This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

How To Remove Searhweb2 & Other Adware

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

:blink: Help!

My cousin downloaded the new MSN Messenger (at least that is what she admitted doing) and since then I've got soooo many adwares/spywares running havoc in my computer.

I have done some investigating, and found that one of them was the lop.com spyware, and the navi bar from searchWeb2.com.

I downloaded both the AdAware SE 1.05 and SpyBot S&D, run them one by one, and finally managed to remove lop.com using the SpyBot software.

This successfully removed the new icons that lop.com voluntarily placed on my desktop.

It did not however have any effect to the Navigation Bar/Search Bar from SearchWeb2 which always appear at the bottom of my I.E.

I also have the McAfee Security Centre and recently it's been warning me all the time about a third party that tries to change my browser settings. So far I have been rejecting the request but the warnings kept coming back.

Anyways, I have read one of your Forum Case which has a similar problem and have run some of the Online Virus Scans recommended. So far no viruses found.
I then downloaded the HiJackThis, this is the log file. Thank you.
———————————————————————————————–
Logfile of HijackThis v1.98.2
Scan saved at 6:52:09 PM, on 02/11/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\McAfee\McAfee Privacy Service\GUARDDOG.EXE
C:\WINDOWS\System32\cisvc.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\McAfee\McAfee Privacy Service\GUARDDOG.EXE
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\cidaemon.exe
C:\WINDOWS\System32\cidaemon.exe
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.shprpnzknzswnqimuemav.us/qzTbU_…LDDv1X3fnUA.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = www.shaw.ca
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost;
O2 - BHO: (no name) - {00461292-23E3-F0C3-846F-697101DCD46C} - C:\DOCUME~1\DAVESA~1\APPLIC~1\THEVIE~1\axisbike.exe
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_12_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: McAfee Privacy Service - {cc4b2ee5-4803-11d7-8a38-00b0d0c6b814} - C:\Program Files\McAfee\McAfee Privacy Service\GDIEHELP.DLL
O2 - BHO: (no name) - {FCADC1D4-B4D6-488A-9812-CDBE1E6D37EB} - C:\WINDOWS\System32\ba_iehlpr.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_12_0.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [McAfee Guardian] C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe /SU
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [MPFTray] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [bookmeoweachview] C:\Documents and Settings\All Users\Application Data\dupe up book meow\Dartlog.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [aciddumb] C:\DOCUME~1\DAVESA~1\APPLIC~1\PROGRA~1\More mail.exe
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Privacy Bar - {cc4b2ee5-4803-11d7-8a38-00b0d0c6b814} - C:\Program Files\McAfee\McAfee Privacy Service\GDIEHELP.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {217234FC-041F-4F27-84AB-8329440C4DED} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/…ropper1_3ca.cab
O16 - DPF: {2359626E-7524-4F87-B04E-22CD38A0C88C} (ICSScannerLight Class) - http://download.zonelabs.com/bin/free/cm/ICSCM.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP…l_v1-0-3-12.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab27513.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real.com/gameconsole/Bundl…ArcadeRdxIE.cab

———————————————————————————————–
hi, it's me again. I just finished running BitDefender and it finds 9 objets. Mostly infected by the Trojan.Downloader.Swizzor. … This is the log file: Thanks again! C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>arrow1.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>arrow2.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>bck1.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>bck2.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>bt11.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>bt12.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>bt13.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>bt21.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>bt22.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>bt23.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>bt31.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>bt32.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>bt33.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>bt41.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>bt42.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>bt43.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>bt51.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>bt52.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>bt53.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>bt61.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>bt62.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>checkbox1.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>checkbox2.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>checkbox3.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>checkbox4.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>default.skn: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>defbtn1.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>defbtn2.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>defbtn3.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>glyph1.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>glyph2.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>glyph3.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>glyph4.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>glyph5.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>glyph6.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>glyph7.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>main.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>preview.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>sprite1.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>tab1.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>tab2.bmp: password protected C:\Documents and Settings\All Users\Application Data\dupe up book meow\Dartlog.exe=>(Upc): infected with Trojan.Downloader.Swizzor.CA C:\Documents and Settings\All Users\Application Data\dupe up book meow\Skip live.exe=>(Upc): infected with Trojan.Downloader.Swizzor.CA C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\News\valert.ui=>CmnIds.vbs: password protected C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\News\valert.ui=>images/arrow_right.gif: password protected C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\News\valert.ui=>images/btn_signup_52x20.gif: password protected C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\News\valert.ui=>images/more_info.gif: password protected C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\News\valert.ui=>images/sidetable_bottom.gif: password protected C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\News\valert.ui=>images/sidetable_bottom_red.gif: password protected C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\News\valert.ui=>images/sidetable_top.gif: password protected C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\News\valert.ui=>images/sidetable_top_red.gif: password protected C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\News\valert.ui=>images/transpix.gif: password protected C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\News\valert.ui=>images/watermark_mys_150x130.gif: password protected C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\News\valert.ui=>oemcfg.vbs: password protected C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\News\valert.ui=>OEMIds.vbs: password protected C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\News\valert.ui=>valert.htm: password protected C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\News\valert.ui=>valert_old.htm: password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AlexaRelated.zip=>related.htm: password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AlexaRelated.zip=>sbRecovery.ini: password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM.zip=>Website Hosting.lnk: password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM.zip=>sbRecovery.ini: password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM1.zip=>Printer Cartridges.lnk: password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM1.zip=>sbRecovery.ini: password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM2.zip=>Travel .lnk: password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM2.zip=>sbRecovery.ini: password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM3.zip=>Internet .lnk: password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM3.zip=>sbRecovery.ini: password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM4.zip=>Casino Online.lnk: password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM4.zip=>sbRecovery.ini: password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM5.zip=>sbRecovery.ini: password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM6.zip=>sbRecovery.ini: password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM7.zip=>sbRecovery.ini: password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit.zip=>sbRecovery.reg: password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit.zip=>sbRecovery.ini: password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit1.zip=>sbRecovery.reg: password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit1.zip=>sbRecovery.ini: password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit2.zip=>sbRecovery.reg: password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit2.zip=>sbRecovery.ini: password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit3.zip=>sbRecovery.reg: password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit3.zip=>sbRecovery.ini: password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit4.zip=>sbRecovery.reg: password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit4.zip=>sbRecovery.ini: password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit5.zip=>sbRecovery.reg: password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit5.zip=>sbRecovery.ini: password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit6.zip=>sbRecovery.reg: password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit6.zip=>sbRecovery.ini: password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit7.zip=>sbRecovery.reg: password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit7.zip=>sbRecovery.ini: password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit8.zip=>sbRecovery.reg: password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit8.zip=>sbRecovery.ini: password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit9.zip=>sbRecovery.reg: password protected C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit9.zip=>sbRecovery.ini: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>arrow1.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>arrow2.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>bck1.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>bck2.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>bt11.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>bt12.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>bt13.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>bt21.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>bt22.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>bt23.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>bt31.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>bt32.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>bt33.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>bt41.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>bt42.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>bt43.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>bt51.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>bt52.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>bt53.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>bt61.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>bt62.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>checkbox1.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>checkbox2.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>checkbox3.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>checkbox4.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>default.skn: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>defbtn1.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>defbtn2.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>defbtn3.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>glyph1.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>glyph2.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>glyph3.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>glyph4.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>glyph5.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>glyph6.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>glyph7.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>main.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>preview.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>sprite1.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>tab1.bmp: password protected C:\Documents and Settings\All Users\Documents\aawsepersonal.exe=>wise0023=>tab2.bmp: password protected C:\Documents and Settings\Dave Sands\Application Data\ProgramDeleteDefy\SizeGlobalBarb.exe=>(Upc): infected with Trojan.Downloader.Swizzor.CB C:\Documents and Settings\Dave Sands\Application Data\ProgramDeleteDefy\uoabqnva.exe=>(Upc): infected with Trojan.Downloader.Swizzor.CA C:\Documents and Settings\Dave Sands\Local Settings\Application Data\Identities\{8D32DF8B-D3B8-4783-A0C5-FE37E2FC8659}\Microsoft\Outlook Express\Sent Items.dbx=>(message 455): infected with VBS.Lamoped.A C:\Documents and Settings\Dave Sands\Local Settings\Temporary Internet Files\Content.IE5\ADM5WPC3\aawsepersonal[1].exe=>wise0023=>arrow1.bmp: password protected C:\Documents and Settings\Dave Sands\Local Settings\Temporary Internet Files\Content.IE5\ADM5WPC3\aawsepersonal[1].exe=>wise0023=>arrow2.bmp: password protected C:\Documents and Settings\Dave Sands\Local Settings\Temporary Internet Files\Content.IE5\ADM5WPC3\aawsepersonal[1].exe=>wise0023=>bck1.bmp: password protected C:\Documents and Settings\Dave Sands\Local Settings\Temporary Internet Files\Content.IE5\ADM5WPC3\aawsepersonal[1].exe=>wise0023=>bck2.bmp: password protected C:\Documents and Settings\Dave Sands\Local Settings\Temporary Internet Files\Content.IE5\ADM5WPC3\aawsepersonal[1].exe=>wise0023=>bt11.bmp: password protected C:\Documents and Settings\Dave Sands\Local Settings\Temporary Internet Files\Content.IE5\ADM5WPC3\aawsepersonal[1].exe=>wise0023=>bt12.bmp: password protected C:\Documents and Settings\Dave Sands\Local Settings\Temporary Internet Files\Content.IE5\ADM5WPC3\aawsepersonal[1].exe=>wise0023=>bt13.bmp: password protected C:\Documents and Settings\Dave Sands\Local Settings\Temporary Internet Files\Content.IE5\ADM5WPC3\aawsepersonal[1].exe=>wise0023=>bt21.bmp: password protected C:\Documents and Settings\Dave Sands\Local Settings\Temporary Internet Files\Content.IE5\ADM5WPC3\aawsepersonal[1].exe=>wise0023=>bt22.bmp: password protected C:\Documents and Settings\Dave Sands\Local Settings\Temporary Internet Files\Content.IE5\ADM5WPC3\aawsepersonal[1].exe=>wise0023=>bt23.bmp: password protected C:\Documents and Settings\Dave Sands\Local Settings\Temporary Internet Files\Content.IE5\ADM5WPC3\aawsepersonal[1].exe=>wise0023=>bt31.bmp: password protected C:\Documents and Settings\Dave Sands\Local Settings\Temporary Internet Files\Content.IE5\ADM5WPC3\aawsepersonal[1].exe=>wise0023=>bt32.bmp: password protected C:\Documents and Settings\Dave Sands\Local Settings\Temporary Internet Files\Content.IE5\ADM5WPC3\aawsepersonal[1].exe=>wise0023=>bt33.bmp: password protected C:\Documents and Settings\Dave Sands\Local Settings\Temporary Internet Files\Content.IE5\ADM5WPC3\aawsepersonal[1].exe=>wise0023=>bt41.bmp: password protected C:\Documents and Settings\Dave Sands\Local Settings\Temporary Internet Files\Content.IE5\ADM5WPC3\aawsepersonal[1].exe=>wise0023=>bt42.bmp: password protected C:\Documents and Settings\Dave Sands\Local Settings\Temporary Internet Files\Content.IE5\ADM5WPC3\aawsepersonal[1].exe=>wise0023=>bt43.bmp: password protected C:\Documents and Settings\Dave Sands\Local Settings\Temporary Internet Files\Content.IE5\ADM5WPC3\aawsepersonal[1].exe=>wise0023=>bt51.bmp: password protected C:\Documents and Settings\Dave Sands\Local Settings\Temporary Internet Files\Content.IE5\ADM5WPC3\aawsepersonal[1].exe=>wise0023=>bt52.bmp: password protected C:\Documents and Settings\Dave Sands\Local Settings\Temporary Internet Files\Content.IE5\ADM5WPC3\aawsepersonal[1].exe=>wise0023=>bt53.bmp: password protected C:\Documents and Settings\Dave Sands\Local Settings\Temporary Internet Files\Content.IE5\ADM5WPC3\aawsepersonal[1].exe=>wise0023=>bt61.bmp: password protected C:\Documents and Settings\Dave Sands\Local Settings\Temporary Internet Files\Content.IE5\ADM5WPC3\aawsepersonal[1].exe=>wise0023=>bt62.bmp: password protected C:\Documents and Settings\Dave Sands\Local Settings\Temporary Internet Files\Content.IE5\ADM5WPC3\aawsepersonal[1].exe=>wise0023=>checkbox1.bmp: password protected C:\Documents and Settings\Dave Sands\Local Settings\Temporary Internet Files\Content.IE5\ADM5WPC3\aawsepersonal[1].exe=>wise0023=>checkbox2.bmp: password protected C:\Documents and Settings\Dave Sands\Local Settings\Temporary Internet Files\Content.IE5\ADM5WPC3\aawsepersonal[1].exe=>wise0023=>checkbox3.bmp: password protected C:\Documents and Settings\Dave Sands\Local Settings\Temporary Internet Files\Content.IE5\ADM5WPC3\aawsepersonal[1].exe=>wise0023=>checkbox4.bmp: password protected C:\Documents and Settings\Dave Sands\Local Settings\Temporary Internet Files\Content.IE5\ADM5WPC3\aawsepersonal[1].exe=>wise0023=>default.skn: password protected C:\Documents and Settings\Dave Sands\Local Settings\Temporary Internet Files\Content.IE5\ADM5WPC3\aawsepersonal[1].exe=>wise0023=>defbtn1.bmp: password protected C:\Documents and Settings\Dave Sands\Local Settings\Temporary Internet Files\Content.IE5\ADM5WPC3\aawsepersonal[1].exe=>wise0023=>defbtn2.bmp: password protected C:\Documents and Settings\Dave Sands\Local Settings\Temporary Internet Files\Content.IE5\ADM5WPC3\aawsepersonal[1].exe=>wise0023=>defbtn3.bmp: password protected C:\Documents and Settings\Dave Sands\Local Settings\Temporary Internet Files\Content.IE5\ADM5WPC3\aawsepersonal[1].exe=>wise0023=>glyph1.bmp: password protected C:\Documents and Settings\Dave Sands\Local Settings\Temporary Internet Files\Content.IE5\ADM5WPC3\aawsepersonal[1].exe=>wise0023=>glyph2.bmp: password protected C:\Documents and Settings\Dave Sands\Local Settings\Temporary Internet Files\Content.IE5\ADM5WPC3\aawsepersonal[1].exe=>wise0023=>glyph3.bmp: password protected C:\Documents and Settings\Dave Sands\Local Settings\Temporary Internet Files\Content.IE5\ADM5WPC3\aawsepersonal[1].exe=>wise0023=>glyph4.bmp: password protected C:\Documents and Settings\Dave Sands\Local Settings\Temporary Internet Files\Content.IE5\ADM5WPC3\aawsepersonal[1].exe=>wise0023=>glyph5.bmp: password protected C:\Documents and Settings\Dave Sands\Local Settings\Temporary Internet Files\Content.IE5\ADM5WPC3\aawsepersonal[1].exe=>wise0023=>glyph6.bmp: password protected C:\Documents and Settings\Dave Sands\Local Settings\Temporary Internet Files\Content.IE5\ADM5WPC3\aawsepersonal[1].exe=>wise0023=>glyph7.bmp: password protected C:\Documents and Settings\Dave Sands\Local Settings\Temporary Internet Files\Content.IE5\ADM5WPC3\aawsepersonal[1].exe=>wise0023=>main.bmp: password protected C:\Documents and Settings\Dave Sands\Local Settings\Temporary Internet Files\Content.IE5\ADM5WPC3\aawsepersonal[1].exe=>wise0023=>preview.bmp: password protected C:\Documents and Settings\Dave Sands\Local Settings\Temporary Internet Files\Content.IE5\ADM5WPC3\aawsepersonal[1].exe=>wise0023=>sprite1.bmp: password protected C:\Documents and Settings\Dave Sands\Local Settings\Temporary Internet Files\Content.IE5\ADM5WPC3\aawsepersonal[1].exe=>wise0023=>tab1.bmp: password protected C:\Documents and Settings\Dave Sands\Local Settings\Temporary Internet Files\Content.IE5\ADM5WPC3\aawsepersonal[1].exe=>wise0023=>tab2.bmp: password protected C:\Documents and Settings\Laura\Application Data\ProgramDeleteDefy\Bowsnounstorebalm.exe=>(Upc): infected with Trojan.Downloader.Swizzor.BX C:\Documents and Settings\Laura\Application Data\ProgramDeleteDefy\SizeGlobalBarb.exe=>(Upc): infected with Trojan.Downloader.Swizzor.BM C:\Documents and Settings\Laura\Application Data\ProgramDeleteDefy\tozlrylt.exe=>(Upc): infected with Trojan.Downloader.Swizzor.CA C:\Documents and Settings\Laura\Application Data\the view\axisbike.exe=>(Upc): infected with Trojan.Downloader.Swizzor.BO C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\agentins.ui=>agent_lang_helper.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\agentins.ui=>agentins.ini: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\agentins.ui=>agntcons.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\agentins.ui=>agntinst.htm: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\agentins.ui=>agntinst.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\agentins.ui=>agntlang.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\agentins.ui=>default.htm: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\agentins.ui=>header.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\agentins.ui=>HtmlUtil.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\agentins.ui=>images/bg_left_1x314.gif: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\agentins.ui=>images/icon_info_16x16.gif: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\agentins.ui=>images/icon_mcafee_61x61.gif: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\agentins.ui=>images/icon_progress_checked_13x13.gif: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\agentins.ui=>images/icon_progress_hot_13x13.gif: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\agentins.ui=>images/icon_progress_unchecked_13x13.gif: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\agentins.ui=>InstUtil.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\agentins.ui=>instwiz.css: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\agentins.ui=>instxp.css: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\agentins.ui=>lang_agnt.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\agentins.ui=>mcccom.lpk: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\agentins.ui=>pbar.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\agentins.ui=>setcss.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\agentins.ui=>SubInfoData.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\agentins.ui=>vssver.scc: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\mpfins.ui=>appcons.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\mpfins.ui=>appinst.htm: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\mpfins.ui=>appinst.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\mpfins.ui=>applang.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\mpfins.ui=>default.htm: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\mpfins.ui=>header.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\mpfins.ui=>images/bg_left_1x314.gif: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\mpfins.ui=>images/icon_info_16x16.gif: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\mpfins.ui=>images/icon_mcafee_61x61.gif: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\mpfins.ui=>images/icon_progress_checked_13x13.gif: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\mpfins.ui=>images/icon_progress_hot_13x13.gif: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\mpfins.ui=>images/icon_progress_unchecked_13x13.gif: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\mpfins.ui=>instwiz.css: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\mpfins.ui=>instxp.css: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\mpfins.ui=>mcccom.lpk: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\mpfins.ui=>mpfins.ini: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\mpfins.ui=>pbar.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\mpfins.ui=>setcss.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\shared\agentcfg.cab=>screm.ui=>agntcons.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\shared\agentcfg.cab=>screm.ui=>agntlang.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\shared\agentcfg.cab=>screm.ui=>comctl.lpk: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\shared\agentcfg.cab=>screm.ui=>config.ini: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\shared\agentcfg.cab=>screm.ui=>pbar.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\shared\agentcfg.cab=>screm.ui=>UnInsStr.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\shared\agentcfg.cab=>screm.ui=>uninst.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\shared\agentcfg.cab=>screm.ui=>uninstall.htm: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MFW\shared\agentcfg.cab=>screm.ui=>vssver.scc: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSC\ENU\agentins.ui=>agent_lang_helper.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSC\ENU\agentins.ui=>agentins.ini: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSC\ENU\agentins.ui=>agntcons.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSC\ENU\agentins.ui=>agntinst.htm: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSC\ENU\agentins.ui=>agntinst.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSC\ENU\agentins.ui=>agntlang.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSC\ENU\agentins.ui=>default.htm: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSC\ENU\agentins.ui=>header.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSC\ENU\agentins.ui=>HtmlUtil.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSC\ENU\agentins.ui=>images/bg_left_1x314.gif: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSC\ENU\agentins.ui=>images/icon_info_16x16.gif: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSC\ENU\agentins.ui=>images/icon_mcafee_61x61.gif: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSC\ENU\agentins.ui=>images/icon_progress_checked_13x13.gif: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSC\ENU\agentins.ui=>images/icon_progress_hot_13x13.gif: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSC\ENU\agentins.ui=>images/icon_progress_unchecked_13x13.gif: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSC\ENU\agentins.ui=>InstUtil.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSC\ENU\agentins.ui=>instwiz.css: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSC\ENU\agentins.ui=>instxp.css: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSC\ENU\agentins.ui=>lang_agnt.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSC\ENU\agentins.ui=>mcccom.lpk: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSC\ENU\agentins.ui=>pbar.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSC\ENU\agentins.ui=>setcss.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSC\ENU\agentins.ui=>SubInfoData.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSC\ENU\agentins.ui=>vssver.scc: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSC\ENU\shared\agentcfg.cab=>screm.ui=>agntcons.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSC\ENU\shared\agentcfg.cab=>screm.ui=>agntlang.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSC\ENU\shared\agentcfg.cab=>screm.ui=>comctl.lpk: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSC\ENU\shared\agentcfg.cab=>screm.ui=>config.ini: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSC\ENU\shared\agentcfg.cab=>screm.ui=>pbar.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSC\ENU\shared\agentcfg.cab=>screm.ui=>UnInsStr.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSC\ENU\shared\agentcfg.cab=>screm.ui=>uninst.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSC\ENU\shared\agentcfg.cab=>screm.ui=>uninstall.htm: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSC\ENU\shared\agentcfg.cab=>screm.ui=>vssver.scc: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\agentins.ui=>agent_lang_helper.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\agentins.ui=>agentins.ini: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\agentins.ui=>agntcons.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\agentins.ui=>agntinst.htm: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\agentins.ui=>agntinst.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\agentins.ui=>agntlang.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\agentins.ui=>default.htm: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\agentins.ui=>header.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\agentins.ui=>HtmlUtil.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\agentins.ui=>images/bg_left_1x314.gif: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\agentins.ui=>images/icon_info_16x16.gif: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\agentins.ui=>images/icon_mcafee_61x61.gif: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\agentins.ui=>images/icon_progress_checked_13x13.gif: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\agentins.ui=>images/icon_progress_hot_13x13.gif: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\agentins.ui=>images/icon_progress_unchecked_13x13.gif: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\agentins.ui=>InstUtil.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\agentins.ui=>instwiz.css: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\agentins.ui=>instxp.css: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\agentins.ui=>lang_agnt.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\agentins.ui=>mcccom.lpk: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\agentins.ui=>pbar.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\agentins.ui=>setcss.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\agentins.ui=>SubInfoData.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\agentins.ui=>vssver.scc: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\mskins.ui=>appcons.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\mskins.ui=>appinst.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\mskins.ui=>apputil.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\mskins.ui=>default.htm: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\mskins.ui=>header.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\mskins.ui=>images/bg_left_1x314.gif: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\mskins.ui=>images/icon_info_16x16.gif: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\mskins.ui=>images/icon_mcafee_61x61.gif: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\mskins.ui=>images/icon_progress_checked_13x13.gif: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\mskins.ui=>images/icon_progress_hot_13x13.gif: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\mskins.ui=>images/icon_progress_unchecked_13x13.gif: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\mskins.ui=>install.htm: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\mskins.ui=>instwiz.css: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\mskins.ui=>instxp.css: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\mskins.ui=>lang_app.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\mskins.ui=>mcccom.lpk: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\mskins.ui=>mskins.ini: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\mskins.ui=>pbar.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\mskins.ui=>setcss.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\Shared\agentcfg.cab=>screm.ui=>agntcons.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\Shared\agentcfg.cab=>screm.ui=>agntlang.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\Shared\agentcfg.cab=>screm.ui=>comctl.lpk: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\Shared\agentcfg.cab=>screm.ui=>config.ini: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\Shared\agentcfg.cab=>screm.ui=>pbar.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\Shared\agentcfg.cab=>screm.ui=>UnInsStr.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\Shared\agentcfg.cab=>screm.ui=>uninst.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\Shared\agentcfg.cab=>screm.ui=>uninstall.htm: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\MSK\Shared\agentcfg.cab=>screm.ui=>vssver.scc: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\agentins.ui=>agent_lang_helper.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\agentins.ui=>agentins.ini: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\agentins.ui=>agntcons.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\agentins.ui=>agntinst.htm: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\agentins.ui=>agntinst.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\agentins.ui=>agntlang.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\agentins.ui=>default.htm: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\agentins.ui=>header.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\agentins.ui=>HtmlUtil.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\agentins.ui=>images/bg_left_1x314.gif: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\agentins.ui=>images/icon_info_16x16.gif: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\agentins.ui=>images/icon_mcafee_61x61.gif: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\agentins.ui=>images/icon_progress_checked_13x13.gif: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\agentins.ui=>images/icon_progress_hot_13x13.gif: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\agentins.ui=>images/icon_progress_unchecked_13x13.gif: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\agentins.ui=>InstUtil.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\agentins.ui=>instwiz.css: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\agentins.ui=>instxp.css: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\agentins.ui=>lang_agnt.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\agentins.ui=>mcccom.lpk: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\agentins.ui=>pbar.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\agentins.ui=>setcss.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\agentins.ui=>SubInfoData.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\agentins.ui=>vssver.scc: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\shared\agentcfg.cab=>screm.ui=>agntcons.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\shared\agentcfg.cab=>screm.ui=>agntlang.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\shared\agentcfg.cab=>screm.ui=>comctl.lpk: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\shared\agentcfg.cab=>screm.ui=>config.ini: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\shared\agentcfg.cab=>screm.ui=>pbar.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\shared\agentcfg.cab=>screm.ui=>UnInsStr.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\shared\agentcfg.cab=>screm.ui=>uninst.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\shared\agentcfg.cab=>screm.ui=>uninstall.htm: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\shared\agentcfg.cab=>screm.ui=>vssver.scc: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\vso\en-us\us\vsoins.cab=>vsoins.ui=>countries.js: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\vso\en-us\us\vsoins.cab=>vsoins.ui=>default.htm: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\vso\en-us\us\vsoins.cab=>vsoins.ui=>header.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\vso\en-us\us\vsoins.cab=>vsoins.ui=>HtmlUtil.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\vso\en-us\us\vsoins.cab=>vsoins.ui=>images/bg_left_1x314.gif: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\vso\en-us\us\vsoins.cab=>vsoins.ui=>images/icon_info_16x16.gif: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\vso\en-us\us\vsoins.cab=>vsoins.ui=>images/icon_mcafee_61x61.gif: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\vso\en-us\us\vsoins.cab=>vsoins.ui=>images/icon_progress_checked_13x13.gif: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\vso\en-us\us\vsoins.cab=>vsoins.ui=>images/icon_progress_hot_13x13.gif: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\vso\en-us\us\vsoins.cab=>vsoins.ui=>images/icon_progress_unchecked_13x13.gif: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\vso\en-us\us\vsoins.cab=>vsoins.ui=>install.htm: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\vso\en-us\us\vsoins.cab=>vsoins.ui=>instwiz.css: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\vso\en-us\us\vsoins.cab=>vsoins.ui=>instxp.css: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\vso\en-us\us\vsoins.cab=>vsoins.ui=>lang_countries.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\vso\en-us\us\vsoins.cab=>vsoins.ui=>lang_vso.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\vso\en-us\us\vsoins.cab=>vsoins.ui=>mcccom.lpk: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\vso\en-us\us\vsoins.cab=>vsoins.ui=>pbar.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\vso\en-us\us\vsoins.cab=>vsoins.ui=>setcss.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\vso\en-us\us\vsoins.cab=>vsoins.ui=>VsoConst.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\vso\en-us\us\vsoins.cab=>vsoins.ui=>vsoins.ini: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\vso\en-us\us\vsoins.cab=>vsoins.ui=>VSOPropConst.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\vsoins.ui=>countries.js: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\vsoins.ui=>default.htm: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\vsoins.ui=>header.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\vsoins.ui=>HtmlUtil.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\vsoins.ui=>images/bg_left_1x314.gif: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\vsoins.ui=>images/icon_info_16x16.gif: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\vsoins.ui=>images/icon_mcafee_61x61.gif: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\vsoins.ui=>images/icon_progress_checked_13x13.gif: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\vsoins.ui=>images/icon_progress_hot_13x13.gif: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\vsoins.ui=>images/icon_progress_unchecked_13x13.gif: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\vsoins.ui=>install.htm: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\vsoins.ui=>instwiz.css: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\vsoins.ui=>instxp.css: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\vsoins.ui=>lang_countries.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\vsoins.ui=>lang_vso.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\vsoins.ui=>mcccom.lpk: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\vsoins.ui=>pbar.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\vsoins.ui=>setcss.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\vsoins.ui=>VsoConst.vbs: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\vsoins.ui=>vsoins.ini: password protected C:\My Downloads\MIS600CDENU.exe=>(CAB Sfx o)=>\VSO\vsoins.ui=>VSOPropConst.vbs: password protected C:\Program Files\Britannica\jre\lib\i18n.jar=>java/text/resources/LocaleElements_zh_TW.class: bad crc C:\Program Files\Britannica\jre\lib\jaws.jar=>sunw/demo/classfile/UTF8Constant.class: bad crc C:\Program Files\Britannica\jre\lib\rt.jar=>sunw/util/EventObject.class: bad crc C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>arrow1.bmp: password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>arrow2.bmp: password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bck1.bmp: password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bck2.bmp: password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt11.bmp: password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt12.bmp: password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt13.bmp: password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt21.bmp: password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt22.bmp: password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt23.bmp: password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt31.bmp: password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt32.bmp: password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt33.bmp: password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt41.bmp: password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt42.bmp: password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt43.bmp: password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt51.bmp: password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt52.bmp: password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt53.bmp: password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt61.bmp: password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>bt62.bmp: password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>checkbox1.bmp: password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>checkbox2.bmp: password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>checkbox3.bmp: password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>checkbox4.bmp: password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>default.skn: password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>defbtn1.bmp: password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>defbtn2.bmp: password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>defbtn3.bmp: password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>glyph1.bmp: password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>glyph2.bmp: password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>glyph3.bmp: password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>glyph4.bmp: password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>glyph5.bmp: password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>glyph6.bmp: password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>glyph7.bmp: password protected C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask=>main.bmp: password protected C:\Program Files&#
Hi ….

I really appreciate your help on this, and sorry for not replying sooner.

This is the most current HJT log file:

Logfile of HijackThis v1.98.2
Scan saved at 8:50:26 PM, on 14/11/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\McAfee\McAfee Privacy Service\GUARDDOG.EXE
C:\WINDOWS\System32\cisvc.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\McAfee\McAfee Privacy Service\GUARDDOG.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Internet Explorer\iexplore.exe
c:\progra~1\intern~1\iexplore.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\Messenger\msmsgs.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\WINDOWS\System32\cidaemon.exe
C:\WINDOWS\System32\cidaemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.tvwwcxbczemk.com/qzTbU_FZ7pyi9/…7DDv1X3fnUA.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = www.shaw.ca
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost;
O2 - BHO: (no name) - {00461292-23E3-F0C3-846F-697101DCD46C} - C:\DOCUME~1\DAVESA~1\APPLIC~1\THEVIE~1\axisbike.exe
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_12_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: McAfee Privacy Service - {cc4b2ee5-4803-11d7-8a38-00b0d0c6b814} - C:\Program Files\McAfee\McAfee Privacy Service\GDIEHELP.DLL
O2 - BHO: (no name) - {FCADC1D4-B4D6-488A-9812-CDBE1E6D37EB} - C:\WINDOWS\System32\ba_iehlpr.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_12_0.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [McAfee Guardian] C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe /SU
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [MPFTray] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [bookmeoweachview] C:\Documents and Settings\All Users\Application Data\dupe up book meow\Dartlog.exe
O4 - HKLM\..\Run: [CleanUp] C:\PROGRA~1\McAfee.com\Shared\mcappins.exe /v=3 /cleanup
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [aciddumb] C:\DOCUME~1\DAVESA~1\APPLIC~1\PROGRA~1\More mail.exe
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Privacy Bar - {cc4b2ee5-4803-11d7-8a38-00b0d0c6b814} - C:\Program Files\McAfee\McAfee Privacy Service\GDIEHELP.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {217234FC-041F-4F27-84AB-8329440C4DED} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/…ropper1_3ca.cab
O16 - DPF: {2359626E-7524-4F87-B04E-22CD38A0C88C} (ICSScannerLight Class) - http://download.zonelabs.com/bin/free/cm/ICSCM.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP…l_v1-0-3-12.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab27513.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real.com/gameconsole/Bundl…ArcadeRdxIE.cab
O16 - DPF: {C81B5180-AFD1-41A3-97E1-99E8D254DB98} (CSS Web Installer Class) - http://www.commandondemand.com/eval/cod/cabs/cssweb.cab
Hello… it's me again. :( I was reading some of the posted messages and said that Messenger Plus may be the possible "entry gate" for all these spywares. I then looked into the Add/Remove programs for both the Windows & Non-Windows components and could not find anything that says Messenger Plus! However, when I looked in My Computer in my C drive, I found a folder that says Messenger Plus. So should I delete this folder then? Thanks in advance.
Messenger plus is not now installed in your system - so you could delete that folder - it may have been what installed the other stuff.

Use 'ctrl' + 'alt' + 'del' (Three keys together) to get taskmanager. Find these processes and 'end task' them (if running).
OR
Use the process viewer in Hijackthis, Config, Misc Tools, Process Viewer, to unload the following running processes (if running).


Dartlog.exe
More mail.exe (Unless you know what this is)

Check these in hijackthis, AND WITH ALL OTHER WINDOWS CLOSED, fix checked.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.tvwwcxbczemk.com/qzTbU_FZ7pyi9/…7DDv1X3fnUA.htm
O2 - BHO: (no name) - {00461292-23E3-F0C3-846F-697101DCD46C} - C:\DOCUME~1\DAVESA~1\APPLIC~1\THEVIE~1\axisbike.exe
O2 - BHO: (no name) - {FCADC1D4-B4D6-488A-9812-CDBE1E6D37EB} - C:\WINDOWS\System32\ba_iehlpr.dll
O4 - HKLM\..\Run: [bookmeoweachview] C:\Documents and Settings\All Users\Application Data\dupe up book meow\Dartlog.exe
O4 - HKCU\..\Run: [aciddumb] C:\DOCUME~1\DAVESA~1\APPLIC~1\PROGRA~1\More mail.exe (Unless you know what this is)

The following activeX controls will reinstall when(and if) you revisit that website, UNLESS you know they are from a safe source, check to remove.

O16 - DPF: {217234FC-041F-4F27-84AB-8329440C4DED} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/…ropper1_3ca.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP…l_v1-0-3-12.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab27513.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real.com/gameconsole/Bundl…ArcadeRdxIE.cab
O16 - DPF: {C81B5180-AFD1-41A3-97E1-99E8D254DB98} (CSS Web Installer Class) - http://www.commandondemand.com/eval/cod/cabs/cssweb.cab

Then Reboot to safe mode (F8 on boot) and delete the following files/folders:-
NOTE: To avoid the risk of any of the above not being found due to them having the 'Hidden' attribute, first make sure that in Folder Options > View hidden and operating system files are set to show:
http://www.xtra.co.nz/help/0,,4155-1916458,00.html
Or items 8 & 9 from this link :
http://www.russelltexas.com/malware/faqhijackthis.htm )

Folder > C:\Documents and Settings\All Users\Application Data\dupe up book meow\Dartlog.exe
File > > C:\DOCUME~1\DAVESA~1\APPLIC~1\PROGRA~1\More mail.exe (Unless you know what this is)

Then Reboot and post a fresh log for me to check.
Hi, Thanks for the help, I have Fix Checked the items you told me to. And delete the Folder/File: Dartlog.exe and More Mail.exe.

Although I dont quite understand what you meant by this: http://www.xtra.co.nz/help/0,,4155-1916458,00.html
Or items 8 & 9 from this link :
http://www.russelltexas.com/malware/faqhijackthis.htm )


This is the new HiJackThis Log:

Logfile of HijackThis v1.98.2
Scan saved at 5:19:12 PM, on 15/11/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\McAfee\McAfee Privacy Service\GUARDDOG.EXE
C:\WINDOWS\System32\cisvc.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\McAfee\McAfee Privacy Service\GUARDDOG.EXE
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = www.shaw.ca
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost;
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_12_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: McAfee Privacy Service - {cc4b2ee5-4803-11d7-8a38-00b0d0c6b814} - C:\Program Files\McAfee\McAfee Privacy Service\GDIEHELP.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_12_0.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [McAfee Guardian] C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe /SU
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [MPFTray] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Privacy Bar - {cc4b2ee5-4803-11d7-8a38-00b0d0c6b814} - C:\Program Files\McAfee\McAfee Privacy Service\GDIEHELP.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {2359626E-7524-4F87-B04E-22CD38A0C88C} (ICSScannerLight Class) - http://download.zonelabs.com/bin/free/cm/ICSCM.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
Those links were to assist you (if you needed it) to set the showing all files (as some are normally hidden from view by windows).

==================================

This is my normal post for when you are clear - which you now are - or seem to be. Please advise of any problems you still have :-

Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
  • Disable and Enable System Restore. - If you are using Windows ME or XP then you should disable and re-enable system restore to make sure there are no infected files found in a restore point.
    You can find instructions on how to enable and re enable system restore here:
    Managing Windows Millennium System Restore
    or
    Windows XP System Restore Guide
    re-enable system restore with instructions from tutorial above
  • Make your Internet Explorer more secure - This can be done by following these simple instructions:
    • From within Internet Explorer click on the Tools menu and then click on Options.
    • Click once on the Security tab
    • Click once on the Internet icon so it becomes highlighted.
    • Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialise and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub-frames across different domains to Prompt
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Use an Anti Virus Software - It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future. See this link for a listing of some on line & their stand-alone anti virus programs:
    Computer Safety On line - Anti-Virus
  • Update your Anti Virus Software - It is imperitive that you update your Anti virus software at least once a week (Even more if you wish). If you do not update your anti virus software then it will not be able to catch any of the new variants that may come out.
  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. For an article on Firewalls and a listing of some available ones see the link below:
    Computer Safety On line - Software Firewalls
  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
  • Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option.
    This will provide real-time spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an anti virus software. A tutorial on installing & using this product can be found here:
    Instructions for - Spybot S & D and Ad-aware
  • Install Ad-Aware - Install and download Ad-Aware. You should also scan your computer with the program on a regular basis just as you would an anti virus software in conjunction with Spybot. A tutorial on installing & using this product can be found here:
    Instructions for - Spybot S & D and Ad-aware
  • Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs. A article on anti-malware products with links for this program and others can be found here:
    Computer Safety on line - Anti-Malware
  • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.

May your God go with you..
hi… uumm… I'm sorry to say that now I have other problems…. :( I did what you suggested, disable and enable System Restore. And then I went to uninstall my SpyBot S&D because I wanted to reinstall it, with the TeaTimer this time. Then, when i was done downloading, it restarted the computer for me. When it was back on, the desktop looked different. Some programs that used to be on the System Tray disappeared. Including the McAfee icon. What was left was the clock and the Windows Update icon. Also, what I noticed was the McAfee window that usually pops out first thing after starting the computer did not pop out this time. So I went to Program Files and tried to click on the McAfee icon from there, nothing happened. I then clicked on IE, nothing happened. Tried on other programs, like Outlook, Roxio… nothing happened either. The cursor just turned into the hourglass without anything happening. Almost in a "hang" situation so I went to Task Manager… to see if there is an application that is Not Responding. But, there was no application listed. I then go to the User name and logged off the current user ID (which is the principal user account & administrator). I then logged in as a different user ID, which also has administrator priviledges. Luckily I can access the Internet thru this one. Altough the icons on the system tray also went missing, except the Windows Update icon. I then downloaded SpyBot with this User Account, run it, fixed 9 problems. Run AdAware SE and deleted 8 objects. Then I logged off, and logged in into the Primary User ID, and still I cannot load IE or any other program with this User ID. What I also noticed is that the computer seems to be slower, and there seems to be shortage of Virtual Memory? Not sure what it is called, but the windows are overlapping when I tried to switch from one to the other… DId I do something wrong when I disable and enable the system restore? Thank you….
hi there…. Pheew!… I truned off the computer completely and started it again. And this time it looks ok… Sorry about that… I hope the system will be OK from now on. It looks normal so far. Thanks again for your help.
No problem - I will leave this topic open for a time - so you can reply if any more problems are found. If so please post back with a Hijackthis log.
Glad we could be of assistance. This topic is now closed. If you wish it
reopened, please send us an email (Click here to email) with a link to your thread.


Donations in support of this Web Site are always appreciated

Do not bother contacting us if you are not the topic starter. A valid,
working link to the closed topic is required along with the user name used.
If the user name does not match the one in the thread linked, the email will be deleted.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI