This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hacked by Spammers

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am being asked by people in my address book if I may have been Hacked by Spammers as they are getting a lot of Spam after contact from me. Also I installed free version of ZoneAlarm and am now not able to access web unless I disable it.

Here is my log after running updated versions of AVG (no virus detected) Adaaware (34 threats all removed) and Spy bot S&D (4 threats removed)



Logfile of HijackThis v1.99.1
Scan saved at 3:52:34 PM, on 28/09/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\nvraidservice.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Slim\SlimServer\SlimTray.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Stanford Folding Project\winFAH.exe
C:\Program Files\Scheduler\MiniReminder\MiniReminder.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Antispyware\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Network\PRTG Traffic Grapher\PRTG Traffic Grapher.exe
C:\Program Files\Network\PRTG Traffic Grapher\PRTG Traffic Grapher.exe
C:\Program Files\Slim\SlimServer\server\slim.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\ups.exe
C:\WINDOWS\system32\WFXSVC.EXE
C:\Program Files\FAX\WFXMOD32.EXE
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files\Stanford Folding Project\FahCore_82.exe
C:\Program Files\Antispyware\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\HiJack This\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Antispyware\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [NVRaidService] C:\WINDOWS\system32\nvraidservice.exe
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Executive Software\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Firewall\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\Torrent\bittorrent.exe" –force_start_minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Antispyware\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Folding@Home 5.03.lnk = ?
O4 - Startup: MiniReminder.lnk = C:\Program Files\Scheduler\MiniReminder\MiniReminder.exe
O4 - Global Startup: SlimServer Tray Tool.lnk = C:\Program Files\Slim\SlimServer\SlimTray.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1154490054000
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\Antispyware\ewido anti-spyware 4.0\guard.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PRTG Service - Paessler Router Traffic Grapher (PRTGService) - Paessler AG - C:\Program Files\Network\PRTG Traffic Grapher\PRTG Traffic Grapher.exe
O23 - Service: SlimServer (slimsvc) - Unknown owner - C:\Program Files\Slim\SlimServer\server\slim.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: WinFax PRO (wfxsvc) - Symantec Corporation - C:\WINDOWS\system32\WFXSVC.EXE
Hello Dmacdmac and Welcome to TomCoyote,

Download the trial version of Spy Sweeper from Here

Install it using the Standard Install option. (You will be asked for your e-mail address, it is safe to give it. If you receive alerts from your firewall, allow all activities for Spy Sweeper)
If you are taken to the internet page, just close the page.
You will be prompted to check for updated definitions, please do so.
(This may take several minutes)
Click on Options > Sweep Options and check Sweep all Folders on Selected drives. Check Local Disc C. Under What to Sweep, check every box.
Click on Sweep and allow it to fully scan your system.If you are prompted to restart the computer, do so immediately. This is a necessary step to kill the infection!
When the sweep has finished, click Remove. Click Select All and then Next
From 'Results', select the Session Log tab. Click Save to File and save the log somewhere convenient.
Exit Spy Sweeper.

Now run this online scan using Internet Explorer:
Kaspersky Online Scanner from http://www.kaspersky.com/virusscanner

Next Click on Launch Kaspersky Online Scanner

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
  • Scan using the following Anti-Virus database:
  • Standard
  • Scan Options:
  • Scan Archives
  • Scan Mail Bases
  • Click OK
  • Now under select a target to scan:
  • Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button:
  • Save the file to your desktop.

Empty Recycle Bin

Reboot and "copy/paste" a new HJT log as well as the Results from Spy Sweeper file, and Kapersky into this thread.
Thanks for the quick reply…here goes

From Spy Sweeeper

11:58 AM: Removal process completed. Elapsed time 00:00:01
11:58 AM: Quarantining All Traces: burstbeacon cookie
11:58 AM: Quarantining All Traces: trb.com cookie
11:58 AM: Quarantining All Traces: serving-sys cookie
11:58 AM: Quarantining All Traces: affiliatefuel.com cookie
11:58 AM: Quarantining All Traces: nextag cookie
11:58 AM: Quarantining All Traces: mediaplex cookie
11:58 AM: Quarantining All Traces: webtrends cookie
11:58 AM: Quarantining All Traces: informit cookie
11:58 AM: Quarantining All Traces: did-it cookie
11:58 AM: Quarantining All Traces: overture cookie
11:58 AM: Quarantining All Traces: 360i cookie
11:58 AM: Quarantining All Traces: burstnet cookie
11:58 AM: Quarantining All Traces: bizrate cookie
11:58 AM: Quarantining All Traces: atwola cookie
11:58 AM: Quarantining All Traces: tacoda cookie
11:58 AM: Quarantining All Traces: advertising cookie
11:58 AM: Quarantining All Traces: yieldmanager cookie
11:58 AM: Quarantining All Traces: about cookie
11:58 AM: Quarantining All Traces: 2o7.net cookie
11:58 AM: Removal process initiated
11:57 AM: Traces Found: 30
11:57 AM: Full Sweep has completed. Elapsed time 00:08:33
11:57 AM: File Sweep Complete, Elapsed Time: 00:06:43
11:54 AM: Warning: Failed to access drive E:
11:54 AM: Warning: Failed to access drive D:
11:53 AM: Warning: Failed to open file "c:\windows\temp\sqlite_a1bws5d5empqlvh". The operation completed successfully
11:50 AM: Starting File Sweep
11:50 AM: Warning: Failed to access drive A:
11:50 AM: Cookie Sweep Complete, Elapsed Time: 00:00:00
11:50 AM: c:\documents and settings\david & renee\cookies\david & [removed][1].txt (ID = 2337)
11:50 AM: c:\documents and settings\david & renee\cookies\david & [removed][2].txt (ID = 2335)
11:50 AM: Found Spy Cookie: burstbeacon cookie
11:50 AM: c:\documents and settings\david & renee\cookies\david & renee@workopolis.122.2o7[1].txt (ID = 1958)
11:50 AM: c:\documents and settings\david & renee\cookies\david & renee@trb[1].txt (ID = 3587)
11:50 AM: Found Spy Cookie: trb.com cookie
11:50 AM: c:\documents and settings\david & renee\cookies\david & renee@tacoda[1].txt (ID = 6444)
11:50 AM: c:\documents and settings\david & renee\cookies\david & renee@serving-sys[1].txt (ID = 3343)
11:50 AM: Found Spy Cookie: serving-sys cookie
11:50 AM: c:\documents and settings\david & renee\cookies\david & [removed][2].txt (ID = 2202)
11:50 AM: Found Spy Cookie: affiliatefuel.com cookie
11:50 AM: c:\documents and settings\david & renee\cookies\david & renee@nextag[1].txt (ID = 5014)
11:50 AM: Found Spy Cookie: nextag cookie
11:50 AM: c:\documents and settings\david & renee\cookies\david & renee@msnportal.112.2o7[1].txt (ID = 1958)
11:50 AM: c:\documents and settings\david & renee\cookies\david & renee@mediaplex[1].txt (ID = 6442)
11:50 AM: Found Spy Cookie: mediaplex cookie
11:50 AM: c:\documents and settings\david & renee\cookies\david & [removed][2].txt (ID = 3669)
11:50 AM: Found Spy Cookie: webtrends cookie
11:50 AM: c:\documents and settings\david & renee\cookies\david & [removed][2].txt (ID = 2038)
11:50 AM: c:\documents and settings\david & renee\cookies\david & renee@informit[2].txt (ID = 2863)
11:50 AM: Found Spy Cookie: informit cookie
11:50 AM: c:\documents and settings\david & renee\cookies\david & renee@homedepotca.122.2o7[1].txt (ID = 1958)
11:50 AM: c:\documents and settings\david & renee\cookies\david & renee@did-it[1].txt (ID = 2523)
11:50 AM: Found Spy Cookie: did-it cookie
11:50 AM: c:\documents and settings\david & renee\cookies\david & [removed][1].txt (ID = 3106)
11:50 AM: Found Spy Cookie: overture cookie
11:50 AM: c:\documents and settings\david & renee\cookies\david & renee@ct.360i[1].txt (ID = 1962)
11:50 AM: Found Spy Cookie: 360i cookie
11:50 AM: c:\documents and settings\david & renee\cookies\david & renee@cnn.122.2o7[2].txt (ID = 1958)
11:50 AM: c:\documents and settings\david & renee\cookies\david & renee@cbs.112.2o7[1].txt (ID = 1958)
11:50 AM: c:\documents and settings\david & renee\cookies\david & [removed][1].txt (ID = 2038)
11:50 AM: c:\documents and settings\david & renee\cookies\david & renee@burstnet[2].txt (ID = 2336)
11:50 AM: Found Spy Cookie: burstnet cookie
11:50 AM: c:\documents and settings\david & renee\cookies\david & renee@bizrate[2].txt (ID = 2308)
11:50 AM: Found Spy Cookie: bizrate cookie
11:50 AM: c:\documents and settings\david & renee\cookies\david & renee@bellglobemediapublishing.122.2o7[1].txt (ID = 1958)
11:50 AM: c:\documents and settings\david & renee\cookies\david & renee@atwola[1].txt (ID = 2255)
11:50 AM: Found Spy Cookie: atwola cookie
11:50 AM: c:\documents and settings\david & renee\cookies\david & [removed][2].txt (ID = 6445)
11:50 AM: Found Spy Cookie: tacoda cookie
11:50 AM: c:\documents and settings\david & renee\cookies\david & renee@advertising[1].txt (ID = 2175)
11:50 AM: Found Spy Cookie: advertising cookie
11:50 AM: c:\documents and settings\david & renee\cookies\david & [removed][1].txt (ID = 3751)
11:50 AM: Found Spy Cookie: yieldmanager cookie
11:50 AM: c:\documents and settings\david & renee\cookies\david & renee@about[1].txt (ID = 2037)
11:50 AM: Found Spy Cookie: about cookie
11:50 AM: c:\documents and settings\david & renee\cookies\david & renee@2o7[2].txt (ID = 1957)
11:50 AM: c:\documents and settings\david & renee\cookies\david & renee@112.2o7[2].txt (ID = 1958)
11:50 AM: Found Spy Cookie: 2o7.net cookie
11:50 AM: Starting Cookie Sweep
11:50 AM: Registry Sweep Complete, Elapsed Time:00:00:07
11:50 AM: Starting Registry Sweep
11:50 AM: Memory Sweep Complete, Elapsed Time: 00:01:36
11:48 AM: Starting Memory Sweep
11:48 AM: Sweep initiated using definitions version 770
11:48 AM: Spy Sweeper 5.0.5.1286 started
11:48 AM: | Start of Session, September 29, 2006 |
********
11:48 AM: | End of Session, September 29, 2006 |
11:48 AM: Your spyware definitions have been updated.
Keylogger Shield: On
BHO Shield: On
IE Security Shield: On
Alternate Data Stream (ADS) Execution Shield: On
Startup Shield: On
Common Ad Sites Shield: Off
Hosts File Shield: On
Spy Communication Shield: On
ActiveX Shield: On
Windows Messenger Service Shield: On
IE Favorites Shield: On
Spy Installation Shield: On
Memory Shield: On
IE Hijack Shield: On
IE Tracking Cookies Shield: Off
11:42 AM: Shield States
11:42 AM: Spyware Definitions: 691
11:42 AM: Spy Sweeper 5.0.5.1286 started
11:42 AM: Spy Sweeper 5.0.5.1286 started
11:42 AM: | Start of Session, September 29, 2006 |

********

KASPERSKY ONLINE SCANNER REPORT
Friday, September 29, 2006 12:43:33 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 29/09/2006
Kaspersky Anti-Virus database records: 214252


Scan Settings
Scan using the following antivirus database standard
Scan Archives true
Scan Mail Bases true

Scan Target My Computer
A:\
C:\
D:\
E:\
F:\

Scan Statistics
Total number of scanned objects 64693
Number of viruses found 0
Number of infected objects 0 / 0
Number of suspicious objects 0
Duration of the scan process 00:38:55

Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped

C:\Documents and Settings\David & Renee\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\David & Renee\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\David & Renee\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\David & Renee\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\David & Renee\Local Settings\History\History.IE5\MSHist012006092920060930\index.dat Object is locked skipped

C:\Documents and Settings\David & Renee\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\David & Renee\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\David & Renee\NTUSER.DAT.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Data\settings.dat Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS00234C1C-DB18-4873-92E6-4876756F1D3B.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS017211A2-C730-45CD-885B-5207CB0E6666.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS0176EDED-2583-441D-BF6A-830BF07A398E.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS0245662F-0D32-4590-980A-AAE495C1A4AF.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS0437B8AA-6A94-48CC-BB7D-6E094FB98A26.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS04AFA614-062A-4327-8FF8-A017CC0C38D2.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS05215A63-C06A-433B-B071-6841216A1242.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS06A5D139-D325-435E-BB3C-7294099CD541.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS0769293F-FD45-4542-841C-9B0BDC969922.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS076A3B55-E8EF-4614-8621-41E5A4FA8210.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS098FEFB3-871B-4314-BCB0-C26448D9492C.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS09DDCC01-0A94-4145-BA26-9EC5732404FA.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS0EFAFCCD-0BF7-4BDA-91C6-50B1A439D3FB.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS111979B6-7B56-44FA-ADDF-320AED511C1D.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS14188A8A-BBDB-4B70-B5B3-8523E40EA292.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS14A90A8D-E761-42FC-BF82-A44C645F8568.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS18B2A89F-42A8-48D9-9AD9-6AE697A041C2.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS197F529B-1053-4941-817C-6ABF72B2DAE6.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1A06717D-761E-4E9C-849A-9CF670745AA4.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1AFC8A66-64E3-4360-9055-CCE288CC92E6.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS23330BA4-DB20-459D-A5B9-5CCA4E3CE508.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS238B86E3-0E21-441D-BBF0-DEB01A894DCC.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS240BEAAB-06C4-404A-942C-5DF6C00CC0F2.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS289AB400-64E1-4131-BCC9-1A6320FFA73E.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS28B4A71F-EB5A-4944-B847-3B55C5A4978E.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS2A6437E1-559F-4430-966D-3F387D1ABF4B.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS2A7D5A27-2911-421D-9470-D399B3D7C6EC.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS2C460F22-3D50-44A2-B217-6A3655B61F68.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS2E1E64D1-2262-469B-9184-893B29BA84A6.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS30F1E8B5-FF90-47AB-8F23-6E7677E4D1C0.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS37E15951-207C-4E57-BB75-9A9EDEAF0D12.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS3DE8D8B3-8308-47FD-8B32-74EA397C0DE1.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS3F3DD09E-BC2C-414A-83F0-D4C69A1CF83C.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS408D98D8-3860-434C-875E-CCA7EC339342.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4335D840-FF51-4BD8-A058-005175B3350A.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4537F21E-8E33-4C97-9C4C-9622B959FFC1.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS461BD133-FE9A-47E1-A89F-F6C86C23B869.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4722A8BA-615D-4CF3-BDE2-279B025CB7F1.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4AD04DED-2987-496C-91ED-0D1C07A12B30.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4FD2CD4B-560F-47EA-9FFE-B789B35374BD.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS5110C772-127E-4AC5-BFA8-1EF0437DC5FC.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS5390CF98-597D-4B88-9C9C-6105C955E7AE.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS54E5F3FE-7C6E-41CD-9F13-588F2F92AE3F.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS579C0E62-91B7-43AC-BDCB-7D222F0D583C.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS58EAC6ED-3E3D-4F9C-A10C-C9ED05078D69.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS59BBA3B8-9EF5-45CC-8925-949A5D4AD395.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS5C7BCEAB-77EA-46ED-968F-F36EBDCB936C.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS5DD9D727-EB15-4AEF-885D-A3CE0519FD20.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS60853FA0-23B4-4FA0-8428-76351182A8B4.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS61603950-A5E8-4D28-88E3-C881F61AA434.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS6453F3A6-4476-4E1B-A16A-A195EBC952FC.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS64C39B05-1336-489A-9134-AA01F8058CA6.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS64D75D5E-D936-43BD-BADA-4412BE5B69C8.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS6659DBCF-78D3-4AC2-8B8C-755080DEB9DD.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS68B92C71-26D9-4D75-AF95-EF8EBCD96D61.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS6A8F45FD-F412-4F94-A139-61BAD8768E28.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS6E102CB2-0686-4F7A-98A3-F2437B0664E0.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS7FDFDAA7-D9B4-4008-AC27-236F3A3C43BD.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS80363F47-07B0-4BF1-9BB7-9130F73E77C0.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS81C8F203-81A0-4635-837C-D330DD1057BF.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS82DE0F38-AD18-4633-9A86-49543BCD7D5F.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS83CA1558-FE3F-4135-A04B-61272F741780.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS88B7C15A-1FAA-4E62-8C73-7DA6798EF189.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8BAF8DCE-DEC2-466B-8E21-A9DBA689B94F.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS904AC6E2-CCC1-467E-B113-5BEF4AF84508.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS9212FC31-4680-4084-BC27-057BC9098C32.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS94393714-2F26-496A-8EAF-CB014490D2E2.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS9E3DB48D-E3A2-4A63-9153-9E6B57EF17A5.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA1523EC7-26AE-4979-8F30-3A1A13254EB8.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA354A90F-50A3-417E-B266-5C568AFA18F9.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA3755025-6808-47F7-B291-DC40B42CA275.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA7B302EC-C02F-46DB-BDE4-3099CAA55473.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSAA139529-A59B-4CCB-B22B-AA022EEAAC8C.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSAC1075BB-30AF-404C-B2C0-03B1F01A7D10.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSAC172119-98C3-4AC2-9C5F-778F95E112D7.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB1BDACEB-DEFF-478E-A88C-686E53ACB40F.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB7D1DD9C-2EAA-4357-940A-12DC8DCBB8CC.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB9764172-152A-40AF-8D92-0D8C1D8D774D.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSBAD5EFF6-1FD6-49E1-9C28-6A0DC5A66539.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSBFE0F62B-077F-449D-BFD6-0D174DA21301.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC24B620E-D31A-4A28-86B9-B78019C2147B.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC6E119D7-9F28-4E88-A4F4-43E04EC3BF7E.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC91B8CE1-47E1-4585-BACF-726811EA7630.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSCACA40A3-C1AF-4FEE-80CC-CD027FFCCFB2.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSCB92FF1C-6ED7-4624-87FE-F5C134F74FBF.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSCBFB536E-ED63-4EA7-998A-DC90DD679CB4.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSCEFA3A93-4195-434A-85E5-C825825603A2.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD39A0980-B617-419F-93AB-0EA1B814E4D2.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD501880D-B642-47F5-9AD0-431B9B536606.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD52B5A6C-79EA-4CD6-B451-1542859A5975.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSDA140DF3-C878-4C5F-8C0C-3122E1A2D156.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSDBCAD8D1-D3C4-4E3D-82B3-2F692B013866.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSDBF43010-A333-48A3-B209-2BAD30D8202D.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSDCA9B02A-7F5B-4979-ABB0-97364413EEDC.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSDCFEB685-69AF-4285-9F48-B1A49917425F.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSE2443DCF-E852-4086-8DED-2B66B057A716.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSE3B9324D-5334-468C-9BB4-E6F21A4BAB84.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSE3EFA867-75BB-446C-8585-6C7C34F85C32.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSEA59002D-B780-470B-8BE7-706E3741600A.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSEAD302B5-BD26-4F25-83EE-7AA37E8A52E2.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSEDDC5752-F417-4805-98A3-D134005B47D3.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSEF1AB012-337B-411E-9F61-201A08DCDE37.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSF22057B4-D1D1-46A0-AD5A-1AC2B42B9A9E.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSF97E9069-097A-4510-96C8-3E0CC454C8B9.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSFA245658-3C51-47B9-8638-DD5CE638D4AC.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSFA957E16-2749-4A2F-9D52-CCF1DD7046C7.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSFBFAC685-909E-424D-8EC0-5023B5483050.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSFE4E4E95-A94C-4F9D-AEE1-E365C49D7DCB.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSFECA4C6F-2BE2-4C90-88F9-CD89266A2F1F.tmp Object is locked skipped

C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

C:\Program Files\FAX\Data\Status.WFD Object is locked skipped

C:\Program Files\FAX\Data\Status.WFF Object is locked skipped

C:\Program Files\FAX\Data\Status.WFG Object is locked skipped

C:\Program Files\FAX\Data\Status.WFR Object is locked skipped

C:\Program Files\FAX\Data\Status.WFX Object is locked skipped

C:\Program Files\FAX\Data\Status2.WFD Object is locked skipped

C:\Program Files\FAX\Data\Status2.WFG Object is locked skipped

C:\Program Files\FAX\Data\Status2.WFX Object is locked skipped

C:\Program Files\FAX\Data\Status3.WFD Object is locked skipped

C:\Program Files\FAX\Data\Status3.WFG Object is locked skipped

C:\Program Files\FAX\Data\Status3.WFX Object is locked skipped

C:\Program Files\FAX\Data\StatusS.WFD Object is locked skipped

C:\Program Files\FAX\Data\StatusS.WFG Object is locked skipped

C:\Program Files\FAX\Data\StatusS.WFX Object is locked skipped

C:\Program Files\Slim\SlimServer\server\Cache\slimserversql.db Object is locked skipped

C:\Program Files\Stanford Folding Project\FAHlog.txt Object is locked skipped

C:\Program Files\Stanford Folding Project\work\logfile_06.txt Object is locked skipped

C:\Program Files\Stanford Folding Project\work\wudata_06.inp Object is locked skipped

C:\Program Files\Stanford Folding Project\work\wudata_06.nfo Object is locked skipped

C:\Program Files\Stanford Folding Project\work\wudata_06.out Object is locked skipped

C:\Program Files\Webroot\Spy Sweeper\Masters\masters.bak Object is locked skipped

C:\Program Files\Webroot\Spy Sweeper\Masters\Masters.const Object is locked skipped

C:\Program Files\Webroot\Spy Sweeper\Masters\masters.mst Object is locked skipped

C:\Program Files\Webroot\Spy Sweeper\Masters.base Object is locked skipped

C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

C:\System Volume Information\_restore{8052BCD7-D648-4FC1-811C-C2309BB51F9A}\RP82\change.log Object is locked skipped

C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

C:\WINDOWS\Internet Logs\fwdbglog.txt Object is locked skipped

C:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped

C:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped

C:\WINDOWS\Internet Logs\MAINSQUEEZE.ldb Object is locked skipped

C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped

C:\WINDOWS\ModemLog_U.S. Robotics 56K Fax PCI.txt Object is locked skipped

C:\WINDOWS\SchedLgU.Txt Object is locked skipped

C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped

C:\WINDOWS\Sti_Trace.log Object is locked skipped

C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped

C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped

C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\default Object is locked skipped

C:\WINDOWS\system32\config\default.LOG Object is locked skipped

C:\WINDOWS\system32\config\SAM Object is locked skipped

C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped

C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\SECURITY Object is locked skipped

C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped

C:\WINDOWS\system32\config\software Object is locked skipped

C:\WINDOWS\system32\config\software.LOG Object is locked skipped

C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\system Object is locked skipped

C:\WINDOWS\system32\config\system.LOG Object is locked skipped

C:\WINDOWS\system32\h323log.txt Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

C:\WINDOWS\Temp\Perflib_Perfdata_7dc.dat Object is locked skipped

C:\WINDOWS\Temp\sqlite_A1BWs5d5EmpQlVH Object is locked skipped

C:\WINDOWS\Temp\ZLT031c3.TMP Object is locked skipped

C:\WINDOWS\Temp\ZLT070a1.TMP Object is locked skipped

C:\WINDOWS\wiadebug.log Object is locked skipped

C:\WINDOWS\wiaservc.log Object is locked skipped

C:\WINDOWS\WindowsUpdate.log Object is locked skipped

F:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

Scan process completed.


HiJack This:

Logfile of HijackThis v1.99.1
Scan saved at 12:50:09 PM, on 29/09/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\nvraidservice.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Firewall\ZoneAlarm\zlclient.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
C:\Program Files\Antispyware\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Slim\SlimServer\SlimTray.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\Stanford Folding Project\winFAH.exe
C:\Program Files\Scheduler\MiniReminder\MiniReminder.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Antispyware\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Outlook Express\msimn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Network\PRTG Traffic Grapher\PRTG Traffic Grapher.exe
C:\Program Files\Network\PRTG Traffic Grapher\PRTG Traffic Grapher.exe
C:\Program Files\Stanford Folding Project\FahCore_82.exe
C:\Program Files\Slim\SlimServer\server\slim.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\ups.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\WFXSVC.EXE
C:\Program Files\FAX\WFXMOD32.EXE
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HiJack This\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Antispyware\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [AVG7_CC] "C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" /STARTUP
O4 - HKLM\..\Run: [NVRaidService] C:\WINDOWS\system32\nvraidservice.exe
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Executive Software\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Firewall\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\Torrent\bittorrent.exe" –force_start_minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Antispyware\Spybot - Search & Destroy\TeaTimer.exe"
O4 - Startup: Folding@Home 5.03.lnk = ?
O4 - Startup: MiniReminder.lnk = C:\Program Files\Scheduler\MiniReminder\MiniReminder.exe
O4 - Global Startup: SlimServer Tray Tool.lnk = C:\Program Files\Slim\SlimServer\SlimTray.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1154490054000
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\Antispyware\ewido anti-spyware 4.0\guard.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PRTG Service - Paessler Router Traffic Grapher (PRTGService) - Paessler AG - C:\Program Files\Network\PRTG Traffic Grapher\PRTG Traffic Grapher.exe
O23 - Service: SlimServer (slimsvc) - Unknown owner - C:\Program Files\Slim\SlimServer\server\slim.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: WinFax PRO (wfxsvc) - Symantec Corporation - C:\WINDOWS\system32\WFXSVC.EXE
Hello dmacdmac,

Glad everything seems to be running fine. You need to update your Java. Please follow the other recommendations to help stay malware free.

Updating Java
  • Download the latest version of Java Runtime Environment (JRE) 5.0 Update 9.
  • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-1_5_0_09-windowsi586-p.exe to install the newest version.
STEP 1.
======
DON’T BECOME OVERCONFIDENT WITH ANTIVIRUS APPLICATIONS INSTALLED!!!

http://forum.malwareremoval.com/viewtopic….39eba6ea0b5e8ee

Stay up to date on security patches and be extremely wary of clicking on links and attachments that arrive unbidden in instant messages and e-mail.

"The number one thing the majority of the malicious code we're seeing now does is disable or delete anti-virus and other security software," Dunham said. "In a lot of cases, once the user clicks on that attachment, it's already too late."


Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
  • Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.


  • Visit Microsoft's Update Site Frequently - It is important that you visit Windows Updates regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

  • Install Ad-Aware - Install and download Ad-Aware. ou should also scan your computer with program on a regular basis just as you would an antivirus software in conjunction with Spybot.
    A tutorial on installing & using this product can be found here:
    Using Ad-aware to remove Spyware, Malware, & Hijackers from Your Computer

  • Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.
    A tutorial on installing & using this product can be found here:
    Using SpywareBlaster to protect your computer from Spyware and Malware

  • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.

  • More info on how to prevent malware you can also find here (By Tony Klein)
Follow this list and your potential for being infected again will reduce dramatically.

Thank you for allowing me to assist you.

Susan
Thanks Susan, I read the article and went back to the download site and found I was downloading the multilanguage file with "NetBean" before, so I downloaded without these options and the file size was under 300KB. Thank you so much again for your help, I am thinking about joining the classroom and perhaps I can help people out in the future. David
Glad we could help!

I am thinking about joining the classroom and perhaps I can help people out in the future.



I hope you do. We have wonderful teachers and a the spirit of cooperation exists. :)
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI