This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

The Troy Horse

39 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Let me have a fresh HJT log and i'll see what I can come up with. I'm assuming that I.E. 7 is responsible for this, but I don't honestly know as I haven't come across this problem before.
hi here is the latest and greatest HJT log…also this pc is running VERY slow…could the trojann have effected speed?

Logfile of HijackThis v1.99.1
Scan saved at 9:58:22 PM, on 30/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINXP\System32\smss.exe
C:\WINXP\system32\winlogon.exe
C:\WINXP\system32\services.exe
C:\WINXP\system32\lsass.exe
C:\WINXP\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINXP\Explorer.EXE
C:\WINXP\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINXP\system32\ctfmon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINXP\system32\crypserv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINXP\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\WINXP\System32\svchost.exe
C:\download central\search.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com/search/ie.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINXP\system32\ctfmon.exe
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1147225346055
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {EF148DBB-5B6D-4130-B2A1-661571E86260} (Playtime Games Launcher) - http://atlantis9.bigfishgames.com/Reef/en_…ameLauncher.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINXP\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINXP\SYSTEM32\WRLogonNTF.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINXP\SYSTEM32\crypserv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
At this moment in time I don't know why your PC is sluggish or why IE is messing about - isn't that reassuring!
If the PC was behaving and now isn't, that suggests that there are still nasties aboard - either they weren't all cleared out first time round or new ones are finding their way in.

The IE problem isn't a major issue, in that your browser still functions so it will keep.

Run the following online scan: Panda ActiveScan.
  • Please note that IE is required to run this scan.
  • You will need to fill in the "Country, region, email address" information before you can download and install the ActiveX components necessary to run the scan.
  • When you are asked to "Select a device to scan…", click on "My Computer".
When the scan has finished, click See Report > Save Report which by default will save the scan results as Activescan.txt in My Documents.

Copy and paste the result of the above scan into your next reply.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Download gmer.zip from here and save it to your Desktop.
You will need to unzip it before you run it.

To do this: Right click on the zipped folder and from the menu that appears, click on Extract All…
In the 'Extraction Wizard' window that opens, click on Next> and in the next window that appears, click on Next> again.
In the final window, click on Finish


Double click gmer.exe to begin:
  • Select the Rootkit Tab at the top.
  • Click the Scan button on the right.
  • When the scan has completed, click the Copy button underneath - this will save the report to your Clipboard.
  • Paste it into Notepad (Start > All Programs > Accessories > Notepad) and save it somewhere convenient.
  • Repeat this for the Autostart Tab.
Copy and paste both reports into your next reply - you may need to post them seperately.
ok here begins the logs with activescan.txt being first;


Incident Status Location

Adware:adware/securityerror Not disinfected c:\winxp\system32\ot.ico
Potentially unwanted tool:application/funweb Not disinfected c:\winxp\downloaded program files\f3initialsetup1.0.0.15.inf
Potentially unwanted tool:application/mywebsearch Not disinfected hkey_classes_root\clsid\{147A976E-EEE1-4377-8EA7-4716E4CDD239}
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\_RESTORE\TEMP\A0091904.CPY
Possible Virus. Not disinfected C:\_RESTORE\ARCHIVE\FS21.CAB[A0034870.CPY][rep52.exe][mdrpdev.exe]
Adware:Adware/MediaBack Not disinfected C:\_RESTORE\ARCHIVE\FS21.CAB[A0034870.CPY][rep52.exe][msprxcore.dll]
Possible Virus. Not disinfected C:\_RESTORE\ARCHIVE\FS21.CAB[A0034870.CPY][rep52.exe][obcore.exe]
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Program Files\PestPatrol\Quarantine\20050401035142.zip[Program Files/MyWebSearch/bar/Game/REVERSI.F3S]
Spyware:Cookie/Peel Not disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\ppq54.tmp
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINXP\system32\gamgspep.exe
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Sharyn\Cookies\sharyn@doubleclick[1].txt

now the gmer rootkit log

GMER 1.0.12.12011 - http://www.gmer.net
Rootkit scan 2006-12-04 00:11:28
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.12 —-

SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwOpenProcess
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwTerminateProcess

—- Devices - GMER 1.0.12 —-

Device \Driver\Tcpip \Device\Ip IRP_MJ_INTERNAL_DEVICE_CONTROL [F9A7885A] avgtdi.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_INTERNAL_DEVICE_CONTROL [F9A7885A] avgtdi.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_INTERNAL_DEVICE_CONTROL [F9A7885A] avgtdi.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_INTERNAL_DEVICE_CONTROL [F9A7885A] avgtdi.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_INTERNAL_DEVICE_CONTROL [F9A7885A] avgtdi.sys

—- EOF - GMER 1.0.12 —-

and now the autostart log
GMER 1.0.12.12011 - http://www.gmer.net
Autostart scan 2006-12-04 00:16:28
Windows 5.1.2600 Service Pack 2


HKLM\SYSTEM\CurrentControlSet\Control\Session Manager@BootExecute = autocheck autochk * SsiEfr.e SsiEfr.e SsiEfr.e /*file not found*/

HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems@Windows = %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16

HKLM\SYSTEM\CurrentControlSet\Control\WOW@cmdline = %SystemRoot%\system32\ntvdm.exe

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon >>>
@UserinitC:\WINXP\system32\userinit.exe, = C:\WINXP\system32\userinit.exe,
@ShellExplorer.exe = Explorer.exe
@System =
@UIHostlogonui.exe = logonui.exe

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ >>>
crypt32chain@DLLName = crypt32.dll
cryptnet@DLLName = cryptnet.dll
cscdll@DLLName = cscdll.dll
ScCertProp@DLLName = wlnotify.dll
Schedule@DLLName = wlnotify.dll
sclgntfy@DLLName = sclgntfy.dll
SensLogn@DLLName = WlNotify.dll
termsrv@DLLName = wlnotify.dll
WgaLogon@DLLName = WgaLogon.dll
wlballoon@DLLName = wlnotify.dll

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows@AppInit_DLLs =

HKLM\SYSTEM\CurrentControlSet\Services\ >>>
AudioSrv /*Windows Audio*/@ = %SystemRoot%\System32\svchost.exe -k netsvcs
AVG Anti-Spyware Guard /*AVG Anti-Spyware Guard*/@ = C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
Avg7Alrt /*AVG7 Alert Manager Server*/@ = C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
Avg7UpdSvc /*AVG7 Update Service*/@ = C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
AVGEMS /*AVG E-mail Scanner*/@ = C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
BITS /*Background Intelligent Transfer Service*/@ = %SystemRoot%\system32\svchost.exe -k netsvcs
Browser /*Computer Browser*/@ = %SystemRoot%\system32\svchost.exe -k netsvcs
Crypkey License /*Crypkey License*/@ = crypserv.exe
CryptSvc /*Cryptographic Services*/@ = %SystemRoot%\system32\svchost.exe -k netsvcs
DcomLaunch /*DCOM Server Process Launcher*/@ = %SystemRoot%\system32\svchost -k DcomLaunch
Dhcp /*DHCP Client*/@ = %SystemRoot%\system32\svchost.exe -k netsvcs
Dnscache /*DNS Client*/@ = %SystemRoot%\system32\svchost.exe -k NetworkService
ERSvc /*Error Reporting Service*/@ = %SystemRoot%\System32\svchost.exe -k netsvcs
Eventlog /*Event Log*/@ = %SystemRoot%\system32\services.exe
helpsvc /*Help and Support*/@ = %SystemRoot%\System32\svchost.exe -k netsvcs
HidServ /*HID Input Service*/@ = %SystemRoot%\System32\svchost.exe -k netsvcs
lanmanserver /*Server*/@ = %SystemRoot%\system32\svchost.exe -k netsvcs
lanmanworkstation /*Workstation*/@ = %SystemRoot%\system32\svchost.exe -k netsvcs
LmHosts /*TCP/IP NetBIOS Helper*/@ = %SystemRoot%\system32\svchost.exe -k LocalService
MDM /*Machine Debug Manager*/@ = "C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE"
PlugPlay /*Plug and Play*/@ = %SystemRoot%\system32\services.exe
PolicyAgent /*IPSEC Services*/@ = %SystemRoot%\system32\lsass.exe
ProtectedStorage /*Protected Storage*/@ = %SystemRoot%\system32\lsass.exe
RpcSs /*Remote Procedure Call (RPC)*/@ = %SystemRoot%\system32\svchost -k rpcss
SamSs /*Security Accounts Manager*/@ = %SystemRoot%\system32\lsass.exe
Schedule /*Task Scheduler*/@ = %SystemRoot%\System32\svchost.exe -k netsvcs
seclogon /*Secondary Logon*/@ = %SystemRoot%\System32\svchost.exe -k netsvcs
SENS /*System Event Notification*/@ = %SystemRoot%\system32\svchost.exe -k netsvcs
SharedAccess /*Windows Firewall/Internet Connection Sharing (ICS)*/@ = %SystemRoot%\system32\svchost.exe -k netsvcs
ShellHWDetection /*Shell Hardware Detection*/@ = %SystemRoot%\System32\svchost.exe -k netsvcs
Spooler /*Print Spooler*/@ = %SystemRoot%\system32\spoolsv.exe
srservice /*System Restore Service*/@ = %SystemRoot%\system32\svchost.exe -k netsvcs
StiSvc /*Windows Image Acquisition (WIA)*/@ = %SystemRoot%\system32\svchost.exe -k imgsvc
Themes /*Themes*/@ = %SystemRoot%\System32\svchost.exe -k netsvcs
TrkWks /*Distributed Link Tracking Client*/@ = %SystemRoot%\system32\svchost.exe -k netsvcs
UMWdf /*Windows User Mode Driver Framework*/@ = C:\WINXP\system32\wdfmgr.exe
W32Time /*Windows Time*/@ = %SystemRoot%\System32\svchost.exe -k netsvcs
WebClient /*WebClient*/@ = %SystemRoot%\system32\svchost.exe -k LocalService
WinDefend /*Windows Defender Service*/@ = "C:\Program Files\Windows Defender\MsMpEng.exe"
winmgmt /*Windows Management Instrumentation*/@ = %systemroot%\system32\svchost.exe -k netsvcs
wscsvc /*Security Center*/@ = %SystemRoot%\System32\svchost.exe -k netsvcs
wuauserv /*Automatic Updates*/@ = %systemroot%\system32\svchost.exe -k netsvcs
WZCSVC /*Wireless Zero Configuration*/@ = %SystemRoot%\System32\svchost.exe -k netsvcs

HKLM\Software\Microsoft\Windows\CurrentVersion\Run >>>
@AVG7_CCC:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP = C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
@type32"C:\Program Files\Microsoft IntelliType Pro\type32.exe" = "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
@IntelliPoint"C:\Program Files\Microsoft IntelliPoint\point32.exe" = "C:\Program Files\Microsoft IntelliPoint\point32.exe"
@SunJavaUpdateSched"C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe" = "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
@!AVG Anti-Spyware"C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized = "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized

HKCU\Software\Microsoft\Windows\CurrentVersion\Run >>>
@Yahoo! Pager"C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet = "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
@ctfmon.exeC:\WINXP\system32\ctfmon.exe = C:\WINXP\system32\ctfmon.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad >>>
@PostBootReminder%SystemRoot%\system32\SHELL32.dll = %SystemRoot%\system32\SHELL32.dll
@CDBurn%SystemRoot%\system32\SHELL32.dll = %SystemRoot%\system32\SHELL32.dll
@WebCheckC:\WINXP\system32\webcheck.dll = C:\WINXP\system32\webcheck.dll
@SysTrayC:\WINXP\system32\stobject.dll = C:\WINXP\system32\stobject.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler >>>
@{438755C2-A8BA-11D1-B96B-00A0C90312E1}%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{8C7461EF-2B13-11d2-BE35-3078302C2030}%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll

HKLM\Software\Classes\Folder\shell\open\command@ = %SystemRoot%\Explorer.exe /idlist,%I,%L

HKLM\Software\Classes\Folder\shell\explore\command@ = %SystemRoot%\Explorer.exe /e,/idlist,%I,%L

HKLM\Software\Classes\ >>>
.exe@ = "%1" %*
.com@ = "%1" %*
.cmd@ = "%1" %*
.bat@ = "%1" %*
.pif@ = "%1" %*
.scr@ = "%1" /S
.hta@ = C:\WINXP\system32\mshta.exe "%1" %*

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks >>>
@{AEB6717E-7E19-11d0-97EE-00C04FD91972}shell32.dll = shell32.dll
@{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}C:\PROGRA~1\WIFD1F~1\MpShHook.dll = C:\PROGRA~1\WIFD1F~1\MpShHook.dll
@{57B86673-276A-48B2-BAE7-C6DBB3020EB8}C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll = C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved >>>
@{00022613-0000-0000-C000-000000000046} /*Multimedia File Property Sheet*/mmsys.cpl = mmsys.cpl
@{176d6597-26d3-11d1-b350-080036a75b03} /*ICM Scanner Management*/icmui.dll = icmui.dll
@{1F2E5C40-9550-11CE-99D2-00AA006E086C} /*NTFS Security Page*/rshx32.dll = rshx32.dll
@{3EA48300-8CF6-101B-84FB-666CCB9BCD32} /*OLE Docfile Property Page*/docprop.dll = docprop.dll
@{40dd6e20-7c17-11ce-a804-00aa003ca9f6} /*Shell extensions for sharing*/ntshrui.dll = ntshrui.dll
@{41E300E0-78B6-11ce-849B-444553540000} /*PlusPack CPL Extension*/%SystemRoot%\system32\themeui.dll = %SystemRoot%\system32\themeui.dll
@{42071712-76d4-11d1-8b24-00a0c9068ff3} /*Display Adapter CPL Extension*/deskadp.dll = deskadp.dll
@{42071713-76d4-11d1-8b24-00a0c9068ff3} /*Display Monitor CPL Extension*/deskmon.dll = deskmon.dll
@{42071714-76d4-11d1-8b24-00a0c9068ff3} /*Display Panning CPL Extension*/deskpan.dll /*file not found*/ = deskpan.dll /*file not found*/
@{4E40F770-369C-11d0-8922-00A024AB2DBB} /*DS Security Page*/dssec.dll = dssec.dll
@{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8} /*Compatibility Page*/SlayerXP.dll = SlayerXP.dll
@{56117100-C0CD-101B-81E2-00AA004AE837} /*Shell Scrap DataHandler*/shscrap.dll = shscrap.dll
@{59099400-57FF-11CE-BD94-0020AF85B590} /*Disk Copy Extension*/diskcopy.dll = diskcopy.dll
@{59be4990-f85c-11ce-aff7-00aa003ca9f6} /*Shell extensions for Microsoft Windows Network objects*/ntlanui2.dll = ntlanui2.dll
@{5DB2625A-54DF-11D0-B6C4-0800091AA605} /*ICM Monitor Management*/%SystemRoot%\System32\icmui.dll = %SystemRoot%\System32\icmui.dll
@{675F097E-4C4D-11D0-B6C1-0800091AA605} /*ICM Printer Management*/%SystemRoot%\system32\icmui.dll = %SystemRoot%\system32\icmui.dll
@{764BF0E1-F219-11ce-972D-00AA00A14F56} /*Shell extensions for file compression*/(null) =
@{77597368-7b15-11d0-a0c2-080036af3f03} /*Web Printer Shell Extension*/printui.dll = printui.dll
@{7988B573-EC89-11cf-9C00-00AA00A14F56} /*Disk Quota UI*/dskquoui.dll = dskquoui.dll
@{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA} /*Encryption Context Menu*/(null) =
@{85BBD920-42A0-1069-A2E4-08002B30309D} /*Briefcase*/syncui.dll = syncui.dll
@{88895560-9AA2-1069-930E-00AA0030EBC8} /*HyperTerminal Icon Ext*/C:\WINXP\system32\hticons.dll = C:\WINXP\system32\hticons.dll
@{BD84B380-8CA2-1069-AB1D-08000948F534} /*Fonts*/fontext.dll = fontext.dll
@{DBCE2480-C732-101B-BE72-BA78E9AD5B27} /*ICC Profile*/%SystemRoot%\system32\icmui.dll = %SystemRoot%\system32\icmui.dll
@{F37C5810-4D3F-11d0-B4BF-00AA00BBB723} /*Printers Security Page*/rshx32.dll = rshx32.dll
@{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} /*Shell extensions for sharing*/ntshrui.dll = ntshrui.dll
@{f92e8c40-3d33-11d2-b1aa-080036a75b03} /*Display TroubleShoot CPL Extension*/deskperf.dll = deskperf.dll
@{7444C717-39BF-11D1-8CD9-00C04FC29D45} /*Crypto PKO Extension*/C:\WINXP\system32\cryptext.dll = C:\WINXP\system32\cryptext.dll
@{7444C719-39BF-11D1-8CD9-00C04FC29D45} /*Crypto Sign Extension*/C:\WINXP\system32\cryptext.dll = C:\WINXP\system32\cryptext.dll
@{7007ACC7-3202-11D1-AAD2-00805FC1270E} /*Network Connections*/C:\WINXP\system32\NETSHELL.dll = C:\WINXP\system32\NETSHELL.dll
@{992CFFA0-F557-101A-88EC-00DD010CCC48} /*Network Connections*/C:\WINXP\system32\NETSHELL.dll = C:\WINXP\system32\NETSHELL.dll
@{E211B736-43FD-11D1-9EFB-0000F8757FCD} /*Scanners & Cameras*/wiashext.dll = wiashext.dll
@{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD} /*Scanners & Cameras*/wiashext.dll = wiashext.dll
@{905667aa-acd6-11d2-8080-00805f6596d2} /*Scanners & Cameras*/wiashext.dll = wiashext.dll
@{3F953603-1008-4f6e-A73A-04AAC7A992F1} /*Scanners & Cameras*/wiashext.dll = wiashext.dll
@{83bbcbf3-b28a-4919-a5aa-73027445d672} /*Scanners & Cameras*/wiashext.dll = wiashext.dll
@{F0152790-D56E-4445-850E-4F3117DB740C} /*Remote Sessions CPL Extension*/C:\WINXP\system32\remotepg.dll = C:\WINXP\system32\remotepg.dll
@{60254CA5-953B-11CF-8C96-00AA00B8708C} /*Shell extensions for Windows Script Host*/C:\WINXP\system32\wshext.dll = C:\WINXP\system32\wshext.dll
@{2206CDB2-19C1-11D1-89E0-00C04FD7A829} /*Microsoft Data Link*/C:\Program Files\Common Files\System\Ole DB\oledb32.dll = C:\Program Files\Common Files\System\Ole DB\oledb32.dll
@{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF} /*Tasks Folder Icon Handler*/C:\WINXP\system32\mstask.dll = C:\WINXP\system32\mstask.dll
@{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF} /*Tasks Folder Shell Extension*/C:\WINXP\system32\mstask.dll = C:\WINXP\system32\mstask.dll
@{D6277990-4C6A-11CF-8D87-00AA0060F5BF} /*Scheduled Tasks*/C:\WINXP\system32\mstask.dll = C:\WINXP\system32\mstask.dll
@{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0} /*Set Program Access and Defaults*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{5F327514-6C5E-4d60-8F16-D07FA08A78ED} /*Auto Update Property Sheet Extension*/C:\WINXP\system32\wuaucpl.cpl = C:\WINXP\system32\wuaucpl.cpl
@{0DF44EAA-FF21-4412-828E-260A8728E7F1} /*Taskbar and Start Menu*/(null) =
@{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0} /*Search*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0} /*Help and Support*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0} /*Help and Support*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0} /*Run…*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0} /*Internet*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0} /*E-mail*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{D20EA4E1-3957-11d2-A40B-0C5020524152} /*Fonts*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{D20EA4E1-3957-11d2-A40B-0C5020524153} /*Administrative Tools*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{596AB062-B4D2-4215-9F74-E9109B0A8153} /*Previous Versions Property Page*/%SystemRoot%\system32\twext.dll = %SystemRoot%\system32\twext.dll
@{9DB7A13C-F208-4981-8353-73CC61AE2783} /*Previous Versions*/%SystemRoot%\system32\twext.dll = %SystemRoot%\system32\twext.dll
@{875CB1A1-0F29-45de-A1AE-CFB4950D0B78} /*Audio Media Properties Handler*/%SystemRoot%\system32\shmedia.dll = %SystemRoot%\system32\shmedia.dll
@{40C3D757-D6E4-4b49-BB41-0E5BBEA28817} /*Video Media Properties Handler*/%SystemRoot%\system32\shmedia.dll = %SystemRoot%\system32\shmedia.dll
@{E4B29F9D-D390-480b-92FD-7DDB47101D71} /*Wav Properties Handler*/%SystemRoot%\system32\shmedia.dll = %SystemRoot%\system32\shmedia.dll
@{87D62D94-71B3-4b9a-9489-5FE6850DC73E} /*Avi Properties Handler*/%SystemRoot%\system32\shmedia.dll = %SystemRoot%\system32\shmedia.dll
@{A6FD9E45-6E44-43f9-8644-08598F5A74D9} /*Midi Properties Handler*/%SystemRoot%\system32\shmedia.dll = %SystemRoot%\system32\shmedia.dll
@{c5a40261-cd64-4ccf-84cb-c394da41d590} /*Video Thumbnail Extractor*/%SystemRoot%\system32\shmedia.dll = %SystemRoot%\system32\shmedia.dll
@{5E6AB780-7743-11CF-A12B-00AA004AE837} /*Microsoft Internet Toolbar*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{22BF0C20-6DA7-11D0-B373-00A0C9034938} /*Download Status*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{91EA3F8B-C99B-11d0-9815-00C04FD91972} /*Augmented Shell Folder*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{6413BA2C-B461-11d1-A18A-080036B11A03} /*Augmented Shell Folder 2*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{F61FFEC1-754F-11d0-80CA-00AA005B4383} /*BandProxy*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{7BA4C742-9E81-11CF-99D3-00AA004AE837} /*Microsoft BrowserBand*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{30D02401-6A81-11d0-8274-00C04FD5AE38} /*IE Search Band*/C:\WINXP\system32\ieframe.dll = C:\WINXP\system32\ieframe.dll
@{169A0691-8DF9-11d1-A1C4-00C04FD75D13} /*In-pane search*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{07798131-AF23-11d1-9111-00A0C98BA67D} /*Web Search*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{AF4F6510-F982-11d0-8595-00AA004CD6D8} /*Registry Tree Options Utility*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{01E04581-4EEE-11d0-BFE9-00AA005B4383} /*&Address*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{A08C11D2-A228-11d0-825B-00AA005B4383} /*Address EditBox*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{00BB2763-6A77-11D0-A535-00C04FD7D062} /*Microsoft AutoComplete*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{7376D660-C583-11d0-A3A5-00C04FD706EC} /*TridentImageExtractor*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{6756A641-DE71-11d0-831B-00AA005B4383} /*MRU AutoComplete List*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A} /*Custom MRU AutoCompleted List*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{7e653215-fa25-46bd-a339-34a2790f3cb7} /*Accessible*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{acf35015-526e-4230-9596-becbe19f0ac9} /*Track Popup Bar*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{00BB2764-6A77-11D0-A535-00C04FD7D062} /*Microsoft History AutoComplete List*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{03C036F1-A186-11D0-824A-00AA005B4383} /*Microsoft Shell Folder AutoComplete List*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{00BB2765-6A77-11D0-A535-00C04FD7D062} /*Microsoft Multiple AutoComplete List Container*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{ECD4FC4E-521C-11D0-B792-00A0C90312E1} /*Shell Band Site Menu*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{3CCF8A41-5C85-11d0-9796-00AA00B90ADF} /*Shell DeskBarApp*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{ECD4FC4C-521C-11D0-B792-00A0C90312E1} /*Shell DeskBar*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{ECD4FC4D-521C-11D0-B792-00A0C90312E1} /*Shell Rebar BandSite*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{DD313E04-FEFF-11d1-8ECD-0000F87A470C} /*User Assist*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11} /*Global Folder Settings*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{EFA24E61-B078-11d0-89E4-00C04FC9E26E} /*Favorites Band*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{0A89A860-D7B1-11CE-8350-444553540000} /*Shell Automation Inproc Service*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} /*Shell DocObject Viewer*/C:\WINXP\system32\ieframe.dll = C:\WINXP\system32\ieframe.dll
@{A5E46E3A-8849-11D1-9D8C-00C04FC99D61} /*Microsoft Browser Architecture*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{FBF23B40-E3F0-101B-8488-00AA003E56F8} /*InternetShortcut*/C:\WINXP\system32\ieframe.dll = C:\WINXP\system32\ieframe.dll
@{3C374A40-BAE4-11CF-BF7D-00AA006946EE} /*Microsoft Url History Service*/C:\WINXP\system32\ieframe.dll = C:\WINXP\system32\ieframe.dll
@{FF393560-C2A7-11CF-BFF4-444553540000} /*History*/C:\WINXP\system32\ieframe.dll = C:\WINXP\system32\ieframe.dll
@{7BD29E00-76C1-11CF-9DD0-00A0C9034933} /*Temporary Internet Files*/C:\WINXP\system32\ieframe.dll = C:\WINXP\system32\ieframe.dll
@{7BD29E01-76C1-11CF-9DD0-00A0C9034933} /*Temporary Internet Files*/C:\WINXP\system32\ieframe.dll = C:\WINXP\system32\ieframe.dll
@{CFBFAE00-17A6-11D0-99CB-00C04FD64497} /*Microsoft Url Search Hook*/C:\WINXP\system32\ieframe.dll = C:\WINXP\system32\ieframe.dll
@{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC} /*IE4 Suite Splash Screen*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{67EA19A0-CCEF-11d0-8024-00C04FD75D13} /*CDF Extension Copy Hook*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{131A6951-7F78-11D0-A979-00C04FD705A2} /*ISFBand OC*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{9461b922-3c5a-11d2-bf8b-00c04fb93661} /*Search Assistant OC*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{3DC7A020-0ACD-11CF-A9BB-00AA004AE837} /*The Internet*/C:\WINXP\system32\ieframe.dll = C:\WINXP\system32\ieframe.dll
@{871C5380-42A0-1069-A2EA-08002B30309D} /*Internet Name Space*/C:\WINXP\system32\ieframe.dll = C:\WINXP\system32\ieframe.dll
@{EFA24E64-B078-11d0-89E4-00C04FC9E26E} /*Explorer Band*/%SystemRoot%\system32\shdocvw.dll = %SystemRoot%\system32\shdocvw.dll
@{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE} /*Sendmail service*/C:\WINXP\system32\sendmail.dll = C:\WINXP\system32\sendmail.dll
@{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE} /*Sendmail service*/C:\WINXP\system32\sendmail.dll = C:\WINXP\system32\sendmail.dll
@{88C6C381-2E85-11D0-94DE-444553540000} /*ActiveX Cache Folder*/C:\WINXP\system32\occache.dll = C:\WINXP\system32\occache.dll
@{E6FB5E20-DE35-11CF-9C87-00AA005127ED} /*WebCheck*/C:\WINXP\system32\webcheck.dll = C:\WINXP\system32\webcheck.dll
@{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE} /*Subscription Mgr*/C:\WINXP\system32\webcheck.dll = C:\WINXP\system32\webcheck.dll
@{F5175861-2688-11d0-9C5E-00AA00A45957} /*Subscription Folder*/C:\WINXP\system32\webcheck.dll = C:\WINXP\system32\webcheck.dll
@{08165EA0-E946-11CF-9C87-00AA005127ED} /*WebCheckWebCrawler*/C:\WINXP\system32\webcheck.dll = C:\WINXP\system32\webcheck.dll
@{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB} /*WebCheckChannelAgent*/%SystemRoot%\system32\webcheck.dll = %SystemRoot%\system32\webcheck.dll
@{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7} /*TrayAgent*/%SystemRoot%\system32\webcheck.dll = %SystemRoot%\system32\webcheck.dll
@{7D559C10-9FE9-11d0-93F7-00AA0059CE02} /*Code Download Agent*/C:\WINXP\system32\webcheck.dll = C:\WINXP\system32\webcheck.dll
@{E6CC6978-6B6E-11D0-BECA-00C04FD940BE} /*ConnectionAgent*/%SystemRoot%\system32\webcheck.dll = %SystemRoot%\system32\webcheck.dll
@{D8BD2030-6FC9-11D0-864F-00AA006809D9} /*PostAgent*/%SystemRoot%\system32\webcheck.dll = %SystemRoot%\system32\webcheck.dll
@{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB} /*WebCheck SyncMgr Handler*/C:\WINXP\system32\webcheck.dll = C:\WINXP\system32\webcheck.dll
@{352EC2B7-8B9A-11D1-B8AE-006008059382} /*Shell Application Manager*/%SystemRoot%\system32\appwiz.cpl = %SystemRoot%\system32\appwiz.cpl
@{0B124F8F-91F0-11D1-B8B5-006008059382} /*Installed Apps Enumerator*/%SystemRoot%\system32\appwiz.cpl = %SystemRoot%\system32\appwiz.cpl
@{CFCCC7A0-A282-11D1-9082-006008059382} /*Darwin App Publisher*/%SystemRoot%\system32\appwiz.cpl = %SystemRoot%\system32\appwiz.cpl
@{e84fda7c-1d6a-45f6-b725-cb260c236066} /*Shell Image Verbs*/%SystemRoot%\system32\shimgvw.dll = %SystemRoot%\system32\shimgvw.dll
@{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178} /*Shell Image Data Factory*/%SystemRoot%\system32\shimgvw.dll = %SystemRoot%\system32\shimgvw.dll
@{00E7B358-F65B-4dcf-83DF-CD026B94BFD4} /*Autoplay for SlideShow*/(null) =
@{3F30C968-480A-4C6C-862D-EFC0897BB84B} /*GDI+ file thumbnail extractor*/C:\WINXP\system32\shimgvw.dll = C:\WINXP\system32\shimgvw.dll
@{9DBD2C50-62AD-11d0-B806-00C04FD706EC} /*Summary Info Thumbnail handler (DOCFILES)*/C:\WINXP\system32\shimgvw.dll = C:\WINXP\system32\shimgvw.dll
@{EAB841A0-9550-11cf-8C16-00805F1408F3} /*HTML Thumbnail Extractor*/C:\WINXP\system32\shimgvw.dll = C:\WINXP\system32\shimgvw.dll
@{eb9b1153-3b57-4e68-959a-a3266bc3d7fe} /*Shell Image Property Handler*/%SystemRoot%\system32\shimgvw.dll = %SystemRoot%\system32\shimgvw.dll
@{CC6EEFFB-43F6-46c5-9619-51D571967F7D} /*Web Publishing Wizard*/%SystemRoot%\system32\netplwiz.dll = %SystemRoot%\system32\netplwiz.dll
@{add36aa8-751a-4579-a266-d66f5202ccbb} /*Print Ordering via the Web*/%SystemRoot%\system32\netplwiz.dll = %SystemRoot%\system32\netplwiz.dll
@{6b33163c-76a5-4b6c-bf21-45de9cd503a1} /*Shell Publishing Wizard Object*/%SystemRoot%\system32\netplwiz.dll = %SystemRoot%\system32\netplwiz.dll
@{58f1f272-9240-4f51-b6d4-fd63d1618591} /*Get a Passport Wizard*/%SystemRoot%\system32\netplwiz.dll = %SystemRoot%\system32\netplwiz.dll
@{7A9D77BD-5403-11d2-8785-2E0420524153} /*User Accounts*/(null) =
@{E88DCCE0-B7B3-11d1-A9F0-00AA0060FA31} /*Compressed (zipped) Folder*/%SystemRoot%\system32\zipfldr.dll = %SystemRoot%\system32\zipfldr.dll
@{BD472F60-27FA-11cf-B8B4-444553540000} /*Compressed (zipped) Folder Right Drag Handler*/%SystemRoot%\system32\zipfldr.dll = %SystemRoot%\system32\zipfldr.dll
@{888DCA60-FC0A-11CF-8F0F-00C04FD7D062} /*Compressed (zipped) Folder SendTo Target*/%SystemRoot%\system32\zipfldr.dll = %SystemRoot%\system32\zipfldr.dll
@{692F0339-CBAA-47e6-B5B5-3B84DB604E87} /*Extensions Manager Folder*/C:\WINXP\system32\extmgr.dll = C:\WINXP\system32\extmgr.dll
@{63da6ec0-2e98-11cf-8d82-444553540000} /*FTP Folders Webview*/C:\WINXP\system32\msieftp.dll = C:\WINXP\system32\msieftp.dll
@{883373C3-BF89-11D1-BE35-080036B11A03} /*Microsoft DocProp Shell Ext*/C:\WINXP\system32\docprop2.dll = C:\WINXP\system32\docprop2.dll
@{A9CF0EAE-901A-4739-A481-E35B73E47F6D} /*Microsoft DocProp Inplace Edit Box Control*/C:\WINXP\system32\docprop2.dll = C:\WINXP\system32\docprop2.dll
@{8EE97210-FD1F-4B19-91DA-67914005F020} /*Microsoft DocProp Inplace ML Edit Box Control*/C:\WINXP\system32\docprop2.dll = C:\WINXP\system32\docprop2.dll
@{0EEA25CC-4362-4A12-850B-86EE61B0D3EB} /*Microsoft DocProp Inplace Droplist Combo Control*/C:\WINXP\system32\docprop2.dll = C:\WINXP\system32\docprop2.dll
@{6A205B57-2567-4A2C-B881-F787FAB579A3} /*Microsoft DocProp Inplace Calendar Control*/C:\WINXP\system32\docprop2.dll = C:\WINXP\system32\docprop2.dll
@{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33} /*Microsoft DocProp Inplace Time Control*/C:\WINXP\system32\docprop2.dll = C:\WINXP\system32\docprop2.dll
@{8A23E65E-31C2-11d0-891C-00A024AB2DBB} /*Directory Query UI*/%SystemRoot%\system32\dsquery.dll = %SystemRoot%\system32\dsquery.dll
@{9E51E0D0-6E0F-11d2-9601-00C04FA31A86} /*Shell properties for a DS object*/%SystemRoot%\system32\dsquery.dll = %SystemRoot%\system32\dsquery.dll
@{163FDC20-2ABC-11d0-88F0-00A024AB2DBB} /*Directory Object Find*/%SystemRoot%\system32\dsquery.dll = %SystemRoot%\system32\dsquery.dll
@{F020E586-5264-11d1-A532-0000F8757D7E} /*Directory Start/Search Find*/%SystemRoot%\system32\dsquery.dll = %SystemRoot%\system32\dsquery.dll
@{0D45D530-764B-11d0-A1CA-00AA00C16E65} /*Directory Property UI*/%SystemRoot%\system32\dsuiext.dll = %SystemRoot%\system32\dsuiext.dll
@{62AE1F9A-126A-11D0-A14B-0800361B1103} /*Directory Context Menu Verbs*/%SystemRoot%\system32\dsuiext.dll = %SystemRoot%\system32\dsuiext.dll
@{ECF03A33-103D-11d2-854D-006008059367} /*MyDocs Copy Hook*/%SystemRoot%\system32\mydocs.dll = %SystemRoot%\system32\mydocs.dll
@{ECF03A32-103D-11d2-854D-006008059367} /*MyDocs Drop Target*/%SystemRoot%\system32\mydocs.dll = %SystemRoot%\system32\mydocs.dll
@{4a7ded0a-ad25-11d0-98a8-0800361b1103} /*MyDocs Properties*/%SystemRoot%\system32\mydocs.dll = %SystemRoot%\system32\mydocs.dll
@{750fdf0e-2a26-11d1-a3ea-080036587f03} /*Offline Files Menu*/%SystemRoot%\System32\cscui.dll = %SystemRoot%\System32\cscui.dll
@{10CFC467-4392-11d2-8DB4-00C04FA31A66} /*Offline Files Folder Options*/%SystemRoot%\System32\cscui.dll = %SystemRoot%\System32\cscui.dll
@{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E} /*Offline Files Folder*/%SystemRoot%\System32\cscui.dll = %SystemRoot%\System32\cscui.dll
@{143A62C8-C33B-11D1-84FE-00C04FA34A14} /*Microsoft Agent Character Property Sheet Handler*/C:\WINXP\msagent\agentpsh.dll = C:\WINXP\msagent\agentpsh.dll
@{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6} /*DfsShell*/C:\WINXP\system32\dfsshlex.dll = C:\WINXP\system32\dfsshlex.dll
@{60fd46de-f830-4894-a628-6fa81bc0190d} /*%DESC_PublishDropTarget%*/%SystemRoot%\system32\photowiz.dll = %SystemRoot%\system32\photowiz.dll
@{7A80E4A8-8005-11D2-BCF8-00C04F72C717} /*MMC Icon Handler*/%SystemRoot%\System32\mmcshext.dll = %SystemRoot%\System32\mmcshext.dll
@{0CD7A5C0-9F37-11CE-AE65-08002B2E1262} /*.CAB file viewer*/cabview.dll = cabview.dll
@{32714800-2E5F-11d0-8B85-00AA0044F941} /*For &People…*/C:\Program Files\Outlook Express\wabfind.dll = C:\Program Files\Outlook Express\wabfind.dll
@{8DD448E6-C188-4aed-AF92-44956194EB1F} /*Windows Media Player Play as Playlist Context Menu Handler*/C:\WINXP\system32\wmpshell.dll = C:\WINXP\system32\wmpshell.dll
@{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C} /*Windows Media Player Burn Audio CD Context Menu Handler*/C:\WINXP\system32\wmpshell.dll = C:\WINXP\system32\wmpshell.dll
@{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD} /*Windows Media Player Add to Playlist Context Menu Handler*/C:\WINXP\system32\wmpshell.dll = C:\WINXP\system32\wmpshell.dll
@{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} /*AVG7 Shell Extension*/C:\Program Files\Grisoft\AVG Free\avgse.dll = C:\Program Files\Grisoft\AVG Free\avgse.dll
@{9F97547E-460A-42C5-AE0C-81C61FFAEBC3} /*AVG7 Find Extension*/C:\Program Files\Grisoft\AVG Free\avgse.dll = C:\Program Files\Grisoft\AVG Free\avgse.dll
@{E0D79304-84BE-11CE-9641-444553540000} /*WinZip*/C:\PROGRA~1\WINZIP\WZSHLSTB.DLL = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
@{E0D79305-84BE-11CE-9641-444553540000} /*WinZip*/C:\PROGRA~1\WINZIP\WZSHLSTB.DLL = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
@{E0D79306-84BE-11CE-9641-444553540000} /*WinZip*/C:\PROGRA~1\WINZIP\WZSHLSTB.DLL = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
@{E0D79307-84BE-11CE-9641-444553540000} /*WinZip*/C:\PROGRA~1\WINZIP\WZSHLSTB.DLL = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
@{640167b4-59b0-47a6-b335-a6b3c0695aea} /*Portable Media Devices*/%SystemRoot%\system32\Audiodev.dll = %SystemRoot%\system32\Audiodev.dll
@{cc86590a-b60a-48e6-996b-41d25ed39a1e} /*Portable Media Devices Menu*/%SystemRoot%\system32\Audiodev.dll = %SystemRoot%\system32\Audiodev.dll
@{21569614-B795-46b1-85F4-E737A8DC09AD} /*Shell Search Band*/%SystemRoot%\system32\browseui.dll = %SystemRoot%\system32\browseui.dll
@{8FF88D21-7BD0-11D1-BFB7-00AA00262A11} /*WinAce Archiver 2.6 Context Menu Shell Extension*/(null) =
@{8FF88D25-7BD0-11D1-BFB7-00AA00262A11} /*WinAce Archiver 2.6 DragDrop Shell Extension*/(null) =
@{8FF88D27-7BD0-11D1-BFB7-00AA00262A11} /*WinAce Archiver 2.6 Context Menu Shell Extension*/(null) =
@{8FF88D23-7BD0-11D1-BFB7-00AA00262A11} /*WinAce Archiver 2.6 Property Sheet Shell Extension*/(null) =
@{B327765E-D724-4347-8B16-78AE18552FC3} /*NeroDigitalIconHandler*/C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll = C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll
@{7F1CF152-04F8-453A-B34C-E609530A9DC8} /*NeroDigitalPropSheetHandler*/C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll = C:\Program Files\Common Files\Ahead\Lib\NeroDigitalExt.dll
@{C2DC6E27-64F9-4273-9623-D74617325F62} /*Messenger ServiceExt Extension*/(null) =
@{5464D816-CF16-4784-B9F3-75C0DB52B499} /*Yahoo! Mail*/C:\PROGRA~1\YAHOO!\COMMON\ymmapi.dll = C:\PROGRA~1\YAHOO!\COMMON\ymmapi.dll
@{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D} /*Messenger Sharing Folders*/C:\Program Files\MSN Messenger\fsshext.8.0.0812.00.dll = C:\Program Files\MSN Messenger\fsshext.8.0.0812.00.dll
@{97FA8AA2-EE77-4FF2-9449-424D8924EF21} /*IntelliType Pro Zooming Control Panel Property Page*/"C:\Program Files\Microsoft IntelliType Pro\itcplzm.dll" = "C:\Program Files\Microsoft IntelliType Pro\itcplzm.dll"
@{111D8120-25EB-4E1C-A4DF-C9EE5FCA35CB} /*IntelliType Pro Scrolling Control Panel Property Page*/"C:\Program Files\Microsoft IntelliType Pro\itcplwhl.dll" = "C:\Program Files\Microsoft IntelliType Pro\itcplwhl.dll"
@{ED6E87C6-8A83-43aa-8208-8DBC8247F4D2} /*IntelliType Pro Key Settings Control Panel Property Page*/"C:\Program Files\Microsoft IntelliType Pro\itcplkey.dll" = "C:\Program Files\Microsoft IntelliType Pro\itcplkey.dll"
@{A2569D1F-4E06-43EC-9825-0088B471BE47} /*IntelliType Pro Wireless Control Panel Property Page*/"C:\Program Files\Microsoft IntelliType Pro\itcplwir.dll" = "C:\Program Files\Microsoft IntelliType Pro\itcplwir.dll"
@{20082881-FC36-4E47-9A7A-644C95FF749F} /*IntelliPoint Wireless Control Panel Property Page*/"C:\Program Files\Microsoft IntelliPoint\ipcplwir.dll" = "C:\Program Files\Microsoft IntelliPoint\ipcplwir.dll"
@{AF90F543-6A3A-4C1B-8B16-ECEC073E69BE} /*IntelliPoint Wheel Control Panel Property Page*/"C:\Program Files\Microsoft IntelliPoint\ipcplwhl.dll" = "C:\Program Files\Microsoft IntelliPoint\ipcplwhl.dll"
@{653DCCC2-13DB-45B2-A389-427885776CFE} /*IntelliPoint Activities Control Panel Property Page*/"C:\Program Files\Microsoft IntelliPoint\ipcplact.dll" = "C:\Program Files\Microsoft IntelliPoint\ipcplact.dll"
@{124597D8-850A-41AE-849C-017A4FA99CA2} /*IntelliPoint Buttons Control Panel Property Page*/"C:\Program Files\Microsoft IntelliPoint\ipcplbtn.dll" = "C:\Program Files\Microsoft IntelliPoint\ipcplbtn.dll"
@{BDEADF00-C265-11D0-BCED-00A0C90AB50F} /*Web Folders*/C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL = C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
@{00020D75-0000-0000-C000-000000000046} /*Microsoft Office Outlook Desktop Icon Handler*/C:\PROGRA~1\MICROS~1\OFFICE11\MLSHEXT.DLL = C:\PROGRA~1\MICROS~1\OFFICE11\MLSHEXT.DLL
@{0006F045-0000-0000-C000-000000000046} /*Microsoft Office Outlook Custom Icon Handler*/C:\PROGRA~1\MICROS~1\OFFICE11\OLKFSTUB.DLL = C:\PROGRA~1\MICROS~1\OFFICE11\OLKFSTUB.DLL
@{42042206-2D85-11D3-8CFF-005004838597} /*Microsoft Office HTML Icon Handler*/C:\Program Files\Microsoft Office\OFFICE11\msohev.dll = C:\Program Files\Microsoft Office\OFFICE11\msohev.dll
@{07C45BB1-4A8C-4642-A1F5-237E7215FF66} /*IE Microsoft BrowserBand*/C:\WINXP\system32\ieframe.dll = C:\WINXP\system32\ieframe.dll
@{1C1EDB47-CE22-4bbb-B608-77B48F83C823} /*IE Fade Task*/C:\WINXP\system32\ieframe.dll = C:\WINXP\system32\ieframe.dll
@{205D7A97-F16D-4691-86EF-F3075DCCA57D} /*IE Menu Desk Bar*/C:\WINXP\system32\ieframe.dll = C:\WINXP\system32\ieframe.dll
@{3028902F-6374-48b2-8DC6-9725E775B926} /*IE AutoComplete*/C:\WINXP\system32\ieframe.dll = C:\WINXP\system32\ieframe.dll
@{43886CD5-6529-41c4-A707-7B3C92C05E68} /*IE Navigation Bar*/C:\WINXP\system32\ieframe.dll = C:\WINXP\system32\ieframe.dll
@{44C76ECD-F7FA-411c-9929-1B77BA77F524} /*IE Menu Site*/C:\WINXP\system32\ieframe.dll = C:\WINXP\system32\ieframe.dll
@{4B78D326-D922-44f9-AF2A-07805C2A3560} /*IE Menu Band*/C:\WINXP\system32\ieframe.dll = C:\WINXP\system32\ieframe.dll
@{6038EF75-ABFC-4e59-AB6F-12D397F6568D} /*IE Microsoft History AutoComplete List*/C:\WINXP\system32\ieframe.dll = C:\WINXP\system32\ieframe.dll
@{6B4ECC4F-16D1-4474-94AB-5A763F2A54AE} /*IE Tracking Shell Menu*/C:\WINXP\system32\ieframe.dll = C:\WINXP\system32\ieframe.dll
@{6CF48EF8-44CD-45d2-8832-A16EA016311B} /*IE IShellFolderBand*/C:\WINXP\system32\ieframe.dll = C:\WINXP\system32\ieframe.dll
@{73CFD649-CD48-4fd8-A272-2070EA56526B} /*IE BandProxy*/C:\WINXP\system32\ieframe.dll = C:\WINXP\system32\ieframe.dll
@{98FF6D4B-6387-4b0a-8FBD-C5C4BB17B4F8} /*IE MRU AutoComplete List*/C:\WINXP\system32\ieframe.dll = C:\WINXP\system32\ieframe.dll
@{9A096BB5-9DC3-4D1C-8526-C3CBF991EA4E} /*IE RSS Feeder Folder*/C:\WINXP\system32\ieframe.dll = C:\WINXP\system32\ieframe.dll
@{9D958C62-3954-4b44-8FAB-C4670C1DB4C2} /*IE Microsoft Shell Folder AutoComplete List*/C:\WINXP\system32\ieframe.dll = C:\WINXP\system32\ieframe.dll
@{B31C5FAE-961F-415b-BAF0-E697A5178B94} /*IE Microsoft Multiple AutoComplete List Container*/C:\WINXP\system32\ieframe.dll = C:\WINXP\system32\ieframe.dll
@{BC476F4C-D9D7-4100-8D4E-E043F6DEC409} /*Microsoft Browser Architecture*/C:\WINXP\system32\ieframe.dll = C:\WINXP\system32\ieframe.dll
@{BFAD62EE-9D54-4b2a-BF3B-76F90697BD2A} /*IE Shell Rebar BandSite*/C:\WINXP\system32\ieframe.dll = C:\WINXP\system32\ieframe.dll
@{E6EE9AAC-F76B-4947-8260-A9F136138E11} /*IE Shell Band Site Menu*/C:\WINXP\system32\ieframe.dll = C:\WINXP\system32\ieframe.dll
@{F2CF5485-4E02-4f68-819C-B92DE9277049} /*&Links*/C:\WINXP\system32\ieframe.dll = C:\WINXP\system32\ieframe.dll
@{F83DAC1C-9BB9-4f2b-B619-09819DA81B0E} /*IE Registry Tree Options Utility*/C:\WINXP\system32\ieframe.dll = C:\WINXP\system32\ieframe.dll
@{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} /*IE User Assist*/C:\WINXP\system32\ieframe.dll = C:\WINXP\system32\ieframe.dll
@{FDE7673D-2E19-4145-8376-BBD58C4BC7BA} /*IE Custom MRU AutoCompleted List*/C:\WINXP\system32\ieframe.dll = C:\WINXP\system32\ieframe.dll

HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved@{BDEADF00-C265-11d0-BCED-00A0C90AB50F} /*Web Folders*/ = C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL

HKLM\Software\Classes\*\shellex\ContextMenuHandlers\ >>>
AVG Anti-Spyware@{8934FCEF-F5B8-468f-951F-78A921CD3920} = C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll
AVG7 Shell Extension@{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} = C:\Program Files\Grisoft\AVG Free\avgse.dll
Offline Files@{750fdf0e-2a26-11d1-a3ea-080036587f03} = %SystemRoot%\System32\cscui.dll
Open With@{09799AFB-AD67-11d1-ABCD-00C04FC30936} = %SystemRoot%\system32\SHELL32.dll
Open With EncryptionMenu@{A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\SHELL32.dll
WinZip@{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
Yahoo! Mail@{5464D816-CF16-4784-B9F3-75C0DB52B499} = C:\PROGRA~1\YAHOO!\COMMON\ymmapi.dll

HKLM\Software\Classes\*\shellex\ContextMenuHandlers >>>
@{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}%SystemRoot%\system32\SHELL32.dll = %SystemRoot%\system32\SHELL32.dll
@{EB4D3CFE-E2AA-4C6E-B2FE-2A749F95D208}C:\Program Files\Nero\Nero 7\Nero BackItUp\NBShell.dll = C:\Program Files\Nero\Nero 7\Nero BackItUp\NBShell.dll

HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ >>>
AVG Anti-Spyware@{8934FCEF-F5B8-468f-951F-78A921CD3920} = C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll
EncryptionMenu@{A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\SHELL32.dll
Offline Files@{750fdf0e-2a26-11d1-a3ea-080036587f03} = %SystemRoot%\System32\cscui.dll
Sharing@{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} = ntshrui.dll
WinZip@{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL

HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ >>>
AVG7 Shell Extension@{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} = C:\Program Files\Grisoft\AVG Free\avgse.dll
WinZip@{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL

HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers@{EB4D3CFE-E2AA-4C6E-B2FE-2A749F95D208} = C:\Program Files\Nero\Nero 7\Nero BackItUp\NBShell.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects >>>
@{02478D38-C3F9-4EFB-9B51-7695ECA05670}C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll = C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
@{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}C:\Program Files\Yahoo!\Common\yiesrvc.dll = C:\Program Files\Yahoo!\Common\yiesrvc.dll
@{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll = C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll

HKCU\Control Panel\[removed] = none /*file not found*/

HKLM\Software\Microsoft\Internet Explorer\Main >>>
@Start Pageabout:blank = about:blank
@Local Page%SystemRoot%\system32\blank.htm = %SystemRoot%\system32\blank.htm

HKCU\Software\Microsoft\Internet Explorer\Main >>>
@Start Pagehttp://www.yahoo.com/ = http://www.yahoo.com/
@Local PageC:\WINXP\system32\blank.htm = C:\WINXP\system32\blank.htm

HKLM\Software\Classes\PROTOCOLS\Filter\ >>>
Class Install Handler@CLSID = C:\WINXP\system32\urlmon.dll
deflate@CLSID = C:\WINXP\system32\urlmon.dll
gzip@CLSID = C:\WINXP\system32\urlmon.dll
lzdhtml@CLSID = C:\WINXP\system32\urlmon.dll
text/webviewhtml@CLSID = %SystemRoot%\system32\SHELL32.dll
text/xml@CLSID = C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL

HKLM\Software\Classes\PROTOCOLS\Handler\ >>>
about@CLSID = C:\WINXP\system32\mshtml.dll
cdl@CLSID = C:\WINXP\system32\urlmon.dll
dvd@CLSID = C:\WINXP\system32\msvidctl.dll
file@CLSID = C:\WINXP\system32\urlmon.dll
ftp@CLSID = C:\WINXP\system32\urlmon.dll
gopher@CLSID = C:\WINXP\system32\urlmon.dll
http@CLSID = C:\WINXP\system32\urlmon.dll
https@CLSID = C:\WINXP\system32\urlmon.dll
its@CLSID = C:\WINXP\system32\itss.dll
javascript@CLSID = C:\WINXP\system32\mshtml.dll
livecall@CLSID = C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
local@CLSID = C:\WINXP\system32\urlmon.dll
mailto@CLSID = C:\WINXP\system32\mshtml.dll
mhtml@CLSID = %SystemRoot%\system32\inetcomm.dll
mk@CLSID = C:\WINXP\system32\urlmon.dll
ms-its@CLSID = C:\WINXP\system32\itss.dll
ms-itss@CLSID = C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL
msnim@CLSID = C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
mso-offdap@CLSID = C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
mso-offdap11@CLSID = C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
res@CLSID = C:\WINXP\system32\mshtml.dll
sysimage@CLSID = %SystemRoot%\system32\mshtml.dll
tv@CLSID = C:\WINXP\system32\msvidctl.dll
vbscript@CLSID = C:\WINXP\system32\mshtml.dll
wia@CLSID = C:\WINXP\system32\wiascr.dll

HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters@Domain =

HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ >>>
000000000001@LibraryPath = %SystemRoot%\System32\mswsock.dll
000000000002@LibraryPath = %SystemRoot%\System32\winrnr.dll
000000000003@LibraryPath = %SystemRoot%\System32\mswsock.dll

HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\ >>>
000000000001@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000002@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000003@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000004@PackedCatalogItem = %SystemRoot%\system32\rsvpsp.dll
000000000005@PackedCatalogItem = %SystemRoot%\system32\rsvpsp.dll
000000000006@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000007@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000008@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000009@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000010@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000011@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000012@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000013@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000014@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000015@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll
000000000016@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll

HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000017@PackedCatalogItem = %SystemRoot%\system32\mswsock.dll

—- EOF - GMER 1.0.12 —-
I don't see anything of any real interest in there, although you can delete these three files:

c:\winxp\system32\ot.ico
c:\winxp\downloaded program files\f3initialsetup1.0.0.15.inf
C:\WINXP\system32\gamgspep.exe


I'm starting to think that this isn't a case of malware, but simply the effect of time and normal usage on the OS, although malicious files may have had a hand in speeding this process up - you did say that you other half wasn't to choosey about what was downloaded. If that's the case, you will need to reinstall to solve the problem.

Give this scan a whirl and post accordingly:

IMPORTANT - A new version of the Kaspersky Online Scanner was released on August 8, 2006. If you have installed a previous version then you need to go to Add/Remove Programs and remove any entries for Kaspersky Online Scanner before you proceed.
* Close all Internet Explorer windows before doing this.

Go here and click the Kaspersky Online Scanner button.
  • Read the Requirements and limitations before you click Accept.
  • Allow the ActiveX download if necessary.
  • Once the database has downloaded click Next.
  • Click Scan Settings and change the "Scan using the following antivirus database" from standard to extended and then click OK.
  • Click on "My Computer" and then put the kettle on!
  • When the scan has completed, click Save Report As…
  • Enter a name for the file in the Filename: text box and then click the down arrow to the right of Save as type: and select text file (*.txt)
  • Click Save - by default the file will be saved to your Desktop, but you can change this if you wish.
Copy and paste the report into your next reply along with a fresh HJT log and a description of how your PC is behaving.
here as requested are the log first the Kasper:

KASPERSKY ONLINE SCANNER REPORT
Thursday, December 07, 2006 4:45:07 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 7/12/2006
Kaspersky Anti-Virus database records: 234691


Scan Settings
Scan using the following antivirus database standard
Scan Archives true
Scan Mail Bases true

Scan Target My Computer
A:\
C:\
D:\
E:\

Scan Statistics
Total number of scanned objects 61334
Number of viruses found 2
Number of infected objects 8 / 0
Number of suspicious objects 0
Duration of the scan process 05:06:28

Infected Object Name Virus Name Last Action
C:\_RESTORE\ARCHIVE\FS21.CAB/A0034870.CPY/stream/data0005/data0002 Infected: Trojan-Clicker.Win32.VB.ip skipped

C:\_RESTORE\ARCHIVE\FS21.CAB/A0034870.CPY/stream/data0005 Infected: Trojan-Clicker.Win32.VB.ip skipped

C:\_RESTORE\ARCHIVE\FS21.CAB/A0034870.CPY/stream Infected: Trojan-Clicker.Win32.VB.ip skipped

C:\_RESTORE\ARCHIVE\FS21.CAB/A0034870.CPY Infected: Trojan-Clicker.Win32.VB.ip skipped

C:\_RESTORE\ARCHIVE\FS21.CAB CAB: infected - 4 skipped

C:\WINXP\system32\config\system.LOG Object is locked skipped

C:\WINXP\system32\config\software.LOG Object is locked skipped

C:\WINXP\system32\config\default.LOG Object is locked skipped

C:\WINXP\system32\config\SECURITY Object is locked skipped

C:\WINXP\system32\config\SAM Object is locked skipped

C:\WINXP\system32\config\SAM.LOG Object is locked skipped

C:\WINXP\system32\config\SECURITY.LOG Object is locked skipped

C:\WINXP\system32\config\AppEvent.Evt Object is locked skipped

C:\WINXP\system32\config\SecEvent.Evt Object is locked skipped

C:\WINXP\system32\config\SysEvent.Evt Object is locked skipped

C:\WINXP\system32\config\SYSTEM Object is locked skipped

C:\WINXP\system32\config\SOFTWARE Object is locked skipped

C:\WINXP\system32\config\DEFAULT Object is locked skipped

C:\WINXP\system32\config\Internet.evt Object is locked skipped

C:\WINXP\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped

C:\WINXP\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped

C:\WINXP\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped

C:\WINXP\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped

C:\WINXP\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

C:\WINXP\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped

C:\WINXP\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped

C:\WINXP\system32\gdxzwo.dll Infected: Trojan-Downloader.Win32.Busky.gen skipped

C:\WINXP\system32\CatRoot2\edb.log Object is locked skipped

C:\WINXP\system32\CatRoot2\tmp.edb Object is locked skipped

C:\WINXP\system32\h323log.txt Object is locked skipped

C:\WINXP\system32\ffmtkbg.dll Infected: Trojan-Downloader.Win32.Busky.gen skipped

C:\WINXP\Debug\PASSWD.LOG Object is locked skipped

C:\WINXP\Sti_Trace.log Object is locked skipped

C:\WINXP\wiaservc.log Object is locked skipped

C:\WINXP\wiadebug.log Object is locked skipped

C:\WINXP\SchedLgU.Txt Object is locked skipped

C:\WINXP\WindowsUpdate.log Object is locked skipped

C:\WINXP\SoftwareDistribution\ReportingEvents.log Object is locked skipped

C:\WINXP\SoftwareDistribution\EventCache\{22004BD6-21A1-48A8-A41E-A24313C30AE8}.bin Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\WDLog-07112006-083759.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\AVG7\Log\emc.log Object is locked skipped

C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\Sharyn\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\Sharyn\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Sharyn\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Sharyn\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped

C:\Documents and Settings\Sharyn\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\Sharyn\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\Sharyn\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\Sharyn\ntuser.dat.LOG Object is locked skipped

C:\System Volume Information\_restore{E74AFBE7-5800-422B-B358-C1FE0B4ED84E}\RP201\A0038327.dll Infected: Trojan-Downloader.Win32.Busky.gen skipped

C:\System Volume Information\_restore{E74AFBE7-5800-422B-B358-C1FE0B4ED84E}\RP221\change.log Object is locked skipped

Scan process completed.

Logfile of HijackThis v1.99.1
Scan saved at 4:52:00 PM, on 7/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINXP\System32\smss.exe
C:\WINXP\system32\winlogon.exe
C:\WINXP\system32\services.exe
C:\WINXP\system32\lsass.exe
C:\WINXP\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINXP\System32\svchost.exe
C:\WINXP\system32\spoolsv.exe
C:\WINXP\Explorer.EXE
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\WINXP\system32\ctfmon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINXP\system32\crypserv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINXP\system32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Sharyn\Desktop\search.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com/search/ie.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINXP\system32\ctfmon.exe
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1147225346055
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {EF148DBB-5B6D-4130-B2A1-661571E86260} (Playtime Games Launcher) - http://atlantis9.bigfishgames.com/Reef/en_…ameLauncher.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINXP\SYSTEM32\WgaLogon.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINXP\SYSTEM32\crypserv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
A couple of what looks like leftovers to go:

C:\WINXP\system32\ffmtkbg.dll
C:\WINXP\system32\gdxzwo.dll


Download the 14 day trial of Webroot's Spy Sweeper from here.
Once the download has completed, double click the file to begin installation.
During the installation you will be given the option to check for updates - click the button to allow it to do so.
Once the installation has completed, your PC will need to be rebooted.

Once your PC has rebooted, open Spy Sweeper:
  • Click the Options button.
  • Select the Update Tab.
  • Click Update Spy Sweeper.
  • I.E. will open displaying a page from the Spy Sweeper website - you can close this as Spy Sweeper will continue to update regardless.
Once the updates have all been downloaded:
  • Select the Sweep Tab.
  • Check all the boxes under "Items to Sweep" and "Other Options".
  • Now click the Start Sweep button.
Once the scan has completed, Spy Sweeper will display the results of the scan. If anything has been found, click Quarantine Selected.
If you are asked to allow a reboot, do so - if not, manually reboot your PC anyway.

Once the PC has rebooted, open Spy Sweeper:
  • Click the Options button on the left.
  • Select the Sweep Tab again.
  • Click the "View Session Log link in the bottom right hand corner.
  • Click the Save to File button - by default the log will be saved as Spy Sweeper Sessions Log.txt in My Documents.
Copy and paste this into your next reply along with a fresh HJT log AND a description of how your PC is behaving.

If you don't wish to use the real-time protection available, do the following:

Click the Shields button on the left hand side
Click each of these Tabs and uncheck every box you find there.
hi Noviciate sorry that it take sme so long to reply but having MAJOR issues with isp…changing from ftel to DODO here in Australia and it is taking foreer to get it done…dayam I miss the states. Here are the logs spysweeper first then HJT: Keylogger: Off BHO Shield: Off IE Security Shield: Off Alternate Data Stream (ADS) Execution Shield: Off Startup Shield: Off Common Ad Sites: Off Hosts File Shield: Off Internet Communication Shield: Off ActiveX Shield: Off Windows Messenger Service Shield: Off IE Favorites Shield: Off Spy Installation Shield: Off Memory Shield: Off IE Hijack Shield: Off IE Tracking Cookies Shield: Off 10:53 AM: Shield States 10:53 AM: Spyware Definitions: 825 10:53 AM: Informational: Loaded AntiVirus Engine: 2.39.2; SDK Version: 4.11; Virus Definitions: 12/19/2006 5:36:18 AM (GMT) 10:48 AM: Spy Sweeper 5.2.3.2132 started Keylogger: Off BHO Shield: Off IE Security Shield: Off Alternate Data Stream (ADS) Execution Shield: Off Startup Shield: Off Common Ad Sites: Off Hosts File Shield: Off Internet Communication Shield: Off ActiveX Shield: Off Windows Messenger Service Shield: Off IE Favorites Shield: Off Spy Installation Shield: Off Memory Shield: Off IE Hijack Shield: Off IE Tracking Cookies Shield: Off 10:31 AM: Shield States 10:30 AM: Spyware Definitions: 825 10:30 AM: Informational: Loaded AntiVirus Engine: 2.39.2; SDK Version: 4.11; Virus Definitions: 12/19/2006 5:36:18 AM (GMT) 10:24 AM: Spy Sweeper 5.2.3.2132 started 10:16 AM: Startup Shield: Off 10:16 AM: Spy Installation Shield: Off 10:16 AM: Memory Shield: Off 10:16 AM: Windows Messenger Service Shield: Off 10:16 AM: Alternate Data Stream (ADS) Execution Shield: Off 10:16 AM: ActiveX Shield: Off 10:16 AM: Hosts File Shield: Off 10:16 AM: Internet Communication Shield: Off 10:16 AM: IE Hijack Shield: Off 10:15 AM: BHO Shield: Off 10:15 AM: IE Security Shield: Off 10:15 AM: IE Favorites Shield: Off 10:13 AM: Removal process completed. Elapsed time 00:02:04 10:11 AM: Quarantining All Traces: addynamix cookie 10:11 AM: Quarantining All Traces: adtech cookie 10:11 AM: Quarantining All Traces: overture cookie 10:11 AM: Quarantining All Traces: webtrends cookie 10:11 AM: Quarantining All Traces: casalemedia cookie 10:11 AM: Quarantining All Traces: statcounter cookie 10:11 AM: Quarantining All Traces: serving-sys cookie 10:11 AM: Quarantining All Traces: atlas dmt cookie 10:11 AM: Quarantining All Traces: yieldmanager cookie 10:11 AM: Quarantining All Traces: adrevolver cookie 10:11 AM: Quarantining All Traces: tribalfusion cookie 10:11 AM: Quarantining All Traces: 2o7.net cookie 10:11 AM: Quarantining All Traces: redsheriff cookies 10:11 AM: Quarantining All Traces: comet cursor 10:11 AM: Quarantining All Traces: Troj/Busky-Gen 10:11 AM: Removal process initiated 4:43 AM: Traces Found: 24 4:43 AM: Full Sweep has completed. Elapsed time 16:26:16 4:43 AM: File Sweep Complete, Elapsed Time: 15:37:18 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\wrongapppath13.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\wrongapppath12.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missinghelpfile8.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missinghelpfile7.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missinghelpfile6.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missinghelpfile5.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missinghelpfile4.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missinghelpfile3.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missinghelpfile2.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missinghelpfile1.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missinghelpfile.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missingshareddll42.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missingshareddll41.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\wrongapppath11.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missingshareddll40.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missingshareddll39.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missingshareddll38.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missingshareddll37.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missingshareddll36.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missingshareddll35.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missingshareddll34.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missingshareddll33.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missingshareddll32.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missingshareddll31.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missingshareddll30.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missingshareddll29.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missingshareddll28.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missingshareddll27.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missingshareddll26.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missingshareddll25.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missingshareddll24.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missingshareddll23.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missingshareddll22.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missingshareddll21.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\wrongapppath10.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\wrongapppath9.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\wrongapppath8.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\wrongapppath7.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missingshareddll20.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missingshareddll19.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missingshareddll18.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missingshareddll17.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missingshareddll16.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missingshareddll15.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missingshareddll14.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missingshareddll13.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missingshareddll12.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missingshareddll11.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missingshareddll10.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missingshareddll9.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missingshareddll8.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missingshareddll7.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missingshareddll6.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missingshareddll5.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missingshareddll4.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missingshareddll3.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\wrongapppath6.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missingshareddll2.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missingshareddll1.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\missingshareddll.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\wrongapppath5.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\wrongapppath4.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\wrongapppath3.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\wrongapppath2.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\wronguninstallinformation1.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\wrongapppath1.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\wrongapppath.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\wronguninstallinformation.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsmediasdk18.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsmediasdk17.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsmediasdk16.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsmediasdk15.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsmediasdk14.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsexplorer32.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsexplorer31.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsexplorer30.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\msmediaplayer15.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\msdirectdraw4.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\msdirectd4.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\internetexplorer12.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\mywebsearch1.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\mywebsearch.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\mywaymywebsearch3.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\mywaymywebsearch2.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\mywaymywebsearch1.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\mywaymywebsearch.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\funwebproducts2.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\funwebproducts1.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\funwebproducts.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\funweb.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\smitfraudctoolbar16.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\smitfraudc4.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\seachtoolbarcorptoolbarvision.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\smitfraudctoolbar15.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\smitfraudc3.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\newdotnet9.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\newdotnet8.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\newdotnet10.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\yazzlesudoku.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\smitfraudctoolbar14.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\smitfraudctoolbar13.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\smitfraudctoolbar12.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\smitfraudctoolbar11.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\smitfraudctoolbar10.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\smitfraudctoolbar9.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\smitfraudctoolbar8.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\smitfraudctoolbar7.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\smitfraudctoolbar6.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\smitfraudctoolbar5.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\smitfraudctoolbar4.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\smitfraudctoolbar3.zip] 4:06 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\newdotnet7.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\smitfraudctoolbar2.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\smitfraudctoolbar1.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\smitfraudc2.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\smitfraudc1.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\smitfraudc.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\newdotnet6.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\newdotnet5.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\newdotnet4.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\smitfraudctoolbar.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\newdotnet2.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\newdotnet1.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\newdotnet3.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\marketscore.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsexplorer29.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsexplorer28.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsexplorer27.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsexplorer26.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsexplorer25.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\msmediaplayer14.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\msdirectdraw3.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\msdirectd3.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\internetexplorer11.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\commondialogs3.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\aheadneroburningrom8.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsexplorer24.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsexplorer23.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\msmediaplayer13.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\aheadneroburningrom7.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsopenwith11.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsmediasdk13.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsmediasdk12.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsmediasdk11.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsmediasdk10.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsmediasdk9.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsexplorer22.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsexplorer21.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsexplorer20.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsexplorer19.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsexplorer18.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\mssearchassistant2.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\spyhunter.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\mspaint1.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\newdotnet.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\msofficeword2.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\msmediaplayer12.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\msmanagementconsole2.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\msdirectdraw2.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\msdirectd2.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\internetexplorer10.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\internetexplorer9.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\commondialogs2.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\aheadneroburningrom6.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\internetexplorer8.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\internetexplorer7.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsexplorer17.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsexplorer16.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsexplorer15.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsexplorer14.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsexplorer13.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\mssearchassistant1.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\msoffice5.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\msoffice6.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\msofficeword1.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\msmediaplayer11.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\msmanagementconsole1.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\msdirectdraw1.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\msdirectd1.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\commondialogs1.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\aheadneroburningrom5.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsexplorer12.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsexplorer11.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\msmediaplayer10.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\aheadneroburningrom4.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\msoffice3.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\winzip7.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\winzip6.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\winzip5.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\winzip4.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\winzip3.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\winzip2.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\winzip1.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\winzip.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsopenwith10.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsopenwith9.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsopenwith8.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsopenwith7.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsopenwith6.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsopenwith5.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsopenwith4.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsopenwith3.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsopenwith2.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsopenwith1.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsopenwith.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsmediasdk8.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsmediasdk7.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsmediasdk6.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsmediasdk5.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsmediasdk4.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsmediasdk3.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsmediasdk2.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsmediasdk1.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsmediasdk.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsexplorer10.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsexplorer9.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsexplorer8.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsexplorer7.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsexplorer6.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsexplorer5.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsexplorer4.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsexplorer3.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsexplorer2.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsexplorer1.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windowsexplorer.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\virtualdub.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\mssearchassistant.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\windows.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\mspaint.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\msoffice4.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\msoffice1.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\msofficeword.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\msofficestartassistant.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\msofficefinder.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\msmediaplayer9.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\msmediaplayer8.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\msmediaplayer7.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\msmediaplayer6.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\msmediaplayer5.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\msmediaplayer4.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\msmediaplayer3.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\msmediaplayer2.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\msmediaplayer1.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\msmediaplayer.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\msmanagementconsole.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\msdirectdraw.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\msoffice.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\msclipartgallery.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\internetexplorer6.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\internetexplorer5.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\internetexplorer4.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\internetexplorer3.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\internetexplorer2.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\internetexplorer1.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\internetexplorer.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\commondialogs.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\bearshare22.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\bearshare21.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\bearshare20.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\bearshare19.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\bearshare18.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\bearshare17.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\bearshare16.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\bearshare15.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\bearshare14.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\bearshare13.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\bearshare12.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\bearshare11.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\bearshare10.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\bearshare9.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\bearshare8.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\msdirectd.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\bearshare7.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\bearshare6.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\bearshare5.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\bearshare4.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\bearshare3.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\bearshare2.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\bearshare1.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\aheadneroburningrom3.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\aheadneroburningrom2.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\aheadneroburningrom1.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\aheadneroburningrom.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\msoffice2.zip] 4:05 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search destroy\recovery\bearshare.zip] 3:42 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\program files\yahoo!\ypsr\quarantine\20061027051920.zip] 3:42 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\program files\yahoo!\ypsr\quarantine\20061019051348.zip] 3:42 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\program files\yahoo!\ypsr\quarantine\20061011065638.zip] 3:42 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\program files\yahoo!\ypsr\quarantine\20060714030056.zip] 3:42 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\program files\yahoo!\ypsr\quarantine\20060713183620.zip] 3:42 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\program files\yahoo!\ypsr\quarantine\20060713132807.zip] 3:42 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\program files\yahoo!\ypsr\quarantine\20060710214213.zip] 3:42 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\program files\yahoo!\ypsr\quarantine\20060707123654.zip] 3:42 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\program files\yahoo!\ypsr\quarantine\20060704190457.zip] 3:42 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\program files\yahoo!\ypsr\quarantine\20060629214954.zip] 3:42 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\program files\yahoo!\ypsr\quarantine\20060629132630.zip] 3:42 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\program files\yahoo!\ypsr\quarantine\20060624233656.zip] 3:42 AM: Warning: AntiVirus engine returned [File Encrypted] on [c:\program files\ya
The size of the log has meant that your post got cut short. Let me have the rest of the Spy Sweeper log, HJT log, and PC description and i'll get back to you.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI