This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Desktop Search And Ceres.dll Won't Go Away

246 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.1
Scan saved at 5:17:04 PM, on 3/25/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Nhksrv.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\WINDOWS\system32\E_S00RP1.EXE
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\SAgent4.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9AA.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\isrvs\desktop.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Emery Wenger\Application Data\eetu.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\d?xplore.exe
C:\Program Files\SpyCatcher\Scheduler daemon.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\AIM95\aim.exe
C:\PROGRAM FILES\OUTLOOK EXPRESS\MSIMN.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft AntiSpyware\GIANTAntiSpywareMain.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.refdesk.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.refdesk.comver=6&ar=msnhome
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast High-Speed Internet
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:8000
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareBlock Class - {0A87E45F-537A-40B4-B812-E2544C21A09F} - C:\Program Files\SpyCatcher\SCActiveBlock.dll
O2 - BHO: RsyncHlpr Class - {16B238D5-80DE-47CE-8F17-B3ECE2C2248D} - C:\WINDOWS\system32\rsyncmon.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: IE Update Class - {5B4AB8E2-6DC5-477A-B637-BF3C1A2E5993} - C:\WINDOWS\isrvs\sysupd.dll
O2 - BHO: (no name) - {8D49B5BF-240D-72D6-2C50-79C2BA5047EE} - C:\WINDOWS\system32\vbsakqc.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [EPSON Stylus CX4600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9AA.EXE /P26 "EPSON Stylus CX4600 Series" /O6 "USB001" /M "Stylus CX4600"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [RSync] C:\WINDOWS\system32\netsync.exe
O4 - HKLM\..\Run: [Desktop Search] C:\WINDOWS\isrvs\desktop.exe
O4 - HKLM\..\Run: [ffis] C:\WINDOWS\isrvs\ffisearch.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [GhostSurfDelSatellite] "C:\Program Files\SpyCatcher\DeleteSatellite.exe"
O4 - HKLM\..\RunOnce: [MicrosoftAntiSpywareCleaner] C:\Program Files\Microsoft AntiSpyware\gcASCleaner.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Scheduler.lnk = C:\Program Files\SpyCatcher\Scheduler daemon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://www.comcastsupport.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} - https://components.viewpoint.com/MTSInstall…od/install.html
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {3A7FE611-1994-4EF1-A09F-99456752289D} - http://install.wildtangent.com/ActiveLaunc…iveLauncher.cab
O16 - DPF: {3F0EECCE-E138-11D1-8712-0060083D83F5} (LPViewer Class) - http://www.mgisoft.com/ActiveX/LPControl.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200212…meInstaller.exe
O16 - DPF: {430DDE24-C051-11CF-95BE-0020AFF75E4F} (ichat xchat Control) - http://tank.wizards.com/chat/data/html/user/msie/msichat.ocx
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…83/mcinsctl.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150/2211dce853ee327f8d16/netzip/RdxIE2.cab
O16 - DPF: {65E7DB1D-0101-4100-BD66-C5C78C917F93} - http://install.wildtangent.com/bgn/partner…lim/install.cab
O16 - DPF: {7D30109B-DD2B-4339-BE80-1CD48723C2BC} (LiveX(v6.0)) - http://216.177.6.142/cab/Live.cab
O16 - DPF: {8E28B3A9-FE83-45D1-B657-D5426B81A121} (CustomerCtrl Class) - http://cs4b.instantservice.com/jars/customerxsigned30.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://jcsg-video2.sdsc.edu/activex/AxisCamControl.cab
O16 - DPF: {B0C207A3-42EE-11D0-9DB3-00805F8A73C5} - http://www.yamaha.co.jp/xg/midplug/controls/yamplay.cab
O16 - DPF: {B3872502-F9FD-4E96-93FF-0D37298F0689} (SOESysInfo Control) - http://eq2beta.station.sony.com/beta_reg/soesysinfo.cab
O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) -
Please do this first:
  • Download the latest version of Ad-Aware:
    http://www.lavasoft.de/support/download/

    After installing AAW, and before running the program.
    Please be sure to update the reference file following the instructions here:
    http://www.lavahelp.net/howto/updref/

    Reconfigure Ad-Aware for Full Scan:

    Launch the program, and click on the Gear at the top of the start screen.

    Click the "Scanning" button.
    Under Drives, Folders and Files, select "Scan within Archives".
    Click "Click here to select Drives + folders" and select your installed hard drives.

    Under Memory & Registry, select all options.
    Click the "Advanced" button.
    Under "Log-file detail level", select all options.
    Click the "Tweaks" button.

    Under "Scanning Engine", select the following:
    "Unload recognized processes during scanning."
    Under "Cleaning Engine", select the following:
    "Let Windows remove files in use after reboot."
    Click on 'Proceed' to save these Preferences.

    Run the Ad-Aware scan and allow it to remove everything it finds and then REBOOT to allow it to finish.
  • If you haven't done so Please Scan with Spybot Search and Destroy:

    1. Download and Install Spybot S&D, accepting the Default Settings

    2. In the Menu Bar at the top of the Spybot window you will see 'Mode'. Make certain that 'default mode' has a check mark beside it.

    3. Close ALL windows except Spybot S&D

    4. Click the button to ‘Search for Updates’ and download and install the Updates.

    5. Next click the button ‘Check for Problems’

    6. When Spybot is complete, it will be showing ‘RED’ (RED) entries ‘BLACK’ entries and ‘GREEN’ (GREEN) entries in the window

    7. Make certain there is a check mark beside all of the RED (RED) entries ONLY.

    8. Choose ‘Fix Selected Problems’ and allow Spybot to fix the RED (RED) entries.

    9. REBOOT to complete the scan.
  • Reboot, make a new HijackThis log and post it here.
Please check out this new log file. I believe I still have some problems since I still have a pop up search in the lower right hand corner of the screen.


Logfile of HijackThis v1.99.1
Scan saved at 9:54:21 PM, on 3/30/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Nhksrv.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\WINDOWS\system32\E_S00RP1.EXE
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\SAgent4.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9AA.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\isrvs\desktop.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\d?xplore.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

http://www.refdesk.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title =

Microsoft Internet Explorer provided by Comcast High-Speed Internet
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet

Settings,ProxyServer = http=127.0.0.1:8000
R0 - HKCU\Software\Microsoft\Internet

Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class -

{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program

Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareBlock Class - {0A87E45F-537A-40B4-B812-E2544C21A09F}

- C:\Program Files\SpyCatcher\SCActiveBlock.dll (file missing)
O2 - BHO: RsyncHlpr Class - {16B238D5-80DE-47CE-8F17-B3ECE2C2248D} -

C:\WINDOWS\system32\rsyncmon.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -

C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: IE Update Class - {5B4AB8E2-6DC5-477A-B637-BF3C1A2E5993} -

C:\WINDOWS\isrvs\sysupd.dll
O2 - BHO: EpsonToolBandKicker Class -

{E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON

Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: McAfee VirusScan -

{BA52B914-B692-46c4-B683-905236F6F655} -

c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: EPSON Web-To-Page -

{EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON

Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program

Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program

Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE

C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [VSOCheckTask]
"c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online]

"c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe]

c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe]

C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [EPSON Stylus CX4600 Series]

C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9AA.EXE /P26 "EPSON

Stylus CX4600 Series" /O6 "USB001" /M "Stylus CX4600"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common

Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] C:\Program
Hi Paraglider, Start->Run…-> type Notepad.exe and press Enter Click "Format", then make sure "WordWrap" is unchecked. Now close Notepad. Run HijackThis again, and click "Do a system scan and save a logfile". Save it as hijackthis.txt. After pressing Save NotePad will open up with the log. Now click Edit > Select all. Click Edit again, and choose "Copy" now. Go to the forums, click Add Reply in this thread, and Paste (Ctrl + V) your log into this topic :)
Logfile of HijackThis v1.99.1
Scan saved at 7:08:19 AM, on 3/31/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Nhksrv.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\WINDOWS\system32\E_S00RP1.EXE
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\SAgent4.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9AA.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\d?xplore.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\system32\devldr32.exe
C:\PROGRAM FILES\OUTLOOK EXPRESS\MSIMN.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.refdesk.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.refdesk.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.refdesk.comver=6&ar=msnhome
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast High-Speed Internet
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:8000
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareBlock Class - {0A87E45F-537A-40B4-B812-E2544C21A09F} - C:\Program Files\SpyCatcher\SCActiveBlock.dll (file missing)
O2 - BHO: RsyncHlpr Class - {16B238D5-80DE-47CE-8F17-B3ECE2C2248D} - C:\WINDOWS\system32\rsyncmon.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: IE Update Class - {5B4AB8E2-6DC5-477A-B637-BF3C1A2E5993} - C:\WINDOWS\isrvs\sysupd.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [EPSON Stylus CX4600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9AA.EXE /P26 "EPSON Stylus CX4600 Series" /O6 "USB001" /M "Stylus CX4600"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [RSync] C:\WINDOWS\system32\netsync.exe
O4 - HKLM\..\Run: [Desktop Search] C:\WINDOWS\isrvs\desktop.exe
O4 - HKLM\..\Run: [ffis] C:\WINDOWS\isrvs\ffisearch.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [MicrosoftAntiSpywareCleaner] C:\Program Files\Microsoft AntiSpyware\gcASCleaner.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://www.comcastsupport.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} - https://components.viewpoint.com/MTSInstall…od/install.html
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {3F0EECCE-E138-11D1-8712-0060083D83F5} (LPViewer Class) - http://www.mgisoft.com/ActiveX/LPControl.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200212…meInstaller.exe
O16 - DPF: {430DDE24-C051-11CF-95BE-0020AFF75E4F} (ichat xchat Control) - http://tank.wizards.com/chat/data/html/user/msie/msichat.ocx
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…83/mcinsctl.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150/2211dce853ee327f8d16/netzip/RdxIE2.cab
O16 - DPF: {7D30109B-DD2B-4339-BE80-1CD48723C2BC} (LiveX(v6.0)) - http://216.177.6.142/cab/Live.cab
O16 - DPF: {8E28B3A9-FE83-45D1-B657-D5426B81A121} (CustomerCtrl Class) - http://cs4b.instantservice.com/jars/customerxsigned30.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://jcsg-video2.sdsc.edu/activex/AxisCamControl.cab
O16 - DPF: {B0C207A3-42EE-11D0-9DB3-00805F8A73C5} - http://www.yamaha.co.jp/xg/midplug/controls/yamplay.cab
O16 - DPF: {B3872502-F9FD-4E96-93FF-0D37298F0689} (SOESysInfo Control) - http://eq2beta.station.sony.com/beta_reg/soesysinfo.cab
O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real.com/gameconsole/Bundl…ArcadeRdxIE.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,20/mcgdmgr.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security2.norton.com/SSC/SharedCont…c/bin/cabsa.cab
O16 - DPF: {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1) -
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSControl_v1-32.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O18 - Filter: text/html - {950238FB-C706-4791-8674-4D429F85897E} - C:\WINDOWS\isrvs\mfiltis.dll
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: EPSON V3 Service2(03) (EPSON_PM_RPCV2_01) - SEIKO EPSON CORPORATION - C:\WINDOWS\system32\E_S00RP1.EXE
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: Netropa NHK Server (Nhksrv) - Unknown owner - C:\WINDOWS\Nhksrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Epson Printer Status Agent4 (StatusAgent4) - SEIKO EPSON CORPORATION - C:\WINDOWS\system32\SAgent4.exe
Hi Paraglider,

1. Run HijackThis (“Do a system scan only”). Put a checkmark near these lines:

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O2 - BHO: SpywareBlock Class - {0A87E45F-537A-40B4-B812-E2544C21A09F} - C:\Program Files\SpyCatcher\SCActiveBlock.dll (file missing)
O2 - BHO: RsyncHlpr Class - {16B238D5-80DE-47CE-8F17-B3ECE2C2248D} - C:\WINDOWS\system32\rsyncmon.dll
O2 - BHO: IE Update Class - {5B4AB8E2-6DC5-477A-B637-BF3C1A2E5993} - C:\WINDOWS\isrvs\sysupd.dll

O4 - HKLM\..\Run: [RSync] C:\WINDOWS\system32\netsync.exe
O4 - HKLM\..\Run: [Desktop Search] C:\WINDOWS\isrvs\desktop.exe
O4 - HKLM\..\Run: [ffis] C:\WINDOWS\isrvs\ffisearch.exe

O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} - https://components.viewpoint.com/MTSInstall…od/install.html
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150/2211dce853ee327f8d16/netzip/RdxIE2.cab

O18 - Filter: text/html - {950238FB-C706-4791-8674-4D429F85897E} - C:\WINDOWS\isrvs\mfiltis.dll


2. Close all other windows and browsers, and hit Fix Checked.

3. Reboot into safe mode by tapping F8 frequently during bootup.
Make sure your settings allow you to view "Hidden files". Open up any explorer windows and click on "Tools" => "Folder Options" => "View" and be sure to check off "Show Hidden Files and Folders".

4. Delete, in safe mode:
Folder
C:\WINDOWS\isrvs

File
C:\WINDOWS\system32\netsync.exe

5. Reboot into normal mode, make a new HijackThis log, and post it here :)
Logfile of HijackThis v1.99.1
Scan saved at 7:04:49 AM, on 4/1/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Nhksrv.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\WINDOWS\system32\E_S00RP1.EXE
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\SAgent4.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9AA.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\d?xplore.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\HijackThis\HijackThis.exe
C:\PROGRAM FILES\OUTLOOK EXPRESS\MSIMN.EXE
C:\Program Files\Internet Explorer\iexplore.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.refdesk.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.refdesk.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.refdesk.comver=6&ar=msnhome
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast High-Speed Internet
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:8000
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [EPSON Stylus CX4600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9AA.EXE /P26 "EPSON Stylus CX4600 Series" /O6 "USB001" /M "Stylus CX4600"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [Desktop Search] C:\WINDOWS\isrvs\desktop.exe
O4 - HKLM\..\Run: [ffis] C:\WINDOWS\isrvs\ffisearch.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\RunOnce: [MicrosoftAntiSpywareCleaner] C:\Program Files\Microsoft AntiSpyware\gcASCleaner.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://www.comcastsupport.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {3F0EECCE-E138-11D1-8712-0060083D83F5} (LPViewer Class) - http://www.mgisoft.com/ActiveX/LPControl.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200212…meInstaller.exe
O16 - DPF: {430DDE24-C051-11CF-95BE-0020AFF75E4F} (ichat xchat Control) - http://tank.wizards.com/chat/data/html/user/msie/msichat.ocx
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…83/mcinsctl.cab
O16 - DPF: {7D30109B-DD2B-4339-BE80-1CD48723C2BC} (LiveX(v6.0)) - http://216.177.6.142/cab/Live.cab
O16 - DPF: {8E28B3A9-FE83-45D1-B657-D5426B81A121} (CustomerCtrl Class) - http://cs4b.instantservice.com/jars/customerxsigned30.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://jcsg-video2.sdsc.edu/activex/AxisCamControl.cab
O16 - DPF: {B0C207A3-42EE-11D0-9DB3-00805F8A73C5} - http://www.yamaha.co.jp/xg/midplug/controls/yamplay.cab
O16 - DPF: {B3872502-F9FD-4E96-93FF-0D37298F0689} (SOESysInfo Control) - http://eq2beta.station.sony.com/beta_reg/soesysinfo.cab
O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real.com/gameconsole/Bundl…ArcadeRdxIE.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,20/mcgdmgr.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security2.norton.com/SSC/SharedCont…c/bin/cabsa.cab
O16 - DPF: {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1) -
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSControl_v1-32.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: EPSON V3 Service2(03) (EPSON_PM_RPCV2_01) - SEIKO EPSON CORPORATION - C:\WINDOWS\system32\E_S00RP1.EXE
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: Netropa NHK Server (Nhksrv) - Unknown owner - C:\WINDOWS\Nhksrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Epson Printer Status Agent4 (StatusAgent4) - SEIKO EPSON CORPORATION - C:\WINDOWS\system32\SAgent4.exe
Hi paraglider,

* Download Killbox from here:
http://www.downloads.subratam.org/KillBox.zip

1. Run HijackThis (“Do a system scan only”). Put a checkmark near these lines:

O4 - HKLM\..\Run: [Desktop Search] C:\WINDOWS\isrvs\desktop.exe
O4 - HKLM\..\Run: [ffis] C:\WINDOWS\isrvs\ffisearch.exe

O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real.com/gameconsole/Bundl…ArcadeRdxIE.cab


2. Close all other windows and browsers, and hit Fix Checked.

3. Run KillBox. In the box where it says Full Path of File to Delete place this in there:
C:\WINDOWS\isrvs

With Delete on Reboot ticked with a dot, press the Red X.

Confirm by clicking on OK.

4. Reboot, make a new HijackThis log, and post it here :)
Logfile of HijackThis v1.99.1
Scan saved at 10:57:45 AM, on 4/1/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Nhksrv.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\WINDOWS\system32\E_S00RP1.EXE
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\SAgent4.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9AA.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\d?xplore.exe
c:\program files\mcafee.com\agent\mcagent.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\PROGRAM FILES\OUTLOOK EXPRESS\MSIMN.EXE
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.refdesk.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.refdesk.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.refdesk.comver=6&ar=msnhome
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast High-Speed Internet
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:8000
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [EPSON Stylus CX4600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9AA.EXE /P26 "EPSON Stylus CX4600 Series" /O6 "USB001" /M "Stylus CX4600"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [Desktop Search] C:\WINDOWS\isrvs\desktop.exe
O4 - HKLM\..\Run: [ffis] C:\WINDOWS\isrvs\ffisearch.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://www.comcastsupport.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {3F0EECCE-E138-11D1-8712-0060083D83F5} (LPViewer Class) - http://www.mgisoft.com/ActiveX/LPControl.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200212…meInstaller.exe
O16 - DPF: {430DDE24-C051-11CF-95BE-0020AFF75E4F} (ichat xchat Control) - http://tank.wizards.com/chat/data/html/user/msie/msichat.ocx
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…83/mcinsctl.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {7D30109B-DD2B-4339-BE80-1CD48723C2BC} (LiveX(v6.0)) - http://216.177.6.142/cab/Live.cab
O16 - DPF: {8E28B3A9-FE83-45D1-B657-D5426B81A121} (CustomerCtrl Class) - http://cs4b.instantservice.com/jars/customerxsigned30.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://jcsg-video2.sdsc.edu/activex/AxisCamControl.cab
O16 - DPF: {B0C207A3-42EE-11D0-9DB3-00805F8A73C5} - http://www.yamaha.co.jp/xg/midplug/controls/yamplay.cab
O16 - DPF: {B3872502-F9FD-4E96-93FF-0D37298F0689} (SOESysInfo Control) - http://eq2beta.station.sony.com/beta_reg/soesysinfo.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,20/mcgdmgr.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security2.norton.com/SSC/SharedCont…c/bin/cabsa.cab
O16 - DPF: {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1) -
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSControl_v1-32.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: EPSON V3 Service2(03) (EPSON_PM_RPCV2_01) - SEIKO EPSON CORPORATION - C:\WINDOWS\system32\E_S00RP1.EXE
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: Netropa NHK Server (Nhksrv) - Unknown owner - C:\WINDOWS\Nhksrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Epson Printer Status Agent4 (StatusAgent4) - SEIKO EPSON CORPORATION - C:\WINDOWS\system32\SAgent4.exe
Logfile of HijackThis v1.99.1
Scan saved at 8:35:46 PM, on 4/1/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Nhksrv.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\WINDOWS\system32\E_S00RP1.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\SAgent4.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9AA.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\devldr32.exe
C:\PROGRAM FILES\OUTLOOK EXPRESS\MSIMN.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.refdesk.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.refdesk.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.refdesk.comver=6&ar=msnhome
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast High-Speed Internet
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:8000
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [EPSON Stylus CX4600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9AA.EXE /P26 "EPSON Stylus CX4600 Series" /O6 "USB001" /M "Stylus CX4600"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [Desktop Search] C:\WINDOWS\isrvs\desktop.exe
O4 - HKLM\..\Run: [ffis] C:\WINDOWS\isrvs\ffisearch.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://www.comcastsupport.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {3F0EECCE-E138-11D1-8712-0060083D83F5} (LPViewer Class) - http://www.mgisoft.com/ActiveX/LPControl.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200212…meInstaller.exe
O16 - DPF: {430DDE24-C051-11CF-95BE-0020AFF75E4F} (ichat xchat Control) - http://tank.wizards.com/chat/data/html/user/msie/msichat.ocx
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…83/mcinsctl.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {7D30109B-DD2B-4339-BE80-1CD48723C2BC} (LiveX(v6.0)) - http://216.177.6.142/cab/Live.cab
O16 - DPF: {8E28B3A9-FE83-45D1-B657-D5426B81A121} (CustomerCtrl Class) - http://cs4b.instantservice.com/jars/customerxsigned30.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://jcsg-video2.sdsc.edu/activex/AxisCamControl.cab
O16 - DPF: {B0C207A3-42EE-11D0-9DB3-00805F8A73C5} - http://www.yamaha.co.jp/xg/midplug/controls/yamplay.cab
O16 - DPF: {B3872502-F9FD-4E96-93FF-0D37298F0689} (SOESysInfo Control) - http://eq2beta.station.sony.com/beta_reg/soesysinfo.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,20/mcgdmgr.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security2.norton.com/SSC/SharedCont…c/bin/cabsa.cab
O16 - DPF: {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1) -
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSControl_v1-32.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: EPSON V3 Service2(03) (EPSON_PM_RPCV2_01) - SEIKO EPSON CORPORATION - C:\WINDOWS\system32\E_S00RP1.EXE
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Netropa NHK Server (Nhksrv) - Unknown owner - C:\WINDOWS\Nhksrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Epson Printer Status Agent4 (StatusAgent4) - SEIKO EPSON CORPORATION - C:\WINDOWS\system32\SAgent4.exe
Hans The Kav report is too large. Even when I break it down to five sections it is still rejected as to large. Is there another way for me to post it or do you want me to break it down into even smaller sections/ Thanks Otto
Statistics: Task start time: 4/1/2005 5:16:04 PM Task completion time: 4/1/2005 8:10:27 PM Objects scanned: 313607 Viruses detected: 13 Viruses disinfected: 0 Objects deleted: 13 Objects quarantined: 0 Settings: Objects to be scanned: My Computer If an infected object is found: Prompt user for action Scan level: Recommended Objects to be excluded from the scan scope: Option not used Report: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AbetterInternet.zip\farmmext.inf;password protected, has not been processed;4/1/2005 5:18:08 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AbetterInternet.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:08 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Adbureau.zip\emery [removed][2].txt;password protected, has not been processed;4/1/2005 5:18:08 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Adbureau.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:08 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Adbureau1.zip\emery [removed][1].txt;password protected, has not been processed;4/1/2005 5:18:08 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Adbureau1.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:08 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdFlow.zip\emery wenger@ad-flow[1].txt;password protected, has not been processed;4/1/2005 5:18:08 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AdFlow.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:08 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom.zip\emery [removed][1].txt;password protected, has not been processed;4/1/2005 5:18:08 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:08 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom1.zip\emery wenger@advertising[1].txt;password protected, has not been processed;4/1/2005 5:18:08 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom1.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:08 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom10.zip\emery [removed][1].txt;password protected, has not been processed;4/1/2005 5:18:08 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom10.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:08 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom11.zip\emery wenger@advertising[1].txt;password protected, has not been processed;4/1/2005 5:18:09 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom11.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:09 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom12.zip\emery [removed][2].txt;password protected, has not been processed;4/1/2005 5:18:09 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom12.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:09 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom13.zip\emery wenger@advertising[1].txt;password protected, has not been processed;4/1/2005 5:18:09 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom13.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:09 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom14.zip\emery [removed][2].txt;password protected, has not been processed;4/1/2005 5:18:09 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom14.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:09 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom15.zip\emery wenger@advertising[1].txt;password protected, has not been processed;4/1/2005 5:18:09 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom15.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:09 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom16.zip\emery [removed][1].txt;password protected, has not been processed;4/1/2005 5:18:09 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom16.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:09 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom17.zip\emery wenger@advertising[1].txt;password protected, has not been processed;4/1/2005 5:18:09 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom17.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:09 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom18.zip\emery [removed][1].txt;password protected, has not been processed;4/1/2005 5:18:09 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom18.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:09 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom19.zip\emery wenger@advertising[1].txt;password protected, has not been processed;4/1/2005 5:18:09 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom19.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:09 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom2.zip\emery [removed][2].txt;password protected, has not been processed;4/1/2005 5:18:09 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom2.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:09 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom20.zip\emery [removed][2].txt;password protected, has not been processed;4/1/2005 5:18:09 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom20.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:09 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom21.zip\emery wenger@advertising[2].txt;password protected, has not been processed;4/1/2005 5:18:09 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom21.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:09 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom22.zip\emery [removed][1].txt;password protected, has not been processed;4/1/2005 5:18:09 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom22.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:09 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom23.zip\emery wenger@advertising[1].txt;password protected, has not been processed;4/1/2005 5:18:09 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom23.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:09 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom24.zip\emery [removed][2].txt;password protected, has not been processed;4/1/2005 5:18:09 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom24.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:09 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom25.zip\emery wenger@advertising[1].txt;password protected, has not been processed;4/1/2005 5:18:09 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom25.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:09 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom26.zip\emery [removed][2].txt;password protected, has not been processed;4/1/2005 5:18:09 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom26.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:09 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom27.zip\emery wenger@advertising[1].txt;password protected, has not been processed;4/1/2005 5:18:09 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom27.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:09 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom28.zip\emery [removed][2].txt;password protected, has not been processed;4/1/2005 5:18:10 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom28.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:10 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom29.zip\emery wenger@advertising[1].txt;password protected, has not been processed;4/1/2005 5:18:10 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom29.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:10 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom3.zip\emery wenger@advertising[1].txt;password protected, has not been processed;4/1/2005 5:18:10 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom3.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:10 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom30.zip\emery [removed][1].txt;password protected, has not been processed;4/1/2005 5:18:10 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom30.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:10 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom31.zip\emery wenger@advertising[2].txt;password protected, has not been processed;4/1/2005 5:18:10 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom31.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:10 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom32.zip\emery [removed][1].txt;password protected, has not been processed;4/1/2005 5:18:10 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom32.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:10 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom33.zip\emery wenger@advertising[1].txt;password protected, has not been processed;4/1/2005 5:18:10 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom33.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:10 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom34.zip\emery [removed][2].txt;password protected, has not been processed;4/1/2005 5:18:10 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom34.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:10 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom35.zip\emery wenger@advertising[1].txt;password protected, has not been processed;4/1/2005 5:18:10 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom35.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:10 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom36.zip\emery [removed][1].txt;password protected, has not been processed;4/1/2005 5:18:10 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom36.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:10 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom37.zip\emery wenger@advertising[1].txt;password protected, has not been processed;4/1/2005 5:18:10 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom37.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:10 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom38.zip\emery [removed][1].txt;password protected, has not been processed;4/1/2005 5:18:10 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom38.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:10 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom39.zip\emery wenger@advertising[2].txt;password protected, has not been processed;4/1/2005 5:18:10 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom39.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:10 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom4.zip\emery [removed][1].txt;password protected, has not been processed;4/1/2005 5:18:10 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom4.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:10 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom40.zip\emery [removed][2].txt;password protected, has not been processed;4/1/2005 5:18:10 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom40.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:10 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom41.zip\emery wenger@advertising[2].txt;password protected, has not been processed;4/1/2005 5:18:10 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom41.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:10 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom5.zip\emery wenger@advertising[1].txt;password protected, has not been processed;4/1/2005 5:18:10 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom5.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:10 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom6.zip\emery [removed][1].txt;password protected, has not been processed;4/1/2005 5:18:10 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom6.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:10 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom7.zip\emery wenger@advertising[1].txt;password protected, has not been processed;4/1/2005 5:18:10 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom7.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:10 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom8.zip\emery [removed][1].txt;password protected, has not been processed;4/1/2005 5:18:11 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom8.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:11 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom9.zip\emery wenger@advertising[1].txt;password protected, has not been processed;4/1/2005 5:18:11 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom9.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:11 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Adviva.zip\emery wenger@adviva[1].txt;password protected, has not been processed;4/1/2005 5:18:11 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Adviva.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:11 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AlexaRelated.zip\RELATED.HTM;password protected, has not been processed;4/1/2005 5:18:11 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AlexaRelated.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:11 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc.zip\emery wenger@atdmt[2].txt;password protected, has not been processed;4/1/2005 5:18:11 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:11 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc1.zip\emery wenger@atdmt[2].txt;password protected, has not been processed;4/1/2005 5:18:11 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc1.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:11 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc10.zip\emery wenger@atdmt[2].txt;password protected, has not been processed;4/1/2005 5:18:11 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc10.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:11 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc11.zip\emery wenger@atdmt[2].txt;password protected, has not been processed;4/1/2005 5:18:11 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc11.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:11 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc12.zip\emery wenger@atdmt[2].txt;password protected, has not been processed;4/1/2005 5:18:11 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc12.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:11 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc13.zip\emery wenger@atdmt[2].txt;password protected, has not been processed;4/1/2005 5:18:11 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc13.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:11 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc14.zip\emery wenger@atdmt[2].txt;password protected, has not been processed;4/1/2005 5:18:11 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc14.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:11 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc15.zip\emery wenger@atdmt[2].txt;password protected, has not been processed;4/1/2005 5:18:11 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc15.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:11 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc16.zip\emery wenger@atdmt[2].txt;password protected, has not been processed;4/1/2005 5:18:11 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc16.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:11 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc17.zip\emery wenger@atdmt[2].txt;password protected, has not been processed;4/1/2005 5:18:11 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc17.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:11 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc18.zip\emery wenger@atdmt[2].txt;password protected, has not been processed;4/1/2005 5:18:11 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc18.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:11 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc19.zip\emery wenger@atdmt[2].txt;password protected, has not been processed;4/1/2005 5:18:11 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc19.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:11 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc2.zip\emery wenger@atdmt[2].txt;password protected, has not been processed;4/1/2005 5:18:11 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc2.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:11 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc20.zip\emery wenger@atdmt[2].txt;password protected, has not been processed;4/1/2005 5:18:11 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc20.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:11 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc21.zip\emery wenger@atdmt[1].txt;password protected, has not been processed;4/1/2005 5:18:12 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc21.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:12 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc22.zip\emery wenger@atdmt[2].txt;password protected, has not been processed;4/1/2005 5:18:12 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc22.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:12 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc23.zip\emery wenger@atdmt[1].txt;password protected, has not been processed;4/1/2005 5:18:12 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc23.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:12 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc24.zip\emery wenger@atdmt[1].txt;password protected, has not been processed;4/1/2005 5:18:12 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc24.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:12 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc3.zip\emery wenger@atdmt[2].txt;password protected, has not been processed;4/1/2005 5:18:12 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc3.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:12 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc4.zip\emery wenger@atdmt[2].txt;password protected, has not been processed;4/1/2005 5:18:12 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc4.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:12 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc5.zip\emery wenger@atdmt[2].txt;password protected, has not been processed;4/1/2005 5:18:12 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc5.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:12 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc6.zip\emery wenger@atdmt[2].txt;password protected, has not been processed;4/1/2005 5:18:12 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc6.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:12 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc7.zip\emery wenger@atdmt[2].txt;password protected, has not been processed;4/1/2005 5:18:12 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc7.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:12 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc8.zip\emery wenger@atdmt[2].txt;password protected, has not been processed;4/1/2005 5:18:12 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc8.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:12 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc9.zip\emery wenger@atdmt[2].txt;password protected, has not been processed;4/1/2005 5:18:12 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc9.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:12 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy.zip\bbchk.exe;password protected, has not been processed;4/1/2005 5:18:12 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:12 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy1.zip\sbRecovery.reg;password protected, has not been processed;4/1/2005 5:18:12 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy1.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:12 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy10.zip\sbRecovery.reg;password protected, has not been processed;4/1/2005 5:18:12 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy10.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:12 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy11.zip\sbRecovery.reg;password protected, has not been processed;4/1/2005 5:18:12 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy11.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:12 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy12.zip\bin/apuc.dll;password protected, has not been processed;4/1/2005 5:18:13 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy12.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:13 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy13.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:13 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy14.zip\bargains.exe;password protected, has not been processed;4/1/2005 5:18:13 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy14.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:13 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy15.zip\bbchk.exe;password protected, has not been processed;4/1/2005 5:18:13 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy15.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:13 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy16.zip\apuc.dll;password protected, has not been processed;4/1/2005 5:18:13 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy16.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:13 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy17.zip\sbRecovery.reg;password protected, has not been processed;4/1/2005 5:18:14 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy17.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:14 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy18.zip\sbRecovery.reg;password protected, has not been processed;4/1/2005 5:18:14 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy18.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:14 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy19.zip\sbRecovery.reg;password protected, has not been processed;4/1/2005 5:18:14 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy19.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:14 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy2.zip\sbRecovery.reg;password protected, has not been processed;4/1/2005 5:18:14 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy2.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:14 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy20.zip\sbRecovery.reg;password protected, has not been processed;4/1/2005 5:18:14 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy20.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:14 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy21.zip\sbRecovery.reg;password protected, has not been processed;4/1/2005 5:18:14 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy21.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:14 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy22.zip\sbRecovery.reg;password protected, has not been processed;4/1/2005 5:18:14 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy22.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:14 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy23.zip\sbRecovery.reg;password protected, has not been processed;4/1/2005 5:18:14 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy23.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:14 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy24.zip\ad.dat;password protected, has not been processed;4/1/2005 5:18:18 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy24.zip\bbi8018.exe;password protected, has not been processed;4/1/2005 5:18:18 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy24.zip\bin2/apuc.dll;password protected, has not been processed;4/1/2005 5:18:18 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy24.zip\bin2/bargains.exe;password protected, has not been processed;4/1/2005 5:18:18 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy24.zip\ub.dat;password protected, has not been processed;4/1/2005 5:18:18 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy24.zip\uninst.exe;password protected, has not been processed;4/1/2005 5:18:18 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy24.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:18 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy25.zip\sbRecovery.reg;password protected, has not been processed;4/1/2005 5:18:18 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy25.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:18 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy26.zip\sbRecovery.reg;password protected, has not been processed;4/1/2005 5:18:18 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy26.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:18 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy27.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:18 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy28.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:18 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy3.zip\sbRecovery.reg;password protected, has not been processed;4/1/2005 5:18:18 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy3.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:18 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy4.zip\sbRecovery.reg;password protected, has not been processed;4/1/2005 5:18:18 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy4.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:18 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy5.zip\sbRecovery.reg;password protected, has not been processed;4/1/2005 5:18:18 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy5.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:18 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy6.zip\bargain.exe;password protected, has not been processed;4/1/2005 5:18:20 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy6.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:20 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy7.zip\sbRecovery.reg;password protected, has not been processed;4/1/2005 5:18:20 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy7.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:20 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy8.zip\sbRecovery.reg;password protected, has not been processed;4/1/2005 5:18:20 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy8.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:20 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy9.zip\ad.dat;password protected, has not been processed;4/1/2005 5:18:22 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy9.zip\bin/apuc.dll;password protected, has not been processed;4/1/2005 5:18:22 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy9.zip\bin/bargains.exe;password protected, has not been processed;4/1/2005 5:18:22 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy9.zip\ub.dat;password protected, has not been processed;4/1/2005 5:18:22 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy9.zip\uninst.exe;password protected, has not been processed;4/1/2005 5:18:22 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BargainBuddy9.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:22 PM
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BFast.zip\emery wenger@bfast[2].txt;password protected, has not been processed;4/1/2005 5:18:22 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BFast.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:22 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BFast1.zip\emery wenger@bfast[2].txt;password protected, has not been processed;4/1/2005 5:18:22 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BFast1.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:22 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BFast10.zip\emery wenger@bfast[1].txt;password protected, has not been processed;4/1/2005 5:18:22 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BFast10.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:22 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BFast11.zip\emery wenger@bfast[1].txt;password protected, has not been processed;4/1/2005 5:18:23 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BFast11.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:23 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BFast12.zip\emery wenger@bfast[2].txt;password protected, has not been processed;4/1/2005 5:18:23 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BFast12.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:23 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BFast13.zip\emery wenger@bfast[2].txt;password protected, has not been processed;4/1/2005 5:18:23 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BFast13.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:23 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BFast14.zip\emery wenger@bfast[2].txt;password protected, has not been processed;4/1/2005 5:18:23 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BFast14.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:23 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BFast15.zip\emery wenger@bfast[1].txt;password protected, has not been processed;4/1/2005 5:18:23 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BFast15.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:23 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BFast16.zip\emery wenger@bfast[1].txt;password protected, has not been processed;4/1/2005 5:18:23 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BFast16.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:23 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BFast17.zip\emery wenger@bfast[2].txt;password protected, has not been processed;4/1/2005 5:18:23 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BFast17.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:23 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BFast18.zip\emery wenger@bfast[1].txt;password protected, has not been processed;4/1/2005 5:18:23 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BFast18.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:23 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BFast19.zip\emery wenger@bfast[2].txt;password protected, has not been processed;4/1/2005 5:18:23 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BFast19.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:23 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BFast2.zip\emery wenger@bfast[2].txt;password protected, has not been processed;4/1/2005 5:18:23 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BFast2.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:23 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BFast20.zip\emery wenger@bfast[1].txt;password protected, has not been processed;4/1/2005 5:18:23 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BFast20.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:23 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BFast3.zip\emery wenger@bfast[2].txt;password protected, has not been processed;4/1/2005 5:18:23 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BFast3.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:23 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BFast4.zip\emery wenger@bfast[2].txt;password protected, has not been processed;4/1/2005 5:18:23 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BFast4.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:23 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BFast5.zip\emery wenger@bfast[2].txt;password protected, has not been processed;4/1/2005 5:18:23 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BFast5.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:23 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BFast6.zip\emery wenger@bfast[1].txt;password protected, has not been processed;4/1/2005 5:18:23 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BFast6.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:23 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BFast7.zip\emery wenger@bfast[1].txt;password protected, has not been processed;4/1/2005 5:18:23 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BFast7.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:23 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BFast8.zip\emery wenger@bfast[1].txt;password protected, has not been processed;4/1/2005 5:18:23 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BFast8.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:23 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BFast9.zip\emery wenger@bfast[2].txt;password protected, has not been processed;4/1/2005 5:18:23 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BFast9.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:23 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CallingHomebiz.zip\farmmext.cab;password protected, has not been processed;4/1/2005 5:18:23 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CallingHomebiz.zip\farmmext.inf;password protected, has not been processed;4/1/2005 5:18:23 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CallingHomebiz.zip\farmmext.ini;password protected, has not been processed;4/1/2005 5:18:23 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CallingHomebiz.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:23 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CallingHomebiz1.zip\ceres.dll;password protected, has not been processed;4/1/2005 5:18:24 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CallingHomebiz1.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:24 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CallingHomebiz2.zip\ceres.cab;password protected, has not been processed;4/1/2005 5:18:24 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CallingHomebiz2.zip\ceres.inf;password protected, has not been processed;4/1/2005 5:18:24 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CallingHomebiz2.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:24 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CallingHomebiz3.zip\ceres.dll;password protected, has not been processed;4/1/2005 5:18:25 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CallingHomebiz3.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:25 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CallingHomebiz4.zip\ceres.dll;password protected, has not been processed;4/1/2005 5:18:26 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CallingHomebiz4.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:26 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CallingHomebiz5.zip\ceres.dll;password protected, has not been processed;4/1/2005 5:18:27 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CallingHomebiz5.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:27 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CallingHomebiz6.zip\ceres.dll;password protected, has not been processed;4/1/2005 5:18:28 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CallingHomebiz6.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:28 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CallingHomebiz7.zip\ceres.dll;password protected, has not been processed;4/1/2005 5:18:29 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CallingHomebiz7.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:29 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CallingHomebiz8.zip\ceres.dll;password protected, has not been processed;4/1/2005 5:18:31 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CallingHomebiz8.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:31 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CallingHomebiz9.zip\ceres.dll;password protected, has not been processed;4/1/2005 5:18:31 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CallingHomebiz9.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:31 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CarpeDiemVars.zip\16.02202;password protected, has not been processed;4/1/2005 5:18:32 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CarpeDiemVars.zip\Hentai-Hard/Hentai-Hard.exe;password protected, has not been processed;4/1/2005 5:18:32 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CarpeDiemVars.zip\Hentai-Hard/Hentai-Hard.ico;password protected, has not been processed;4/1/2005 5:18:32 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CarpeDiemVars.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:32 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ClickAgents.zip\emery wenger@clickagents[1].txt;password protected, has not been processed;4/1/2005 5:18:32 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ClickAgents.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:32 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ClickAgents1.zip\emery wenger@clickagents[1].txt;password protected, has not been processed;4/1/2005 5:18:32 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ClickAgents1.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:32 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ClickAgents2.zip\emery wenger@clickagents[1].txt;password protected, has not been processed;4/1/2005 5:18:32 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ClickAgents2.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:32 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ClipgenieDownloadWare.zip\Digital Signature 20031117.htm;password protected, has not been processed;4/1/2005 5:18:32 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ClipgenieDownloadWare.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:32 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CometCursors.zip\CC_42_18.PNF;password protected, has not been processed;4/1/2005 5:18:32 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CometCursors.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:32 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CometCursors1.zip\sbRecovery.reg;password protected, has not been processed;4/1/2005 5:18:32 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CometCursors1.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:32 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CometCursors2.zip\sbRecovery.reg;password protected, has not been processed;4/1/2005 5:18:32 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CometCursors2.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:32 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CometCursors3.zip\Core/cnfmgr.js;password protected, has not been processed;4/1/2005 5:18:32 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CometCursors3.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:32 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction.zip\emery wenger@qksrv[1].txt;password protected, has not been processed;4/1/2005 5:18:32 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:32 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction1.zip\emery wenger@commission-junction[1].txt;password protected, has not been processed;4/1/2005 5:18:32 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction1.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:32 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction10.zip\emery wenger@qksrv[1].txt;password protected, has not been processed;4/1/2005 5:18:32 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction10.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:32 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction11.zip\emery wenger@commission-junction[1].txt;password protected, has not been processed;4/1/2005 5:18:32 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction11.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:32 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction12.zip\emery wenger@qksrv[1].txt;password protected, has not been processed;4/1/2005 5:18:33 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction12.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:33 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction13.zip\emery wenger@commission-junction[1].txt;password protected, has not been processed;4/1/2005 5:18:33 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction13.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:33 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction14.zip\emery wenger@qksrv[1].txt;password protected, has not been processed;4/1/2005 5:18:33 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction14.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:33 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction15.zip\emery wenger@commission-junction[1].txt;password protected, has not been processed;4/1/2005 5:18:33 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction15.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:33 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction16.zip\emery wenger@qksrv[1].txt;password protected, has not been processed;4/1/2005 5:18:33 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction16.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:33 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction17.zip\emery wenger@commission-junction[1].txt;password protected, has not been processed;4/1/2005 5:18:33 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction17.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:33 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction18.zip\emery wenger@qksrv[1].txt;password protected, has not been processed;4/1/2005 5:18:33 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction18.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:33 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction19.zip\emery wenger@commission-junction[1].txt;password protected, has not been processed;4/1/2005 5:18:33 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction19.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:33 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction2.zip\emery wenger@qksrv[1].txt;password protected, has not been processed;4/1/2005 5:18:33 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction2.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:33 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction20.zip\emery wenger@qksrv[1].txt;password protected, has not been processed;4/1/2005 5:18:33 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction20.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:33 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction21.zip\emery wenger@commission-junction[1].txt;password protected, has not been processed;4/1/2005 5:18:33 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction21.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:33 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction22.zip\emery wenger@qksrv[2].txt;password protected, has not been processed;4/1/2005 5:18:33 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction22.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:33 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction23.zip\emery wenger@commission-junction[1].txt;password protected, has not been processed;4/1/2005 5:18:33 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction23.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:33 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction24.zip\emery wenger@qksrv[2].txt;password protected, has not been processed;4/1/2005 5:18:33 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction24.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:33 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction25.zip\emery wenger@qksrv[2].txt;password protected, has not been processed;4/1/2005 5:18:33 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction25.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:33 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction26.zip\emery wenger@commission-junction[1].txt;password protected, has not been processed;4/1/2005 5:18:33 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction26.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:33 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction27.zip\emery wenger@qksrv[2].txt;password protected, has not been processed;4/1/2005 5:18:33 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction27.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:33 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction28.zip\emery wenger@qksrv[1].txt;password protected, has not been processed;4/1/2005 5:18:33 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction28.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:33 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction29.zip\emery wenger@qksrv[1].txt;password protected, has not been processed;4/1/2005 5:18:33 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction29.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:33 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction3.zip\emery wenger@qksrv[2].txt;password protected, has not been processed;4/1/2005 5:18:33 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction3.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:33 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction30.zip\emery wenger@commission-junction[1].txt;password protected, has not been processed;4/1/2005 5:18:33 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction30.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:33 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction31.zip\emery wenger@qksrv[2].txt;password protected, has not been processed;4/1/2005 5:18:34 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction31.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:34 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction32.zip\emery wenger@commission-junction[1].txt;password protected, has not been processed;4/1/2005 5:18:34 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction32.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:34 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction4.zip\emery wenger@qksrv[1].txt;password protected, has not been processed;4/1/2005 5:18:34 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction4.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:34 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction5.zip\emery wenger@commission-junction[1].txt;password protected, has not been processed;4/1/2005 5:18:34 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction5.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:34 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction6.zip\emery wenger@qksrv[1].txt;password protected, has not been processed;4/1/2005 5:18:34 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction6.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:34 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction7.zip\emery wenger@commission-junction[1].txt;password protected, has not been processed;4/1/2005 5:18:34 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction7.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:34 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction8.zip\emery wenger@qksrv[1].txt;password protected, has not been processed;4/1/2005 5:18:34 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction8.zip\sbRecovery.ini;password protected, has not been processed;4/1/2005 5:18:34 PM C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction9.zip\emery wenger@commission-junction[1].txt;password protected, has not been processed;4/1/2005 5:18:34 PM

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI