5200fd6b68ff1_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8b180bf27c45e973f1879ebbc69568e4_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8b3e47b3ef310b61215ee21795a33ecd_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8cfe1b4ab68d265e56bec1d7d14520c9_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8d4bfe071c0b253f9f3fa7d394f10681_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8deba4ab3e0d7103bfee2270bbb7f720_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8e9e6b2f63152f429a065ea6f9896a2b_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8f8410b4f427d8756414db0e15508265_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8fec2de8a53d62919f97a2190d305a4f_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9015e77ad3c468c87ca4218477a3f94e_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\90e82cb0ff10afd58d8a2b16d5dd0eb4_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\94ff35ad6a3e700622ad6a9df612162e_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\954846321b4bf72d0676af742dff2309_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9579c3e4e7d20cd9474d6ea9217ebdbd_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\96a7ddf197f107d421533daeefd31c85_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\973b1ce9064d4b92403072bdd3873677_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9823d9fb33862436ed3862f339361e87_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\989ad249bc1b9ebc9ed8e636339fbe16_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\98ccdcadb25ff7a99d7ef563599775ff_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\996f58c24508614f7caff52a79d45cd6_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9a78f12a2f904b4a7d6edae9ad65470e_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9c31ceb504ff13d97b02894127022c0d_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9d66fb9f8f27ae17ba3fbaf0ecfffc13_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9e44df699ffa4f96504d303ec8146cdf_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9e68ac9a78deb8722a9d34a91f422f3e_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9e86ba275eedaf4ba3e0644a5e87b600_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9ee54658d4e746c42e691ef4864f0b94_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9eecb6e7288889a15e1b84cba1444d06_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9f4412c976061419d9f4a279660169d0_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9fabe4ff75b9f94f5672b1dc2a628cfd_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a046e933fa4669e5087db0c5eee96e50_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a0a99f00a2c6eac7014a874f5b295848_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a0fb92a7297a00f61064fcec29ea631c_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a11e017bab41ff6f907b8c817144d7e5_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a16ae0143ffe9a956a74e63a3c80fa1a_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a17c1c1d71e7b86d70cadf9cd8fad75f_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a17e39a286256064bb6ba985a8689961_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a1891be8dda53e61ec16e54856349870_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a1befb90d805f4228a41330d0ca3e9bd_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a2c778958f6330f22ea6dbe9588f6b73_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a30b2fd9b5cdec69fa1b19088f30bb23_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a314c3b8619cfc033c9c30edf16ec1e5_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a37112b5dd9fe2139d2d1d5800328536_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a41d2df5a9b0622740db390cdfc537f7_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a4ae6558f98282840c10b22ba8912b35_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a4bd8ca4b23fcfd8cdd3b2760a3903ec_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped
IP Logged
GodsSoldier
Newbie
*





   


Posts: 15
Re: Please Help - HijackThis Scan log
« Reply #12 on: May 25th, 2008, 2:30pm »
Quote Quote  Modify Modify

Kaspersky log cont:
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a4d48bca4abf3d56579495d98c1fe6d4_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a4ef8cc469c8d24c19e716c92b25e929_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a81e0746b07aafa07bcdb1a018abe138_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a90e8532454bbef1207e119bc189ccbf_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a9428cab5a7ed38f279bfbeedd728aee_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a95531d220ed9edc21e1fc5f9cb5958e_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a9687b12d340176222f06df04db66502_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\aa17e4cc353393e1d3145258804d516d_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\aac3ce5bee43f3119da5591eedd0990a_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ab00cbb72803aefb2d141ad2dc7a4be5_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ab7e8ac9a38746547c24dab4c8241a22_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\abcaebbf3aba46e8c33622e5ad783bd3_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\abd7095d086ff536d310fd7bbcfc9e04_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ac291cce7ed6db7d138beaebc78a0b91_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ac3ea1a0ba128e6c12f8d2fdb53f27e0_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ad4860445c6cec376b65ab9941fb5bb9_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\adc6765c80930fea8322c0d04b228e84_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\adf8c18ff27396c4516ce214afe0485c_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\adff20ac48202f31e9249ad182cce13b_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\aea888dd98aded4718c45eaabf3a5f54_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b01c6f9a74ec1fb3b6a00e570aec1dce_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b04d90f7f9e492a2cd7dfc5a81c87688_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b05e99509dc83b833724d382930395de_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b07ecde1b2ae6dae3ed5f381c3eca74b_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b160c1e51e56e525143d3ad2fc210d93_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b1d79b5bab445438ddad39fddbc7adbd_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b2260f9dc1c68cde48c05ddf7253520e_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b3b75ff1ddecd34faed2284d396f4d68_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b483fb017658297050728866b5520f7e_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b4fd669e93606535152746b95f37917b_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b628454a59c136ea36bf8a79dbab0fc9_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b7441e10fa6cb07b1858bcab998b1dd6_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b74dee301a23af42973e5231577f210f_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b881fe174c206d24f7b6d141de1a6781_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b9f730845dec8f3ed37df891302e8bf3_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bab3b2f4b013ec9daa28a1756949a6e3_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bb0e48d4366afa1bc7cf1f133f73f17d_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bb64c9af1110bd18e88c6daa193a2700_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bd033e6a26413a0dbb87a6a733040475_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bd0ff4b5de944bbca456805a4c92a618_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bd3175214e1cdd0f13a280bb3ac4b5a7_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bd791e4fbea3bd9c68d7efe1a4361fa5_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bdf368ec555acb853c1f1b1a53733315_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\be00acd093fc3757bddbdcfbc1e0160c_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\be522288c642187cab25dcbd1dab69ed_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bfc087a66cd47487bde65320e7d978b4_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c008a4f1ba44bde2fcaa2c8e764f0c69_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c0795d4e8f1e104015d58afd4214f354_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c0e2a8334cf3e27b1f5babada79824c5_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c104624438b3792eef4eabff9b0d71fe_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c15720acb3df21df9ae9dfe0f3095e11_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c15c0832ed3e89e3b0b9083af4d9a40f_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c1a715109ffdfae482239e8b010d25b6_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c1b7ac8301b2b3b12bf71f1550c25aac_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c3d6cc6b0ec132d019b7783f0d03dc6f_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c468e7872f0bbd3f26dc376d78729e61_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c473ca1463d5d698d9806d06dc5d7918_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c482819cba20097ec4792cdc662f6e35_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c4ba7df5685570bcb0d4c2746afa0b74_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c5b286bf0260640d2fdd4dbc5ca6c659_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c6e474085a5f44136eb5c70ed7df24cf_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c6f9abd9ab16fd01c012600b07424767_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped
IP Logged
GodsSoldier
Newbie
*





   


Posts: 15
Re: Please Help - HijackThis Scan log
« Reply #13 on: May 25th, 2008, 2:31pm »
Quote Quote  Modify Modify

Kaspersky log cont:
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c77154453753b0ea63ed057108083be2_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c788a26eeccc1dc3fb0098cd1b80b261_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c90357a15941be18dab715cb5ae24f70_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c9373a489720a750ec3c0119d4a00755_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c98df32aafca86f45f74fa3309387206_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c99652a87ed994ff3959008026e54b06_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c9a7fdfab02ce53644f56ed9abd0b485_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cae437fb8df0de7aa3d12163bfc65bb9_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cb2716d59b8f5ea38b622735bec0b576_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cb62f91097727b8ceae10b08fe5b43c7_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cc3e33ffbe11f7125f7e219ccf60f4ba_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ccf56551d5a82f20b3d54bf38cf3db8e_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cfb8a1e457a9fdd444e4c63d45715987_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cfee443c90c7f86b5a85534180e68bf9_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d0d1b6e95a4a4c73138f7a8a99413e3f_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d0d24664dff9c018d45e8d454e6d26b7_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d1221d12322bec0c3c6a48eb9a053ec2_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d1b088bd5f665c997f6e41bc290c065f_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d1b61929b28470650058bd787b0efc47_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d330d85e5032cdf17fa95fe40613fda6_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d38cca2fa029b0a3514a8dcd149916d4_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d3e141f3900582cc46cc356994b29bde_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d4368fb4a8ae0e20d9e24df3edbfdff7_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d4f99b5ec950152ca864f38c530fa1e7_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d51d2cfcaffbae3524a9b07e5ad76da4_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d61938906c12c47bab81b3fc84093ed9_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d754326a32b3ebdaea672e4a95400bef_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d7f58e51316985a99e2e43f47b8587de_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d81a78e1c004cc662d6c3c3f3db86e0c_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d840ec84028ea576c3a0e23c7d07024b_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d8e14ddb5b7cf5ec6252d0ef4c78cc90_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d993dcdcb0368cbaae247ee80bd5d4be_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\da00bf9227f103b7f1571a741c2a3804_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\db2d7d588be643d3c8fecdd30f878a79_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dc390551b9f8eb35005a4a9e8e0399dc_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dce8cfd6db405d8c239181c81144fd27_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dd079185106d8e9ec9e3081ac66a0f19_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\de79d697f8865e27e02599519c1a7ae8_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\deded7fb12ada3954366c1b98c0d58a2_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\df29199baff7d77b7bd476344bdedc07_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e0843ccd055785ec90c776552a33d6a2_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e20045493ccda9afd3edb4ccedf16531_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e23801f11fcb87021804d2737bf947a7_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e2c0ff42faf4ed0b59eb5196132baa1e_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e2e50e02edf38f0f225cc71b84983b6d_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e3a02d420592fa28896206af420ad09c_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e501708fbb68f3e862f7f2ebb5b5aded_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e52eadc2b8658372ad027b1fd4662d85_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e550a2a6c3b2a5da4f0ea2d208f5c8f2_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e6a89085982d9ca170e7b18dbbca82d4_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e87b7e36ca1e7f566443b03073f8cf08_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e8c1b6c9be9a9d4f02007143c3497b93_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e90e411d7eec1801f4ccd93409470e89_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ea901899986aa43e97792a88f698bd19_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ea90f922d5260690bdefe93fdd3ee953_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\eabb4582ad72c84516ce421ba0b6ce90_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\eb3b5b156dcc04b46f1d362862710a13_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\eb816f641ac5ff7cf8177f9be64bd966_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ebd0880dc01e72f67a12a6fdec05feef_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ec8d64d2ffa6a0ea912e5f7afb5b2087_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ed0e0129c0f8ad60607227bea3d7bf63_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ed3ac46c3f2614b984e92c80332ea7ea_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ee302fc64ad4806c9ab0ce5858d688fa_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\eed4c166d5a342fffdbfa7bddbbeaa5c_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ef9a515fc4ab10fc4a8b0beafe8f4bd0_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\efe2b907bf45aaff9cd3e8253b4d659f_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f20b50f35dfba84d211da55ed68ac7de_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f2141cd396f7799086b4eb440e82b8dc_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f2443b828a0408a5dcd1dd82174c4076_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f2b5c09ed39317ccd8b8a1cc0e8e970d_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f43865f2bbb4bcd8330287bdd65ebb57_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f4447a8f0c808b4825e1d1d5a252f662_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f4ae023934639bd05849e518e0bc21f9_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f50c13a1f80e4d27065b8de33e48ef89_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f66b614ead932742abdeaaf37eaf049e_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f734ce16e92b4a4d533ac7a8a2dd21e5_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f8531a86be987916be744ba6754ad146_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f8d22a4792b604fff12d4178900bd46b_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f8d6dc99a5dff6d59097a9e4b0daa21b_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f9225ed3744631d1d8a9757e24fe31fe_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f9b3eb76993fc2e4f57688880330e59a_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fa9c2015b716c4b2cf8c3e6a3212e5ce_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fa9ee1414a34523691ac3699c8492141_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fb4c042db177adb13a13ab4ffa8ba9c3_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fbe1ab8aa8c3b99af035575eb56315e9_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fbee8351a87b9d2fc5df94186cf25550_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fc5ea5c5b78125185119f812dfff3707_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fda31c5d612a369e71ca869ab2fcabca_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fe160a5e42ade51f760897dee26828a4_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fec7244b6f4b2a6b4721747856bffe3a_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ff8b7116a136ce83b09e22639786ad76_7 b71fbce-dff3-42c2-9259-d2367eb8daa9  
Object is locked  
skipped
IP Logged
GodsSoldier
Newbie
*





   


Posts: 15
Re: Please Help - HijackThis Scan log
« Reply #14 on: May 25th, 2008, 2:32pm »
Quote Quote  Modify Modify

Kaspersky log cont:
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped  
 
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped  
 
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCAInternetOptimizer2.zip/install.exe Suspicious: Password-protected-EXE skipped  
 
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCAInternetOptimizer2.zip ZIP: suspicious - 1 skipped  
 
C:\Documents and Settings\Flaca\Application Data\McAfee\MBK\ARBUSFILE.GDB Object is locked skipped  
 
C:\Documents and Settings\Flaca\Application Data\Microsoft\Templates\Normal.dot Object is locked skipped  
 
C:\Documents and Settings\Flaca\Cookies\index.dat Object is locked skipped  
 
C:\Documents and Settings\Flaca\Local Settings\Application Data\ApplicationHistory\McAfeeDataBackup.exe.e548c4c.ini.inuse Object is locked skipped  
 
C:\Documents and Settings\Flaca\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped  
 
C:\Documents and Settings\Flaca\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped  
 
C:\Documents and Settings\Flaca\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped  
 
C:\Documents and Settings\Flaca\Local Settings\History\History.IE5\index.dat Object is locked skipped  
 
C:\Documents and Settings\Flaca\Local Settings\History\History.IE5\MSHist012008052520080526\index.dat Object is locked skipped  
 
C:\Documents and Settings\Flaca\Local Settings\Temp\fb_1960.lck Object is locked skipped  
 
C:\Documents and Settings\Flaca\Local Settings\Temp\~DF4BE4.tmp Object is locked skipped  
 
C:\Documents and Settings\Flaca\Local Settings\Temp\~DF9182.tmp Object is locked skipped  
 
C:\Documents and Settings\Flaca\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped  
 
C:\Documents and Settings\Flaca\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped  
 
C:\Documents and Settings\Flaca\ntuser.dat Object is locked skipped  
 
C:\Documents and Settings\Flaca\ntuser.dat.LOG Object is locked skipped  
 
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped  
 
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped  
 
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped  
 
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped  
 
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped  
 
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped  
 
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped  
 
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped  
 
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped  
 
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped  
 
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped  
 
C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP5\change.lo g Object is locked skipped  
 
C:\WINDOWS\assembly\NativeImages1_v2.0.50727\AnonAswLib\1.0.0.2___58c7c1 aa\AnonAswLib.dll_ Object is locked skipped  
 
C:\WINDOWS\assembly\NativeImages1_v2.0.50727\AnonAswSvc\1.0.0.2___f7d9ae 30\AnonAswSvc.exe_ Object is locked skipped  
 
C:\WINDOWS\assembly\NativeImages1_v2.0.50727\AnonMgmtSvc\1.0.0.2___5fc57 ce2\AnonMgmtSvc.exe_ Object is locked skipped  
 
C:\WINDOWS\assembly\NativeImages1_v2.0.50727\AnonServiceLib\1.0.0.2___41 194bdb\AnonServiceLib.dll_ Object is locked skipped  
 
C:\WINDOWS\CSC\00000001 Object is locked skipped  
 
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20060929-120705-00.hd mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20060929-120705-00.md mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20061019-004200-00.hd mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20061019-004200-00.md mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20061019-124810-00.md mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20061020-041515-00.hd mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20061020-041515-00.md mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20061020-132653-00.hd mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20061020-132653-00.md mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20061021-175106-00.hd mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20061021-175106-00.md mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20061101-032902-00.hd mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20061101-032902-00.md mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20061102-002522-00.hd mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20061102-002522-00.md mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20061102-145650-00.hd mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20061102-145650-00.md mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20061103-052934-00.hd mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20061103-052934-00.md mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20061104-035237-00.hd mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20061104-035237-00.md mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20061105-054346-00.hd mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20061105-054346-00.md mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20061106-035720-00.hd mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20061106-035720-00.md mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20061107-005435-00.hd mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20061107-005435-00.md mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20061110-151702-00.hd mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20061110-151702-00.md mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20061110-154424-00.hd mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20061110-154424-00.md mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070118-141629-00.hd mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070118-141629-00.md mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070127-051743-00.hd mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070127-051743-00.md mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070127-174009-00.hd mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070127-174009-00.md mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070201-014017-00.hd mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070201-014017-00.md mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070220-043832-00.hd mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070220-043832-00.md mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070221-051738-00.hd mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070221-051738-00.md mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070222-061511-00.hd mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070222-061511-00.md mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070223-054425-00.hd mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070223-054425-00.md mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070224-202210-00.hd mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070224-202210-00.md mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070225-040555-00.hd mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070225-040555-00.md mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070225-180304-00.hd mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070225-180304-00.md mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070226-040848-00.hd mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070226-040848-00.md mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070302-050750-00.md mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070302-182637-00.hd mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070302-182637-00.md mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070303-180222-00.hd mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070303-180222-00.md mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070308-053716-00.hd mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070308-053716-00.md mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070313-172432-00.hd mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070313-172432-00.md mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070315-042148-00.hd mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070315-042148-00.md mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070317-171803-00.hd mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070317-171803-00.md mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070321-034500-00.hd mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070321-034500-00.md mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070321-124030-00.hd mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070321-124030-00.md mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070329-051426-00.hd mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070329-051426-00.md mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070406-034751-00.md mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070504-042337-00.hd mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070504-042337-00.md mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070507-040455-00.hd mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070507-040455-00.md mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070524-151921-00.hd mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070524-151921-00.md mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070526-031408-00.md mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070526-190612-00.hd mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070526-190612-00.md mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070528-173138-00.hd mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070528-173138-00.md mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070529-043036-00.hd mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070529-043036-00.md mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070530-041129-00.hd mp Object is locked skipped  
 
C:\WINDOWS\PCHealth\ERRORREP\UserDumps\svchost.exe.20070530-041129-00.md mp Object is locked skipped
IP Logged
Pages: 1 2  Reply Reply  Notify of replies Notify of replies   Send Topic Send Topic   Print Print

« Previous topic | Next topic »