Another trojan.zlob.g

View previous topic View next topic Go down

Solved Another trojan.zlob.g

Post by MarcusMarcus on Tue Dec 09, 2008 6:01 pm

Hey i also experience trouble with trojan.zlob.g. I tried to remove it with my "Spyware Doctor" but it doesnt seem to have worked. A window pops up for me with headline
"Security Center Alert"
stating "To help protect your computer, Windows Forewall has blocked activity of harmful software."
and further "Do you want to block this suspicious software?
Name: Trojan.Zlob.G
Risk Level: High
Description Trojan.Zlob.G is a trojan program that records keystrokes and takes screen shots of the computer, stealing personal financial information"
With a pressable button that says "Enable protection"

This is my log from Hijackthis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:54:06, on 2008-12-09
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program\D-Tools\daemon.exe
C:\Program\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program\iTunes\iTunesHelper.exe
C:\WINDOWS\vVX1000.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program\Windows Live\Messenger\MsnMsgr.Exe
C:\Program\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program\Nokia\Nokia PC Suite 7\PCSync2.exe
C:\Program\Logitech\MouseWare\system\em_exec.exe
C:\Program\Delade filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\CTSvcCDA.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program\PC Connectivity Solution\ServiceLayer.exe
C:\Program\iPod\bin\iPodService.exe
C:\WINDOWS\System32\alg.exe
C:\Program\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program\Delade filer\Nokia\MPAPI\MPAPI3s.exe
C:\Program\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program\Mozilla Firefox\firefox.exe
C:\Program\Spyware Doctor\pctsAuxs.exe
C:\Program\Spyware Doctor\pctsSvc.exe
C:\Program\Spyware Doctor\pctsTray.exe
C:\Program\Spyware Doctor\pctsGui.exe
C:\Documents and Settings\Marcus\Skrivbord\Hijack(GP)This.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [You must be registered and logged in to see this link.]
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [You must be registered and logged in to see this link.]
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live inloggningshjälpen - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program\Delade filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program\google\googletoolbar2.dll
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKLM\..\Run: [Media Codec Update Service] C:\Program\Essentials Codec Pack\update.exe -silent
O4 - HKLM\..\Run: [ISTray] "C:\Program\Spyware Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [Nokia.PCSync] "C:\Program\Nokia\Nokia PC Suite 7\PCSync2.exe" /NoDialog
O4 - HKCU\..\Run: [AntispywareBot] C:\Program\AntispywareBot\AntispywareBot.exe -boot
O4 - HKCU\..\Run: [AntispywareBot] C:\Program\AntispywareBot\AntispywareBot.exe -boot
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKAL TJÄNST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nsu_ui_client.exe] C:\Program\Nokia\Nokia Software Updater\nsu_ui_client.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nsu_ui_client.exe] C:\Program\Nokia\Nokia Software Updater\nsu_ui_client.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\Program\SPYWAR~2\tools\iesdpb.dll (file missing)
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - [You must be registered and logged in to see this link.]
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - [You must be registered and logged in to see this link.]
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - [You must be registered and logged in to see this link.]
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - [You must be registered and logged in to see this link.]
O16 - DPF: {C81B5180-AFD1-41A3-97E1-99E8D254DB98} - [You must be registered and logged in to see this link.]
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program\DELADE~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program\Delade filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTSvcCDA.EXE
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program\Delade filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program\Spyware Doctor\pctsSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program\Webroot\Spy Sweeper\WRSSSDK.exe

--
End of file - 9053 bytes


Thanks for any help you can offer.
M

MarcusMarcus
Beginner
Beginner

Posts Posts : 4
Joined Joined : 2008-12-09
OS OS : Windows XP home edition
Points Points : 29180
# Likes # Likes : 0

View user profile

Back to top Go down

Solved Re: Another trojan.zlob.g

Post by Belahzur on Tue Dec 09, 2008 6:09 pm

Hello.


  • Download combofix from here, use the top links - [You must be registered and logged in to see this link.]
  • Double click on ComboFix.exe.
  • Follow the prompts. NOTE:
  • ComboFix will check to see if the Microsoft Windows Recovery Console is installed.
    ***It's strongly recommended to have the Recovery Console installed before doing any malware removal.***

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will automatically proceed with its scan.


  • The Recovery Console provides a recovery/repair mode should a problem occur during a Combofix run.



  • Allow ComboFix to download the Recovery Console.
  • Accept the End-User License Agreement.
  • The Recovery Console will be installed.
  • You will this next prompt that asks if you want to continue the malware scan, select yes



  • Allow combofix to run
  • Post C:\combofix.txt back here.

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245059
# Likes # Likes : 1

View user profile

Back to top Go down

Solved Re: Another trojan.zlob.g

Post by MarcusMarcus on Tue Dec 09, 2008 7:05 pm

ComboFix 08-12-07.04 - Marcus 2008-12-09 19:50:03.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1053.18.498 [GMT 1:00]
Körs från: c:\documents and settings\Marcus\Skrivbord\ComboFix.exe
* Skapade en ny återställningspunkt
.

((((((((((((((((((((((((((((((((((((((( Andra raderingar ))))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Skrivbord\AntiSpywareBot.lnk
c:\documents and settings\All Users\Start-meny\Program\AntiSpywareBot
c:\documents and settings\All Users\Start-meny\Program\AntiSpywareBot\AntispywareBot on the Web.lnk
c:\documents and settings\All Users\Start-meny\Program\AntiSpywareBot\AntispywareBot.lnk
c:\documents and settings\Marcus\Application Data\AntispywareBot
c:\documents and settings\Marcus\Application Data\AntispywareBot\Log\2008 Dec 09 - 02_06_14 AM_546.log
c:\documents and settings\Marcus\Application Data\AntispywareBot\Log\2008 Dec 09 - 03_00_06 AM_343.log
c:\documents and settings\Marcus\Application Data\AntispywareBot\Log\2008 Dec 09 - 03_00_07 AM_453.log
c:\documents and settings\Marcus\Application Data\AntispywareBot\Log\2008 Dec 09 - 09_48_06 AM_515.log
c:\documents and settings\Marcus\Application Data\AntispywareBot\Log\2008 Dec 09 - 11_50_39 AM_703.log
c:\documents and settings\Marcus\Application Data\AntispywareBot\rs.dat
c:\documents and settings\Marcus\Application Data\AntispywareBot\Settings\ScanResults.pie
c:\documents and settings\Marcus\Application Data\Google\kjzna1562565.exe
c:\documents and settings\Marcus\Application Data\Google\spcffwl.dll
c:\program\AntiSpywareBot
c:\program\AntiSpywareBot\AntispywareBot.exe
c:\program\AntiSpywareBot\AntispywareBot.url
c:\program\AntiSpywareBot\DataBase.ref
c:\program\AntiSpywareBot\SpyCleaner.dll
c:\program\AntiSpywareBot\TCL.dll
c:\program\AntiSpywareBot\vistaCPtasks.xml
c:\program\AntiSpywareBot\zlib.dll
c:\windows\Downloaded Program Files\setup.inf
c:\windows\system32\404Fix.exe
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
c:\windows\Tasks.\AntiSpywareBot Scheduled Scan.job

.
((((((((((((((((((((( Filer Skapade från 2008-11-09 till 2008-12-09 ))))))))))))))))))))))))))))))))))))
.

2008-12-22 05:59 . 2008-12-22 05:59 447,200 --a------ c:\windows\system32\OpenQuicktimeLib.dll
2008-12-22 05:59 . 2008-12-22 05:59 332,512 --a------ c:\windows\system32\3ivxVfWCodec.dll
2008-12-22 05:59 . 2008-12-22 05:59 25,312 --a------ c:\windows\system32\SamsungVfWCodec.dll
2008-12-22 05:59 . 2008-12-22 05:59 25,312 --a------ c:\windows\system32\DivXVfWCodec.dll
2008-12-22 05:58 . 2008-12-22 05:58 1,155,808 --a------ c:\windows\system32\3ivx.dll
2008-12-22 05:52 . 2008-12-22 05:52 66,272 --a------ c:\windows\system32\libfaac.dll
2008-12-09 04:42 . 2008-12-09 09:41 d-------- c:\documents and settings\Marcus\.housecall6.6
2008-12-02 18:20 . 2008-12-02 18:20 78,848 --a------ c:\windows\system32\drivers\SSHDRV85.sys
2008-12-02 17:58 . 2008-12-07 20:02 d-------- c:\program\Ascaron Entertainment
2008-12-01 18:37 . 2008-12-01 18:37 94,208 --a------ c:\windows\DIIUnin.exe
2008-12-01 18:37 . 2008-12-01 18:52 31,347 --a------ c:\windows\DIIUnin.dat
2008-12-01 18:37 . 2008-12-01 18:37 2,829 --a------ c:\windows\DIIUnin.pif
2008-12-01 18:15 . 2008-12-07 14:14 d-------- c:\program\Diablo II
2008-11-30 22:42 . 2008-11-30 22:42 d-------- c:\program\Essentials Codec Pack
2008-11-30 22:39 . 2008-11-30 22:39 d-------- c:\program\3ivx
2008-11-30 20:03 . 2008-11-30 21:04 139,264 --a------ c:\windows\War3Unin.exe
2008-11-30 20:03 . 2008-11-30 21:09 70,097 --a------ c:\windows\War3Unin.dat
2008-11-30 20:03 . 2008-11-30 21:04 2,829 --a------ c:\windows\War3Unin.pif
2008-11-30 20:00 . 2008-12-08 23:35 d-------- c:\program\Warcraft III
2008-11-30 19:28 . 2008-11-30 19:28 d-------- c:\program\Quake III Arena
2008-11-30 19:27 . 2008-11-30 19:28 821 --a------ c:\windows\QIII.INI
2008-11-26 02:18 . 2008-11-26 02:39 d-------- c:\documents and settings\Marcus\Application Data\mIRC
2008-11-21 07:26 . 2008-11-21 07:26 d-------- c:\program\Delade filer\Skype
2008-11-21 07:26 . 2008-12-09 11:50 d-------- c:\documents and settings\Marcus\Application Data\skypePM
2008-11-21 07:26 . 2008-11-21 07:26 56 --ah----- c:\windows\system32\ezsidmv.dat
2008-11-12 10:52 . 2008-09-04 18:17 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2008-11-12 10:36 . 2008-10-24 12:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-09 17:23 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-12-09 17:13 --------- d-----w c:\program\Spyware Doctor
2008-12-09 11:11 --------- d-----w c:\documents and settings\Marcus\Application Data\Skype
2008-12-09 08:45 --------- d-----w c:\program\Google
2008-12-05 22:38 --------- d-----w c:\documents and settings\Marcus\Application Data\OpenOffice.org2
2008-12-01 17:51 21,840 ----atw c:\windows\system32\SIntfNT.dll
2008-12-01 17:51 17,212 ----atw c:\windows\system32\SIntf32.dll
2008-12-01 17:51 12,067 ----atw c:\windows\system32\SIntf16.dll
2008-11-13 14:12 --------- d-----w c:\program\Switch Off
2008-11-11 15:20 --------- d-----w c:\program\Windows Media Connect 2
2008-11-11 15:14 --------- d-----w c:\program\DOSBox-0.71
2008-11-04 19:19 --------- d-----w c:\program\Nokia
2008-11-04 19:19 --------- d-----w c:\program\Delade filer\PCSuite
2008-11-04 19:19 --------- d-----w c:\program\Delade filer\Nokia
2008-11-04 19:17 --------- d-----w c:\documents and settings\All Users\Application Data\Installations
2008-11-04 19:13 --------- d-----w c:\documents and settings\All Users\Application Data\Nokia
2008-11-04 18:43 --------- d-----w c:\program\MSXML 6.0
2008-11-04 18:40 --------- d-----w c:\documents and settings\Marcus\Application Data\PC Suite
2008-11-04 18:39 0 ---ha-w c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-11-04 18:39 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2008-11-04 18:39 --------- d-----w c:\documents and settings\All Users\Application Data\PC Suite
2008-11-04 18:36 --------- d-----w c:\documents and settings\Marcus\Application Data\Nokia
2008-11-04 18:33 --------- d-----w c:\program\PC Connectivity Solution
2008-11-04 18:33 --------- d-----w c:\program\DIFX
2008-10-29 19:15 30 ----a-w c:\documents and settings\Marcus\jagex_runescape_preferences.dat
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 13:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-13 06:29 --------- d-----w c:\program\MSECache
2008-10-12 10:40 --------- d-----w c:\program\NOS
2008-10-12 10:40 --------- d-----w c:\documents and settings\All Users\Application Data\NOS
2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-09-15 15:27 1,846,400 ----a-w c:\windows\system32\win32k.sys
2008-09-10 01:16 1,307,648 ------w c:\windows\system32\msxml6.dll
.

(((((((((((((((((((((((((((((((((((( Startpunkter i registret )))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Not* tomma poster & legitima standardposter visas inte
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MsnMsgr"="c:\program\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"Skype"="c:\program\Skype\Phone\Skype.exe" [2008-11-07 21633320]
"PC Suite Tray"="c:\program\Nokia\Nokia PC Suite 7\PCSuite.exe" [2008-10-02 1124352]
"Nokia.PCSync"="c:\program\Nokia\Nokia PC Suite 7\PCSync2.exe" [2008-06-17 1249280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"DAEMON Tools-1033"="c:\program\D-Tools\daemon.exe" [2002-09-24 73728]
"Adobe Photo Downloader"="c:\program\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-07-07 57344]
"SunJavaUpdateSched"="c:\program\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-30 7630848]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-08-30 86016]
"QuickTime Task"="c:\program\QuickTime\qttask.exe" [2007-06-29 286720]
"iTunesHelper"="c:\program\iTunes\iTunesHelper.exe" [2007-07-31 271672]
"VX1000"="c:\windows\vVX1000.exe" [2006-12-06 707360]
"Media Codec Update Service"="c:\program\Essentials Codec Pack\update.exe" [2007-04-08 303104]
"ISTray"="c:\program\Spyware Doctor\pctsTray.exe" [2008-08-25 1168264]
"CTHelper"="CTHELPER.EXE" [2003-10-06 c:\windows\system32\CTHELPER.EXE]
"Logitech Utility"="Logi_MwX.Exe" [2003-12-17 c:\windows\LOGI_MWX.EXE]
"nwiz"="nwiz.exe" [2006-08-30 c:\windows\system32\nwiz.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nsu_ui_client.exe"="c:\program\Nokia\Nokia Software Updater\nsu_ui_client.exe" [2008-09-14 1635576]

c:\documents and settings\All Users\Start-meny\Program\Autostart\
Adobe Reader Speed Launch.lnk - c:\program\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 29696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.3IV2"= 3ivxVfWCodec.dll
"vidc.SEDG"= SamsungVfWCodec.dll
"vidc.DX50"= DivXVfWCodec.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program\\Messenger\\msmsgs.exe"=
"c:\\Program\\GlobalSCAPE\\CuteFTP\\cutftp32.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program\\iTunes\\iTunes.exe"=
"c:\\Program\\Atari\\Neverwinter Nights 2\\nwn2main.exe"=
"c:\\Program\\Atari\\Neverwinter Nights 2\\nwn2main_amdxp.exe"=
"c:\\Program\\Atari\\Neverwinter Nights 2\\nwupdate.exe"=
"c:\\Program\\Atari\\Neverwinter Nights 2\\nwn2server.exe"=
"c:\\Program\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724

R0 SSI;SSI;c:\windows\system32\Drivers\SSI.SYS [2006-09-26 78336]
R0 St323dk;St323dk;c:\windows\system32\drivers\St323dk.sys [2002-10-13 88736]
R1 SSHDRV85;SSHDRV85;\??\c:\windows\system32\drivers\SSHDRV85.sys [2008-12-02 78848]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program\Spyware Doctor\pctsAuxs.exe [2008-12-09 356920]
S3 ASPI;Advanced SCSI Programming Interface Driver;\??\c:\windows\System32\DRIVERS\ASPI32.sys [2006-11-16 16512]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program\NOS\bin\getPlus_HelperSvc.exe [2008-10-12 33752]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{df3f86ca-9864-11dc-b7ee-0007e987e201}]
\Shell\AutoRun\command - G:\LaunchU3.exe -a

*Newly Created Service* - PROCEXP90
.
Innehållet i mappen 'Schemalagda aktiviteter'

2008-09-25 c:\windows\Tasks\Microsoft_Hardware_Launch_vVX1000_exe.job
- c:\windows\vVX1000.exe [2006-12-06 00:38]
.
- - - - FÖRÄLDRALÖSA POSTER SOM TAGITS BORT - - - -

HKCU-Run-Smax4 - c:\documents and settings\Marcus\Application Data\Google\kjzna1562565.exe
Notify-AtiExtEvent - (no file)


.
------- Extra genomsökning -------
.
uStart Page = [You must be registered and logged in to see this link.]
uSearchMigratedDefaultURL = [You must be registered and logged in to see this link.]

O16 -: DirectAnimation Java Classes - [You must be registered and logged in to see this link.]
c:\windows\Downloaded Program Files\DirectAnimation Java Classes.osd

O16 -: Microsoft XML Parser for Java - [You must be registered and logged in to see this link.]
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd

c:\windows\system32\msvcrt.dll - c:\windows\system32\mfc42.dll
c:\windows\system32\olepro32.dll
c:\windows\Downloaded Program Files\Housecall_ActiveX.dll
O16 -: {6E5A37BF-FD42-463A-877C-4EB7002E68AE}
[You must be registered and logged in to see this link.]
c:\windows\Downloaded Program Files\hcImpl.inf
FireFox -: Profile - c:\documents and settings\Marcus\Application Data\Mozilla\Firefox\Profiles\bx6ziayp.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - [You must be registered and logged in to see this link.]
FF -: plugin - c:\program\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - c:\program\Mozilla Firefox\plugins\npitunes.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
Rootkit scan 2008-12-09 19:53:29
Windows 5.1.2600 Service Pack 3 NTFS

detected NTDLL code modification:
ZwClose

genomsöker dolda processer ...

genomsöker dolda autostartpunkter ...

genomsöker dolda filer ...

genomsökningen avslutades lyckosamt
dolda filer: 0

**************************************************************************
.
--------------------- DLLer installerade under pågående processer ---------------------

- - - - - - - > 'winlogon.exe'(796)
c:\windows\system32\WRLogonNTF.dll
.
Sluttid: 2008-12-09 19:56:05
ComboFix-quarantined-files.txt 2008-12-09 18:55:02

Före genomsökningen: 44 674 674 688 byte ledigt
Efter genomsökningen: 45,879,529,472 byte ledigt

WindowsXP-KB310994-SP2-Home-BootDisk-SVE.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

238 --- E O F --- 2008-11-12 14:29:16

MarcusMarcus
Beginner
Beginner

Posts Posts : 4
Joined Joined : 2008-12-09
OS OS : Windows XP home edition
Points Points : 29180
# Likes # Likes : 0

View user profile

Back to top Go down

Solved Re: Another trojan.zlob.g

Post by Belahzur on Tue Dec 09, 2008 7:08 pm

Looks good, what problems remain?
Delete this folder:
C:\Qoobox

Your version of Java is outdated and needs to be updated to take advantage of fixes that have eliminated security vulnerabilities.
Updating Java:

  • Download the latest version of [You must be registered and logged in to see this link.].
  • Select the first option where it says "Java SE Runtime Environment (JRE) 6 Update 11".
  • Click the "Download" button to the right.
  • In the Window that opens, select your platform and language, check the "agree" box, and click Continue.
  • Click on the link to download Windows Offline Installation and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add or Remove Programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
    - Examples of older versions in Add or Remove Programs:
    - Java 2 Runtime Environment, SE v1.4.2
    - J2SE Runtime Environment 5.0
    - J2SE Runtime Environment 5.0 Update 2
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u11-windows-i586-p.exe that you downloaded to install the newest version.
Please make sure the new version of Java is installed before you run JavaRa.

Please download JavaRa from [You must be registered and logged in to see this link.]

  • First, unzip it.
  • Then run JavaRa.
  • Select English from the drop down menu and press Select.
  • This will open JavaRa.
  • Press Remove older versions
  • Press yes to the prompt.
  • It will make a log file of what it's removed.
  • Copy and paste the log back here.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245059
# Likes # Likes : 1

View user profile

Back to top Go down

Solved Re: Another trojan.zlob.g

Post by MarcusMarcus on Tue Dec 09, 2008 7:49 pm

In the "Add or Remove Programs"-list i also have "Java(TM) 6 Update 2" aswell as 3,4,5,6 and 7. Should i remove these aswell?

MarcusMarcus
Beginner
Beginner

Posts Posts : 4
Joined Joined : 2008-12-09
OS OS : Windows XP home edition
Points Points : 29180
# Likes # Likes : 0

View user profile

Back to top Go down

Solved Re: Another trojan.zlob.g

Post by Belahzur on Tue Dec 09, 2008 7:59 pm

Yes.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245059
# Likes # Likes : 1

View user profile

Back to top Go down

Solved Re: Another trojan.zlob.g

Post by MarcusMarcus on Tue Dec 09, 2008 8:50 pm

No problems remain, to my knowledge atleast. Thanks alot for all the help. Here's the log from JavaRa:

JavaRa 1.11 Removal Log.

Report follows after line.

------------------------------------

The JavaRa removal process was started on Tue Dec 09 21:40:50 2008

Found and removed: C:\Program\Java\jre1.6.0_02

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\JavaPlugin.150

Found and removed: SOFTWARE\Classes\JavaPlugin.150_06

Found and removed: SOFTWARE\Classes\JavaPlugin.150_09

Found and removed: SOFTWARE\Classes\JavaPlugin.150_10

Found and removed: SOFTWARE\Classes\JavaWebStart.isInstalled.1.5.0.0

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}

------------------------------------

Finished reporting.

There was one more thing. When i opened Mozilla firefox a window named "tillägg" which means something like "addons" in english pops up stating that 2 new "addons" have been installed "Java quick starter 1.0" and "PC sync 2 Synchronisation Extension 1.0.0.658" have been installed, giving me the option to inactivate them, should i just close that window?
Yet again, thanks for all your help, it's much appreciated.
M

MarcusMarcus
Beginner
Beginner

Posts Posts : 4
Joined Joined : 2008-12-09
OS OS : Windows XP home edition
Points Points : 29180
# Likes # Likes : 0

View user profile

Back to top Go down

Solved Re: Another trojan.zlob.g

Post by Belahzur on Tue Dec 09, 2008 8:56 pm

Java quick starter is the new version of Java, you can disable that if you want to.
The PC sync 2 Synchronisation Extension can be used to Sync add-ons with other browsers like Google Chrome, you can also disable this add-on if you want to.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245059
# Likes # Likes : 1

View user profile

Back to top Go down

Solved Re: Another trojan.zlob.g

Post by Doctor Inferno on Thu Jan 15, 2009 8:05 am

Since this issue is resolved, this topic is closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter.

Everyone else, please open a new topic for your questions.


Please be a GeekPolice fan on [You must be registered and logged in to see this link.]



Have we helped you? [You must be registered and logged in to see this link.] | Doctor by day, ninja by night.

Doctor Inferno
Administrator
Administrator

Posts Posts : 12017
Joined Joined : 2007-12-26
Gender Gender : Male
OS OS : Windows 7 Home Premium and Ultimate X64
Protection Protection : Kaspersky PURE and Malwarebytes' Anti-Malware
Points Points : 104594
# Likes # Likes : 0

View user profile

Back to top Go down

View previous topic View next topic Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum