Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Might Be Hijacked - Can't Open The Task Manager


  • This topic is locked This topic is locked
8 replies to this topic

#1 Ooskus

Ooskus

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:02:19 AM

Posted 19 June 2006 - 08:28 AM

I installed Limewire this weekend, and the uninstalled it. Now Task Manager won't run, and I cannot get in toe registry editor. I ran Spy ware Doctor, Spigot, CW Shredder and Norton Antivirus, then rebooted in safe mode with command prompt, and removed the Limewire directory and files. Then ran regedit from safe mode, and purged the registry of all references to Limewire. When I boot in normal mode, I still cannot run regedit (the message is that it is being used by another program), and I cannot open the Task Manager - nothing happens when I try to open it. I rebooted, and immediately on rebooting, when the system was still loading, I was able to open the Task Manager. Under "applications" there was an installer running, I stopped it, and then ran regedit. Both opened, no problem. When I rebooted, and waited until everything was loaded, I again could not open Task Manager or regedit. Please help - this is driving me nuts. Below is a copy of my latest Hijackthis log file. Thanks in advance for any help you can give me.
Logfile of HijackThis v1.99.1
Scan saved at 7:20:39 AM, on 6/19/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5296.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\System32\cisvc.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Sunbelt Software\iHateSpam\ihsService.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Sunbelt Software\iHateSpam\ihsSpamFilterEngine.exe
C:\WINDOWS\system32\Tablet.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\Sunbelt Software\iHateSpam\ihsMailProxyServer.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=552...cid={SUB_CLCID}
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Henry en Lorraine, Newtown, PA
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PaltalkWebLogin - {502C3BA4-2C3E-4317-BC29-C0445E82B1F9} - C:\Program Files\Common Files\Paltalk\PaltalkWebLogin.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [ihsService.exe] "C:\Program Files\Sunbelt Software\iHateSpam\ihsService.exe"
O4 - HKLM\..\RunServices: [p2p networking] p2pnetworking.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: taskmgr.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.comcastsupport.com/sdcxuser/asp/tgctlsr.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1145107492156
O16 - DPF: {BB383206-6DA1-4E80-B62A-3DF950FCC697} (Create & Print ActiveX Plug-in) - http://ak.imgag.com/imgag/cp/install/AxCtp2.cab
O16 - DPF: {D68217F4-1DF9-45C1-BFA6-61DBD5464527} (Genealogy Browser) - http://66.119.139.74/cabs/zinst.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup162.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/aio/en/check/qdiagh.cab?326
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O20 - Winlogon Notify: WBSrv - C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: LiveShare P2P Server (RoxLiveShare) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxLiveShare.exe
O23 - Service: RoxMediaDB - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
O23 - Service: RoxUpnpRenderer (RoxUPnPRenderer) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCom\RoxUpnpRenderer.exe
O23 - Service: RoxUpnpServer - Sonic Solutions - C:\Program Files\Roxio\Easy Media Creator 8\Digital Home\RoxUpnpServer.exe
O23 - Service: Roxio Hard Drive Watcher (RoxWatch) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe

BC AdBot (Login to Remove)

 


#2 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:07:19 AM

Posted 19 June 2006 - 11:42 AM

Hello,

* Download Brute Force Uninstaller.
Unzip it to a folder of itís own (c:\BFU).
Read here how to unzip/extract properly:
http://metallica.geekstogo.com/xpcompressedexplanation.html
Start the Brute Force Uninstaller by doubleclicking BFU.exe

Next to the 'scriptfile to execute'-window you'll see a little icon as shown in next picture: Posted Image
When you click that icon, a little window will open that says: 'Please enter the full URL to the sript you want to execute'
In the field, copy and paste next URL:

http://metallica.geekstogo.com/alcanshorty.bfu

Click Ok.
Then click execute in Brute Force Uninstaller.

Extra note:
If nothing happens after pressing the Execute button, this means that the script didn't download. In that case, download the script
( alcanshorty.bfu ) manually from above url ( rightclick on it and choose 'save as' and save it in your BFU-folder). Then start BFU.exe again and click the browse button next to the 'scriptfile to execute'-window
Browse to the script you downloaded and Click Ok and Execute in Brute Force Uninstaller.


Wait for the complete script execution box to popup and press OK.
Press exit to terminate the BFU program.

Then,

* Start HijackThis, close all open windows leaving only HijackThis running. Place a check against each of the following:

O4 - HKLM\..\RunServices: [p2p networking] p2pnetworking.exe
O4 - Global Startup: taskmgr.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O16 - DPF: {D68217F4-1DF9-45C1-BFA6-61DBD5464527} (Genealogy Browser) - http://66.119.139.74/cabs/zinst.cab


* Click on Fix Checked when finished and exit HijackThis.
Make sure your Internet Explorer is closed when you click Fix Checked!

Please download Ewido anti-malware; it is a free version of the program.
  • Install ewido security suite
  • When installing, under "Additional Options" uncheck..
    • Install background guard
    • Install scan via context menu
  • Launch ewido by double-clicking on the icon on your desktop.
  • The program will now open to the main screen.
  • When you run ewido for the first time, you may get a warning "Database could not be found!". Click OK. We will fix this in a moment.
  • You will need to update ewido to the latest definition files.
    • On the left hand side of the main screen click update.
    • Then click on Start Update.
  • The update will start and a progress bar will show the updates being installed.
    (the status bar at the bottom will display ("Update successful")
If you are having problems with the updater, you can use this link to manually update ewido.
ewido manual updates

* Open Ewido anti-malware
Click on scanner

* Click Complete System Scan and the scan will begin.
* During the scan it will prompt you to clean files, click OK
* When the scan is finished, look at the bottom of the screen and click the Save report button.
* Save the report to your desktop

Close Ewido

If during your scan Ewido "crashes" or "hangs", please try scanning again.
Before running the scan, click on 'Scanner' (the 3rd bar from the top on the left) and Choose 'Settings'.
Uncheck 'Scan in NTFS Alternate Data Streams' as this can cause problems in overly infected systems.
Click 'OK' and then start the scan again.


Reboot.

Post a new hijackthislog together with the Ewido log in your next reply.
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#3 Ooskus

Ooskus
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:02:19 AM

Posted 19 June 2006 - 12:41 PM

Thanks. Will do, and I'll let you know how it turned out. Your help is much appreciated.

#4 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:07:19 AM

Posted 19 June 2006 - 12:44 PM

Yes, it's really important you post the logs afterwards. :thumbsup:

Success.
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#5 Ooskus

Ooskus
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:02:19 AM

Posted 20 June 2006 - 01:27 PM

OK. Everything seems fine now - regedit works, and so does the task manager. Below are the hijackthis log and the ewido log.

Thanks again for everything.

Logfile of HijackThis v1.99.1
Scan saved at 7:05:56 AM, on 6/20/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5296.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\System32\cisvc.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\Tablet.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Sunbelt Software\iHateSpam\ihsService.exe
C:\Program Files\Sunbelt Software\iHateSpam\ihsSpamFilterEngine.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\Sunbelt Software\iHateSpam\ihsMailProxyServer.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Sunbelt Software\iHateSpam\ihsClientUI.exe
C:\Program Files\Sunbelt Software\iHateSpam\ihsMain.exe
C:\Program Files\AIM95\aim.exe
C:\Program Files\ICQ\Icq.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\LVComsX.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\Explorer.EXE
C:\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=552...cid={SUB_CLCID}
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Henry en Lorraine, Newtown, PA
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PaltalkWebLogin - {502C3BA4-2C3E-4317-BC29-C0445E82B1F9} - C:\Program Files\Common Files\Paltalk\PaltalkWebLogin.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [ihsService.exe] "C:\Program Files\Sunbelt Software\iHateSpam\ihsService.exe"
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.comcastsupport.com/sdcxuser/asp/tgctlsr.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1145107492156
O16 - DPF: {BB383206-6DA1-4E80-B62A-3DF950FCC697} (Create & Print ActiveX Plug-in) - http://ak.imgag.com/imgag/cp/install/AxCtp2.cab
O16 - DPF: {D68217F4-1DF9-45C1-BFA6-61DBD5464527} (Genealogy Browser) - http://66.119.139.74/cabs/zinst.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup162.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/aio/en/check/qdiagh.cab?326
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O20 - Winlogon Notify: WBSrv - C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: LiveShare P2P Server (RoxLiveShare) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxLiveShare.exe
O23 - Service: RoxMediaDB - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
O23 - Service: RoxUpnpRenderer (RoxUPnPRenderer) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCom\RoxUpnpRenderer.exe
O23 - Service: RoxUpnpServer - Sonic Solutions - C:\Program Files\Roxio\Easy Media Creator 8\Digital Home\RoxUpnpServer.exe
O23 - Service: Roxio Hard Drive Watcher (RoxWatch) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe

---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------

+ Created at: 8:07:28 PM 6/19/2006

+ Scan result:



C:\Documents and Settings\Henry\Shared\_\007 DVD Maker v3.0.0.45.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\25 To Life-RELOADED iSO.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\5star Audio Studio 1.4.9.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\ADAPT PT V7.20.1.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\ADAPT RC V5.00.2.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Abbott & Costello Meet the Mummy (1955).rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Abbott and Costello Meet The Invisible Man.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Acronis Disk Director Suite v10.0.2117.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Active@ File Recovery 7.1 Build 257 Professional Editio.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Ad-Aware SE Pro 1.0.6r1.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Ad-Aware SE Professional Edition 1.06r1.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Adobe Acrobat 3D 7.07.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Adobe Audition v2.0.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Adobe Photoshop 9 CS2.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Advanced Desktop Shield v1.8.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Advanced Emailer v3.1.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Advanced X Video Converter v4.33.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Adventures of Ichabod and Mr. Toad (Disney Gold Classic).rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Allok Video Joiner v1.6.4.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\AoA DVD COPY v2.7.2.7.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Apollo DVD Copy v4.6.7.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Artlantis R v1.1.0.12 Retail.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Aurora Media Workshop v3.3.8.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Aurora Media Workshop v3.319.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\AutoRun Architect v2.20.0.1.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\AutoRun Pro Enterprise v8.0.0.71.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Avid Softimage XSi Advanced 5.11 Retail.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Awakening v1.0.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\BSPlayer Pro v2.0.937.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Barrow Hill.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Battlefield 1942 iSO.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Beyond Good and Evil - iSO.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Bicentennial Man DVDRip Xvid.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\BulletProofSoft Spyware Adware Remover v9.3.0.7.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Cadlink SignLab Vinyl 7.1 Rev.1 Build 4 Retail.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Cars Radiator Springs Adventures.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Cars (2006).rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Cars-PLEX iSO.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Cars.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Chrome Division - Doomsday Rock'n'Roll (2006).rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\City Life iSO.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\CloneDVD 3.9.4.0.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Coffee Break-RiTUEL.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\CoffeeCup Website Color Schemer 3.0.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\ConceptDraw Project v2.1.4.0 Retail.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\ConvertXtoDVD v2.0.13.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Cookie Remover Platinum 2004 v1.0.7.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Croc 2 iSO.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Cross Racing Championship 2005.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\CyberCafePro v5.0 Server & Client (FULL).rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\DVD Cover Searcher v3.1.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\DVD Info Pro 4.56.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\DVD PixPlay v3.0.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\DVD neXt Copy v1.0.4.1.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\DVD to iPod Converter v3.21 . . With keymaker.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\DVD-Cloner III v3.20.894.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Daath - The Hinderers (2006).rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Dark Water.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Database Workbench v2.8.5.3.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Dear wendy.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Demons & Wizards - Touched By The Crimson King.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Destruction Derby 2 iSO.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Deus Ex 2 Invisible War iSO.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\DivX Create Bundle v6.1.1.3.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Dreamer Inspired by a True Story (2005).rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Droppix Recorder v1.7.5.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Easy DVD CD Burner v3.0.75.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\EasyBoot v5.0.7.482.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\EasyPDF v2.2.1.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Edguy- Mandrake.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Eight Legged Freaks.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Empire Falls (2005).rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\End Of Spear DVD-R.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Error Doctor 2006 v1.3.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Extensis PhotoFrame v2.5.2.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\F.E.A.R. - First Encounter Assault Recon iSO.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Fable The Lost Chapters iSO.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Failure To Launch.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Fantastic Four DVDRip XviD-DiAMOND.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Fates Warning - Inside Out.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Fear and Loathing in Las Vegas DVDRip Xvid.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Fearless DVDRip Xvid EN Subs.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\FeedDemon v2.0.0.24.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\FinePrint v5.54.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\FlashFXP v3.4.0 Build.1140 FINAL Proper.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\FontExplorerL.M ver.4.2.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Form Pilot Home v2.09.02.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Forum Proxy Leecher v1.05.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Future Cop L.A.P.D..rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\GameBoost v1.5.15.2006.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Gammadyne Mailer v26.1.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Garfield A Tail Of Two Kitties CAM VCD-PreVail.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\GenePix Pro v6.0.1.26.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Gertrudis Pro 2.5.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Ghostbusters II DVDRip Xvid.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Ginger Snaps Back The Beginning.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Golden Bow Systems VoptXP v7.22.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Golden Hawk CDRWin v4.0C.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Google Earth 4 Beta.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\HTML Password Lock v3.28.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Half Life 2 Episode One iSO.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Half-Life 2 Episode One - PROViSiON iSO.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Half-Life 2 Episode One.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Halloween.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\HardCopy Pro v2.7.1.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Heed - The Call.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Heroes of Might and Magic V iSO.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Hillstone Staff Manager v2.1.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Hitman Blood Money.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Hitman Blood Money EMUDVD-Unleashed iSO.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Hostel XviD German UnCut.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\House of Wax DVDRip Xvid.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\HydraIRC 0.3.126.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\I-TV Plus Plus Platinium v1.0.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\IE DOM Inspector 1.5.2.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\IL-2 Sturmovik iSO.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Imagine me and you.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Inbit Messenger v2.5.0.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\InstantGet v2.02.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Jet Li The Enforcer.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Just Like Heaven DVDRip XviD-DiAMOND.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Kaspersky Internet Security 6.0.1.323 Beta.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Kaspersky Internet Security 6.0.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Kidulthood 2006 LiMiTED DVDRip XviD-LiNE.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Laurel & Hardy Love 'em And Weep & Perfect Day.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Laurel & Hardy-Come Clean & Early to Bed.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Laurel & Hardy-Sugar Daddies & Thats My Wife.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\MOBILedit! v2.0.0.13.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\MP3 Doctor 5.11.049.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Mafia iSO.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Magic Burning Studio.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Magic Translator v7.00.6332.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Magix Movie Edit Pro 11 v5.5.4.1 Retail.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Mail Snoop Pro v1.12.030.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Manhunt.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Matmos - Rose Has Teeth In the Mouth of A Bea.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Matmos - The West.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Maze Creator STD v3.31.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\McAfee Enterprise Edition 8.0i.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\MechWarrior 4 - Mercenaries iSO.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\MessengerLog 5.35 Pro.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Minitab Release 14.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Minotaur DVDRip Xvid.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Mission Impossible 3 TS Xvid HQ.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Monarch v8.01 Pro Retail.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\MonitorIT v8.009.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Morrowind and Bloodmoon.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Movie DVD Creator v1.02.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Mylidian - Birth Of The Prophet (2006).rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Nacho Libre TS SVCD-PreVail.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Native Instruments Guitar Rig v2.02 Retail.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Native Instruments Kontakt v2.11 Retail.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Nature Illusion Studio v1.13.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\NetObjects Fusion 9.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\No1 DVD Ripper v3.1.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Ocean FTP Server v1.1.7.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Omniform Premium 5.0.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Omniform Premium v5.0.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Operation Flashpoint Game Of The Year Edition iSO.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Over The Hedge (2006).rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\PCMedik v2.5.15.2006.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\PDF Filler Pilot v1.27.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\PDF Maker Pilot v1.27.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\PHPedit ver.2.4.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\PPT to Flash Studio ver.2.9.9.11.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Pagan's Mind - Infinity Divine.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Painkiller.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Peter Jacksons King Kong iSO.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Photo Collage Studio v1.3.6.0 Retail.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Poseidon PROPER TS XviD-HUSTLE.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Power Iso 2.8 % 3.1.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\PowerCHM 5.4 build 0315.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Prince of Persia - The Two Thrones iSO.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\QMsAddin Collection v2.12 Retail.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\ReGet Deluxe v4.2.264.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Red Circuit - Trance State (2006).rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\RegRestore PC TuneUp v5.0.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Registry Booster v1.1.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Replay Music v2.41.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Replay SlingCorder v1.04.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Rise And Fall Civilizations At War SFCloneDVD PROPER-iTWINS.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Rome - Total War Barbarian Invasion iSO.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Rugby League 2.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Rumour Has It.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Russel Peters Live in New York HDTVRip Xvid.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\SEO Studio Enterprise v2.0.4.2031.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\SFV Checker v1.17.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Sarm Soft WebAlbum v3.7.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Scar Symmetry - 2 albums.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Selteco Bannershop GIF Animator v5.0.71.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Sensible Soccer 2006.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Sentinel XviD German.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Serious Sam 2.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Ship Simulator 2006.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Shrek 2 Team Action.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Sid and Nancy DVDRip Xvid.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Silent Hill 2006 TC XviD.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Sin City DVDRip Xvid.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Sinner GigAlarm v1.29 BETA.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Slither TS Xvid.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Sparx Systems Entreprise Architect 6.1.79.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\SpeederXP v1.6.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Spy Kids 3-D Game Over.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\SpyStopper Pro v4.60.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Spymate (2006).rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Spyware Doctor 3.8.0.2581.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Spyware Nuker XT v4.6.47.1650.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Stardock WindowFX v3.0.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Steganos Security Suite 2006 v8.0.4.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Super Internet TV 6.6.0.0.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Super Utilities Pro 6.35.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Super Utilities Pro v6.35.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Super Video Splitter v2.8.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\SuperRam v5.5.15.2006.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\System Cleaner v5.51E.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Team Manager Football 2006.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\The Breakup 2006 TS SVCD-HafVCD.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\The Da Vinci Code HQ TS Xvid.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\The DaVinci Code PROPER TC XviD-KY.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\The Fast And The Furious Tokyo Drift CAM-HYdRO.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\The Great Raid DVDRip XviD-DiAMOND.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\The Honeymooners 2005 PROPER DVDRip XviD-iNCiTE.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\The Mummy Returns DVDRip Xvid.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\The Omen iNTERNAL TC XviD-ASTEROiDS.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\The Sims 2 Open for Business Expansion iSO.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\The Sims 2 iSO.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\The Wild TS Xvid HQ.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Throttle v6.5.15.2006.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Tidy Start Menu v 2.9.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Tivity Xtivity v1.31.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\TweakNow PowerPack 2006 Professional v1.1.7.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\UllmanSoft Sudoku Son v1.04.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Ultimate ZIP Cracker v7.3.1.7.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Ultraviolet - 2006.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Ultraviolet Unrated 2006 DVDRip XviD-xV.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\V for Vendetta DVDRip XviD-DoNE.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Vanilla Sky DVDRip Xvid.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Versis Full Speed v2.1.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Virtual Painter Deluxe v5.0 Retail.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\VoptXP 7.22.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Walk The Line.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Wallpaper Changer v2.04.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Web Translator v7.00.6319.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\WinAVI Video Converter v7.6.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\WinRAR 3.51.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\WinRAR v3.60 Beta 5 Incl. DosRAR.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\WinTasks Administrator v 5.03.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\WinUtilities 5.1.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\WinUtilities v5.1.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Winamp Pro 5.23.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\World Soccer Winning Eleven 9 International.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\World War II Combat Road To Berlin-PLEX.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\WorldCoins v1.0.2259.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\X Ways Forensics v13.0 SR-1.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Xilisoft Video Converter 3.17.0616.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\XoftSpySE 4.26.187.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\Zathura (2005).rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\ZoneAlarm 6.5.714.000.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\eScan Corporate Edition v8.0.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\n00zn00zn00zn00z.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Documents and Settings\Henry\Shared\_\no1 DVD Ripper 2.4.0.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\t.rar/Setup.exe -> Backdoor.IRCBot.dd : No action taken.
C:\Program Files\Smoky City Design\The Panorama Factory V4\Panorama_v4.2_Crk.exe -> Downloader.Harnig.bq : No action taken.
:mozilla.12:C:\Documents and Settings\Henry\Application Data\Netscape\NSB\Profiles\cejhud0q.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.7:C:\Documents and Settings\Henry\Application Data\Netscape\NSB\Profiles\cejhud0q.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.8:C:\Documents and Settings\Henry\Application Data\Netscape\NSB\Profiles\cejhud0q.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.9:C:\Documents and Settings\Henry\Application Data\Netscape\NSB\Profiles\cejhud0q.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Henry\Cookies\henry@2o7[2].txt -> TrackingCookie.2o7 : No action taken.
I:\Herinstallasies\Express Assist\EA7Backup.Henry.2005-11-26.21-55.eaz/^IE Data^/C/henry@2o7[2].txt -> TrackingCookie.2o7 : No action taken.
I:\Herinstallasies\Express Assist\EA7Backup.Henry.2005-11-26.21-55.eaz/^IE Data^/C/henry@microsofteup.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
I:\Herinstallasies\Express Assist\EA7Backup.Henry.2005-11-26.21-55.eaz/^IE Data^/C/henry@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
I:\Herinstallasies\Express Assist\EA7Backup.Henry1.2005-8-30.17-17.eaz/^IE Data^/C/henry1@2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Henry\Cookies\henry@aavalue[1].txt -> TrackingCookie.Aavalue : No action taken.
C:\Documents and Settings\Henry\Cookies\henry@adc.aavalue[1].txt -> TrackingCookie.Aavalue : No action taken.
I:\Herinstallasies\Express Assist\EA7Backup.Henry1.2005-8-30.17-17.eaz/^IE Data^/C/henry1@abcsearch[2].txt -> TrackingCookie.Abcsearch : No action taken.
C:\Documents and Settings\Henry\Cookies\henry@adbrite[1].txt -> TrackingCookie.Adbrite : No action taken.
C:\Documents and Settings\Henry\Cookies\henry@rotator.adjuggler[1].txt -> TrackingCookie.Adjuggler : No action taken.
C:\Documents and Settings\Henry\Cookies\henry@ad.adocean[2].txt -> TrackingCookie.Adocean : No action taken.
:mozilla.13:C:\Documents and Settings\Henry\Application Data\Netscape\NSB\Profiles\cejhud0q.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.14:C:\Documents and Settings\Henry\Application Data\Netscape\NSB\Profiles\cejhud0q.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.15:C:\Documents and Settings\Henry\Application Data\Netscape\NSB\Profiles\cejhud0q.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.17:C:\Documents and Settings\Henry\Application Data\Netscape\NSB\Profiles\cejhud0q.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
C:\Documents and Settings\Henry\Cookies\henry@advertising[1].txt -> TrackingCookie.Advertising : No action taken.
:mozilla.19:C:\Documents and Settings\Henry\Application Data\Netscape\NSB\Profiles\cejhud0q.default\cookies.txt -> TrackingCookie.Atdmt : No action taken.
C:\Documents and Settings\Henry\Cookies\henry@atdmt[2].txt -> TrackingCookie.Atdmt : No action taken.
I:\Herinstallasies\Express Assist\EA7Backup.Henry.2005-11-26.21-55.eaz/^IE Data^/C/henry@atdmt[2].txt -> TrackingCookie.Atdmt : No action taken.
C:\Documents and Settings\Henry\Cookies\henry@bluemountain[2].txt -> TrackingCookie.Bluemountain : No action taken.
I:\Herinstallasies\Express Assist\EA7Backup.Henry1.2005-8-30.17-17.eaz/^IE Data^/C/henry1@citi.bridgetrack[1].txt -> TrackingCookie.Bridgetrack : No action taken.
I:\Herinstallasies\Express Assist\EA7Backup.Henry.2005-11-26.21-55.eaz/^IE Data^/C/henry@casalemedia[1].txt -> TrackingCookie.Casalemedia : No action taken.
C:\Documents and Settings\Henry\Cookies\henry@ad1.clickhype[1].txt -> TrackingCookie.Clickhype : No action taken.
I:\Herinstallasies\Express Assist\EA7Backup.Henry.2005-11-26.21-55.eaz/^IE Data^/C/henry@com[2].txt -> TrackingCookie.Com : No action taken.
C:\Documents and Settings\Henry\Cookies\henry@data.coremetrics[1].txt -> TrackingCookie.Coremetrics : No action taken.
I:\Herinstallasies\Express Assist\EA7Backup.Henry.2005-11-26.21-55.eaz/^IE Data^/C/henry@data.coremetrics[1].txt -> TrackingCookie.Coremetrics : No action taken.
C:\Documents and Settings\Henry\Cookies\henry@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : No action taken.
:mozilla.21:C:\Documents and Settings\Henry\Application Data\Netscape\NSB\Profiles\cejhud0q.default\cookies.txt -> TrackingCookie.Doubleclick : No action taken.
C:\Documents and Settings\Henry\Cookies\henry@doubleclick[1].txt -> TrackingCookie.Doubleclick : No action taken.
I:\Herinstallasies\Express Assist\EA7Backup.Henry.2005-11-26.21-55.eaz/^IE Data^/C/henry@doubleclick[1].txt -> TrackingCookie.Doubleclick : No action taken.
C:\Documents and Settings\Henry\Cookies\henry@e-2dj6wjkysgdzidq.stats.esomniture[1].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Henry\Cookies\henry@e-2dj6wjlyogczwlo.stats.esomniture[2].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Henry\Cookies\henry@e-2dj6wjnyagd5glo.stats.esomniture[1].txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Henry\Cookies\henry@adopt.euroclick[1].txt -> TrackingCookie.Euroclick : No action taken.
C:\Documents and Settings\Henry\Cookies\henry@fastclick[1].txt -> TrackingCookie.Fastclick : No action taken.
C:\Documents and Settings\Henry\Cookies\henry@media.fastclick[2].txt -> TrackingCookie.Fastclick : No action taken.
I:\Herinstallasies\Express Assist\EA7Backup.Henry.2005-11-26.21-55.eaz/^IE Data^/C/henry@ehg-acdsystems.hitbox[1].txt -> TrackingCookie.Hitbox : No action taken.
I:\Herinstallasies\Express Assist\EA7Backup.Henry.2005-11-26.21-55.eaz/^IE Data^/C/henry@ehg-comcast.hitbox[1].txt -> TrackingCookie.Hitbox : No action taken.
I:\Herinstallasies\Express Assist\EA7Backup.Henry.2005-11-26.21-55.eaz/^IE Data^/C/henry@ehg-idg.hitbox[1].txt -> TrackingCookie.Hitbox : No action taken.
I:\Herinstallasies\Express Assist\EA7Backup.Henry.2005-11-26.21-55.eaz/^IE Data^/C/henry@hitbox[1].txt -> TrackingCookie.Hitbox : No action taken.<

#6 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:07:19 AM

Posted 20 June 2006 - 03:53 PM

Clean hijackthislog here.

How are things now?
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#7 Ooskus

Ooskus
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:02:19 AM

Posted 20 June 2006 - 07:26 PM

All seems good. Again, thank you.

#8 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:07:19 AM

Posted 21 June 2006 - 02:47 AM

Glad I could help. :thumbsup:

To keep this clean in the future, I would suggest the following things:

Install Spywareblaster
SpywareBlaster doesn`t scan and clean for so-called spyware, but prevents it from being installed in the first place. It blocks the popular spyware ActiveX controls, and also prevents the installation of any of them via a webpage.

* Avoid illegal sites, because that's where most malware is present.
* Don't click on links inside popups.
* Don't click on links in spam messages claiming to offer anti-spyware software; because most of these so called removers ARE spyware.
* Download free software only from sites you know and trust. Because a lot of free software can bundle other software, including spyware.

Let your antispywarescanner(s) scan frequently and don't forget to update before.

And I do suggest you perform an online virusscan once in a while. (Housecall and/or Bitdefender). Because what one virusscanner can't find another one maybe can.
Also make sure that your virusscanner, the one that is installed on your system is always up to date!

Make sure your windows has the latest updates: http://windowsupdate.microsoft.com/

If you are having XP SP2, read here how to configure Security Features for Internet Explorer:
http://www.microsoft.com/technet/security/...xp/iesecxp.mspx

Also visit this Free Online Scanner for PC Health and Safety and Microsoft Security At Home for tips to Protect your Pc, Protect yourself and Protect your Family.

More info on how to prevent malware you can also find here (By Tony Klein)
and here: http://wiki.castlecops.com/Malware_Prevent...nt_Re-infection

If you want to fight back the Malware Writers that have made your life a misery, please take a look here.

Happy surfing again! :flowers:
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#9 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:07:19 AM

Posted 23 June 2006 - 07:53 AM

Since this issue appears resolved ... this Topic is closed.

If you need this topic reopened, please request this by sending the moderating team
a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic.
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users