February 13, 2012, 01:31:02 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: SMF - Just Installed!
 
   Home   Help Search Login Register  

Help! the dreaded Win 32 dialer virus got me!


AddThis Social Bookmark Button AddThis Feed Button
Pages: [1]
  Print  
Author Topic: Help! the dreaded Win 32 dialer virus got me!  (Read 4224 times)
Lionhous
Newbie
*
Posts: 1


View Profile
« on: September 28, 2007, 02:44:40 PM »

I'm dealing with a series of problems;
symptoms began w/ hijacked browser (IE) dissapeared Control Panel as well as error messages;
error loading c;/windows system 32 /rautvld.dll
 "         "               "                "         32/drvwab.dll
"          "           c:/progra~1/mywebs~1/bar/1.bin/MWSBAR.DLL
I ran AVG in safe mode but it would not generate a report for me
I ran Spybot and Adaware SE but have no reports either.
I ran HiJack This and got the log (no fixes applied)

Finally I ran Kapersky,whicjh I'm not sure I understand whether it has dealt with the problem or not; because it says it cant fix the Win 32 dialer virus, but then says it will delete it.

I got my control panel back and the automatic IE running has stopped.

Here are the logs;
HiJack This
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:13:13 PM, on 9/28/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\3Com_DMI\3CDMINIC.EXE
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Yahoo!\browser\ybrwicon.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Hewlett-Packard\PhotoSmart\Photosmart 430 Series\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe
C:\Program Files\Hewlett-Packard\PhotoSmart\Photosmart 430 Series\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIA.EXE
C:\Program Files\Hewlett-Packard\PhotoSmart\Photosmart 430 Series\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Webshots\WebshotsTray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\winlogon.exe
C:\Documents and Settings\Craig\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://smbusiness.dellnet.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
O2 - BHO: (no name) - {57D6708C-88E2-4CAB-9FA4-78BB8CA3A3C4} - C:\WINDOWS\system32\hggeecy.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: IEHlprObj Class - {ABCDECF0-4B15-11D1-ABED-709549C10000} - C:\WINDOWS\system32\vtr441.dll (file missing)
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\ycomp5_1_6_0.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O4 - HKLM\..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [TCASUTIEXE] TCAUDIAG -off
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\PhotoSmart\Photosmart 430 Series\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe"
O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
O4 - HKLM\..\Run: [Deskup] C:\Program Files\Iomega\DriveIcons\deskup.exe /IMGSTART
O4 - HKLM\..\Run: [CXMon] "C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe"
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\PhotoSmart\Photosmart 430 Series\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [ADUserMon] C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [EPSON Stylus Photo R220 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIA.EXE /P30 "EPSON Stylus Photo R220 Series" /O6 "USB001" /M "Stylus Photo R220"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\MWSBAR.DLL,S
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [CTDrive] rundll32.exe C:\WINDOWS\system32\drvwab.dll,startup
O4 - HKLM\..\Run: [WinAVX] C:\WINDOWS\system32\WinAvXX.exe
O4 - HKLM\..\Run: [SystemOptimizer] rundll32.exe "C:\WINDOWS\system32\rauytvld.dll",forkonce
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Walgreens PhotoShow Media Manager] C:\PROGRA~1\WALGRE~1\WALGRE~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [WinAVX] C:\WINDOWS\system32\WinAvXX.exe
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKUS\S-1-5-21-2881275538-357967339-2079644369-1005\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'Lisa')
O4 - HKUS\S-1-5-21-2881275538-357967339-2079644369-1005\..\Run: [runsysspool] C:\WINDOWS\System32\service.exe (User 'Lisa')
O4 - HKUS\S-1-5-21-2881275538-357967339-2079644369-1005\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe (User 'Lisa')
O4 - HKUS\S-1-5-21-2881275538-357967339-2079644369-1005\..\Run: [WinAVX] C:\WINDOWS\system32\WinAvXX.exe (User 'Lisa')
O4 - S-1-5-21-2881275538-357967339-2079644369-1005 Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe (User 'Lisa')
O4 - S-1-5-21-2881275538-357967339-2079644369-1005 User Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe (User 'Lisa')
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=zuzeb004YYUS_zuzeb002
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper2007261.dll
O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1125453527984
O16 - DPF: {90051A81-3018-4826-8B38-DD60B6B53F9C} (Snapfish File Upload ActiveX Control) - http://www.costcophotocenter.com/CostcoUpload.cab
O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = mydomain.com
O17 - HKLM\System\CS1\Services\VxD\MSTCP: Domain = mydomain.com
O20 - AppInit_DLLs: C:\WINDOWS\system32\hanonvt.ini
O20 - Winlogon Notify: hggeecy - hggeecy.dll (file missing)
O23 - Service: 3Com DMI Agent (3ComDMIService) - 3Com Corporation - C:\WINDOWS\System32\3Com_DMI\3CDMINIC.EXE
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
O23 - Service: CopyPwd Service (CpPwdSvc) - Unknown owner - C:\Program Files\Laplink\PCmover\cppwdsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\SYSTEM32\YPCSER~1.EXE
O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega Corporation - C:\Program Files\Iomega\AutoDisk\ADService.exe

--
End of file - 13282 bytes

Protection : running
--------------------
Total scanned:   345394
Detected:   46
Untreated:   7
Start time:   9/27/2007 3:36:56 PM
Duration:   02:56:04


Detected
--------
Status   Object
------   ------
deleted: Trojan program Trojan.Win32.Dialer.qn   File: C:\WINDOWS\SYSTEM32\WINMMT32.DLL//PE_Patch.PECompact//PecBundle//PECompact
deleted: Trojan program Trojan.Win32.Agent.bck   File: C:\Documents and Settings\Craig\Local Settings\Temp\lgjlsyyo.exe
deleted: Trojan program Trojan.Win32.Agent.bck   File: C:\Documents and Settings\Craig\Local Settings\Temp\xvdawygm.exe
deleted: Trojan program Trojan.Win32.Agent.bck   File: C:\Documents and Settings\Lisa\Local Settings\Temp\jximeljg.exe
deleted: Trojan program Trojan.Win32.Agent.bck   File: C:\Documents and Settings\Lisa\Local Settings\Temp\nhrdecyk.exe
deleted: Trojan program Trojan.Win32.Agent.bck   File: C:\Documents and Settings\Lisa\Local Settings\Temp\rgfvtint.exe
deleted: Trojan program Trojan.Win32.Agent.bck   File: C:\Documents and Settings\Lisa\Local Settings\Temp\ubbjbfsx.exe
detected: Trojan program Trojan.Win32.Agent.bck   File: C:\Documents and Settings\Lisa\Local Settings\Temp\yalosmum.exe
detected: Trojan program Trojan.Win32.Agent.bck   File: C:\Documents and Settings\Lisa\Local Settings\Temp\ysnwdvjy.exe
deleted: Trojan program Trojan.Win32.Agent.qt   File: C:\System Volume Information\_restore{E87A81FB-FDCF-4B92-A20C-951710F82D7C}\RP733\A0053600.exe//PE_Patch.PECompact//PecBundle//PECompact
deleted: Trojan program Trojan-Downloader.Win32.Agent.bxx   File: C:\System Volume Information\_restore{E87A81FB-FDCF-4B92-A20C-951710F82D7C}\RP735\A0054201.exe
deleted: Trojan program Trojan-Downloader.Win32.Agent.bxx   File: C:\System Volume Information\_restore{E87A81FB-FDCF-4B92-A20C-951710F82D7C}\RP735\A0054206.exe
deleted: Trojan program Trojan-Downloader.Win32.Agent.bxx   File: C:\System Volume Information\_restore{E87A81FB-FDCF-4B92-A20C-951710F82D7C}\RP735\A0054218.exe
deleted: Trojan program Trojan-Downloader.Win32.Agent.bxx   File: C:\System Volume Information\_restore{E87A81FB-FDCF-4B92-A20C-951710F82D7C}\RP736\A0054220.exe
deleted: Trojan program Trojan-Downloader.Win32.Agent.bxx   File: C:\System Volume Information\_restore{E87A81FB-FDCF-4B92-A20C-951710F82D7C}\RP736\A0054221.exe
deleted: Trojan program Trojan-Downloader.Win32.Agent.bxx   File: C:\System Volume Information\_restore{E87A81FB-FDCF-4B92-A20C-951710F82D7C}\RP736\A0054222.exe
detected: Trojan program Trojan-Downloader.Win32.Alphabet.z   File: C:\System Volume Information\_restore{E87A81FB-FDCF-4B92-A20C-951710F82D7C}\RP736\A0054236.exe//PE_Patch.PECompact//PecBundle//PECompact
detected: Trojan program Trojan-Downloader.Win32.Zlob.bqu   File: C:\System Volume Information\_restore{E87A81FB-FDCF-4B92-A20C-951710F82D7C}\RP736\A0054244.exe//stream//data0006
detected: Trojan program Trojan-Downloader.Win32.Alphabet.p   File: C:\System Volume Information\_restore{E87A81FB-FDCF-4B92-A20C-951710F82D7C}\RP736\A0054279.exe//PE_Patch.PECompact//PecBundle//PECompact
deleted: Trojan program Trojan-Downloader.Win32.Agent.bxx   File: C:\System Volume Information\_restore{E87A81FB-FDCF-4B92-A20C-951710F82D7C}\RP736\A0054280.ini
deleted: Trojan program Trojan-Downloader.Win32.Agent.bxx   File: C:\System Volume Information\_restore{E87A81FB-FDCF-4B92-A20C-951710F82D7C}\RP736\A0057205.exe
deleted: Trojan program Trojan-Downloader.Win32.Agent.bxx   File: C:\System Volume Information\_restore{E87A81FB-FDCF-4B92-A20C-951710F82D7C}\RP736\A0057206.exe
deleted: Trojan program Trojan-Downloader.Win32.Agent.bxx   File: C:\System Volume Information\_restore{E87A81FB-FDCF-4B92-A20C-951710F82D7C}\RP736\A0057207.exe
deleted: Trojan program Trojan-Downloader.Win32.Agent.bxx   File: C:\System Volume Information\_restore{E87A81FB-FDCF-4B92-A20C-951710F82D7C}\RP736\A0058204.exe
deleted: Trojan program Trojan-Downloader.Win32.Agent.bxx   File: C:\System Volume Information\_restore{E87A81FB-FDCF-4B92-A20C-951710F82D7C}\RP736\A0058205.exe
deleted: Trojan program Trojan-Downloader.Win32.Agent.bxx   File: C:\System Volume Information\_restore{E87A81FB-FDCF-4B92-A20C-951710F82D7C}\RP736\A0058206.exe
deleted: Trojan program Trojan-Downloader.Win32.Agent.bxx   File: C:\System Volume Information\_restore{E87A81FB-FDCF-4B92-A20C-951710F82D7C}\RP739\A0058243.exe
deleted: Trojan program Trojan-Downloader.Win32.Agent.bxx   File: C:\System Volume Information\_restore{E87A81FB-FDCF-4B92-A20C-951710F82D7C}\RP739\A0058244.exe
deleted: Trojan program Trojan-Downloader.Win32.Agent.bxx   File: C:\System Volume Information\_restore{E87A81FB-FDCF-4B92-A20C-951710F82D7C}\RP739\A0058245.exe
deleted: Trojan program Trojan-Downloader.Win32.Agent.bxx   File: C:\System Volume Information\_restore{E87A81FB-FDCF-4B92-A20C-951710F82D7C}\RP739\A0059204.exe
deleted: Trojan program Trojan-Downloader.Win32.Agent.bxx   File: C:\System Volume Information\_restore{E87A81FB-FDCF-4B92-A20C-951710F82D7C}\RP739\A0059205.exe
deleted: Trojan program Trojan-Downloader.Win32.Agent.bxx   File: C:\System Volume Information\_restore{E87A81FB-FDCF-4B92-A20C-951710F82D7C}\RP739\A0059206.exe
deleted: Trojan program Trojan-Downloader.Win32.Agent.bxx   File: C:\System Volume Information\_restore{E87A81FB-FDCF-4B92-A20C-951710F82D7C}\RP739\A0059213.exe
deleted: Trojan program Trojan-Downloader.Win32.Agent.bxx   File: C:\System Volume Information\_restore{E87A81FB-FDCF-4B92-A20C-951710F82D7C}\RP739\A0061246.exe
deleted: Trojan program Trojan-Downloader.Win32.Agent.bxx   File: C:\System Volume Information\_restore{E87A81FB-FDCF-4B92-A20C-951710F82D7C}\RP739\A0061247.exe
deleted: Trojan program Trojan-Downloader.Win32.Agent.bxx   File: C:\System Volume Information\_restore{E87A81FB-FDCF-4B92-A20C-951710F82D7C}\RP739\A0061248.exe
deleted: Trojan program Trojan-Downloader.Win32.Agent.bxx   File: C:\System Volume Information\_restore{E87A81FB-FDCF-4B92-A20C-951710F82D7C}\RP740\A0062255.exe
deleted: Trojan program Trojan-Downloader.Win32.Agent.bxx   File: C:\System Volume Information\_restore{E87A81FB-FDCF-4B92-A20C-951710F82D7C}\RP740\A0062256.exe
deleted: Trojan program Trojan-Downloader.Win32.Agent.bxx   File: C:\System Volume Information\_restore{E87A81FB-FDCF-4B92-A20C-951710F82D7C}\RP740\A0062257.exe
detected: adware not-a-virus:AdWare.Win32.Virtumonde.jp   File: C:\System Volume Information\_restore{E87A81FB-FDCF-4B92-A20C-951710F82D7C}\RP740\A0062282.dll
deleted: Trojan program Trojan.Win32.Dialer.qn   File: C:\System Volume Information\_restore{E87A81FB-FDCF-4B92-A20C-951710F82D7C}\RP740\A0062283.dll//PE_Patch.PECompact//PecBundle//PECompact
deleted: Trojan program Trojan-Downloader.Win32.Agent.bxx   File: C:\System Volume Information\_restore{E87A81FB-FDCF-4B92-A20C-951710F82D7C}\RP740\A0062284.exe
deleted: Trojan program Trojan-Downloader.Win32.Agent.bxx   File: C:\System Volume Information\_restore{E87A81FB-FDCF-4B92-A20C-951710F82D7C}\RP740\A0062286.exe
deleted: Trojan program Trojan-Downloader.Win32.Agent.bxx   File: C:\System Volume Information\_restore{E87A81FB-FDCF-4B92-A20C-951710F82D7C}\RP740\A0062301.dll//PE_Patch.UPX//UPX
detected: adware not-a-virus:AdWare.Win32.Virtumonde.jp   File: C:\System Volume Information\_restore{E87A81FB-FDCF-4B92-A20C-951710F82D7C}\RP740\A0062324.dll
deleted: Trojan program Trojan.Win32.Dialer.qn   File: C:\System Volume Information\_restore{E87A81FB-FDCF-4B92-A20C-951710F82D7C}\RP765\A0073250.dll//PE_Patch.PECompact//PecBundle//PECompact


Events
------
Time   Event
----   -----
9/27/2007 3:08:11 PM   A full computer scan has never been performed. You are advised to perform a full scan as soon as possible.
9/27/2007 3:08:17 PM   Protection of your computer started.
9/27/2007 3:10:44 PM   Process  (PID 1852) tried to access Kaspersky Anti-Virus process (PID 1884), but the action has been blocked by the Self-Defense component. No action on your part is required.
9/27/2007 3:10:44 PM   Process  (PID 1852) tried to access Kaspersky Anti-Virus process (PID 2888), but the action has been blocked by the Self-Defense component. No action on your part is required.
9/27/2007 3:12:01 PM   File C:\WINDOWS\SYSTEM32\WINMMT32.DLL//PE_Patch.PECompact//PecBundle//PECompact: detected Trojan program 'Trojan.Win32.Dialer.qn'. User: HOME\DELLBURT-CCI$, computer: localhost.
9/27/2007 3:12:01 PM   Security threats have been detected. You are advised to neutralize them immediately.
9/27/2007 3:13:20 PM   File C:\WINDOWS\SYSTEM32\WINMMT32.DLL//PE_Patch.PECompact//PecBundle//PECompact: detected Trojan program 'Trojan.Win32.Dialer.qn'.
9/27/2007 3:13:21 PM   File C:\WINDOWS\SYSTEM32\WINMMT32.DLL will be deleted on system restart.
9/27/2007 3:13:35 PM   Startup object HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winmmt32\winmmt32: deleted.
9/27/2007 3:16:35 PM   Please restart your computer to complete the installation of new or updated protection components.
9/27/2007 3:16:45 PM   File C:\WINDOWS\system32\winmmt32.dll//PE_Patch.PECompact//PecBundle//PECompact: detected Trojan program 'Trojan.Win32.Dialer.qn'.
9/27/2007 3:16:46 PM   File C:\WINDOWS\system32\winmmt32.dll//PE_Patch.PECompact//PecBundle//PECompact: detected Trojan program 'Trojan.Win32.Dialer.qn'.
9/27/2007 3:18:22 PM   File black.lst is missing or corrupted. Please run Updater to fix this problem.
9/27/2007 3:18:22 PM   Please restart your computer to complete the installation of new or updated protection components.
9/27/2007 3:18:24 PM    Update completed successfully
9/27/2007 3:30:22 PM   File C:\WINDOWS\SYSTEM32\winmmt32.dll//PE_Patch.PECompact//PecBundle//PECompact: detected Trojan program 'Trojan.Win32.Dialer.qn'.
9/27/2007 3:30:22 PM   File C:\WINDOWS\SYSTEM32\winmmt32.dll//PE_Patch.PECompact//PecBundle//PECompact: detected Trojan program 'Trojan.Win32.Dialer.qn'.
9/27/2007 3:36:25 PM   A full computer scan has never been performed. You are advised to perform a full scan as soon as possible.
9/27/2007 3:36:44 PM   Process  (PID 1860) tried to access Kaspersky Anti-Virus process (PID 1884), but the action has been blocked by the Self-Defense component. No action on your part is required.
9/27/2007 3:36:56 PM   Protection of your computer started.
9/27/2007 3:47:12 PM   File C:\Documents and Settings\Craig\My Documents\application EXE\New Folder\aawsepersonal.exe//WISE0020.BIN/Ad-Aware SE Default.skn: is password protected.
9/27/2007 3:47:12 PM   File C:\Documents and Settings\Craig\My Documents\application EXE\New Folder\aawsepersonal.exe//WISE0020.BIN/arrow1.bmp: is password protected.
9/27/2007 3:47:12 PM   File C:\Documents and Settings\Craig\My Documents\application EXE\New Folder\aawsepersonal.exe//WISE0020.BIN/arrow2.bmp: is password protected.
9/27/2007 3:47:12 PM   File C:\Documents and Settings\Craig\My Documents\application EXE\New Folder\aawsepersonal.exe//WISE0020.BIN/bck1.bmp: is password protected.
9/27/2007 3:47:12 PM   File C:\Documents and Settings\Craig\My Documents\application EXE\New Folder\aawsepersonal.exe//WISE0020.BIN/bt11.bmp: is password protected.
9/27/2007 3:47:12 PM   File C:\Documents and Settings\Craig\My Documents\application EXE\New Folder\aawsepersonal.exe//WISE0020.BIN/bt12.bmp: is password protected.
9/27/2007 3:47:12 PM   File C:\Documents and Settings\Craig\My Documents\application EXE\New Folder\aawsepersonal.exe//WISE0020.BIN/bt13.bmp: is password protected.
9/27/2007 3:47:12 PM   File C:\Documents and Settings\Craig\My Documents\application EXE\New Folder\aawsepersonal.exe//WISE0020.BIN/bt21.bmp: is password protected.
9/27/2007 3:47:12 PM   File C:\Documents and Settings\Craig\My Documents\application EXE\New Folder\aawsepersonal.exe//WISE0020.BIN/bt22.bmp: is password protected.
9/27/2007 3:47:12 PM   File C:\Documents and Settings\Craig\My Documents\application EXE\New Folder\aawsepersonal.exe//WISE0020.BIN/bt23.bmp: is password protected.
9/27/2007 3:47:12 PM   File C:\Documents and Settings\Craig\My Documents\application EXE\New Folder\aawsepersonal.exe//WISE0020.BIN/bt31.bmp: is password protected.
9/27/2007 3:47:12 PM   File C:\Documents and Settings\Craig\My Documents\application EXE\New Folder\aawsepersonal.exe//WISE0020.BIN/bt32.bmp: is password protected.
9/27/2007 3:47:12 PM   File C:\Documents and Settings\Craig\My Documents\application EXE\New Folder\aawsepersonal.exe//WISE0020.BIN/bt33.bmp: is password protected.
9/27/2007 3:47:12 PM   File C:\Documents and Settings\Craig\My Documents\application EXE\New Folder\aawsepersonal.exe//WISE0020.BIN/bt41.bmp: is password protected.
9/27/2007 3:47:12 PM   File C:\Documents and Settings\Craig\My Documents\application EXE\New Folder\aawsepersonal.exe//WISE0020.BIN/bt42.bmp: is password protected.
9/27/2007 3:47:12 PM   File C:\Documents and Settings\Craig\My Documents\application EXE\New Folder\aawsepersonal.exe//WISE0020.BIN/bt43.bmp: is password protected.
9/27/2007 3:47:12 PM   File C:\Documents and Settings\Craig\My Documents\application EXE\New Folder\aawsepersonal.exe//WISE0020.BIN/bt51.bmp: is password protected.
9/27/2007 3:47:12 PM   File C:\Documents and Settings\Craig\My Documents\application EXE\New Folder\aawsepersonal.exe//WISE0020.BIN/bt52.bmp: is password protected.
9/27/2007 3:47:12 PM   File C:\Documents and Settings\Craig\My Documents\application EXE\New Folder\aawsepersonal.exe//WISE0020.BIN/bt53.bmp: is password protected.
9/27/2007 3:47:12 PM   File C:\Documents and Settings\Craig\My Documents\application EXE\New Folder\aawsepersonal.exe//WISE0020.BIN/bt61.bmp: is password protected.
9/27/2007 3:47:12 PM   File C:\Documents and Settings\Craig\My Documents\application EXE\New Folder\aawsepersonal.exe//WISE0020.BIN/bt62.bmp: is password protected.
9/27/2007 3:47:12 PM   File C:\Documents and Settings\Craig\My Documents\application EXE\New Folder\aawsepersonal.exe//WISE0020.BIN/checkbox1.bmp: is password protected.
9/27/2007 3:47:12 PM   File C:\Documents and Settings\Craig\My Documents\application EXE\New Folder\aawsepersonal.exe//WISE0020.BIN/checkbox2.bmp: is password protected.
9/27/2007 3:47:12 PM   File C:\Documents and Settings\Craig\My Documents\application EXE\New Folder\aawsepersonal.exe//WISE0020.BIN/checkbox3.bmp: is password protected.
9/27/2007 3:47:12 PM   File C:\Documents and Settings\Craig\My Documents\application EXE\New Folder\aawsepersonal.exe//WISE0020.BIN/checkbox4.bmp: is password protected.
9/27/2007 3:47:12 PM   File C:\Documents and Settings\Craig\My Documents\application EXE\New Folder\aawsepersonal.exe//WISE0020.BIN/defbtn1.bmp: is password protected.
9/27/2007 3:47:12 PM   File C:\Documents and Settings\Craig\My Documents\application EXE\New Folder\aawsepersonal.exe//WISE0020.BIN/defbtn2.bmp: is password protected.
9/27/2007 3:47:12 PM   File C:\Documents and Settings\Craig\My Documents\application EXE\New Folder\aawsepersonal.exe//WISE0020.BIN/defbtn3.bmp: is password protected.
9/27/2007 3:47:12 PM   File C:\Documents and Settings\Craig\My Documents\application EXE\New Folder\aawsepersonal.exe//WISE0020.BIN/glyph1.bmp: is password protected.
9/27/2007 3:47:12 PM   File C:\Documents and Settings\Craig\My Documents\application EXE\New Folder\aawsepersonal.exe//WISE0020.BIN/glyph2.bmp: is password protected.
9/27/2007 3:47:12 PM   File C:\Documents and Settings\Craig\My Documents\application EXE\New Folder\aawsepersonal.exe//WISE0020.BIN/glyph3.bmp: is password protected.
9/27/2007 3:47:12 PM   File C:\Documents and Settings\Craig\My Documents\application EXE\New Folder\aawsepersonal.exe//WISE0020.BIN/glyph4.bmp: is password protected.
9/27/2007 3:47:12 PM   File C:\Documents and Settings\Craig\My Documents\application EXE\New Folder\aawsepersonal.exe//WISE0020.BIN/glyph5.bmp: is password protected.
9/27/2007 3:47:12 PM   File C:\Documents and Settings\Craig\My Documents\application EXE\New Folder\aawsepersonal.exe//WISE0020.BIN/glyph6.bmp: is password protected.
9/27/2007 3:47:12 PM   File C:\Documents and Settings\Craig\My Documents\application EXE\New Folder\aawsepersonal.exe//WISE0020.BIN/glyph7.bmp: is password protected.
9/27/2007 3:47:12 PM   File C:\Documents and Settings\Craig\My Documents\application EXE\New Folder\aawsepersonal.exe//WISE0020.BIN/main.bmp: is password protected.
9/27/2007 3:47:12 PM   File C:\Documents and Settings\Craig\My Documents\application EXE\New Folder\aawsepersonal.exe//WISE0020.BIN/preview.bmp: is password protected.
9/27/2007 3:47:12 PM   File C:\Documents and Settings\Craig\My Documents\application EXE\New Folder\aawsepersonal.exe//WISE0020.BIN/sprite1.bmp: is password protected.
9/27/2007 4:03:51 PM   Email message attachment Outlook\Archive Folders\Top of Personal Folders\Sent Items\[From:Craig Smith][Subject:screenshots][Time:2004/01/12 22:18:46]/[TIC] Lionhaus r12Jan20042101.zip/zip.txt: is password protected.
9/27/2007 4:03:51 PM   Email message attachment Outlook\Archive Folders\Top of Personal Folders\Sent Items\[From:Craig Smith][Subject:screenshots][Time:2004/01/12 22:18:46]/[TIC] Lionhaus r12Jan20042101.zip/zip2.txt: is password protected.
9/27/2007 4:03:52 PM   Email message attachment Outlook\Archive Folders\Top of Personal Folders\Sent Items\[From:Craig Smith][Subject:screenshots][Time:2004/01/12 22:18:46]/[TIC] Lionhaus r12Jan20042101.zip/zip3.txt: is password protected.
9/27/2007 4:03:52 PM   Email message attachment Outlook\Archive Folders\Top of Personal Folders\Sent Items\[From:Craig Smith][Subject:screenshots][Time:2004/01/12 22:18:46]/[TIC] Lionhaus r12Jan20042101.zip/zip4.txt: is password protected.
9/27/2007 4:03:52 PM   Email message attachment Outlook\Archive Folders\Top of Personal Folders\Sent Items\[From:Craig Smith][Subject:screenshots][Time:2004/01/12 22:18:46]/[TIC] Lionhaus r12Jan20042101.zip/Blackbart@invisiblewarriors.com_Action_508.jpg: is password protected.
9/27/2007 4:03:52 PM   Email message attachment Outlook\Archive Folders\Top of Personal Folders\Sent Items\[From:Craig Smith][Subject:screenshots][Time:2004/01/12 22:18:46]/[TIC] Lionhaus r12Jan20042101.zip/Blackbart@invisiblewarriors.com_Models_508.jpg: is password protected.
9/27/2007 4:03:52 PM   Email message attachment Outlook\Archive Folders\Top of Personal Folders\Sent Items\[From:Craig Smith][Subject:screenshots][Time:2004/01/12 22:18:46]/[TIC] Lionhaus r12Jan20042101.zip/Blackbart@invisiblewarriors.com_Scores_508.jpg: is password protected.
9/27/2007 4:03:52 PM   Email message attachment Outlook\Archive Folders\Top of Personal Folders\Sent Items\[From:Craig Smith][Subject:screenshots][Time:2004/01/12 22:18:46]/[TIC] Lionhaus r12Jan20042101.zip/[TIC] Lionhaus r12Jan20041001.jpg: is password protected.
9/27/2007 4:23:48 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom.zip/lisa@servedby.advertising[1].txt: is password protected.
9/27/2007 4:23:48 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:48 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom1.zip/craig@servedby.advertising[2].txt: is password protected.
9/27/2007 4:23:48 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom1.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:48 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom10.zip/lisa@servedby.advertising[2].txt: is password protected.
9/27/2007 4:23:48 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom10.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:48 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom11.zip/lisa@advertising[2].txt: is password protected.
9/27/2007 4:23:48 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom11.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:48 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom2.zip/craig@advertising[2].txt: is password protected.
9/27/2007 4:23:48 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom2.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:48 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom3.zip/lisa@advertising[2].txt: is password protected.
9/27/2007 4:23:48 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom3.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:48 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom4.zip/lisa@servedby.advertising[2].txt: is password protected.
9/27/2007 4:23:48 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom4.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:48 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom5.zip/lisa@advertising[1].txt: is password protected.
9/27/2007 4:23:48 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom5.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:48 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom6.zip/lisa@servedby.advertising[1].txt: is password protected.
9/27/2007 4:23:48 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom6.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom7.zip/craig@servedby.advertising[2].txt: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom7.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom8.zip/craig@advertising[1].txt: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom8.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom9.zip/lisa@advertising[1].txt: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom9.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AlexaRelated.zip/RELATED.HTM: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AlexaRelated.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc.zip/craig@atdmt[2].txt: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc1.zip/lisa@atdmt[2].txt: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc1.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc2.zip/craig@atdmt[1].txt: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc2.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc3.zip/lisa@atdmt[2].txt: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc3.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc4.zip/craig@atdmt[2].txt: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc4.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc5.zip/lisa@atdmt[2].txt: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc5.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc6.zip/craig@atdmt[1].txt: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc6.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc7.zip/lisa@atdmt[2].txt: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc7.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc8.zip/craig@atdmt[2].txt: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc8.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BFast.zip/lisa@bfast[2].txt: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BFast.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BFast1.zip/lisa@bfast[2].txt: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BFast1.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BFast2.zip/lisa@bfast[2].txt: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BFast2.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BraveSentry.zip/xpupdate.exe: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BraveSentry.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BraveSentry1.zip/sbRecovery.reg: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BraveSentry1.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BraveSentry2.zip/sbRecovery.reg: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BraveSentry2.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BraveSentry3.zip/BraveSentry.lic: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BraveSentry3.zip/BraveSentry0.bs: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BraveSentry3.zip/BraveSentry0.dll: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BraveSentry3.zip/BraveSentry1.bs: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BraveSentry3.zip/BraveSentry2.dll: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BraveSentry3.zip/Uninstall.exe: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BraveSentry3.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BraveSentry4.zip/sbRecovery.reg: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BraveSentry4.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction.zip/lisa@qksrv[1].txt: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction1.zip/lisa@commission-junction[1].txt: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction1.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction2.zip/craig@qksrv[1].txt: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction2.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction3.zip/lisa@qksrv[1].txt: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction3.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction4.zip/lisa@qksrv[2].txt: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction4.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction5.zip/lisa@commission-junction[1].txt: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction5.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch.zip/sbRecovery.reg: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoreMetrics.zip/lisa@data.coremetrics[1].txt: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoreMetrics.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoreMetrics1.zip/craig@data.coremetrics[2].txt: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoreMetrics1.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DoubleClick.zip/craig@doubleclick[1].txt: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DoubleClick.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DoubleClick1.zip/lisa@doubleclick[2].txt: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DoubleClick1.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DoubleClick2.zip/craig@doubleclick[1].txt: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DoubleClick2.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DoubleClick3.zip/lisa@doubleclick[1].txt: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DoubleClick3.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DoubleClick4.zip/craig@doubleclick[2].txt: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DoubleClick4.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DoubleClick5.zip/lisa@doubleclick[1].txt: is password protected.
9/27/2007 4:23:49 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DoubleClick5.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DoubleClick6.zip/lisa@doubleclick[1].txt: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DoubleClick6.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DoubleClick7.zip/craig@doubleclick[1].txt: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DoubleClick7.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit.zip/sbRecovery.reg: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit1.zip/sbRecovery.reg: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit1.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit2.zip/sbRecovery.reg: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit2.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit3.zip/sbRecovery.reg: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit3.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit4.zip/sbRecovery.reg: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit4.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit5.zip/sbRecovery.reg: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit5.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Enliven.zip/lisa@ads.enliven[1].txt: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Enliven.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Excite.zip/lisa@excite[2].txt: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Excite.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FastClick.zip/craig@fastclick[2].txt: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FastClick.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FastClick1.zip/lisa@fastclick[3].txt: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FastClick1.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FastClick2.zip/lisa@media.fastclick[1].txt: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FastClick2.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FastClick3.zip/lisa@fastclick[1].txt: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FastClick3.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FastClick4.zip/lisa@fastclick[1].txt: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FastClick4.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FastClick5.zip/craig@fastclick[1].txt: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FastClick5.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FastClick6.zip/lisa@media.fastclick[2].txt: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FastClick6.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FastClick7.zip/lisa@fastclick[1].txt: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FastClick7.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FastClick8.zip/craig@fastclick[1].txt: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FastClick8.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWeb.zip/sbRecovery.reg: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWeb.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWeb1.zip/sbRecovery.reg: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWeb1.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWeb10.zip/sbRecovery.reg: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWeb10.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWeb11.zip/sbRecovery.reg: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWeb11.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWeb12.zip/sbRecovery.reg: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWeb12.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWeb13.zip/sbRecovery.reg: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWeb13.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWeb14.zip/sbRecovery.reg: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWeb14.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWeb2.zip/sbRecovery.reg: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWeb2.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWeb3.zip/sbRecovery.reg: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWeb3.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWeb4.zip/sbRecovery.reg: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWeb4.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWeb5.zip/sbRecovery.reg: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWeb5.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWeb6.zip/sbRecovery.reg: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWeb6.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWeb7.zip/sbRecovery.reg: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWeb7.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWeb8.zip/sbRecovery.reg: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWeb8.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWeb9.zip/sbRecovery.reg: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWeb9.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWebProducts.zip/sbRecovery.reg: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWebProducts.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWebProducts1.zip/sbRecovery.reg: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWebProducts1.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWebProducts10.zip/sbRecovery.reg: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWebProducts10.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWebProducts11.zip/sbRecovery.reg: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWebProducts11.zip/sbRecovery.ini: is password protected.
9/27/2007 4:23:50 PM   File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FunWebProd
Logged

My job is to comfort the disturbed, and disturb the comfortable!
junior08jr8
Newbie
*
Posts: 194



View Profile
« Reply #1 on: November 15, 2007, 03:36:03 PM »

Please download the new Hijackthis 2.02 run it and post a log here.
Logged
Pages: [1]
  Print  
 
Jump to:  




Recommended software:
STOPzilla
(90/100)
STOPzilla is a powerful anti-spyware program that detects, blocks, and removes malicious software allowing users to surf the Web not worrying about spyware, Trojan horses,...
Malwarebytes Anti Malware
(88/100)
There are loads of malware removers on the net today and most of them are lightweight applications, which usually means they’re fast and don’t...
Spyware Doctor
(87/100)
Spyware Doctor is a very powerful, but yet highly user-friendly spyware remover, made by PC Tools, reputable computer security experts. This product provides effective and...
SpyHunter
(86/100)
SpyHunter is a quite simple, but yet highly effective spyware remover with an easy-to-use interface. This program is an excellent choice for users, who are...
XoftSpySE Anti Spyware
(84/100)
XoftSpySE, an anti-spyware program made by ParetoLogic, Inc., is a simple, but effective on-demand scanner with the typical set of functions but very easy to...
Encyclopedia of parasites:

Spreading the knowledge:

It is very hard to fight Computer parasites alone in internet space. If you have a website we would be more than happy if you would help us to spread the knowledge about latest threats. You can help your visitors to manage their Computer system manually without aditional expences. Knowledge is the power, we just need to spread it.
add text box
rss feed
help other