Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

My Pc Is Infected With Darksma (downloader).


  • Please log in to reply
35 replies to this topic

#1 CID1

CID1

  • Members
  • 32 posts
  • OFFLINE
  •  
  • Local time:04:27 PM

Posted 22 March 2007 - 08:01 AM

Darksma was found two days ago on my PC. I did a search after, for the 1st time, my bowser was directed automatically to an unwanted page (some marketing ad). Darksma came up on my Yahoo anti-spy as a downloader. Yet every time I removed it, it would be right back there. (It must have something in the memory that keeps putting it back. I don't know. I'm not that computer savvy). I downloaded Spybot (Nice program BTW) and though it found 7 negative programs, it didn't find darksma. I tried an Ad-aware program (NoAdware) that said it would remove darksma, but it was a worthless program and a waste of time. It didn't find anything. Norton was no help, but then I have an older version (with updates) and it may not be suited to for this issue. So I have concluded the Hijackthis is the way to go.

Differences that I have noticed.
1) A major jump in the number of blocked pop ups.
2) A few pop ups now get through.
3) Every few minute the 1st I.E. window opened will automatically go to another page that is marketing some product. A lot of times it is to buy anti-spyware.
4) In the Internet options/ privacy/ managed sites (edit) there is now a major (and I mean MAJOR) amount of blocked sites there that I have never seen/heard of before.
5) This morning I booted up my PC and after I logged in all that showed up was the background. No Desktop Icons, no Taskbar, nothing. CTRL+ALT+DEL wouldn't work and right click didn't open it's usual menu. (I got a little scared). I turned off my PC the booted it up again and everything came up this time (Yeah, I wiped the sweat off my forehead). An interesting note. The same thing happened right after I finished purging those 7 items that Spybot found. Everything disappeared, but the background. I had to reboot. Ż\(°_o)/Ż

Now I must say, as I'm not familiar with spyware, adware, trojans and all that stuff, I'm afraid to imput any personal log in info. Like passwords, email account and forum log ins. I really didn't even want to log in to my email to activate my account here, but I had no choice. This draksma may not steal that kind of info, but the sites it is directing my browser to may have downloaded something that will. I just don't know.
(It sucks. I'm a GameFAQs forum addict). Maybe I'm being paranoid. Anyway, on with the log.

Oh and Thank you for having this service! ^_^

-----------------------------------------------------------------------------------------------------------------------------

-------------------------------!!!UPDATE!!! as of 12:05 am 3/23/07----------------------------------------------------

(I have used the edit button to update my post instead of posting a reply in the hope of not resetting my place in the queue).

Additional problems:

1) Urgent!!!
One of the 7 malicious programs that Spybot found, one keeps returning.
Smitfraud-c Toolbar888
This malware keeps coming back even if I have Spybot delete it, immediately reboot and have Spybot check again before anything else is launched. I not sure when I got this, bit I believe it was downloaded after and because of darksma. I speculate this because of the description of Smitfraud that I have seen elsewhere on this forum.
Excerpt from another topic: Ok, I think I have a Smitfraud Malware! The only thing I see it doing is randomly opening IE browser windows to sites like: adultfriendfinder.com, yourshopz.com, exittracking.com, megashopcity.com, etc, etc. . .
I have the same problem yet I never had it happen till I got darksma. This leads me to believe that draksma put Smitfraud on my PC. Please help in it’s removal. Thank you.

This is what was presented in Spybot’s analysis:

Smitfraud-c Toolbar888 1 entry
(Settings) HKEY_LOCAL_MACHINE\SOFTWARE\Araf15 Registry key

Details:
Company:
Product: Smitfraud-C.Toolbar888
Threat: Malware


Description
Smitfraud-C.Toolbar888 is connecting to malicious website without giving the user a possibility to cancel that process.
It also adds a randomly named dll to the Winlogon Notify, which will make it very resistable to removal.


---

2) Norton’s auto protect was shut down. I then turned it back on and scanned my PC again. It found 5 “program integrity” errors. I had to run Norton WinDoctor in order to fix these, but it only was able to fix one of them. The 4 remaining each have a missing file. I will list the 4 issues here: (It lists the severity for all 4 as medium).

Summary –
One or more programs on your computer reference files that are inaccessible or cannot be found. This might cause the program to run improperly or not at all.

Details –
1) Missing File: “C:\Program File\Adobe\Reader8.0\Reader\AcroRd32.exe”
C:\Program File\Adobe\Reader8.0\Reader\AcroRd32.exe” cannot access a necessary file, “msvcp80.dll.”

2) [b]Missing File: “C:\Program File\Adobe\Reader8.0\Reader\AcroRd32.exe”[/b]
C:\Program File\Adobe\Reader8.0\Reader\AcroRd32.exe” cannot access a necessary file, “msvcp80.dll.”

3) Missing File: “C:\Program Files\Common
Files\InstallSheild\Professional\RunTime\09\00\Intel32\DotNetInstaller.exe”

“C:\Program Files\Common Files\InstallSheild\Professional\RunTime\09\00\Intel32\DotNetInstaller.exe” cannot access a necessary file, “mscoree.dll.”

4) Missing File: “C:\Program Files\Common
Files\InstallSheild\Professional\RunTime\09\00\Intel32\DotNetInstaller.exe”

“C:\Program Files\Common Files\InstallSheild\Professional\RunTime\09\00\Intel32\DotNetInstaller.exe” cannot access a necessary file, “mscoree.dll.”


---

I am going to continue the original list of differences that I have noticed since acquiring darksma.

6) At least 4 processes are no longer there when I boot up. Luckily they are ones that I commonly close anyway. It may just be a coincident and that windows just stopped running them once it recognized a pattern of them being ended.
7) When I went to my hotmail account to verify my registration here, the page was very messed up. All the graphics for the icons were enlarged, many of the items were located in the wrong place and none of the emails would open. Only after refreshing my page was the problem corrected. This same problem happened on the page that lists my active posts on the GameFAQs forum. (Yes I took the risk and logged in to my account there.
8) Something called Windows Live ID now seems to be in effect. I have never seen this before until yesterday. I don’t know what it is, but I would like it gone.

---

Please help me in fixing all of this. For the last year I have never had any problems before. I am very careful in what I do online. I am no experienced in handling these kind of problems. My computer is vital to my job and my life. I use it every day for numerous tasks. Everyday that I have to deal with this is a blow to my daily activates. Again, thank you.

---

I am now going to list a new Hijackthis that was just made as there may be differences do to resent deletions that I have made.

-------------------------------This is the resent and current log of my registry---------------------------------------

Logfile of HijackThis v1.99.1
Scan saved at 12:01:31 AM, on 3/23/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\taskmgr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gamefaqs.com/
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {ad5df14b-b221-4d49-a631-6c6a9fc7ce69} - C:\WINDOWS\system32\dfros4.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LogonStudio] "C:\Program Files\WinCustomize\LogonStudio\logonstudio.exe" /RANDOM
O4 - HKLM\..\Run: [2chkdsk] rundll32.exe "C:\WINDOWS\xxywvt.dll",setvm
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O15 - Trusted Zone: www.gamefaqs.com
O15 - Trusted Zone: http://www.gamefaqs.com
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/...nst20040510.cab
O20 - Winlogon Notify: dfros4 - C:\WINDOWS\SYSTEM32\dfros4.dll
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe

-------------------------------End of resent log and of the update------------------------------------------------------

-------------------------------The original, old Hijack log from yesterday morning-----------------------------------

Logfile of HijackThis v1.99.1
Scan saved at 4:34:44 AM, on 3/22/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\NoAdware5.0\NoAdware5.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gamefaqs.com/
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {ad5df14b-b221-4d49-a631-6c6a9fc7ce69} - C:\WINDOWS\system32\dfros4.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LogonStudio] "C:\Program Files\WinCustomize\LogonStudio\logonstudio.exe" /RANDOM
O4 - HKLM\..\Run: [2chkdsk] rundll32.exe "C:\WINDOWS\xxywvt.dll",setvm
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O15 - Trusted Zone: www.gamefaqs.com
O15 - Trusted Zone: http://www.gamefaqs.com
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/...nst20040510.cab
O20 - Winlogon Notify: dfros4 - C:\WINDOWS\SYSTEM32\dfros4.dll
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe

-------------------------------------------------End of old log------------------------------------------------------------

Edited by CID1, 23 March 2007 - 02:19 AM.

CID

"There is power in numbers."

BC AdBot (Login to Remove)

 


#2 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:07:27 PM

Posted 24 March 2007 - 09:24 AM

Hello CID1 and welcome to the BC HijackThis forum. Let's see what else might be hiding in there.

Download WinPFind3u.exe to your Desktop and double-click on it to extract the files. It will create a folder named WinPFind3u on your desktop.
  • Close ALL OTHER PROGRAMS.
  • Open the WinPFind3u folder and double-click on WinPFind3U.exe to start the program.
  • Under Additional Scans click the checkboxes in front of the following items to select them:

    • Desktop Components
      Policy Settings
      Additional Folder Scans
  • Now click the Run Scan button on the toolbar.
  • Let it run unhindered until it finishes.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Use the Add Reply button and Copy/Paste the information back here. I will review it when it comes in. If, after posting, the last line is not < End of Report > then the log is too big to fit into a single post and you will need to split it into multiple posts.

Cheers.

OT
I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image

#3 CID1

CID1
  • Topic Starter

  • Members
  • 32 posts
  • OFFLINE
  •  
  • Local time:04:27 PM

Posted 24 March 2007 - 08:54 PM

Thanks for the reply OldTimer.

I have downloaded and am running WinPFind3u.exe.

However there program seems to have frozen as it has not completed it's scan in a while and Task manager states its status as Not Responding.

I don't know if I should end the program and run the scan again or just let it continue as is, unchanged.
Please inform.

Also, when I installed WinPFind3u.exe, I put it into a new file in my Program Files folder instead of my desktop. Yet an icon still appeared on my desktop. I'm not sure that it is connected to WinPFind3u.exe as it's Properties list it as being created on February 22, 07, a month ago??? The program is called 01. When I tried to run it, Spybot notified my that it was trying to make a couple registry changes. I denied of coarse. I am going to purge 01 unless you state otherwise.
CID

"There is power in numbers."

#4 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:07:27 PM

Posted 24 March 2007 - 09:25 PM

Hi CID1. There is no installation. The downloaded executable will simply extract the files it needs. It will not create any files or folders with and 01 in the name.

Delete any downloaded files and any folders you currently have and then follow the steps above exactly. Do not place the files anywhere but on the Desktop.

Cheers.

OT
I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image

#5 CID1

CID1
  • Topic Starter

  • Members
  • 32 posts
  • OFFLINE
  •  
  • Local time:04:27 PM

Posted 25 March 2007 - 02:31 AM

Hello OT,

Sorry that was a miss used word. When I said installation, I meant extraction. Anyway, 01 is gone as is the previous download. I have redone the steps, this time precisely as you have said.

The result however is still the same. WinPFind3u.exe becomes "Not Responding" and takes up 100% of my CPU usage. That last time I left it on for over 6 hours and it never finished its task. I don't see how this attempt will be any different. I will however leave it on till you reply. Please and other ideas you have would be appreciated.

Is there anything is my registry that I can change to get rid of darksma and Smitfraud? Also will these malicious programs steal my personal log in info? Should I continue to avoid logging into my email and other accounts?

Thanks,
CID

P.S. Also it seems now that my Internet Explorer is prone to freezing. It's a bit of an effort just to get this reply to you. Anyway, talk to ya.
CID

"There is power in numbers."

#6 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:07:27 PM

Posted 25 March 2007 - 07:11 AM

Hi CID1. At the bottom of the screen in the status bar it will tell you what area it is currently scanning (or stuck on). What does it say?

Cheers.

OT
I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image

#7 CID1

CID1
  • Topic Starter

  • Members
  • 32 posts
  • OFFLINE
  •  
  • Local time:04:27 PM

Posted 25 March 2007 - 02:51 PM

Question. Will these malicious programs steal my personal log in info? Should I continue to avoid logging into my email and other accounts? Please advise.


I have done multiple tests and it seems to get stuck on a random mixture of these 3 areas that it is currently scanning. To note it gets stuck just a second or two after I start the scan.
The 3 are:
* Scanning Run Keys…
* Scanning Window Services…
* Scanning Processes…
CID

"There is power in numbers."

#8 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:07:27 PM

Posted 25 March 2007 - 09:15 PM

Hi CID1. I can't really say what can or cannot happen until we can see what's on the system

Try running the scan in Safe Mode. To boot to Safe Mode follow these steps:

Start in Safe Mode Using the F8 method:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until the boot menu appears.
  • Use the arrow keys to select the Safe Mode menu item.
  • Press the Enter key.
Note: You must be logon using an account that has Administrator rights to run this program.

Cheers.

OT
I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image

#9 CID1

CID1
  • Topic Starter

  • Members
  • 32 posts
  • OFFLINE
  •  
  • Local time:04:27 PM

Posted 25 March 2007 - 10:22 PM

I booted up in Safe mode just as you said. I got the same exact problem. The WinPFind3u.exe froze seconds into starting the scan.

Also, I would like to be here when you are so that we can communicate at a more frequent rate. What time will you be here online. I will make sure to be here as well regardlees of the time of day. (I am in the US pacific time zone).

Note: While booting back up (regularly) I got this message for the 1st time.

(Title)
RUNDLL

(Message Detail)
Error loading C:\WINDOWS\xxywvt.dll
The specified module could not be found.

CID

"There is power in numbers."

#10 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:07:27 PM

Posted 26 March 2007 - 04:22 AM

Hi CID1. Let's try this:

Download ComboFix by sUBs:

NOTE: In the event you already have ComboFix, this is a new version that I need you to download.
  • Save it to your desktop.
  • Double-click combofix.exe and follow the prompts.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Cheers.

OT

Edited by OldTimer, 26 March 2007 - 04:23 AM.

I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image

#11 CID1

CID1
  • Topic Starter

  • Members
  • 32 posts
  • OFFLINE
  •  
  • Local time:04:27 PM

Posted 26 March 2007 - 05:23 AM

ComboFix 07-03-23 - Running from: "C:\Documents and Settings\MYST\Desktop"

(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\qoobox\purity\DOCUME~1
C:\qoobox\purity\DOCUME~1\MYST
C:\qoobox\purity\DOCUME~1\MYST\MYDOCU~1
C:\qoobox\purity\DOCUME~1\MYST\MYDOCU~1\from.txt
C:\qoobox\purity\DOCUME~1\MYST\MYDOCU~1\RACLE~1
C:\qoobox\purity\DOCUME~1\MYST\MYDOCU~1\RACLE~1\j?vaw.exe
C:\qoobox\purity\Program Files\Common Files\ICROSO~1
C:\qoobox\purity\Program Files\Common Files\RACLE~1
C:\qoobox\purity\WINDOWS\MCROSO~1.NET
C:\qoobox\purity\WINDOWS\MCROSO~1.NET\M?crosoft.NET
C:\qoobox\purity\WINDOWS\MCROSO~1.NET\rundll32.exe


((((((((((((((((((((((((((((((( Files Created from 2007-02-26 to 2007-03-26 ))))))))))))))))))))))))))))))))))


2007-03-25 19:39 106,539 --a------ C:\WINDOWS\jkhhhg.dll
2007-03-25 17:37 60,928 --a------ C:\WINDOWS\system32\vtzblf.dll
2007-03-24 18:00 <DIR> d-------- C:\Program Files\Trouble shoot
2007-03-23 02:43 2 --a------ C:\WINDOWS\system32\wnstssv32.exe
2007-03-23 02:42 69 --a-s---- C:\WINDOWS\url1.bat
2007-03-23 01:57 32,768 --a------ C:\WINDOWS\system32\svchtoost.exe
2007-03-23 01:57 32,768 --a------ C:\WINDOWS\NOTEDAD.EXE
2007-03-22 19:56 108,613 --a------ C:\tmp4.tmp.exe
2007-03-20 22:59 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-03-20 09:31 <DIR> d-------- C:\WINDOWS\system32\appmgmt
2007-03-20 09:13 <DIR> d-------- C:\DOCUME~1\MYST\APPLIC~1\Help
2007-03-19 21:52 27,312 --a------ C:\WINDOWS\system32\cbaby.exe
2007-03-19 21:52 19,950 --a------ C:\WINDOWS\system32\dfros4.dll
2007-03-19 21:47 8,535 --a------ C:\WINDOWS\system32\vtsrpml.dll


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-03-22 03:33 -------- d-------- C:\DOCUME~1\MYST\APPLIC~1\uniblue
2007-03-22 03:31 -------- d-------- C:\Program Files\google
2007-03-19 21:42 -------- d-------- C:\Program Files\quicktime
2007-03-19 21:42 -------- d-------- C:\Program Files\messenger
2007-02-09 07:17 -------- d-------- C:\Program Files\wincustomize


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"
"SpybotSD TeaTimer"="C:\\Program Files\\Spybot - Search & Destroy\\TeaTimer.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"NAV Agent"="C:\\PROGRA~1\\NORTON~1\\NORTON~1\\navapw32.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"LogonStudio"="\"C:\\Program Files\\WinCustomize\\LogonStudio\\logonstudio.exe\" /RANDOM"
"2chkdsk"="rundll32.exe \"C:\\WINDOWS\\xxywvt.dll\",setvm"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="msmsgs"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"inimapping"="0"


[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"IESet"="IExplorer.dll .dbt"

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dfros4

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0



Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Norton AntiVirus - Scan my computer.job
C:\WINDOWS\tasks\Norton SystemWorks One Button Checkup.job
C:\WINDOWS\tasks\Symantec NetDetect.job
C:\WINDOWS\tasks\Uniblue SpyEraser.job


********************************************************************

catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net

scanning hidden processes ...

scanning hidden services ...

scanning hidden autostart entries ...

scanning hidden files ...

C:\RECYCLER\NPROTECT
C:\RECYCLER\NPROTECT\00000964.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00000965.JPG 32768 bytes
C:\RECYCLER\NPROTECT\00000966.SWF 49152 bytes
C:\RECYCLER\NPROTECT\00000967.SWF 12288 bytes
C:\RECYCLER\NPROTECT\00000968.JS 4096 bytes
C:\RECYCLER\NPROTECT\00000969.GIF 96 bytes
C:\RECYCLER\NPROTECT\00000970.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00000971 8192 bytes
C:\RECYCLER\NPROTECT\00000972 8192 bytes
C:\RECYCLER\NPROTECT\00000973 8192 bytes
C:\RECYCLER\NPROTECT\00000974 8192 bytes
C:\RECYCLER\NPROTECT\00000975 8192 bytes
C:\RECYCLER\NPROTECT\00000976 8192 bytes
C:\RECYCLER\NPROTECT\00000977 8192 bytes
C:\RECYCLER\NPROTECT\00000978 8192 bytes
C:\RECYCLER\NPROTECT\00000979 8192 bytes
C:\RECYCLER\NPROTECT\00000980.JPG 16384 bytes
C:\RECYCLER\NPROTECT\00000981.PHP 16384 bytes
C:\RECYCLER\NPROTECT\00000982.GIF 48 bytes
C:\RECYCLER\NPROTECT\00000983.JS 4096 bytes
C:\RECYCLER\NPROTECT\00000984.XML 16384 bytes
C:\RECYCLER\NPROTECT\00000985.XML 16384 bytes
C:\RECYCLER\NPROTECT\00000986.XML 16384 bytes
C:\RECYCLER\NPROTECT\00000987.PNG 4096 bytes
C:\RECYCLER\NPROTECT\00000988.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00000989.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00000990.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00000991.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00000992.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00000993.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00000994.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00000995.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00000996.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00000997.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00000998.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00000999.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001000.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001001.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001002.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001003.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001004.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001005.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001006.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001007.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001008.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001009.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001010.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001011.SWF 24576 bytes
C:\RECYCLER\NPROTECT\00001012.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001013.GIF 32768 bytes
C:\RECYCLER\NPROTECT\00001014 24 bytes
C:\RECYCLER\NPROTECT\00001015.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001016.SWF 73728 bytes
C:\RECYCLER\NPROTECT\00001017.JPG 16384 bytes
C:\RECYCLER\NPROTECT\00001018.JPG 8192 bytes
C:\RECYCLER\NPROTECT\00001019.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001020 24 bytes
C:\RECYCLER\NPROTECT\00001021.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001022.GIF 12288 bytes
C:\RECYCLER\NPROTECT\00001023.GIF 12288 bytes
C:\RECYCLER\NPROTECT\00001024.SWF 40960 bytes
C:\RECYCLER\NPROTECT\00001025.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001026.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001027.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001028.SWF 405504 bytes
C:\RECYCLER\NPROTECT\00001029 24 bytes
C:\RECYCLER\NPROTECT\00001030.FLV 1671168 bytes
C:\RECYCLER\NPROTECT\00001031 400 bytes
C:\RECYCLER\NPROTECT\00001032 4096 bytes
C:\RECYCLER\NPROTECT\00001033 4096 bytes
C:\RECYCLER\NPROTECT\00001034 4096 bytes
C:\RECYCLER\NPROTECT\00001035 16 bytes
C:\RECYCLER\NPROTECT\00001036 4096 bytes
C:\RECYCLER\NPROTECT\00001037.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001038 4096 bytes
C:\RECYCLER\NPROTECT\00001039 4096 bytes
C:\RECYCLER\NPROTECT\00001040 4096 bytes
C:\RECYCLER\NPROTECT\00001041 4096 bytes
C:\RECYCLER\NPROTECT\00001042 4096 bytes
C:\RECYCLER\NPROTECT\00001043 4096 bytes
C:\RECYCLER\NPROTECT\00001044 4096 bytes
C:\RECYCLER\NPROTECT\00001045 16 bytes
C:\RECYCLER\NPROTECT\00001046.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001047.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001048.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001049.GIF 12288 bytes
C:\RECYCLER\NPROTECT\00001050.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001051.SWF 49152 bytes
C:\RECYCLER\NPROTECT\00001052.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001053.PNG 4096 bytes
C:\RECYCLER\NPROTECT\00001054.PNG 8192 bytes
C:\RECYCLER\NPROTECT\00001055.PNG 8192 bytes
C:\RECYCLER\NPROTECT\00001056.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001057.JPG 12288 bytes
C:\RECYCLER\NPROTECT\00001058.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001059.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001060.FLV 831488 bytes
C:\RECYCLER\NPROTECT\00001061.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001062 8192 bytes
C:\RECYCLER\NPROTECT\00001063.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001064.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001065.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001066.SWF 36864 bytes
C:\RECYCLER\NPROTECT\00001067.GIF 20480 bytes
C:\RECYCLER\NPROTECT\00001068.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001069 24 bytes
C:\RECYCLER\NPROTECT\00001070.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001071.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001072.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001073.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001074.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001075.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001076 384 bytes
C:\RECYCLER\NPROTECT\00001077.2 20480 bytes
C:\RECYCLER\NPROTECT\00001078.29 4096 bytes
C:\RECYCLER\NPROTECT\00001079.33 12288 bytes
C:\RECYCLER\NPROTECT\00001080.09 40960 bytes
C:\RECYCLER\NPROTECT\00001081 464 bytes
C:\RECYCLER\NPROTECT\00001082 184 bytes
C:\RECYCLER\NPROTECT\00001083 4096 bytes
C:\RECYCLER\NPROTECT\00001084 456 bytes
C:\RECYCLER\NPROTECT\00001085 448 bytes
C:\RECYCLER\NPROTECT\00001086 456 bytes
C:\RECYCLER\NPROTECT\00001087 448 bytes
C:\RECYCLER\NPROTECT\00001088 448 bytes
C:\RECYCLER\NPROTECT\00001089 456 bytes
C:\RECYCLER\NPROTECT\00001090.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001091 480 bytes
C:\RECYCLER\NPROTECT\00001092 480 bytes
C:\RECYCLER\NPROTECT\00001093 480 bytes
C:\RECYCLER\NPROTECT\00001094 480 bytes
C:\RECYCLER\NPROTECT\00001095 480 bytes
C:\RECYCLER\NPROTECT\00001096 480 bytes
C:\RECYCLER\NPROTECT\00001097 480 bytes
C:\RECYCLER\NPROTECT\00001098 480 bytes
C:\RECYCLER\NPROTECT\00001099 480 bytes
C:\RECYCLER\NPROTECT\00001100 480 bytes
C:\RECYCLER\NPROTECT\00001101 480 bytes
C:\RECYCLER\NPROTECT\00001102 480 bytes
C:\RECYCLER\NPROTECT\00001103 480 bytes
C:\RECYCLER\NPROTECT\00001104 480 bytes
C:\RECYCLER\NPROTECT\00001105 480 bytes
C:\RECYCLER\NPROTECT\00001106 480 bytes
C:\RECYCLER\NPROTECT\00001107 480 bytes
C:\RECYCLER\NPROTECT\00001108 480 bytes
C:\RECYCLER\NPROTECT\00001109 480 bytes
C:\RECYCLER\NPROTECT\00001110 480 bytes
C:\RECYCLER\NPROTECT\00001111 480 bytes
C:\RECYCLER\NPROTECT\00001112 4096 bytes
C:\RECYCLER\NPROTECT\00001113 480 bytes
C:\RECYCLER\NPROTECT\00001114 4096 bytes
C:\RECYCLER\NPROTECT\00001115 480 bytes
C:\RECYCLER\NPROTECT\00001116.SWF 28672 bytes
C:\RECYCLER\NPROTECT\00001117.PNG 4096 bytes
C:\RECYCLER\NPROTECT\00001118.GIF 304 bytes
C:\RECYCLER\NPROTECT\00001119.GIF 48 bytes
C:\RECYCLER\NPROTECT\00001120.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001121.HTM 176 bytes
C:\RECYCLER\NPROTECT\00001122.HTM 176 bytes
C:\RECYCLER\NPROTECT\00001123.HTM 176 bytes
C:\RECYCLER\NPROTECT\00001124.HTM 176 bytes
C:\RECYCLER\NPROTECT\00001125.HTM 176 bytes
C:\RECYCLER\NPROTECT\00001126.HTM 176 bytes
C:\RECYCLER\NPROTECT\00001127.HTM 176 bytes
C:\RECYCLER\NPROTECT\00001128.HTM 176 bytes
C:\RECYCLER\NPROTECT\00001129.HTM 184 bytes
C:\RECYCLER\NPROTECT\00001130.PHP 24576 bytes
C:\RECYCLER\NPROTECT\00001131.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001132.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001133.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001134.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001135.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001136.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001137.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001138.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001139.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001140.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001141 4096 bytes
C:\RECYCLER\NPROTECT\00001142.HTM 12288 bytes
C:\RECYCLER\NPROTECT\00001143.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001144.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001145.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001146.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001147.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001148.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001149.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001150.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001151.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001152.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001153 4096 bytes
C:\RECYCLER\NPROTECT\00001154.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001155.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001156.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001157.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001158.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001159.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001160.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001161.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001162.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001163.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001164.HTM 12288 bytes
C:\RECYCLER\NPROTECT\00001165.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001166.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001167.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001168.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001169.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001170.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001171.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001172.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001173.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001174.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001175.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001176.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001177.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001178.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001179.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001180.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001181.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001182.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001183.HTM 12288 bytes
C:\RECYCLER\NPROTECT\00001184.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001185.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001186.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001187.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001188.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001189.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001190.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001191.ASP 8192 bytes
C:\RECYCLER\NPROTECT\00001192.ASP 32768 bytes
C:\RECYCLER\NPROTECT\00001193.JS 12288 bytes
C:\RECYCLER\NPROTECT\00001194.GIF 384 bytes
C:\RECYCLER\NPROTECT\00001195.CSS 12288 bytes
C:\RECYCLER\NPROTECT\00001196.JPG 8192 bytes
C:\RECYCLER\NPROTECT\00001197.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001198.GIF 96 bytes
C:\RECYCLER\NPROTECT\00001199.GIF 8192 bytes
C:\RECYCLER\NPROTECT\00001200.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001201.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001202.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001203.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001204.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001205.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001206.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001207.CFM 4096 bytes
C:\RECYCLER\NPROTECT\00001208.CFM 4096 bytes
C:\RECYCLER\NPROTECT\00001209.CFM 4096 bytes
C:\RECYCLER\NPROTECT\00001210.CFM 4096 bytes
C:\RECYCLER\NPROTECT\00001211.CFM 4096 bytes
C:\RECYCLER\NPROTECT\00001212.CFM 4096 bytes
C:\RECYCLER\NPROTECT\00001213.CFM 4096 bytes
C:\RECYCLER\NPROTECT\00001214.PNG 4096 bytes
C:\RECYCLER\NPROTECT\00001215.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001216.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001217.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001218.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001219.GIF 152 bytes
C:\RECYCLER\NPROTECT\00001220.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001221.GIF 48 bytes
C:\RECYCLER\NPROTECT\00001222.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001223.GIF 48 bytes
C:\RECYCLER\NPROTECT\00001224.JPG 32768 bytes
C:\RECYCLER\NPROTECT\00001225.swf 20480 bytes
C:\RECYCLER\NPROTECT\00001226.swf 32768 bytes
C:\RECYCLER\NPROTECT\00001227 704 bytes
C:\RECYCLER\NPROTECT\00001228 4096 bytes
C:\RECYCLER\NPROTECT\00001229 4096 bytes
C:\RECYCLER\NPROTECT\00001230.gif 12288 bytes
C:\RECYCLER\NPROTECT\00001231.jsp 8 bytes
C:\RECYCLER\NPROTECT\00001232 4096 bytes
C:\RECYCLER\NPROTECT\00001233.swf 32768 bytes
C:\RECYCLER\NPROTECT\00001234.swf 32768 bytes
C:\RECYCLER\NPROTECT\00001235.swf 8192 bytes
C:\RECYCLER\NPROTECT\00001236.swf 24576 bytes
C:\RECYCLER\NPROTECT\00001237 4096 bytes
C:\RECYCLER\NPROTECT\00001238 4096 bytes
C:\RECYCLER\NPROTECT\00001239 4096 bytes
C:\RECYCLER\NPROTECT\00001240 4096 bytes
C:\RECYCLER\NPROTECT\00001241.jsp 8 bytes
C:\RECYCLER\NPROTECT\00001242 4096 bytes
C:\RECYCLER\NPROTECT\00001243.gif 16384 bytes
C:\RECYCLER\NPROTECT\00001244 4096 bytes
C:\RECYCLER\NPROTECT\00001245 4096 bytes
C:\RECYCLER\NPROTECT\00001246.swf 32768 bytes
C:\RECYCLER\NPROTECT\00001247 4096 bytes
C:\RECYCLER\NPROTECT\00001248 4096 bytes
C:\RECYCLER\NPROTECT\00001249.jsp 8 bytes
C:\RECYCLER\NPROTECT\00001250 544 bytes
C:\RECYCLER\NPROTECT\00001251 352 bytes
C:\RECYCLER\NPROTECT\00001252 4096 bytes
C:\RECYCLER\NPROTECT\00001253.jsp 8 bytes
C:\RECYCLER\NPROTECT\00001254 4096 bytes
C:\RECYCLER\NPROTECT\00001255 528 bytes
C:\RECYCLER\NPROTECT\00001256 4096 bytes
C:\RECYCLER\NPROTECT\00001257 4096 bytes
C:\RECYCLER\NPROTECT\00001258.jsp 8 bytes
C:\RECYCLER\NPROTECT\00001259 616 bytes
C:\RECYCLER\NPROTECT\00001260 4096 bytes
C:\RECYCLER\NPROTECT\00001261 4096 bytes
C:\RECYCLER\NPROTECT\00001262 4096 bytes
C:\RECYCLER\NPROTECT\00001263.swf 32768 bytes
C:\RECYCLER\NPROTECT\00001264 4096 bytes
C:\RECYCLER\NPROTECT\00001265.CSS 4096 bytes
C:\RECYCLER\NPROTECT\00001266.swf 32768 bytes
C:\RECYCLER\NPROTECT\00001267 4096 bytes
C:\RECYCLER\NPROTECT\00001268 4096 bytes
C:\RECYCLER\NPROTECT\00001269 4096 bytes
C:\RECYCLER\NPROTECT\00001270.jsp 8 bytes
C:\RECYCLER\NPROTECT\00001271 4096 bytes
C:\RECYCLER\NPROTECT\00001272.swf 20480 bytes
C:\RECYCLER\NPROTECT\00001273 4096 bytes
C:\RECYCLER\NPROTECT\00001274 4096 bytes
C:\RECYCLER\NPROTECT\00001275.swf 28672 bytes
C:\RECYCLER\NPROTECT\00001276 4096 bytes
C:\RECYCLER\NPROTECT\00001277.GIF 56 bytes
C:\RECYCLER\NPROTECT\00001278 520 bytes
C:\RECYCLER\NPROTECT\00001279.swf 20480 bytes
C:\RECYCLER\NPROTECT\00001280 4096 bytes
C:\RECYCLER\NPROTECT\00001281 4096 bytes
C:\RECYCLER\NPROTECT\00001282.swf 20480 bytes
C:\RECYCLER\NPROTECT\00001283 4096 bytes
C:\RECYCLER\NPROTECT\00001284.swf 32768 bytes
C:\RECYCLER\NPROTECT\00001285 344 bytes
C:\RECYCLER\NPROTECT\00001286 4096 bytes
C:\RECYCLER\NPROTECT\00001287.jsp 8 bytes
C:\RECYCLER\NPROTECT\00001288 4096 bytes
C:\RECYCLER\NPROTECT\00001289 4096 bytes
C:\RECYCLER\NPROTECT\00001290 4096 bytes
C:\RECYCLER\NPROTECT\00001291 4096 bytes
C:\RECYCLER\NPROTECT\00001292.jsp 8 bytes
C:\RECYCLER\NPROTECT\00001293.jsp 8 bytes
C:\RECYCLER\NPROTECT\00001294 4096 bytes
C:\RECYCLER\NPROTECT\00001295.jsp 8 bytes
C:\RECYCLER\NPROTECT\00001296 4096 bytes
C:\RECYCLER\NPROTECT\00001297 4096 bytes
C:\RECYCLER\NPROTECT\00001298 4096 bytes
C:\RECYCLER\NPROTECT\00001299.php 4096 bytes
C:\RECYCLER\NPROTECT\00001300 4096 bytes
C:\RECYCLER\NPROTECT\00001301.jsp 8 bytes
C:\RECYCLER\NPROTECT\00001302 4096 bytes
C:\RECYCLER\NPROTECT\00001303.GIF 384 bytes
C:\RECYCLER\NPROTECT\00001304.GIF 96 bytes
C:\RECYCLER\NPROTECT\00001305.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001306.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001307.GIF 272 bytes
C:\RECYCLER\NPROTECT\00001308.GIF 248 bytes
C:\RECYCLER\NPROTECT\00001309.JS 12288 bytes
C:\RECYCLER\NPROTECT\00001310.BIN 232 bytes
C:\RECYCLER\NPROTECT\00001311.JS 4096 bytes
C:\RECYCLER\NPROTECT\00001312.HTM 488 bytes
C:\RECYCLER\NPROTECT\00001313.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001314 40960 bytes
C:\RECYCLER\NPROTECT\00001315.JPG 57344 bytes
C:\RECYCLER\NPROTECT\00001316.JS 4096 bytes
C:\RECYCLER\NPROTECT\00001317 8192 bytes
C:\RECYCLER\NPROTECT\00001318.JS 4096 bytes
C:\RECYCLER\NPROTECT\00001319.XML 4096 bytes
C:\RECYCLER\NPROTECT\00001320.XML 128 bytes
C:\RECYCLER\NPROTECT\00001321.XML 128 bytes
C:\RECYCLER\NPROTECT\00001322.HTM 12288 bytes
C:\RECYCLER\NPROTECT\00001323.HTM 12288 bytes
C:\RECYCLER\NPROTECT\00001324.000 61440 bytes
C:\RECYCLER\NPROTECT\00001325 8192 bytes
C:\RECYCLER\NPROTECT\00001326.FLV 512000 bytes
C:\RECYCLER\NPROTECT\00001327.ini 72 bytes
C:\RECYCLER\NPROTECT\00001328.JS 8192 bytes
C:\RECYCLER\NPROTECT\00001329 40960 bytes
C:\RECYCLER\NPROTECT\00001330.GIF 128 bytes
C:\RECYCLER\NPROTECT\00001331.GIF 16384 bytes
C:\RECYCLER\NPROTECT\00001332.JPG 40960 bytes
C:\RECYCLER\NPROTECT\00001333.GIF 48 bytes
C:\RECYCLER\NPROTECT\00001334.JS 400 bytes
C:\RECYCLER\NPROTECT\00001335.JPG 24576 bytes
C:\RECYCLER\NPROTECT\00001336.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001337.HTM 168 bytes
C:\RECYCLER\NPROTECT\00001338.JS 4096 bytes
C:\RECYCLER\NPROTECT\00001339.GIF 48 bytes
C:\RECYCLER\NPROTECT\00001340 8 bytes
C:\RECYCLER\NPROTECT\00001341 8 bytes
C:\RECYCLER\NPROTECT\00001342.SWF 12288 bytes
C:\RECYCLER\NPROTECT\00001343.JS 16384 bytes
C:\RECYCLER\NPROTECT\00001344.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001345.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001346.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001347.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001348.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001349.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001350.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001351.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001352.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001353.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001354.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001355.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001356.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001357.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001358.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001359.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001360.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001361.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001362.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001363.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001364.GIF 24576 bytes
C:\RECYCLER\NPROTECT\00001365.JS 88 bytes
C:\RECYCLER\NPROTECT\00001366.JS 4096 bytes
C:\RECYCLER\NPROTECT\00001367.GIF 24576 bytes
C:\RECYCLER\NPROTECT\00001368.CSS 12288 bytes
C:\RECYCLER\NPROTECT\00001369.GIF 176 bytes
C:\RECYCLER\NPROTECT\00001370.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001371.GIF 8192 bytes
C:\RECYCLER\NPROTECT\00001372.PHP 24576 bytes
C:\RECYCLER\NPROTECT\00001373.PHP 20480 bytes
C:\RECYCLER\NPROTECT\00001374.PHP 40960 bytes
C:\RECYCLER\NPROTECT\00001375.PHP 20480 bytes
C:\RECYCLER\NPROTECT\00001376.JPG 20480 bytes
C:\RECYCLER\NPROTECT\00001377.HTM 368 bytes
C:\RECYCLER\NPROTECT\00001378.MED 416 bytes
C:\RECYCLER\NPROTECT\00001379.HTM 368 bytes
C:\RECYCLER\NPROTECT\00001380.MED 4096 bytes
C:\RECYCLER\NPROTECT\00001381.HTM 360 bytes
C:\RECYCLER\NPROTECT\00001382.GIF 56 bytes
C:\RECYCLER\NPROTECT\00001383.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001384.JPG 8192 bytes
C:\RECYCLER\NPROTECT\00001385.FLV 507904 bytes
C:\RECYCLER\NPROTECT\00001386.JS 4096 bytes
C:\RECYCLER\NPROTECT\00001387.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001388.GIF 8192 bytes
C:\RECYCLER\NPROTECT\00001389.GIF 48 bytes
C:\RECYCLER\NPROTECT\00001390.GIF 48 bytes
C:\RECYCLER\NPROTECT\00001391.GIF 48 bytes
C:\RECYCLER\NPROTECT\00001392.GIF 48 bytes
C:\RECYCLER\NPROTECT\00001393.GIF 48 bytes
C:\RECYCLER\NPROTECT\00001394.GIF 48 bytes
C:\RECYCLER\NPROTECT\00001395.GIF 48 bytes
C:\RECYCLER\NPROTECT\00001396.GIF 48 bytes
C:\RECYCLER\NPROTECT\00001397.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001398.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001399.JPG 16384 bytes
C:\RECYCLER\NPROTECT\00001400.JPG 12288 bytes
C:\RECYCLER\NPROTECT\00001401.CSS 8192 bytes
C:\RECYCLER\NPROTECT\00001402 408 bytes
C:\RECYCLER\NPROTECT\00001403.GIF 8192 bytes
C:\RECYCLER\NPROTECT\00001404.GIF 53248 bytes
C:\RECYCLER\NPROTECT\00001405.GIF 16384 bytes
C:\RECYCLER\NPROTECT\00001406 72 bytes
C:\RECYCLER\NPROTECT\00001407 80 bytes
C:\RECYCLER\NPROTECT\00001408.JS 12288 bytes
C:\RECYCLER\NPROTECT\00001409.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001410.JPG 8192 bytes
C:\RECYCLER\NPROTECT\00001411 4096 bytes
C:\RECYCLER\NPROTECT\00001412 4096 bytes
C:\RECYCLER\NPROTECT\00001413 4096 bytes
C:\RECYCLER\NPROTECT\00001414 4096 bytes
C:\RECYCLER\NPROTECT\00001415 608 bytes
C:\RECYCLER\NPROTECT\00001416 4096 bytes
C:\RECYCLER\NPROTECT\00001417 4096 bytes
C:\RECYCLER\NPROTECT\00001418 608 bytes
C:\RECYCLER\NPROTECT\00001419 4096 bytes
C:\RECYCLER\NPROTECT\00001420 4096 bytes
C:\RECYCLER\NPROTECT\00001421 608 bytes
C:\RECYCLER\NPROTECT\00001422.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001423 608 bytes
C:\RECYCLER\NPROTECT\00001424 4096 bytes
C:\RECYCLER\NPROTECT\00001425 4096 bytes
C:\RECYCLER\NPROTECT\00001426 4096 bytes
C:\RECYCLER\NPROTECT\00001427 608 bytes
C:\RECYCLER\NPROTECT\00001428 608 bytes
C:\RECYCLER\NPROTECT\00001429 608 bytes
C:\RECYCLER\NPROTECT\00001430 4096 bytes
C:\RECYCLER\NPROTECT\00001431 608 bytes
C:\RECYCLER\NPROTECT\00001432 608 bytes
C:\RECYCLER\NPROTECT\00001433 608 bytes
C:\RECYCLER\NPROTECT\00001434.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001435 4096 bytes
C:\RECYCLER\NPROTECT\00001436 616 bytes
C:\RECYCLER\NPROTECT\00001437 16 bytes
C:\RECYCLER\NPROTECT\00001438 616 bytes
C:\RECYCLER\NPROTECT\00001439 616 bytes
C:\RECYCLER\NPROTECT\00001440 616 bytes
C:\RECYCLER\NPROTECT\00001441 4096 bytes
C:\RECYCLER\NPROTECT\00001442 4096 bytes
C:\RECYCLER\NPROTECT\00001443 4096 bytes
C:\RECYCLER\NPROTECT\00001444 608 bytes
C:\RECYCLER\NPROTECT\00001445 4096 bytes
C:\RECYCLER\NPROTECT\00001446.PHP 8192 bytes
C:\RECYCLER\NPROTECT\00001447.PHP 8192 bytes
C:\RECYCLER\NPROTECT\00001448.JS 4096 bytes
C:\RECYCLER\NPROTECT\00001449.JS 4096 bytes
C:\RECYCLER\NPROTECT\00001450.CSS 4096 bytes
C:\RECYCLER\NPROTECT\00001451.JS 24576 bytes
C:\RECYCLER\NPROTECT\00001452.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001453.GIF 504 bytes
C:\RECYCLER\NPROTECT\00001454.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001455 45056 bytes
C:\RECYCLER\NPROTECT\00001456.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001457.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001458.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001459.GIF 8192 bytes
C:\RECYCLER\NPROTECT\00001460.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001461.JPG 12288 bytes
C:\RECYCLER\NPROTECT\00001462.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001463.JS 16384 bytes
C:\RECYCLER\NPROTECT\00001464.CSS 8192 bytes
C:\RECYCLER\NPROTECT\00001465.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001466.GIF 12288 bytes
C:\RECYCLER\NPROTECT\00001467.GIF 12288 bytes
C:\RECYCLER\NPROTECT\00001468.JPG 8192 bytes
C:\RECYCLER\NPROTECT\00001469.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001470.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001471.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001472.GIF 16384 bytes
C:\RECYCLER\NPROTECT\00001473.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001474.GIF 56 bytes
C:\RECYCLER\NPROTECT\00001475.JPG 304 bytes
C:\RECYCLER\NPROTECT\00001476.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001477.FLV 2289664 bytes
C:\RECYCLER\NPROTECT\00001478.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001479.CFM 80 bytes
C:\RECYCLER\NPROTECT\00001480.HTM 56 bytes
C:\RECYCLER\NPROTECT\00001481.CFM 80 bytes
C:\RECYCLER\NPROTECT\00001482.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001483.SWF 98304 bytes
C:\RECYCLER\NPROTECT\00001484 8 bytes
C:\RECYCLER\NPROTECT\00001485.GIF 48 bytes
C:\RECYCLER\NPROTECT\00001486.JPG 24576 bytes
C:\RECYCLER\NPROTECT\00001487.FLV 1880064 bytes
C:\RECYCLER\NPROTECT\00001488.GIF 192 bytes
C:\RECYCLER\NPROTECT\00001489.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001490.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001491.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001492.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001493.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001494.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001495.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001496.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001497.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001498.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001499.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001500.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001501.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001502.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001503.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001504.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001505.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001506.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001507.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001508.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001509.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001510.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001511.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001512.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001513.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001514.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001515.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001516.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001517.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001518.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001519.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001520.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001521.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001522.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001523.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001524.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001525.CSS 12288 bytes
C:\RECYCLER\NPROTECT\00001526 4096 bytes
C:\RECYCLER\NPROTECT\00001527 8192 bytes
C:\RECYCLER\NPROTECT\00001528.PHP 20480 bytes
C:\RECYCLER\NPROTECT\00001529.PHP 24576 bytes
C:\RECYCLER\NPROTECT\00001530.PHP 20480 bytes
C:\RECYCLER\NPROTECT\00001531.PHP 20480 bytes
C:\RECYCLER\NPROTECT\00001532.PNG 4096 bytes
C:\RECYCLER\NPROTECT\00001533.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001534.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001535.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001536.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001537.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001538.GIF 136 bytes
C:\RECYCLER\NPROTECT\00001539.GIF 568 bytes
C:\RECYCLER\NPROTECT\00001540.HTM 16384 bytes
C:\RECYCLER\NPROTECT\00001541.HTM 16384 bytes
C:\RECYCLER\NPROTECT\00001542.GIF 368 bytes
C:\RECYCLER\NPROTECT\00001543.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001544.JS 12288 bytes
C:\RECYCLER\NPROTECT\00001545.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001546.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001547.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001548.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001549.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001550.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001551.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001552.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001553.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001554.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001555.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001556.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001557.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001558.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001559.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001560.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001561.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001562.JSP 424 bytes
C:\RECYCLER\NPROTECT\00001563 131072 bytes
C:\RECYCLER\NPROTECT\00001564.GIF 216 bytes
C:\RECYCLER\NPROTECT\00001565.GIF 528 bytes
C:\RECYCLER\NPROTECT\00001566.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001567.PNG 4096 bytes
C:\RECYCLER\NPROTECT\00001568.AXD 12288 bytes
C:\RECYCLER\NPROTECT\00001569.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001570.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001571.GIF 192 bytes
C:\RECYCLER\NPROTECT\00001572 20480 bytes
C:\RECYCLER\NPROTECT\00001573.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001574.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001575.PNG 4096 bytes
C:\RECYCLER\NPROTECT\00001576.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001577.GIF 48 bytes
C:\RECYCLER\NPROTECT\00001578.GIF 64 bytes
C:\RECYCLER\NPROTECT\00001579.JPG 12288 bytes
C:\RECYCLER\NPROTECT\00001580.PNG 4096 bytes
C:\RECYCLER\NPROTECT\00001581.PNG 4096 bytes
C:\RECYCLER\NPROTECT\00001582.GIF 48 bytes
C:\RECYCLER\NPROTECT\00001583.GIF 272 bytes
C:\RECYCLER\NPROTECT\00001584.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001585.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001586 8192 bytes
C:\RECYCLER\NPROTECT\00001587 8192 bytes
C:\RECYCLER\NPROTECT\00001588.GIF 112 bytes
C:\RECYCLER\NPROTECT\00001589.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001590.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001591.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001592.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001593.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001594.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001595.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001596.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001597.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001598.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001599.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001600.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001601.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001602.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001603.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001604.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001605.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001606.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001607.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001608.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001609.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001610.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001611.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001612.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001613.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001614.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001615.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001616.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001617.JPG 45056 bytes
C:\RECYCLER\NPROTECT\00001618.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001619.GIF 312 bytes
C:\RECYCLER\NPROTECT\00001620.GIF 64 bytes
C:\RECYCLER\NPROTECT\00001621.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001622.PNG 8192 bytes
C:\RECYCLER\NPROTECT\00001623.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001624.SWF 77824 bytes
C:\RECYCLER\NPROTECT\00001625.JS 49152 bytes
C:\RECYCLER\NPROTECT\00001626 8192 bytes
C:\RECYCLER\NPROTECT\00001627 8192 bytes
C:\RECYCLER\NPROTECT\00001628 8192 bytes
C:\RECYCLER\NPROTECT\00001629 8192 bytes
C:\RECYCLER\NPROTECT\00001630 8192 bytes
C:\RECYCLER\NPROTECT\00001631 8192 bytes
C:\RECYCLER\NPROTECT\00001632 8192 bytes
C:\RECYCLER\NPROTECT\00001633 8192 bytes
C:\RECYCLER\NPROTECT\00001634 8192 bytes
C:\RECYCLER\NPROTECT\00001635 8192 bytes
C:\RECYCLER\NPROTECT\00001636.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001637.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001638.HTM 184 bytes
C:\RECYCLER\NPROTECT\00001639.JS 4096 bytes
C:\RECYCLER\NPROTECT\00001640.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001641.CSS 20480 bytes
C:\RECYCLER\NPROTECT\00001642.JS 4096 bytes
C:\RECYCLER\NPROTECT\00001643.XML 16384 bytes
C:\RECYCLER\NPROTECT\00001644.XML 16384 bytes
C:\RECYCLER\NPROTECT\00001645.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001646.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001647.GIF 144 bytes
C:\RECYCLER\NPROTECT\00001648.AXD 24576 bytes
C:\RECYCLER\NPROTECT\00001649.JPG 45056 bytes
C:\RECYCLER\NPROTECT\00001650.CSS 8192 bytes
C:\RECYCLER\NPROTECT\00001651.PNG 4096 bytes
C:\RECYCLER\NPROTECT\00001652.GIF 88 bytes
C:\RECYCLER\NPROTECT\00001653.HTM 280 bytes
C:\RECYCLER\NPROTECT\00001654.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001655.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001656.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001657.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001658.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001659.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001660.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001661.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001662.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001663.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001664.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001665.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001666.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001667.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001668.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001669.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001670.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001671.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001672.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001673.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001674.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001675.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001676.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001677.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001678.JS 104 bytes
C:\RECYCLER\NPROTECT\00001679.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001680.SWF 32768 bytes
C:\RECYCLER\NPROTECT\00001681.ini 72 bytes
C:\RECYCLER\NPROTECT\00001682.CSS 16384 bytes
C:\RECYCLER\NPROTECT\00001683.JPG 8192 bytes
C:\RECYCLER\NPROTECT\00001684.JPG 16384 bytes
C:\RECYCLER\NPROTECT\00001685.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001686 24 bytes
C:\RECYCLER\NPROTECT\00001687.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001688.JPG 8192 bytes
C:\RECYCLER\NPROTECT\00001689.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001690 24 bytes
C:\RECYCLER\NPROTECT\00001691.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001692.GIF 56 bytes
C:\RECYCLER\NPROTECT\00001693.HTM 28672 bytes
C:\RECYCLER\NPROTECT\00001694.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001695.JPG 16384 bytes
C:\RECYCLER\NPROTECT\00001696 24 bytes
C:\RECYCLER\NPROTECT\00001697.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001698.GIF 12288 bytes
C:\RECYCLER\NPROTECT\00001699.JPG 24576 bytes
C:\RECYCLER\NPROTECT\00001700.JPG 8192 bytes
C:\RECYCLER\NPROTECT\00001701.JPG 8192 bytes
C:\RECYCLER\NPROTECT\00001702.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001703.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001704.FLV 4661248 bytes
C:\RECYCLER\NPROTECT\00001705.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001706.SWF 32768 bytes
C:\RECYCLER\NPROTECT\00001707.PNG 4096 bytes
C:\RECYCLER\NPROTECT\00001708.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001709.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001710 4096 bytes
C:\RECYCLER\NPROTECT\00001711 4096 bytes
C:\RECYCLER\NPROTECT\00001712 4096 bytes
C:\RECYCLER\NPROTECT\00001713 16 bytes
C:\RECYCLER\NPROTECT\00001714 16 bytes
C:\RECYCLER\NPROTECT\00001715 16 bytes
C:\RECYCLER\NPROTECT\00001716 4096 bytes
C:\RECYCLER\NPROTECT\00001717 4096 bytes
C:\RECYCLER\NPROTECT\00001718 4096 bytes
C:\RECYCLER\NPROTECT\00001719 16 bytes
C:\RECYCLER\NPROTECT\00001720 4096 bytes
C:\RECYCLER\NPROTECT\00001721 4096 bytes
C:\RECYCLER\NPROTECT\00001722 4096 bytes
C:\RECYCLER\NPROTECT\00001723 4096 bytes
C:\RECYCLER\NPROTECT\00001724 4096 bytes
C:\RECYCLER\NPROTECT\00001725 16 bytes
C:\RECYCLER\NPROTECT\00001726 16 bytes
C:\RECYCLER\NPROTECT\00001727.SWF 24576 bytes
C:\RECYCLER\NPROTECT\00001728.GIF 8192 bytes
C:\RECYCLER\NPROTECT\00001729.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001730.FLV 3502080 bytes
C:\RECYCLER\NPROTECT\00001731.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001732.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001733.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001734 24 bytes
C:\RECYCLER\NPROTECT\00001735.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001736.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001737.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001738.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001739.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001740.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001741.GIF 4096 bytes
C:\RECYCLER\NPROTECT\00001742 4096 bytes
C:\RECYCLER\NPROTECT\00001743 20480 bytes
C:\RECYCLER\NPROTECT\00001744.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001745.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001746.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001747.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001748.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001749.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001750.06 16 bytes
C:\RECYCLER\NPROTECT\00001751.02 4096 bytes
C:\RECYCLER\NPROTECT\00001752 464 bytes
C:\RECYCLER\NPROTECT\00001753 184 bytes
C:\RECYCLER\NPROTECT\00001754 184 bytes
C:\RECYCLER\NPROTECT\00001755 456 bytes
C:\RECYCLER\NPROTECT\00001756 456 bytes
C:\RECYCLER\NPROTECT\00001757 456 bytes
C:\RECYCLER\NPROTECT\00001758 448 bytes
C:\RECYCLER\NPROTECT\00001759 448 bytes
C:\RECYCLER\NPROTECT\00001760 448 bytes
C:\RECYCLER\NPROTECT\00001761 448 bytes
C:\RECYCLER\NPROTECT\00001762 456 bytes
C:\RECYCLER\NPROTECT\00001763 448 bytes
C:\RECYCLER\NPROTECT\00001764 456 bytes
C:\RECYCLER\NPROTECT\00001765 456 bytes
C:\RECYCLER\NPROTECT\00001766.HTM 176 bytes
C:\RECYCLER\NPROTECT\00001767.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001768 304 bytes
C:\RECYCLER\NPROTECT\00001769 480 bytes
C:\RECYCLER\NPROTECT\00001770 480 bytes
C:\RECYCLER\NPROTECT\00001771 480 bytes
C:\RECYCLER\NPROTECT\00001772 480 bytes
C:\RECYCLER\NPROTECT\00001773 480 bytes
C:\RECYCLER\NPROTECT\00001774 480 bytes
C:\RECYCLER\NPROTECT\00001775 480 bytes
C:\RECYCLER\NPROTECT\00001776 480 bytes
C:\RECYCLER\NPROTECT\00001777 480 bytes
C:\RECYCLER\NPROTECT\00001778 480 bytes
C:\RECYCLER\NPROTECT\00001779 480 bytes
C:\RECYCLER\NPROTECT\00001780 480 bytes
C:\RECYCLER\NPROTECT\00001781 480 bytes
C:\RECYCLER\NPROTECT\00001782 536 bytes
C:\RECYCLER\NPROTECT\00001783 472 bytes
C:\RECYCLER\NPROTECT\00001784 480 bytes
C:\RECYCLER\NPROTECT\00001785 480 bytes
C:\RECYCLER\NPROTECT\00001786 480 bytes
C:\RECYCLER\NPROTECT\00001787 4096 bytes
C:\RECYCLER\NPROTECT\00001788.GIF 48 bytes
C:\RECYCLER\NPROTECT\00001789.GIF 48 bytes
C:\RECYCLER\NPROTECT\00001790.GIF 48 bytes
C:\RECYCLER\NPROTECT\00001791.GIF 48 bytes
C:\RECYCLER\NPROTECT\00001792.HTM 296 bytes
C:\RECYCLER\NPROTECT\00001793.AAV 128 bytes
C:\RECYCLER\NPROTECT\00001794.HTM 184 bytes
C:\RECYCLER\NPROTECT\00001795.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001796.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001797.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001798.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001799.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001800.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001801.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001802.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001803.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001804.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001805 4096 bytes
C:\RECYCLER\NPROTECT\00001806.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001807.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001808.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001809.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001810.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001811.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001812.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001813.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001814.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001815.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001816.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001817 496 bytes
C:\RECYCLER\NPROTECT\00001818.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001819.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001820.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001821.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001822.HTM 12288 bytes
C:\RECYCLER\NPROTECT\00001823.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001824.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001825.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001826.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001827.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001828.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001829.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001830.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001831.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001832.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001833.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001834.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001835.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001836.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001837.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001838.HTM 8192 bytes
C:\RECYCLER\NPROTECT\00001839.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001840.JS 8192 bytes
C:\RECYCLER\NPROTECT\00001841.GIF 72 bytes
C:\RECYCLER\NPROTECT\00001842.JPG 4096 bytes
C:\RECYCLER\NPROTECT\00001843.JSP 61440 bytes
C:\RECYCLER\NPROTECT\00001844.GIF 128 bytes
C:\RECYCLER\NPROTECT\00001845.DO 128 bytes
C:\RECYCLER\NPROTECT\00001846.JPG 8192 bytes
C:\RECYCLER\NPROTECT\00001847.CSS 4096 bytes
C:\RECYCLER\NPROTECT\00001848.GIF 8192 bytes
C:\RECYCLER\NPROTECT\00001849.JPG 8192 bytes
C:\RECYCLER\NPROTECT\00001850.GIF 328 bytes
C:\RECYCLER\NPROTECT\00001851.GIF 224 bytes
C:\RECYCLER\NPROTECT\00001852.GIF 8192 bytes
C:\RECYCLER\NPROTECT\00001853.GIF 160 bytes
C:\RECYCLER\NPROTECT\00001854.PNG 4096 bytes
C:\RECYCLER\NPROTECT\00001855.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001856.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001857.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001858.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001859.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001860.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001861.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001862.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001863.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001864.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001865.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001866.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001867.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001868.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001869.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001870.HTM 4096 bytes
C:\RECYCLER\NPROTECT\00001871.CFM 4096 b
CID

"There is power in numbers."

#12 CID1

CID1
  • Topic Starter

  • Members
  • 32 posts
  • OFFLINE
  •  
  • Local time:04:27 PM

Posted 26 March 2007 - 05:31 AM

Hello OT,

Well that was the ComboFix log. Thanks for the link.

Note: After the scan was done, Spybot caught a multiple of attempts to change the registry. Not knowing what they were I denied them all. I don't believe it was related to ComboFix, just a coninsedence. However, if ComboFix is suposed to make changes to the registry I have to know which to approve.

Anyway, I'll check back regularly for any updates. As I said before, I will make myself available if there is a regular time that you are here, you just need inform.

Thank you, talk to you soon OT.
CID

"There is power in numbers."

#13 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:07:27 PM

Posted 26 March 2007 - 04:31 PM

Hi CID1. It looks like we have a few things going on here. Please print these directions so you have them available. We will be booting to Safe mode during this process and the internet will not be accessible. As far as Spybot goes, if you are running the TeaTimer program that is part of Spybot you should disable it when running any scanning programs that are removing malware. TeaTimer will block any attempts to cleanup the issues so it is best to not have it running.

Next, perform the following steps in order:

Step #1

Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Turn your computer back on.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.

Step #2

Download SDFix and save it to your desktop.

Now reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.
  • In Safe Mode, right click the SDFix.zip folder and choose Extract All.
  • Open the extracted folder and double click RunThis.bat to start the script.
  • Type Y to begin the script.
  • It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • Your system will take longer that normal to restart as the fixtool will be running and removing files.
  • When the desktop loads the Fixtool will complete the removal and display Finished, then press any key to end the script and load your desktop icons.
Step #3

Next, download AVG anti-spyware from HERE and save that file to your desktop.
  • Once you have downloaded AVG Anti-Spyware, locate the icon on the desktop and double-click it to launch the set up program.
  • Once the setup is complete you will need to run AVG Anti-Spyware and update the definition files.
  • On the main screen select the icon "Update" then select the "Update now" link.
    • Next select the "Start Update" button, the update will start and a progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
  • Once in the Settings screen, under "How to act" select "Quarantine".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
Close AVG Anti-Spyware, Do Not run a scan just yet, we will shortly.
  • Reboot your computer into SafeMode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight SafeMode then hit enter.
    IMPORTANT: Do not open any other windows or programs while AVG Anti-Spyware is scanning, it may interfere with the scanning proccess:
  • Launch AVG Anti-Spyware by double-clicking the icon on your desktop.
  • Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
  • AVG Anti-Spyware will now begin the scanning process, be patient this may take a little time.
    Once the scan is complete do the following:
    • IMake sure that Set all elements to: shows Quarantine, if not click on the link and choose Quarantine from the popup menu.
    • At the bottom of the window click on the "Apply all actions" button
    Note: Don't save the report before you hit the Apply action button.
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the screen and save it to a text file on your system (make sure to remember where you saved that file, this is important).
  • Close AVG Anti-Spyware and reboot your system back into Normal Mode.
Step #4

Post the following back here:
  • Log from Vundofix (C:\Vundofix.txt)
  • Log from SDFix (Report.txt, present in the SDFix-folder)
  • Log from AVG Antispyware you saved previously
  • Try running WinPFind3u again and post that log.
Cheers.

OT
I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image

#14 CID1

CID1
  • Topic Starter

  • Members
  • 32 posts
  • OFFLINE
  •  
  • Local time:04:27 PM

Posted 26 March 2007 - 05:18 PM

Good aftrenoon (or evening I guess where you're at) OT.

I am commencing your instructions now. I will report back immediately after I have finished. Talk to you then.
CID

"There is power in numbers."

#15 OldTimer

OldTimer

    Malware Expert


  • Members
  • 11,092 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:North Carolina
  • Local time:07:27 PM

Posted 26 March 2007 - 07:32 PM

Hi CID1. I will be around for a little while yet tonight. If you are still having a problem running WinPFind3u there is a new verison available. I found a bug that I was able to reproduce that was causing it to hang on some systems. I have fixed it and that problem should not occur now.

Delete the current copy that you have and download the latest version here. Then try the scan again. Also, you must be logged on with an account that has Administrator privileges.

Cheers.

OT

Edited by OldTimer, 26 March 2007 - 07:33 PM.

I do not respond to PM's requesting help. That's what the forums are here for. Please use them so that others may benefit from your questions and the responses you receive.
OldTimer

Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users