This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijack log - Slow computer 1 ghz toshiba laptop

62 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I've been given this extremely slowly working Toshiba laptop with lots of junk on it, I don't think I need PartyPoker or a bunch of other stuff slowing things down. Please help.

Logfile of HijackThis v1.99.1
Scan saved at 9:27:38 AM, on 12/14/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\PackethSvc.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\System32\CePMTray.exe
C:\WINDOWS\system32\EXSHOW95.EXE
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\toshiba\ivp\ism\ivpsvmgr.exe
C:\Program Files\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.begin2search.com/sidesearch.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dogpile.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.begin2search.com/sidesearch.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.begin2search.com/sidesearch.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.toshiba.com/
O1 - Hosts: 216.130.185.143 www.adwave.com
O1 - Hosts: 216.130.185.143 adwave.com
O1 - Hosts: 216.130.185.143 www.xzoomy.com
O1 - Hosts: 216.130.185.143 xzoomy.com
O1 - Hosts: 216.130.185.143 www.advnt01.com
O1 - Hosts: 216.130.185.143 advnt01.com
O1 - Hosts: 216.130.185.143 www.adwave.com
O1 - Hosts: 216.130.185.143 adwave.com
O1 - Hosts: 216.130.185.143 www.xzoomy.com
O1 - Hosts: 216.130.185.143 xzoomy.com
O1 - Hosts: 216.130.185.143 www.advnt01.com
O1 - Hosts: 216.130.185.143 advnt01.com
O1 - Hosts: 216.130.185.143 www.adwave.com
O1 - Hosts: 216.130.185.143 adwave.com
O1 - Hosts: 216.130.185.143 www.xzoomy.com
O1 - Hosts: 216.130.185.143 xzoomy.com
O1 - Hosts: 216.130.185.143 www.advnt01.com
O1 - Hosts: 216.130.185.143 advnt01.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [CeEPOWER] C:\WINDOWS\System32\CePMTray.exe
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [EXSHOW95.EXE] EXSHOW95.EXE
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PrivacyScanner] C:\Program Files\Privacy Champion\pscan.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://www.sabetproperties.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1096563775790
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1153314960998
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Virtual NIC Service (PackethSvc) - America Online, Inc. - C:\WINDOWS\System32\PackethSvc.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
Hi, Welcome to TomCoyote! I'm Angelfire777 and it'll be my pleasure to assist you in your problem. Please hold on while I research a fix for you.
*Click Start > Control Panel > Add or Remove Programs and uninstall the items I listed in bold if found.

Party Poker

Privacy Champion
Please uninstall that program since it is considered as a Rogue Antispyware application as listed HERE.

Microsoft AntiSpyware
The above program is now called Windows Defender. Please uninstall it and download Windows Defender HERE

*Reboot

____________________

If you have installed Windows Defender,

You need To disable Windows Defender temporarily, it can stop our fix.
  • Open Microsoft Windows Defender. Click Start > Programs > Windows Defender
  • Click on Tools > General Settings
  • Under Real-time Protection options, unselect the turn on real-time protection check box.
  • Click Save
After all of the fixes are complete it is very important that you enable Real-time Protection again.

____________________

*Download The Hoster by FunkyToad
Unzip the program and run it.
  • Click "Restore Original Hosts", click "OK"
  • Exit the program.

*Open HijackThis > choose Scan Only > Place a checkmark in the boxes beside these entries in bold.

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.begin2search.com/sidesearch.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dogpile.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.begin2search.com/sidesearch.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.begin2search.com/sidesearch.html
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [PrivacyScanner] C:\Program Files\Privacy Champion\pscan.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)


Did you add the following in your trusted list? If not, please fix the entry:

O15 - Trusted Zone: http://www.sabetproperties.com

Close your browsers and all open windows except for HijackThis, then click "Fix checked".

_____________________

Open Windows Explorer then navigate to these folders and delete them:

C:\Program Files\PartyPoker
C:\Program Files\Privacy Champion

Empty your recycle bin.

Reboot.
_____________________

Download Superantispyware
  • Load Superantispyware and click the check for updates button.
  • Once the update is finished click the scan your computer button.
  • Check Perform Complete Scan and then next.
  • Superantispyware will now scan your computer and when its finished it will list all the infections it has found.
  • Make sure that they all have a check next to them and press next.
  • Click finish and you will be taken back to the main interface.
  • Click Preferences and then click the statistics/logs tab. Click the dated log and press view log and a text file will appear.
  • Copy and paste the log onto the forum.
On your next reply, please include a fresh HijackThis log and the SUPERantspyware log.
OK here are the 2 log files:

Logfile of HijackThis v1.99.1
Scan saved at 1:09:24 PM, on 12/19/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\System32\CePMTray.exe
C:\toshiba\ivp\ism\pinger.exe
C:\WINDOWS\system32\EXSHOW95.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Symantec AntiVirus\DoScan.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.toshiba.com/
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [CeEPOWER] C:\WINDOWS\System32\CePMTray.exe
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [EXSHOW95.EXE] EXSHOW95.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://www.sabetproperties.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1096563775790
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1153314960998
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe


SUPERAntiSpyware Scan Log
Generated 12/19/2006 at 12:51 PM

Application Version : 3.4.1000

Core Rules Database Version : 3150
Trace Rules Database Version: 1166

Scan type : Complete Scan
Total Scan Time : 01:11:42

Memory items scanned : 452
Memory threats detected : 0
Registry items scanned : 5405
Registry threats detected : 2
File items scanned : 28450
File threats detected : 8

Keylogger.SafeSurfing
C:\WINDOWS\SYSTEM32\IDCTUP20.EXE
HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\idctrrun
HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\idctrrun#Path

Adware.Tracking Cookie
C:\Documents and Settings\Stefanie\Cookies\[removed][1].txt
C:\Documents and Settings\Stefanie\Cookies\stefanie@atdmt[1].txt
C:\Documents and Settings\Stefanie\Cookies\stefanie@partypoker[2].txt
C:\Documents and Settings\Stefanie\Cookies\[removed][1].txt
C:\Documents and Settings\Stefanie\Cookies\stefanie@247realmedia[2].txt
C:\Documents and Settings\Stefanie\Cookies\stefanie@partygaming.122.2o7[1].txt

Unclassified.Unknown Origin
C:\SYSTEM VOLUME INFORMATION\_RESTORE{E126D0E1-B902-48D5-B5DE-630CE9695C8A}\RP1211\A0046324.EXE
Still so slow I can't believe it. This morning I ran SuperAntiSpyware from the system tray icon by right clicking to view the menu and selecting "Find out whats running on your computer." It took over 7 minutes for IE 7 to open to their web page and another 5 minutes to run their scan. I still need help. Here are the results of their scan as to what is running on my computer: Recognized SAFE Applications and Files Show/Hide Info Running Applications ALG.EXE Application Layer Gateway Service More Info Description Component of Internet Connection Sharing and Internet Connection Firewall File Location on your Computer C:\WINDOWS\System32\alg.exe Registry Path and CLSID where file was detected on your Computer File Size (bytes) 44544 MD5 Checksum/Fingerprint f1958fbf86d5c004cf19a5951a9514b7 Company Name Microsoft Corp. Company Url/Website www.microsoft.com File Version Information Show/Hide Version Information File Description Application Layer Gateway Service File Version 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Product Name Microsoft® Windows® Operating System Product Version 5.1.2600.2180 Internal Name ALG.exe Original File Name ALG.exe Legal Copyright © Microsoft Corporation. All rights reserved. Legal Trademarks Private Build Special Build APNTEX.EXE Alps Pointing-device Driver for Windows NT/2000/XP More Info Description Alps Pointing-device Driver for Windows NT/2000/XP File Location on your Computer C:\Program Files\Apoint2K\Apntex.exe Registry Path and CLSID where file was detected on your Computer File Size (bytes) 32768 MD5 Checksum/Fingerprint f7e39e84313445d360a26cdd96cc173b Company Name Alps Electric Co., Ltd. Company Url/Website File Version Information Show/Hide Version Information File Description Alps Pointing-device Driver for Windows NT/2000 File Version 5.0.1.13 Product Name Alps Pointing-device Driver for Windows NT/2000 Product Version 5.0.1.13 Internal Name Alps Pointing-device Driver for Windows NT/2000 Original File Name ApntEx.exe Legal Copyright Copyright © 1998-2001 Alps Electric Co., Ltd. Legal Trademarks Private Build Special Build APOINT.EXE Alps Pointing-device Driver More Info Description Alps Pointing-device Driver File Location on your Computer C:\Program Files\Apoint2K\Apoint.exe Registry Path and CLSID where file was detected on your Computer File Size (bytes) 118784 MD5 Checksum/Fingerprint d3ad61f2e803379544141142e9357e58 Company Name Alps Electric Co., Ltd. Company Url/Website www.alps.com File Version Information Show/Hide Version Information File Description Alps Pointing-device Driver File Version 5.3.1.106 Product Name Alps Pointing-device Driver Product Version 5.3.1.106 Internal Name Alps Pointing-device Driver Original File Name Apoint.exe Legal Copyright Copyright © 1999-2001 Alps Electric Co., Ltd. Legal Trademarks Private Build Special Build CCAPP.EXE Client Portion of Norton AntiVirus 2003/2004 More Info Description Handles part of the e-mail scanning process. File Location on your Computer C:\Program Files\Common Files\Symantec Shared\ccApp.exe Registry Path and CLSID where file was detected on your Computer File Size (bytes) 48752 MD5 Checksum/Fingerprint 696f43558ea1c4bff475a4b8ecc5cac4 Company Name Symantec Corporation Company Url/Website www.symantec.com File Version Information Show/Hide Version Information File Description Symantec User Session File Version 103.5.1.9 Product Name Client and Host Security Platform Product Version 103.5.1.9 Internal Name ccApp Original File Name ccApp.exe Legal Copyright Copyright © 2000-2005 Symantec Corporation. All rights reserved. Legal Trademarks Private Build Special Build CCEVTMGR.EXE Symantec Event Manager Service More Info Description Programs and services used by Norton AntiVirus 2003/2004. File Location on your Computer C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe Registry Path and CLSID where file was detected on your Computer File Size (bytes) 185968 MD5 Checksum/Fingerprint 83053d67f40cd00d5fb3baa2c4d6f9ec Company Name Symantec Corporation Company Url/Website www.symantec.com File Version Information Show/Hide Version Information File Description Symantec Event Manager Service File Version 103.5.1.9 Product Name Client and Host Security Platform Product Version 103.5.1.9 Internal Name ccEvtMgr Original File Name ccEvtMgr.exe Legal Copyright Copyright © 2000-2005 Symantec Corporation. All rights reserved. Legal Trademarks Private Build Special Build CCSETMGR.EXE Symantec Settings Manager Service More Info Description Symantec Settings Manager Service. Part of Client and Host Security Platform File Location on your Computer C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe Registry Path and CLSID where file was detected on your Computer File Size (bytes) 161392 MD5 Checksum/Fingerprint 2013a368106f5eb9aa6f492369f8063c Company Name Symantec Corporation Company Url/Website www.symantec.com File Version Information Show/Hide Version Information File Description Symantec Settings Manager Service File Version 103.5.1.9 Product Name Client and Host Security Platform Product Version 103.5.1.9 Internal Name ccSetMgr Original File Name ccSetMgr.exe Legal Copyright Copyright © 2000-2005 Symantec Corporation. All rights reserved. Legal Trademarks Private Build Special Build CEPMTRAY.EXE Toshiba Power Management Applet More Info Description Toshiba Power Management Applet File Location on your Computer C:\WINDOWS\System32\CePMTray.exe Registry Path and CLSID where file was detected on your Computer File Size (bytes) 90112 MD5 Checksum/Fingerprint 75f4a49b758e09ac4006969e50d08586 Company Name COMPAL ELECTRONIC INC. Company Url/Website www.compal.com File Version Information Show/Hide Version Information File Description CeTray MFC Application File Version 1, 2, 0, 0 Product Name CeTray Application Product Version 1, 2, 0, 0 Internal Name CeTray Original File Name CeTray.EXE Legal Copyright Copyright © 2001 Legal Trademarks Private Build Special Build CSRSS.EXE Client/Server Subsystem More Info Description Handles various Windows run-time operations File Location on your Computer \??\C:\WINDOWS\system32\csrss.exe Registry Path and CLSID where file was detected on your Computer File Size (bytes) 0 MD5 Checksum/Fingerprint Company Name Microsoft Corp Company Url/Website www.microsoft.com File Version Information Show/Hide Version Information File Description File Version Product Name Product Version Internal Name Original File Name Legal Copyright Legal Trademarks Private Build Special Build CTFMON.EXE CTF Loader - Part of Microsoft Office XP More Info Description The CTF Loader is part of Microsoft Office XP. It is used to activate the Language Bar (voice recognition). File Location on your Computer C:\WINDOWS\system32\ctfmon.exe Registry Path and CLSID where file was detected on your Computer File Size (bytes) 15360 MD5 Checksum/Fingerprint 24232996a38c0b0cf151c2140ae29fc8 Company Name Microsoft Corporation Company Url/Website www.microsoft.com File Version Information Show/Hide Version Information File Description CTF Loader File Version 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Product Name Microsoft® Windows® Operating System Product Version 5.1.2600.2180 Internal Name CTFMON Original File Name CTFMON.EXE Legal Copyright © Microsoft Corporation. All rights reserved. Legal Trademarks Private Build Special Build DEFWATCH.EXE Virus Definition Daemon More Info Description Part of Symantec AntiVirus File Location on your Computer C:\Program Files\Symantec AntiVirus\DefWatch.exe Registry Path and CLSID where file was detected on your Computer File Size (bytes) 19648 MD5 Checksum/Fingerprint 955924c3532efb803b0661b6aa516126 Company Name Symantec Corporation Company Url/Website www.symantec.com File Version Information Show/Hide Version Information File Description Virus Definition Daemon File Version 10.0.0.359 Product Name Symantec AntiVirus Product Version 10.0.0.359 Internal Name DefWatch Original File Name DefWatch.exe Legal Copyright Copyright 1998 - 2005 Symantec Corporation. All rights reserved. Legal Trademarks Private Build Special Build DOSCAN.EXE Symantec AntiVirus Application Component More Info Description Symantec AntiVirus Application Component File Location on your Computer C:\Program Files\Symantec AntiVirus\DoScan.exe Registry Path and CLSID where file was detected on your Computer File Size (bytes) 18624 MD5 Checksum/Fingerprint 62a7e7827da6df250b6772535cce65b3 Company Name Symantec Corporation Company Url/Website www.symantec.com File Version Information Show/Hide Version Information File Description Symantec AntiVirus File Version 10.0.0.359 Product Name Symantec AntiVirus Product Version 10.0.0.359 Internal Name Original File Name Legal Copyright Copyright 1991 - 2005 Symantec Corporation. All rights reserved. Legal Trademarks Private Build Special Build EXPLORER.EXE Microsoft Windows Explorer More Info Description Explorer is used to view folders and files in Microsoft Windows. File Location on your Computer C:\WINDOWS\Explorer.EXE Registry Path and CLSID where file was detected on your Computer File Size (bytes) 1032192 MD5 Checksum/Fingerprint a0732187050030ae399b241436565e64 Company Name Microsoft Corp Company Url/Website www.microsoft.com File Version Information Show/Hide Version Information File Description Windows Explorer File Version 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) Product Name Microsoft® Windows® Operating System Product Version 6.00.2900.2180 Internal Name explorer Original File Name EXPLORER.EXE Legal Copyright © Microsoft Corporation. All rights reserved. Legal Trademarks Private Build Special Build EXSHOW95.EXE Kensington Expert Mouse Software More Info Description Used by Kensington Expert mouse File Location on your Computer C:\WINDOWS\system32\EXSHOW95.EXE Registry Path and CLSID where file was detected on your Computer File Size (bytes) 45056 MD5 Checksum/Fingerprint 78ccb5acafed4ed2bac0e2443627b1b5 Company Name Kensington Company Url/Website www.kensington.com File Version Information Show/Hide Version Information File Description Kensington MouseWorks Win32 Support File Version 5.61 Product Name Kensington MouseWorks Driver Product Version 5.61 Internal Name KMOUSE Original File Name EXSHOW95.EXE Legal Copyright Copyright )2001 ACCO Brands, Inc. Legal Trademarks Private Build Special Build FXSSVC.EXE Microsoft Fax Service More Info Description Microsoft® Fax Server File Location on your Computer C:\WINDOWS\system32\fxssvc.exe Registry Path and CLSID where file was detected on your Computer File Size (bytes) 267776 MD5 Checksum/Fingerprint fcbd571fa0ee8dc238944ae5fab74461 Company Name Microsoft Corporation Company Url/Website www.microsoft.com File Version Information Show/Hide Version Information File Description Fax Service File Version 5.2.2600.2180 (xpsp_sp2_rtm.040803-2158) Product Name Microsoft® Windows® Operating System Product Version 5.2.2600.2180 Internal Name FXSSVC.EXE Original File Name FXSSVC.EXE Legal Copyright © Microsoft Corporation. All rights reserved. Legal Trademarks Private Build Special Build HKCMD.EXE Intel® Common User Interface More Info Description Installed with Intel media devices. Used for configuration and diagnosis. File Location on your Computer C:\WINDOWS\System32\hkcmd.exe Registry Path and CLSID where file was detected on your Computer File Size (bytes) 98304 MD5 Checksum/Fingerprint 5cdc8d00aab04f11128e9064cdf496be Company Name Intel Corporation Company Url/Website www.intel.com File Version Information Show/Hide Version Information File Description hkcmd Module File Version 3,0,0,1335 Product Name Intel® Common User Interface Product Version 7,0,0,1335 Internal Name HKCMD Original File Name HKCMD.EXE Legal Copyright Copyright 1999-2001, Intel Corporation Legal Trademarks Private Build Special Build IEXPLORE.EXE Microsoft Internet Explorer More Info Description Microsoft Internet Explorer (Browser) File Location on your Computer C:\Program Files\Internet Explorer\IEXPLORE.EXE Registry Path and CLSID where file was detected on your Computer File Size (bytes) 622080 MD5 Checksum/Fingerprint 5334d4461aa92a7b008755fe6d13c5f2 Company Name Microsoft Corp Company Url/Website www.microsoft.com File Version Information Show/Hide Version Information File Description Internet Explorer File Version 7.00.5730.11 (winmain(wmbla).061017-1135) Product Name Windows® Internet Explorer Product Version 7.00.5730.11 Internal Name iexplore Original File Name IEXPLORE.EXE Legal Copyright © Microsoft Corporation. All rights reserved. Legal Trademarks Private Build Special Build IGFXTRAY.EXE Intel Graphics Tray Application More Info Description Installed with Intel Motherboard software to control Intel Graphics hardware. File Location on your Computer C:\WINDOWS\System32\igfxtray.exe Registry Path and CLSID where file was detected on your Computer File Size (bytes) 151552 MD5 Checksum/Fingerprint e22ea03c4c2fc0fb626d6754969f522b Company Name Intel Corporation Company Url/Website www.intel.com File Version Information Show/Hide Version Information File Description igfxTray Module File Version 3,0,0,1335 Product Name Intel® Common User Interface Product Version 7,0,0,1335 Internal Name IGFXTRAY Original File Name IGFXTRAY.EXE Legal Copyright Copyright 1999-2001, Intel Corporation Legal Trademarks Private Build Special Build IVPSVMGR.EXE IVP Service Manager Application More Info Description Installed on Toshiba Laptops. Handles software updates for Toshiba software. File Location on your Computer C:\toshiba\ivp\ism\ivpsvmgr.exe Registry Path and CLSID where file was detected on your Computer File Size (bytes) 454656 MD5 Checksum/Fingerprint dfea8fbc97d08d3737b9518be56ccd3c Company Name TOSHIBA Corporation Company Url/Website www.toshiba.com File Version Information Show/Hide Version Information File Description IVP Service Manager Application File Version 3.2 Product Name Software Upgrades Product Version 3.2 Internal Name IVPSVMGR Original File Name IVPSVMGR.EXE Legal Copyright © 1997-2001 Toshiba Corporation Legal Trademarks Private Build 3.2B1 (010322_1514) Special Build LSASS.EXE Local Security Authority Service More Info Description Handles security authentication under Microsoft Windows File Location on your Computer C:\WINDOWS\system32\lsass.exe Registry Path and CLSID where file was detected on your Computer File Size (bytes) 13312 MD5 Checksum/Fingerprint 84885f9b82f4d55c6146ebf6065d75d2 Company Name Microsoft Corp Company Url/Website www.microsoft.com File Version Information Show/Hide Version Information File Description LSA Shell (Export Version) File Version 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Product Name Microsoft® Windows® Operating System Product Version 5.1.2600.2180 Internal Name lsass.exe Original File Name lsass.exe Legal Copyright © Microsoft Corporation. All rights reserved. Legal Trademarks Private Build Special Build MDM.EXE Microsoft Debug Manager More Info Description Installed with Microsoft Visual Studio and Microsoft Office. This is a helper for the script debugger. File Location on your Computer C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE Registry Path and CLSID where file was detected on your Computer File Size (bytes) 322120 MD5 Checksum/Fingerprint 11f714f85530a2bd134074dc30e99fca Company Name Microsoft Corp Company Url/Website www.microsoft.com File Version Information Show/Hide Version Information File Description Machine Debug Manager File Version 7.00.9466 Product Name Microsoft® Visual Studio .NET Product Version 7.00.9466 Internal Name mdm.exe Original File Name mdm.exe Legal Copyright © Microsoft Corporation. All rights reserved. Legal Trademarks Private Build Special Build MSASCUI.EXE Windows Defender User Interface More Info Description Windows Defender User Interface File Location on your Computer C:\Program Files\Windows Defender\MSASCui.exe Registry Path and CLSID where file was detected on your Computer File Size (bytes) 866584 MD5 Checksum/Fingerprint 77c03bf23ae56b0a31ae4d5bb4b3d0ac Company Name Microsoft Corporation Company Url/Website www.microsoft.com File Version Information Show/Hide Version Information File Description Windows Defender User Interface File Version 1.1.1593.0 Product Name Windows Defender Product Version 1.1.1593.0 Internal Name MSASCUI Original File Name MSASCUI.exe Legal Copyright © Microsoft Corporation. All rights reserved. Legal Trademarks Private Build Special Build MSMPENG.EXE Microsoft Windows Defender Service Executable More Info Description Microsoft Windows Defender Service Executable File Location on your Computer C:\Program Files\Windows Defender\MsMpEng.exe Registry Path and CLSID where file was detected on your Computer File Size (bytes) 13592 MD5 Checksum/Fingerprint f45dd1e1365d857dd08bc23563370d0e Company Name Microsoft Corporation Company Url/Website www.microsoft.com File Version Information Show/Hide Version Information File Description Service Executable File Version 1.1.1593.0 Product Name Windows Defender Product Version 1.1.1593.0 Internal Name MsMpEng.exe Original File Name MsMpEng.exe Legal Copyright © Microsoft Corporation. All rights reserved. Legal Trademarks Private Build Special Build MSMSGS.EXE MSN Messenger System Tray Application More Info Description MSN Messenger instant messenger client. File Location on your Computer C:\Program Files\Messenger\msmsgs.exe Registry Path and CLSID where file was detected on your Computer File Size (bytes) 1694208 MD5 Checksum/Fingerprint 74e6e96c6f0e2eca4edbb7f7a468f259 Company Name Microsoft Corp Company Url/Website www.microsoft.com File Version Information Show/Hide Version Information File Description Windows Messenger File Version 4.7.3001 Product Name Messenger Product Version Version 4.7.3001 Internal Name msmsgs Original File Name msmsgs.exe Legal Copyright Copyright © Microsoft Corporation 2004 Legal Trademarks Microsoft® is a registered trademark of Microsoft Corporation in the U.S. and/or other countries. Private Build Special Build QTTASK.EXE QuickTime Task More Info Description QuickTime Task File Location on your Computer C:\Program Files\QuickTime\qttask.exe Registry Path and CLSID where file was detected on your Computer File Size (bytes) 282624 MD5 Checksum/Fingerprint 383145864f6543c97a7e1b78505d2f1c Company Name Apple Computer, Inc. Company Url/Website www.apple.com File Version Information Show/Hide Version Information File Description QuickTime Task File Version 7.1 Product Name QuickTime Product Version QuickTime 7.1 Internal Name QuickTime Task Original File Name QTTask.exe Legal Copyright Copyright Apple Computer, Inc. 1989-2006 Legal Trademarks Private Build Special Build REALPLAY.EXE RealPlayer More Info Description RealPlayer Multimedia Player Application File Location on your Computer C:\Program Files\Real\RealPlayer\RealPlay.exe Registry Path and CLSID where file was detected on your Computer File Size (bytes) 208941 MD5 Checksum/Fingerprint 166d4304b61e489c68864e2d08b7c89c Company Name RealNetworks, Inc. Company Url/Website www.real.com File Version Information Show/Hide Version Information File Description RealPlayer File Version 6.0.12.1483 Product Name RealPlayer (32-bit) Product Version 6.0.12.1483 Internal Name REALPLAY Original File Name REALPLAY.EXE Legal Copyright Copyright © RealNetworks, Inc. 1995-2004 Legal Trademarks RealAudio™ is a trademark of RealNetworks, Inc. Private Build Special Build REALSCHED.EXE RealNetworks Scheduler More Info Description RealNetworks Scheduler. Part of the RealPlayer Installation. File Location on your Computer C:\Program Files\Common Files\Real\Update_OB\realsched.exe Registry Path and CLSID where file was detected on your Computer File Size (bytes) 180269 MD5 Checksum/Fingerprint 1ac2c58b587c70de64582ad41ee79fba Company Name RealNetworks, Inc. Company Url/Website www.real.com File Version Information Show/Hide Version Information File Description RealNetworks Scheduler File Version 0.1.0.3510 Product Name RealPlayer (32-bit) Product Version 0.1.0.3510 Internal Name schedapp Original File Name realsched.exe Legal Copyright Copyright © RealNetworks, Inc. 1995-2004 Legal Trademarks RealAudio™ is a trademark of RealNetworks, Inc. Private Build Special Build RTVSCAN.EXE Norton AntiVirus Scan Component More Info Description Norton AntiVirus Scan Component is part of the Norton AntiVirus for Windows NT systems Virus Scanner. File Location on your Computer C:\Program Files\Symantec AntiVirus\Rtvscan.exe Registry Path and CLSID where file was detected on your Computer File Size (bytes) 1726656 MD5 Checksum/Fingerprint 870b4355eef89d2d37c162593a8feccc Company Name Symantec Corporation Company Url/Website www.symantec.com File Version Information Show/Hide Version Information File Description Symantec AntiVirus File Version 10.0.0.359 Product Name Symantec AntiVirus Product Version 10.0.0.359 Internal Name Original File Name Legal Copyright Copyright 1991 - 2005 Symantec Corporation. All rights reserved. Legal Trademarks Private Build Special Build SAVROAM.EXE SAVRoam - Symantec AntiVirus Roaming More Info Description SAVRoam - Symantec AntiVirus Roaming File Location on your Computer C:\Program Files\Symantec AntiVirus\SavRoam.exe Registry Path and CLSID where file was detected on your Computer File Size (bytes) 124608 MD5 Checksum/Fingerprint 778f31aa8685426ca2d0d38b423c2512 Company Name Symantec Corporation Company Url/Website www.symantec.com File Version Information Show/Hide Version Information File Description SAVRoam File Version 10.0.0.359 Product Name Symantec SAVRoam Product Version 10.0.0.359 Internal Name SAVRoam Original File Name SAVRoam.exe Legal Copyright Copyright 2002 - 2005 Symantec Corporation. All rights reserved. Legal Trademarks Private Build Special Build SERVICES.EXE Windows Services Controller More Info Description Used under NT based systems (NT, 2000, XP) to manage system services File Location on your Computer C:\WINDOWS\system32\services.exe Registry Path and CLSID where file was detected on your Computer File Size (bytes) 108032 MD5 Checksum/Fingerprint c6ce6eec82f187615d1002bb3bb50ed4 Company Name Microsoft Corp Company Url/Website www.microsoft.com File Version Information Show/Hide Version Information File Description Services and Controller app File Version 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Product Name Microsoft® Windows® Operating System Product Version 5.1.2600.2180 Internal Name services.exe Original File Name services.exe Legal Copyright © Microsoft Corporation. All rights reserved. Legal Trademarks Private Build Special Build SMSS.EXE Session Manager More Info Description Used by the Terminal Server of Microsoft Windows to manage sessions File Location on your Computer \SystemRoot\System32\smss.exe Registry Path and CLSID where file was detected on your Computer File Size (bytes) 0 MD5 Checksum/Fingerprint Company Name Microsoft Corp Company Url/Website www.microsoft.com File Version Information Show/Hide Version Information File Description File Version Product Name Product Version Internal Name Original File Name Legal Copyright Legal Trademarks Private Build Special Build SPOOLSV.EXE Print Spooler Service More Info Description Microsoft Windows printer spooler. Handles print jobs from all Windows applications. File Location on your Computer C:\WINDOWS\system32\spoolsv.exe Registry Path and CLSID where file was detected on your Computer File Size (bytes) 57856 MD5 Checksum/Fingerprint da81ec57acd4cdc3d4c51cf3d409af9f Company Name Microsoft Corp Company Url/Website www.microsoft.com File Version Information Show/Hide Version Information File Description Spooler SubSystem App File Version 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519) Product Name Microsoft® Windows® Operating System Product Version 5.1.2600.2696 Internal Name spoolsv.exe Original File Name spoolsv.exe Legal Copyright © Microsoft Corporation. All rights reserved. Legal Trademarks Private Build Special Build SUPERANTISPYWARE.EXE SUPERAntiSpyware Application More Info Description SUPERAntiSpyware Application File Location on your Computer C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe Registry Path and CLSID where file was detected on your Computer File Size (bytes) 1294336 MD5 Checksum/Fingerprint 6b886baa18fb72130da05aac9d09daf4 Company Name SUPERAntiSpyware.com Company Url/Website www.superantispyware.com File Version Information Show/Hide Version Information File Description SUPERAntiSpyware File Version 3, 4, 0, 1000 Product Name SUPERAntiSpyware Product Version 3, 4, 0, 1000 Internal Name SUPERAntiSpyware Original File Name SUPERAntiSpyware.exe Legal Copyright Copyright © 2005-2006 by SUPERAntiSpyware.com and SUPERAdBlocker.com Legal Trademarks Private Build Special Build SVCHOST.EXE Generic Host Process for Win32 Services More Info Description Generic Host Process for Win32 Services File Location on your Computer C:\WINDOWS\system32\svchost.exe Registry Path and CLSID where file was detected on your Computer File Size (bytes) 14336 MD5 Checksum/Fingerprint 8f078ae4ed187aaabc0a305146de6716 Company Name Microsoft Corporation Company Url/Website www.microsoft.com File Version Information Show/Hide Version Information File Description Generic Host Process for Win32 Services File Version 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Product Name Microsoft® Windows® Operating System Product Version 5.1.2600.2180 Internal Name svchost.exe Original File Name svchost.exe Legal Copyright © Microsoft Corporation. All rights reserved. Legal Trademarks Private Build Special Build SVCHOST.EXE Generic Host Process for Win32 Services More Info Description Generic Host Process for Win32 Services File Location on your Computer C:\WINDOWS\system32\svchost.exe Registry Path and CLSID where file was detected on your Computer File Size (bytes) 14336 MD5 Checksum/Fingerprint 8f078ae4ed187aaabc0a305146de6716 Company Name Microsoft Corporation Company Url/Website www.microsoft.com File Version Information Show/Hide Version Information File Description Generic Host Process for Win32 Services File Version 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Product Name Microsoft® Windows® Operating System Product Version 5.1.2600.2180 Internal Name svchost.exe Original File Name svchost.exe Legal Copyright © Microsoft Corporation. All rights reserved. Legal Trademarks Private Build Special Build SVCHOST.EXE Generic Host Process for Win32 Services More Info Description Generic Host Process for Win32 Services File Location on your Computer C:\WINDOWS\System32\svchost.exe Registry Path and CLSID where file was detected on your Computer File Size (bytes) 14336 MD5 Checksum/Fingerprint 8f078ae4ed187aaabc0a305146de6716 Company Name Microsoft Corporation Company Url/Website www.microsoft.com File Version Information Show/Hide Version Information File Description Generic Host Process for Win32 Services File Version 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Product Name Microsoft® Windows® Operating System Product Version 5.1.2600.2180 Internal Name svchost.exe Original File Name svchost.exe Legal Copyright © Microsoft Corporation. All rights reserved. Legal Trademarks Private Build Special Build SVCHOST.EXE Generic Host Process for Win32 Services More Info Description Generic Host Process for Win32 Services File Location on your Computer C:\WINDOWS\System32\svchost.exe Registry Path and CLSID where file was detected on your Computer File Size (bytes) 14336 MD5 Checksum/Fingerprint 8f078ae4ed187aaabc0a305146de6716 Company Name Microsoft Corporation Company Url/Website www.microsoft.com File Version Information Show/Hide Version Information File Description Generic Host Process for Win32 Services File Version 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Product Name Microsoft® Windows® Operating System Product Version 5.1.2600.2180 Internal Name svchost.exe Original File Name svchost.exe Legal Copyright © Microsoft Corporation. All rights reserved. Legal Trademarks Private Build Special Build SVCHOST.EXE Generic Host Process for Win32 Services More Info Description Generic Host Process for Win32 Services File Location on your Computer C:\WINDOWS\System32\svchost.exe Registry Path and CLSID where file was detected on your Computer File Size (bytes) 14336 MD5 Checksum/Fingerprint 8f078ae4ed187aaabc0a305146de6716 Company Name Microsoft Corporation Company Url/Website www.microsoft.com File Version Information Show/Hide Version Information File Description Generic Host Process for Win32 Services File Version 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Product Name Microsoft® Windows® Operating System Product Version 5.1.2600.2180 Internal Name svchost.exe Original File Name svchost.exe Legal Copyright © Microsoft Corporation. All rights reserved. Legal Trademarks Private Build Special Build SVCHOST.EXE Generic Host Process for Win32 Services More Info Description Generic Host Process for Win32 Services File Location on your Computer C:\WINDOWS\System32\svchost.exe Registry Path and CLSID where file was detected on your Computer File Size (bytes) 14336 MD5 Checksum/Fingerprint 8f078ae4ed187aaabc0a305146de6716 Company Name Microsoft Corporation Company Url/Website www.microsoft.com File Version Information Show/Hide Version Information File Description Generic Host Process for Win32 Services File Version 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Product Name Microsoft® Windows® Operating System Product Version 5.1.2600.2180 Internal Name svchost.exe Original File Name svchost.exe Legal Copyright © Microsoft Corporation. All rights reserved. Legal Trademarks Private Build Special Build SVCHOST.EXE Generic Host Process for Win32 Services More Info Description Generic Host Process for Win32 Services File Location on your Computer C:\WINDOWS\System32\svchost.exe Registry Path and CLSID where file was detected on your Computer File Size (bytes) 14336 MD5 Checksum/Fingerprint 8f078ae4ed187aaabc0a305146de6716 Company Name Microsoft Corporation Company Url/Website www.microsoft.com File Version Information Show/Hide Version Information File Description Generic Host Process for Win32 Services File Version 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Product Name Microsoft® Windows® Operating System Product Version 5.1.2600.2180 Internal Name svchost.exe Original File Name svchost.exe Legal Copyright © Microsoft Corporation. All rights reserved. Legal Trademarks Private Build Special Build VPTRAY.EXE Norton AntiVirus Component More Info Description Norton AntiVirus Component part of the Norton AntiVirus Virus Scanner for Windows NT Systems. File Location on your Computer C:\PROGRA~1\SYMANT~1\VPTray.exe Registry Path and CLSID where file was detected on your Computer File Size (bytes) 85184 MD5 Checksum/Fingerprint 1b5036466136a1451bdba17b6aebecb3 Company Name Symantec Corporation Company Url/Website www.symantec.com File Version Information Show/Hide Version Information File Description Symantec AntiVirus File Version 10.0.0.359 Product Name Symantec AntiVirus Product Version 10.0.0.359 Internal Name Original File Name Legal Copyright Copyright 1991 - 2005 Symantec Corporation. All rights reserved. Legal Trademarks Private Build Special Build WINLOGON.EXE Windows NT/2000/XP Logon Process More Info Description Manages user logon and logoff information. File Location on your Computer \??\C:\WINDOWS\system32\winlogon.exe Registry Path and CLSID where file was detected on your Computer File Size (bytes) 0 MD5 Checksum/Fingerprint Company Name Microsoft Corp Company Url/Website www.microsoft.com File Version Information Show/Hide Version Information File Description File Version Product Name Product Version Internal Name Original File Name Legal Copyright Legal Trademarks Private Build Special Build WMIPRVSE.EXE Windows Management Instrumentation More Info Description WMI provides facilities for local and remote management and monitoring of WIndows File Location on your Computer C:\WINDOWS\System32\wbem\wmiprvse.exe Registry Path and CLSID where file was detected on your Computer File Size (bytes) 218112 MD5 Checksum/Fingerprint 075ea6c849ab0fe416a3d6dd65c3cf41 Company Name Microsoft Corp. Company Url/Website www.microsoft.com File Version Information Show/Hide Version Information File Description WMI File Version 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Product Name Microsoft® Windows® Operating System Product Version 5.1.2600.2180 Internal Name Wmiprvse.exe Original File Name Wmiprvse.exe Legal Copyright © Microsoft Corporation. All rights reserved. Legal Trademarks Private Build Special Build WUAUCLT.EXE Microsoft Automatic Updates More Info Description Microsoft Automatic Updates Application File Location on your Computer C:\WINDOWS\system32\wuauclt.exe Registry Path and CLSID where file was detected on your Computer File Size (bytes) 124184 MD5 Checksum/Fingerprint ebf1ab7e4fc05cabf2f4680d2a45f827 Company Name Microsoft Corporation Company Url/Website www.microsoft.com File Version Information Show/Hide Version Information File Description Automatic Updates File Version 5.8.0.2469 built by: lab01_n(wmbla) Product Name Microsoft® Windows® Operating System Product Version 5.8.0.2469 Internal Name wuauclt.exe Original File Name wuauclt.exe Legal Copyright © Microsoft Corporation. All rights reserved. Legal Trademarks Private Build Special Build Browser Extensions, Toolbars and Registry Applications IEFRAME.DLL Shell Browser UI Library More Info Description Shell Browser UI Library File Location on your Computer C:\WINDOWS\system32\ieframe.dll Registry Path and CLSID where file was detected on your Computer Software\Microsoft\Internet Explorer\URLSearchHooks {CFBFAE00-17A6-11D0-99CB-00C04FD64497} File Size (bytes) 6049280 MD5 Checksum/Fingerprint 914f39ef1d068737012ff7f90025f848 Company Name Microsoft Corporation Company Url/Website www.microsoft.com File Version Information Show/Hide Version Information File Description Internet Explorer File Version 7.00.5730.11 (winmain(wmbla).061017-1135) Product Name Windows® Internet Explorer Product Version 7.00.5730.11 Internal Name IEFRAME.DLL Original File Name IEFRAME.DLL Legal Copyright © Microsoft Corporation. All rights reserved. Legal Trademarks Private Build Special Build MPSHHOOK.DLL Microsoft Windows Defender Shell Execute Hook More Info Description Microsoft Windows Defender Shell Execute Hook File Location on your Computer C:\PROGRA~1\WIFD1F~1\MpShHook.dll Registry Path and CLSID where file was detected on your Computer Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} File Size (bytes) 83224 MD5 Checksum/Fingerprint f9d82b82f1b7c0b2d2606a987073f58c Company Name Microsoft Corporation Company Url/Website www.microsoft.com File Version Information Show/Hide Version Information File Description Shell Execution Monitor File Version 1.1.1593.0 Product Name Windows Defender Product Version 1.1.1593.0 Internal Name MpShHook Original File Name MpShHook.dll Legal Copyright © Microsoft Corporation. All rights reserved. Legal Trademarks Private Build Special Build SASSEH.DLL SUPERAntispyware ShellExecuteHook More Info Description SUPERAntispyware ShellExecuteHook used to detect harmful applications as they start. File Location on your Computer C:\Program Files\SUPERAntiSpyware\SASSEH.DLL Registry Path and CLSID where file was detected on your Computer Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} File Size (bytes) 77824 MD5 Checksum/Fingerprint 4c8c7ab29c2447e1906a4d9a87468c15 Company Name SuperAdBlocker.com Company Url/Website www.superadblocker.com File Version Information Show/Hide Version Information File Description ShellExecuteHook File Version 1, 0, 0, 1006 Product Name SuperAntiSpyware Product Version 1.0.0.1 Internal Name SABSEHPS.DLL Original File Name SASSEH.DLL Legal Copyright © Copyright 2004-2006 SuperAdBlocker.com Legal Trademarks Private Build Special Build SDHELPER.DLL Spybot Search and Destroy Browser Extension More Info Description Used to block "bad" downloads. Part of Spybot Search and Destroy File Location on your Computer C:\PROGRA~1\SPYBOT~1\SDHelper.dll Registry Path and CLSID where file was detected on your Computer Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects {53707962-6F74-2D53-2644-206D7942484F} File Size (bytes) 744960 MD5 Checksum/Fingerprint abf5ba518c6a5ed104496ff42d19ad88 Company Name Safer Networking Limited Company Url/Website File Version Information Show/Hide Version Information File Description Bad download blocker File Version 1, 3, 0, 12 Product Name Spybot - Search & Destroy Product Version 1, 3, 0, 12 Internal Name Original File Name sdhelper.dll Legal Copyright © 2000-2004 Patrick M. Kolla / Safer Networking Limited. Alle Rechte vorbehalten. Legal Trademarks "Spybot" und "Spybot - Search & Destroy" sind registrierte Warenzeichen. Private Build Special Build SHDOCVW.DLL Microsoft Shell Document Object More Info Description Part of Microsoft Windows. Contains various commonly used application components for webbrowser hosting. File Location on your Computer %SystemRoot%\System32\shdocvw.dll Registry Path and CLSID where file was detected on your Computer Software\Microsoft\Internet Explorer\Explorer Bars {4D5C8C25-D075-11d0-B416-00C04FB90376} File Size (bytes) 1497088 MD5 Checksum/Fingerprint 559b2d22a1ee947a7eaed530c7ff9320 Company Name Microsoft Corporation Company Url/Website www.microsoft.com File Version Information Show/Hide Version Information File Description Shell Doc Object and Control Library File Version 6.00.2900.2987 (xpsp.060901-0211) Product Name Microsoft® Windows® Operating System Product Version 6.00.2900.2987 Internal Name SHDOCVW.DLL Original File Name SHDOCVW.DLL Legal Copyright © Microsoft Corporation. All rights reserved. Legal Trademarks Private Build Special Build SHDOCVW.DLL Microsoft Shell Document Object More Info Description Part of Microsoft Windows. Contains various commonly used application components for webbrowser hosting. File Location on your Computer %SystemRoot%\System32\shdocvw.dll Registry Path and CLSID where file was detected on your Computer Software\Microsoft\Internet Explorer\Explorer Bars {EFA24E61-B078-11D0-89E4-00C04FC9E26E} File Size (bytes) 1497088 MD5 Checksum/Fingerprint 559b2d22a1ee947a7eaed530c7ff9320 Company Name Microsoft Corporation Company Url/Website www.microsoft.com File Version Information Show/Hide Version Information File Description Shell Doc Object and Control Library File Version 6.00.2900.2987 (xpsp.060901-0211) Product Name Microsoft® Windows® Operating System Product Version 6.00.2900.2987 Internal Name SHDOCVW.DLL Original File Name SHDOCVW.DLL Legal Copyright © Microsoft Corporation. All rights reserved. Legal Trademarks Private Build Special Build SHDOCVW.DLL Microsoft Shell Document Object More Info Description Part of Microsoft Windows. Contains various commonly used application components for webbrowser hosting. File Location on your Computer %SystemRoot%\System32\shdocvw.dll Registry Path and CLSID where file was detected on your Computer Software\Microsoft\Internet Explorer\Explorer Bars {EFA24E64-B078-11D0-89E4-00C04FC9E26E} File Size (bytes) 1497088 MD5 Checksum/Fingerprint 559b2d22a1ee947a7eaed530c7ff9320 Company Name Microsoft Corporation Company Url/Website www.microsoft.com File Version Information Show/Hide Version Information File Description Shell Doc Object and Control Library File Version 6.00.2900.2987 (xpsp.060901-0211) Product Name Microsoft® Windows® Operating System Product Version 6.00.2900.2987 Internal Name SHDOCVW.DLL Original File Name SHDOCVW.DLL Legal Copyright © Microsoft Corporation. All rights reserved. Legal Trademarks Private Build Special Build SHELL32.DLL Shell32.DLL is part of the Microsoft Windows Operating System More Info Description Shell32.DLL is part of the Microsoft Windows Operating System and contains icons, and API functions used by the Windows Shell. File Location on your Computer shell32.dll Registry Path and CLSID where file was detected on your Computer Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks {AEB6717E-7E19-11d0-97EE-00C04FD91972} File Size (bytes) 0 MD5 Checksum/Fingerprint XXXX Company Name Microsoft Corporation Company Url/Website www.microsoft.com File Version Information Show/Hide Version Information File Description File Version Product Name Product Version Internal Name Original File Name Legal Copyright Legal Trademarks Private Build Special Build SHELL32.DLL Shell32.DLL is part of the Microsoft Windows Operating System More Info Description Shell32.DLL is part of the Microsoft Windows Operating System and contains icons, and API functions used by the Windows Shell. File Location on your Computer %SystemRoot%\system32\SHELL32.dll Registry Path and CLSID where file was detected on your Computer Software\Microsoft\Internet Explorer\Explorer Bars {C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1} File Size (bytes) 8453632 MD5 Checksum/Fingerprint f056b4771408966694de5d9bf79b48f8 Company Name Microsoft Corporation Company Url/Website www.microsoft.com File Version Information Show/Hide Version Information File Description Windows Shell Common Dll File Version 6.00.2900.2951 (xpsp_sp2_gdr.060713-0009) Product Name Microsoft® Windows® Operating System Product Version 6.00.2900.2951 Internal Name SHELL32 Original File Name SHELL32.DLL Legal Copyright © Microsoft Corporation. All rights reserved. Legal Trademarks Private Build Special Build Startup Applications ADOBEUPDATEMANAGER.EXE Adobe Update Manager More Info Description Adobe Update Manager File Location on your Computer C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe Registry Path and CLSID where file was detected on your Computer Software\Microsoft\Windows\CurrentVersion\Run File Size (bytes) 313472 MD5 Checksum/Fingerprint 43f3f6d33c793089a7c32b45da16094b Company Name Adobe Systems Incorporated Company Url/Website www.adobe.com File Version Information Show/Hide Version Information File Description Adobe Update Manager File Version 3.1.0.10 Product Name Adobe Update Manager Product Version 3.0 Internal Name AdobeUpdateManager Original File Name AdobeUpdateManager.exe Legal Copyright Copyright © 1998-2004 Adobe Systems Incorporated. All rights reserved. Legal Trademarks Private Build Special Build APOINT.EXE Alps Pointing-device Driver More Info Description Alps Pointing-device Driver File Location on your Computer C:\Program Files\Apoint2K\Apoint.exe Registry Path and CLSID where file was detected on your Computer Software\Microsoft\Windows\CurrentVersion\Run File Size (bytes) 118784 MD5 Checksum/Fingerprint d3ad61f2e803379544141142e9357e58 Company Name Alps Electric Co., Ltd. Company Url/Website www.alps.com File Version Information Show/Hide Version Information File Description Alps Pointing-device Driver File Version 5.3.1.106 Product Name Alps Pointing-device Driver Product Version 5.3.1.106 Internal Name Alps Pointing-device Driver Original File Name Apoint.exe Legal Copyright Copyright © 1999-2001 Alps Electric Co., Ltd. Legal Trademarks Private Build Special Build CCAPP.EXE Client Portion of Norton AntiVirus 2003/2004 More Info Description Handles part of the e-mail scanning process. File Location on your Computer C:\Program Files\Common Files\Symantec Shared\ccApp.exe Registry Path and CLSID where file was detected on your Computer Software\Microsoft\Windows\CurrentVersion\Run File Size (bytes) 48752 MD5 Checksum/Fingerprint 696f43558ea1c4bff475a4b8ecc5cac4 Company Name Symantec Corporation Company Url/Website www.symantec.com File Version Information Show/Hide Version Information File Description Symantec User Session File Version 103.5.1.9 Product Name Client and Host Security Platform Product Version 103.5.1.9 Internal Name ccApp Original File Name ccApp.exe Legal Copyright Copyright © 2000-2005 Symantec Corporation. All rights reserved. Legal Trademarks Private Build Special Build CEPMTRAY.EXE Toshiba Power Management Applet More Info Description Toshiba Power Management Applet File Location on your Computer C:\WINDOWS\System32\CePMTray.exe Registry Path and CLSID where file was detected on your Computer Software\Microsoft\Windows\CurrentVersion\Run File Size (bytes) 90112 MD5 Checksum/Fingerprint 75f4a49b758e09ac4006969e50d08586 Company Name COMPAL ELECTRONIC INC. Company Url/Website www.compal.com File Version Information Show/Hide Version Information File Description CeTray MFC Application File Version 1, 2, 0, 0 Product Name CeTray Application Product Version 1, 2, 0, 0 Internal Name CeTray Original File Name CeTray.EXE Legal Copyright Copyright © 2001 Legal Trademarks Private Build Special Build CTFMON.EXE CTF Loader - Part of Microsoft Office XP More Info Description The CTF Loader is part of Microsoft Office XP. It is used to activate the Language Bar (voice recognition). File Location on your Computer C:\WINDOWS\system32\ctfmon.exe Registry Path and CLSID where file was detected on your Computer Software\Microsoft\Windows\CurrentVersion\Run File Size (bytes) 15360 MD5 Checksum/Fingerprint 24232996a38c0b0cf151c2140ae29fc8 Company Name Microsoft Corporation Company Url/Website www.microsoft.com File Version Information Show/Hide Version Information File Description CTF Loader File Version 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Product Name Microsoft® Windows® Operating System Product Version 5.1.2600.2180 Internal Name CTFMON Original File Name CTFMON.EXE Legal Copyright © Microsoft Corporation. All rights reserved. Legal Trademarks Private Build Special Build HKCMD.EXE Intel® Common User Interface More Info Description Installed with Intel media devices. Used for configuration and diagnosis. File Location on your Computer C:\WINDOWS\System32\hkcmd.exe Registry Path and CLSID where file was detected on your Computer Software\Microsoft\Windows\CurrentVersion\Run File Size (bytes) 98304 MD5 Checksum/Fingerprint 5cdc8d00aab04f11128e9064cdf496be Company Name Intel Corporation Company Url/Website www.intel.com File Version Information Show/Hide Version Information File Description hkcmd Module File Version 3,0,0,1335 Product Name Intel® Common User Interface Product Version 7,0,0,1335 Internal Name HKCMD Original File Name HKCMD.EXE Legal Copyright Copyright 1999-2001, Intel Corporation Legal Trademarks Private Build Special Build IGFXTRAY.EXE Intel Graphics Tray Application More Info Description Installed with Intel Motherboard software to control Intel Graphics hardware. File Location on your Computer C:\WINDOWS\System32\igfxtray.exe Registry Path and CLSID where file was detected on your Computer Software\Microsoft\Windows\CurrentVersion\Run File Size (bytes) 151552 MD5 Checksum/Fingerprint e22ea03c4c2fc0fb626d6754969f522b Company Name Intel Corporation Company Url/Website www.intel.com File Version Information Show/Hide Version Information File Description igfxTray Module File Version 3,0,0,1335 Product Name Intel® Common User Interface Product Version 7,0,0,1335 Internal Name IGFXTRAY Original File Name IGFXTRAY.EXE Legal Copyright Copyright 1999-2001, Intel Corporation Legal Trademarks Private Build Special Build MSASCUI.EXE Windows Defender User Interface More Info Description Windows Defender User Interface File Location on your Computer C:\Program Files\Windows Defender\MSASCui.exe Registry Path and CLSID where file was detected on your Computer Software\Microsoft\Windows\CurrentVersion\Run File Size (bytes) 866584 MD5 Checksum/Fingerprint 77c03bf23ae56b0a31ae4d5bb4b3d0ac Company Name Microsoft Corporation Company Url/Website www.microsoft.com File Version Information Show/Hide Version Information File Description Windows Defender User Interface File Version 1.1.1593.0 Product Name Windows Defender Product Version 1.1.1593.0 Internal Name MSASCUI Original File Name MSASCUI.exe Legal Copyright © Microsoft Corporation. All rights reserved. Legal Trademarks Private Build Special Build MSMSGS.EXE MSN Messenger System Tray Application More Info Description MSN Messenger instant messenger client. File Location on your Computer C:\Program Files\Messenger\msmsgs.exe Registry Path and CLSID where file was detected on your Computer Software\Microsoft\Windows\CurrentVersion\Run File Size (bytes) 1694208 MD5 Checksum/Fingerprint 74e6e96c6f0e2eca4edbb7f7a468f259 Company Name Microsoft Corp Company Url/Website www.microsoft.com File Version Information Show/Hide Version Information File Description Windows Messenger File Version 4.7.3001 Product Name Messenger Product Version Version 4.7.3001 Internal Name msmsgs Original File Name msmsgs.exe Legal Copyright Copyright © Microsoft Corporation 2004 Legal Trademarks Microsoft® is a registered trademark of Microsoft Corporation in the U.S. and/or other countries. Private Build Special Build PINGER.EXE TOSHIBA Pinger / Software Upgrade Monitor More Info Description TOSHIBA Pinger / Software Upgrade Monitor File Location on your Computer c:\toshiba\ivp\ism\pinger.exe Registry Path and CLSID where file was detected on your Computer Software\Microsoft\Windows\CurrentVersion\Run File Size (bytes) 147456 MD5 Checksum/Fingerprint d15cff835910d271b28b8ba86bb88727 Company Name Toshiba Corporation Company Url/Website www.toshiba.com File Version Information Show/Hide Version Information File Description Toshiba Pinger File Version 3.3 Product Name Software Upgrades Product Version 3.3 Internal Name PINGER Original File Name PINGER.EXE Legal Copyright © 1997-2001 Toshiba Corporation Legal Trademarks Private Build 3.3B2 Special Build 01111-40201 QTTASK.EXE QuickTime Task More Info Description QuickTime Task File Location on your Computer C:\Program Files\QuickTime\qttask.exe Registry Path and CLSID where file was detected on your Computer Software\Microsoft\Windows\CurrentVersion\Run File Size (bytes) 282624 MD5 Checksum/Fingerprint 383145864f6543c97a7e1b78505d2f1c Company Name Apple Computer, Inc. Company Url/Website www.apple.com File Version Information Show/Hide Version Information File Description QuickTime Task File Version 7.1 Product Name QuickTime Product Version QuickTime 7.1 Internal Name QuickTime Task Original File Name QTTask.exe Legal Copyright Copyright Apple Computer, Inc. 1989-2006 Legal Trademarks Private Build Special Build REALSCHED.EXE RealNetworks Scheduler More Info Descripti
Continued… here is the end of the report: Private Build Special Build REALSCHED.EXE RealNetworks Scheduler More Info Description RealNetworks Scheduler. Part of the RealPlayer Installation. File Location on your Computer C:\Program Files\Common Files\Real\Update_OB\realsched.exe Registry Path and CLSID where file was detected on your Computer Software\Microsoft\Windows\CurrentVersion\Run File Size (bytes) 180269 MD5 Checksum/Fingerprint 1ac2c58b587c70de64582ad41ee79fba Company Name RealNetworks, Inc. Company Url/Website www.real.com File Version Information Show/Hide Version Information File Description RealNetworks Scheduler File Version 0.1.0.3510 Product Name RealPlayer (32-bit) Product Version 0.1.0.3510 Internal Name schedapp Original File Name realsched.exe Legal Copyright Copyright © RealNetworks, Inc. 1995-2004 Legal Trademarks RealAudio™ is a trademark of RealNetworks, Inc. Private Build Special Build SUPERANTISPYWARE.EXE SUPERAntiSpyware Application More Info Description SUPERAntiSpyware Application File Location on your Computer C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe Registry Path and CLSID where file was detected on your Computer Software\Microsoft\Windows\CurrentVersion\Run File Size (bytes) 1294336 MD5 Checksum/Fingerprint 6b886baa18fb72130da05aac9d09daf4 Company Name SUPERAntiSpyware.com Company Url/Website www.superantispyware.com File Version Information Show/Hide Version Information File Description SUPERAntiSpyware File Version 3, 4, 0, 1000 Product Name SUPERAntiSpyware Product Version 3, 4, 0, 1000 Internal Name SUPERAntiSpyware Original File Name SUPERAntiSpyware.exe Legal Copyright Copyright © 2005-2006 by SUPERAntiSpyware.com and SUPERAdBlocker.com Legal Trademarks Private Build Special Build VPTRAY.EXE Norton AntiVirus Component More Info Description Norton AntiVirus Component part of the Norton AntiVirus Virus Scanner for Windows NT Systems. File Location on your Computer C:\PROGRA~1\SYMANT~1\VPTray.exe Registry Path and CLSID where file was detected on your Computer Software\Microsoft\Windows\CurrentVersion\Run File Size (bytes) 85184 MD5 Checksum/Fingerprint 1b5036466136a1451bdba17b6aebecb3 Company Name Symantec Corporation Company Url/Website www.symantec.com File Version Information Show/Hide Version Information File Description Symantec AntiVirus File Version 10.0.0.359 Product Name Symantec AntiVirus Product Version 10.0.0.359 Internal Name Original File Name Legal Copyright Copyright 1991 - 2005 Symantec Corporation. All rights reserved. Legal Trademarks Private Build Special Build Recognized UNSAFE Applications and Files Show/Hide Info Running Applications Browser Extensions, Toolbars and Registry Applications Startup Applications There are no recognized UNSAFE applications running on your computer Unrecognized Applications and Files Show/Hide Info Running Applications WMPNETWK.EXE C:\Program Files\Windows Media Player\WMPNetwk.exe More Info File Location on your Computer C:\Program Files\Windows Media Player\WMPNetwk.exe Registry Path and CLSID where file was detected on your Computer File Size (bytes) 913408 MD5 Checksum/Fingerprint f74e3d9a7fa9556c3bbb14d4e5e63d3b File Version Information Show/Hide Version Information Company Name Microsoft Corporation File Description Windows Media Player Network Sharing Service File Version 11.0.5721.5145 (WMP_11.061018-2006) Product Name Microsoft® Windows® Operating System Product Version 11.0.5721.5145 Internal Name Windows Media Player Network Sharing Service Original File Name WMPNetwk.exe Legal Copyright © Microsoft Corporation. All rights reserved. Legal Trademarks Private Build Special Build WMPNSCFG.EXE C:\Program Files\Windows Media Player\WMPNSCFG.exe More Info File Location on your Computer C:\Program Files\Windows Media Player\WMPNSCFG.exe Registry Path and CLSID where file was detected on your Computer File Size (bytes) 204288 MD5 Checksum/Fingerprint 7eaed08ccca4ddde61a388c82598cfa9 File Version Information Show/Hide Version Information Company Name Microsoft Corporation File Description Windows Media Player Network Sharing Service Configuration Application File Version 11.0.5721.5145 (WMP_11.061018-2006) Product Name Microsoft® Windows® Operating System Product Version 11.0.5721.5145 Internal Name Original File Name WMPNSCFG.EXE Legal Copyright © Microsoft Corporation. All rights reserved. Legal Trademarks Private Build Special Build Browser Extensions, Toolbars and Registry Applications Startup Applications WMPNSCFG.EXE C:\Program Files\Windows Media Player\WMPNSCFG.exe More Info File Location on your Computer C:\Program Files\Windows Media Player\WMPNSCFG.exe Registry Path and CLSID where file was detected on your Computer Software\Microsoft\Windows\CurrentVersion\Run File Size (bytes) 204288 MD5 Checksum/Fingerprint 7eaed08ccca4ddde61a388c82598cfa9 File Version Information Show/Hide Version Information Company Name Microsoft Corporation File Description Windows Media Player Network Sharing Service Configuration Application File Version 11.0.5721.5145 (WMP_11.061018-2006) Product Name Microsoft® Windows® Operating System Product Version 11.0.5721.5145 Internal Name Original File Name WMPNSCFG.EXE Legal Copyright © Microsoft Corporation. All rights reserved. Legal Trademarks Private Build Special Build
Download combofix.exe

1. Double click combofix.exe & follow the prompts.
2. When finished, it shall produce a log for you. Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall.
Thank you Angelfire for your continued help. Here is the ComboFix log: Stefanie - 06-12-22 9:41:58.72 Service Pack 2 ComboFix 06.11.27 - Running from: "C:\Documents and Settings\Stefanie\Desktop" ((((((((((((((((((((((((((((((( Files Created from 2006-11-22 to 2006-12-22 )))))))))))))))))))))))))))))))))) 2006-12-21 09:27 d——– C:\Documents and Settings\All Users\Application Data\Adobe 2006-12-19 12:07 0 –a—— C:\WINDOWS\system32\INETDCTR.DLL 2006-12-19 12:07 0 –a—— C:\WINDOWS\system32\IDCTUP20.EXE 2006-12-19 12:07 0 –a—— C:\WINDOWS\system32\CMMGR32.EXE 2006-12-19 12:07 0 –a—— C:\WINDOWS\ORUN32.EXE 2006-12-19 11:24 d——– C:\Program Files\SUPERAntiSpyware 2006-12-19 11:24 d——– C:\Documents and Settings\Stefanie\Application Data\SUPERAntiSpyware.com 2006-12-19 11:19 d——– C:\Program Files\Common Files\Wise Installation Wizard 2006-12-19 11:01 d——– C:\Program Files\hoster 2006-12-19 10:56 d——– C:\Program Files\Windows Defender 2006-12-14 09:24 d——– C:\Program Files\hijackthis 2006-12-13 10:36 d——– C:\Documents and Settings\Stefanie\Application Data\Lavasoft 2006-12-13 10:35 d——– C:\Program Files\Lavasoft 2006-12-13 09:49 dr-h—– C:\Documents and Settings\Stefanie\Recent 2006-12-12 10:52 dr-h—– C:\SD_VOICE 2006-12-12 10:31 974,848 –a—— C:\WINDOWS\system32\mfc70.dll 2006-12-12 10:31 7 –a—— C:\WINDOWS\system32\Voicech.dll 2006-12-12 10:31 487,424 –a—— C:\WINDOWS\system32\msvcp70.dll 2006-12-12 10:31 17,432 –a—— C:\WINDOWS\system32\drivers\IcRecUsb.sys 2006-12-12 10:31 15 –a—— C:\WINDOWS\system32\Ve_pm.dll 2006-12-12 10:31 d——– C:\Program Files\Panasonic 2006-12-12 09:58 d——– C:\WINDOWS\system32\drivers\UMDF 2006-12-12 09:37 36,352 ——— C:\WINDOWS\system32\tsgqec.dll 2006-12-12 09:37 288,768 ——— C:\WINDOWS\system32\rhttpaa.dll 2006-12-12 09:37 116,736 ——— C:\WINDOWS\system32\aaclient.dll (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2006-12-22 09:27 ——– d——– C:\Program Files\Symantec AntiVirus 2006-12-22 09:10 ——– d——– C:\Program Files\Common Files\Adobe 2006-12-22 09:10 ——– d——– C:\Documents and Settings\Stefanie\Application Data\AdobeUM 2006-12-19 12:07 ——– d——– C:\Program Files\Toshiba VirtualTech 2006-12-19 11:34 ——– d–h—– C:\Program Files\InstallShield Installation Information 2006-12-19 11:19 ——– d——– C:\Program Files\Common Files 2006-12-19 09:56 ——– d——– C:\Program Files\Adobe 2006-12-19 09:52 ——– d——– C:\Program Files\AIM95 2006-12-18 10:22 ——– d——– C:\Program Files\Outlook Express 2006-12-18 10:22 ——– d——– C:\Program Files\Common Files\System 2006-12-12 10:06 ——– d——– C:\Program Files\Windows Media Connect 2 2006-12-12 10:05 ——– d——– C:\Program Files\Windows Media Player 2006-12-06 10:57 ——– d——– C:\Program Files\Avery Wizard 3.0 2006-11-27 10:35 ——– d——– C:\Program Files\Spybot - Search & Destroy 2006-11-16 10:18 ——– d——– C:\Program Files\Common Files\Avery 2006-11-14 09:46 ——– d——– C:\Program Files\Internet Explorer 2006-11-13 01:02 1866240 –a—— C:\WINDOWS\system32\mstscax.dll 2006-11-08 00:06 679424 –a—— C:\WINDOWS\system32\inetcomm.dll 2006-11-07 03:06 600576 –a—— C:\WINDOWS\system32\mstsc.exe 2006-11-01 09:48 ——– d—s—- C:\Documents and Settings\Stefanie\Application Data\Microsoft 2006-10-30 11:06 ——– d——– C:\Program Files\OfficeUpdate11 2006-10-30 10:59 ——– d——– C:\Program Files\Microsoft Works 2006-10-30 10:59 ——– d——– C:\Program Files\Common Files\Microsoft Shared 2006-10-30 10:34 ——– d——– C:\Program Files\Common Files\L&H 2006-10-30 10:33 ——– d——– C:\Program Files\Microsoft ActiveSync 2006-10-30 10:32 ——– d——– C:\Program Files\Common Files\DESIGNER 2006-10-30 10:31 ——– d——– C:\Program Files\MICROSOFT VISUAL STUDIO 2006-10-30 10:31 ——– d——– C:\Program Files\Microsoft Office 2006-10-30 10:30 ——– d——– C:\Program Files\Microsoft.NET 2006-10-27 15:09 6049280 ——— C:\WINDOWS\system32\ieframe.dll 2006-10-27 15:09 50688 ——— C:\WINDOWS\system32\msfeedsbs.dll 2006-10-27 15:09 458752 ——— C:\WINDOWS\system32\msfeeds.dll 2006-10-27 15:09 413696 –a—— C:\WINDOWS\system32\vbscript.dll 2006-10-27 15:09 231424 –a—— C:\WINDOWS\system32\webcheck.dll 2006-10-27 15:09 180736 ——— C:\WINDOWS\system32\ieui.dll 2006-10-27 15:09 156160 –a—— C:\WINDOWS\system32\msls31.dll 2006-10-27 02:44 71680 –a—— C:\WINDOWS\system32\admparse.dll 2006-10-27 02:44 55296 –a—— C:\WINDOWS\system32\iesetup.dll 2006-10-27 02:44 54784 –a—— C:\WINDOWS\system32\ie4uinit.exe 2006-10-27 02:44 43008 –a—— C:\WINDOWS\system32\iernonce.dll 2006-10-27 02:44 382976 –a—— C:\WINDOWS\system32\iedkcs32.dll 2006-10-27 02:44 229376 –a—— C:\WINDOWS\system32\ieaksie.dll 2006-10-27 02:44 152064 –a—— C:\WINDOWS\system32\ieakeng.dll 2006-10-27 02:44 13312 –a—— C:\WINDOWS\system32\ieudinit.exe 2006-10-27 02:44 123904 –a—— C:\WINDOWS\system32\advpack.dll 2006-10-27 02:42 161792 –a—— C:\WINDOWS\system32\ieakui.dll 2006-10-19 08:56 713216 –a—— C:\WINDOWS\system32\sxs.dll 2006-10-18 21:58 8704 –a—— C:\WINDOWS\system32\wdfmgr.exe 2006-10-18 21:58 8704 –a—— C:\WINDOWS\system32\uwdf.exe 2006-10-18 21:47 99840 –a—— C:\WINDOWS\system32\wmpshell.dll 2006-10-18 21:47 991744 –a—— C:\WINDOWS\system32\drmv2clt.dll 2006-10-18 21:47 937984 –a—— C:\WINDOWS\system32\WMNetMgr.dll 2006-10-18 21:47 8231936 –a—— C:\WINDOWS\system32\wmploc.dll 2006-10-18 21:47 767488 ——— C:\WINDOWS\system32\WMVSENCD.dll 2006-10-18 21:47 757248 –a—— C:\WINDOWS\system32\WMADMOD.dll 2006-10-18 21:47 7168 –a—— C:\WINDOWS\system32\asferror.dll 2006-10-18 21:47 656896 ——— C:\WINDOWS\system32\WMVXENCD.dll 2006-10-18 21:47 63488 –a—— C:\WINDOWS\system32\wpdmtpus.dll 2006-10-18 21:47 629760 –a—— C:\WINDOWS\system32\wpd_ci.dll 2006-10-18 21:47 613376 ——— C:\WINDOWS\system32\wmpmde.dll 2006-10-18 21:47 603648 –a—— C:\WINDOWS\system32\WMSPDMOD.dll 2006-10-18 21:47 542720 –a—— C:\WINDOWS\system32\blackbox.dll 2006-10-18 21:47 535040 ——— C:\WINDOWS\system32\wmdrmsdk.dll 2006-10-18 21:47 429056 –a—— C:\WINDOWS\system32\wmdrmdev.dll 2006-10-18 21:47 414208 –a—— C:\WINDOWS\system32\msscp.dll 2006-10-18 21:47 4096 –a—— C:\WINDOWS\system32\wmvdmoe2.dll 2006-10-18 21:47 4096 –a—— C:\WINDOWS\system32\wmvdmod.dll 2006-10-18 21:47 4096 –a—— C:\WINDOWS\system32\WMVADVE.DLL 2006-10-18 21:47 4096 –a—— C:\WINDOWS\system32\WMVADVD.dll 2006-10-18 21:47 4096 –a—— C:\WINDOWS\system32\wmsdmoe2.dll 2006-10-18 21:47 4096 –a—— C:\WINDOWS\system32\wmsdmod.dll 2006-10-18 21:47 4096 –a—— C:\WINDOWS\system32\wdfapi.dll 2006-10-18 21:47 4096 –a—— C:\WINDOWS\system32\MPG4DMOD.dll 2006-10-18 21:47 4096 ——— C:\WINDOWS\system32\MP4SDMOD.dll 2006-10-18 21:47 4096 ——— C:\WINDOWS\system32\MP43DMOD.dll 2006-10-18 21:47 38400 ——— C:\WINDOWS\system32\wpdshextres.dll 2006-10-18 21:47 37376 –a—— C:\WINDOWS\system32\wmdmps.dll 2006-10-18 21:47 35840 –a—— C:\WINDOWS\system32\wpdconns.dll 2006-10-18 21:47 356352 –a—— C:\WINDOWS\system32\wpdsp.dll 2006-10-18 21:47 348672 –a—— C:\WINDOWS\system32\wmdrmnet.dll 2006-10-18 21:47 33792 –a—— C:\WINDOWS\system32\wmdmlog.dll 2006-10-18 21:47 321536 –a—— C:\WINDOWS\system32\mswmdm.dll 2006-10-18 21:47 317440 ——— C:\WINDOWS\system32\MP4SDECD.dll 2006-10-18 21:47 314880 –a—— C:\WINDOWS\system32\wmpdxm.dll 2006-10-18 21:47 295936 ——— C:\WINDOWS\system32\wmpeffects.dll 2006-10-18 21:47 284160 ——— C:\WINDOWS\system32\PortableDeviceApi.dll 2006-10-18 21:47 276992 –a—— C:\WINDOWS\system32\audiodev.dll 2006-10-18 21:47 27136 –a—— C:\WINDOWS\system32\mspmsnsv.dll 2006-10-18 21:47 2603008 ——— C:\WINDOWS\system32\WpdShext.dll 2006-10-18 21:47 259072 ——— C:\WINDOWS\system32\MPG4DECD.dll 2006-10-18 21:47 259072 ——— C:\WINDOWS\system32\MP43DECD.dll 2006-10-18 21:47 2450944 –a—— C:\WINDOWS\system32\wmvcore.dll 2006-10-18 21:47 242688 –a—— C:\WINDOWS\system32\wmpasf.dll 2006-10-18 21:47 229376 –a—— C:\WINDOWS\system32\cewmdm.dll 2006-10-18 21:47 227328 –a—— C:\WINDOWS\system32\wmerror.dll 2006-10-18 21:47 222208 –a—— C:\WINDOWS\system32\WMASF.dll 2006-10-18 21:47 212992 ——— C:\WINDOWS\system32\MFPLAT.dll 2006-10-18 21:47 211456 –a—— C:\WINDOWS\system32\qasf.dll 2006-10-18 21:47 204288 –a—— C:\WINDOWS\system32\wmpsrcwp.dll 2006-10-18 21:47 199168 ——— C:\WINDOWS\system32\PortableDeviceWMDRM.dll 2006-10-18 21:47 179712 –a—— C:\WINDOWS\system32\msnetobj.dll 2006-10-18 21:47 175616 –a—— C:\WINDOWS\system32\mspmsp.dll 2006-10-18 21:47 166912 ——— C:\WINDOWS\system32\PortableDeviceTypes.dll 2006-10-18 21:47 1661440 –a—— C:\WINDOWS\system32\wmpencen.dll 2006-10-18 21:47 1574912 ——— C:\WINDOWS\system32\WMVENCOD.dll 2006-10-18 21:47 157184 –a—— C:\WINDOWS\system32\wmidx.dll 2006-10-18 21:47 154624 –a—— C:\WINDOWS\system32\wpdmtp.dll 2006-10-18 21:47 1543680 ——— C:\WINDOWS\system32\WMVDECOD.dll 2006-10-18 21:47 1382912 ——— C:\WINDOWS\system32\WMVSDECD.dll 2006-10-18 21:47 133632 ——— C:\WINDOWS\system32\WPDShServiceObj.dll 2006-10-18 21:47 1329152 –a—— C:\WINDOWS\system32\WMSPDMOE.dll 2006-10-18 21:47 132096 ——— C:\WINDOWS\system32\PortableDeviceWiaCompat.dll 2006-10-18 21:47 130048 ——— C:\WINDOWS\system32\wmpps.dll 2006-10-18 21:47 11264 –a—— C:\WINDOWS\system32\LAPRXY.dll 2006-10-18 21:47 1117696 –a—— C:\WINDOWS\system32\WMADMOE.dll 2006-10-18 21:47 101888 ——— C:\WINDOWS\system32\PortableDeviceClassExtension.dll 2006-10-18 20:03 100864 –a—— C:\WINDOWS\system32\logagent.exe 2006-10-18 20:00 249856 ——— C:\WINDOWS\system32\drmupgds.exe 2006-10-18 20:00 17408 ——— C:\WINDOWS\system32\wpdshextautoplay.exe 2006-10-17 13:06 78336 –a—— C:\WINDOWS\system32\ieencode.dll 2006-10-17 13:05 40960 –a—— C:\WINDOWS\system32\licmgr10.dll 2006-10-17 13:05 206336 ——— C:\WINDOWS\system32\WinFXDocObj.exe 2006-10-17 13:05 105984 –a—— C:\WINDOWS\system32\url.dll 2006-10-17 13:04 101376 –a—— C:\WINDOWS\system32\occache.dll 2006-10-17 13:03 17408 –a—— C:\WINDOWS\system32\corpol.dll 2006-10-17 12:58 61952 ——— C:\WINDOWS\system32\icardie.dll 2006-10-17 12:58 12288 ——— C:\WINDOWS\system32\msfeedssync.exe 2006-10-17 12:57 36352 –a—— C:\WINDOWS\system32\imgutil.dll 2006-10-17 12:57 266752 ——— C:\WINDOWS\system32\iertutil.dll 2006-10-17 12:56 45568 –a—— C:\WINDOWS\system32\mshta.exe 2006-10-17 12:28 48128 –a—— C:\WINDOWS\system32\mshtmler.dll 2006-10-17 12:27 380928 ——— C:\WINDOWS\system32\ieapfltr.dll 2006-10-13 07:35 142336 –a—— C:\WINDOWS\system32\nwprovau.dll 2006-10-11 11:24 58880 –a—— C:\WINDOWS\system32\pnrpnsp.dll 2006-10-11 11:24 553984 –a—— C:\WINDOWS\system32\p2psvc.dll 2006-10-11 11:24 313344 –a—— C:\WINDOWS\system32\p2pgraph.dll 2006-10-11 11:24 153088 –a—— C:\WINDOWS\system32\p2p.dll 2006-10-11 11:24 116224 –a—— C:\WINDOWS\system32\p2pnetsh.dll 2006-10-11 11:24 104960 –a—— C:\WINDOWS\system32\p2pgasvc.dll 2006-10-02 15:28 312128 ——— C:\WINDOWS\system32\msdelta.dll 2006-09-28 20:13 95344 ——— C:\WINDOWS\system32\WUDFCoinstaller.dll 2006-09-28 18:56 55808 ——— C:\WINDOWS\system32\WudfSvc.dll 2006-09-28 18:56 316416 ——— C:\WINDOWS\system32\WUDFx.dll 2006-09-28 18:56 165376 ——— C:\WINDOWS\system32\WudfPlatform.dll 2006-09-28 18:56 146432 ——— C:\WINDOWS\system32\WudfHost.exe 2006-09-25 17:58 23856 –a—— C:\WINDOWS\system32\spupdsvc.exe (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries are not shown [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] "MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background" "ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe" "WMPNSCFG"="C:\\Program Files\\Windows Media Player\\WMPNSCFG.exe" "SUPERAntiSpyware"="C:\\Program Files\\SUPERAntiSpyware\\SUPERAntiSpyware.exe" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce] "FlashPlayerUpdate"="C:\\WINDOWS\\system32\\Macromed\\Flash\\GetFlash.exe" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] "IgfxTray"="C:\\WINDOWS\\System32\\igfxtray.exe" "HotKeysCmds"="C:\\WINDOWS\\System32\\hkcmd.exe" "Apoint"="C:\\Program Files\\Apoint2K\\Apoint.exe" "CeEPOWER"="C:\\WINDOWS\\System32\\CePMTray.exe" "Pinger"="c:\\toshiba\\ivp\\ism\\pinger.exe /run" @="" "EXSHOW95.EXE"="EXSHOW95.EXE" "ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\"" "vptray"="C:\\PROGRA~1\\SYMANT~1\\VPTray.exe" "TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot" "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime" "Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI] "Installed"="1" "NoChange"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS] "Installed"="1" [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components] "DeskHtmlVersion"=dword:00000110 "DeskHtmlMinorVersion"=dword:00000005 "Settings"=dword:00000001 "GeneralFlags"=dword:00000000 [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" "Flags"=dword:00000002 "Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,00,03,00,00,00,\ 00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 "CurrentState"=hex:04,00,00,40 "OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\ ff,ff,04,00,00,00 "RestoredStateInfo"=hex:18,00,00,00,f2,01,00,00,23,00,00,00,7c,00,00,00,72,00,\ 00,00,01,00,00,00 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"="" "{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook" "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"="" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 "Btn_Search"=dword:00000000 "SpecifyDefaultButtons"=dword:00000000 [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "dontdisplaylastusername"=dword:00000000 "legalnoticecaption"="" "legalnoticetext"="" "shutdownwithoutlogon"=dword:00000001 "undockwithoutlogon"=dword:00000001 [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 "Btn_Search"=dword:00000000 "SpecifyDefaultButtons"=dword:00000000 [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 "Btn_Search"=dword:00000000 "SpecifyDefaultButtons"=dword:00000000 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload] "PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}" "CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}" "WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" "SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}" "WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}" HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll" Contents of the 'Scheduled Tasks' folder C:\WINDOWS\tasks\MP Scheduled Scan.job C:\WINDOWS\tasks\Symantec NetDetect.job Completion time: 06-12-22 9:46:43.83 C:\ComboFix.txt … 06-12-22 09:46
*Using Windows Explorer, find and delete these files:

C:\WINDOWS\system32\INETDCTR.DLL
C:\WINDOWS\system32\IDCTUP20.EXE

Empty your recycle bin.

Reboot.


*Run Kaspersky Online Scanner

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest Definition Files.
  • Once the Scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings.
  • In the Scan Settings, make that the following are selected:
    o Scan using the following Anti-Virus database:
    + Extended (If available otherwise Standard)
    o Scan Options:
    + Scan Archives
    + Scan Mail Bases
  • Click OK.
  • Now under select a target to scan select My Computer.
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button:
  • Save the file to your Desktop.
*I would like you to scan a few files for me.

Please go HERE. Click browse then, navigate to this file:

C:\WINDOWS\ORUN32.EXE

Then click submit.

Do the same for this file: C:\WINDOWS\system32\CMMGR32.EXE

Please post the results to your next reply.

If Jotti is too busy, you can go HERE and do the same as above.

On your next reply, please include a fresh hijackThis log along with the kaspersky log.
The 2 files: C:\WINDOWS\ORUN32.EXE C:\WINDOWS\system32\CMMGR32.EXE Returned the following result for both files: The file you uploaded is 0 bytes. It is very likely a firewall or a piece of malware is prohibiting you from uploading this file Here is my Kaspersky Online Antivirus Log, I did not fix anything: ——————————————————————————- KASPERSKY ONLINE SCANNER REPORT Tuesday, December 26, 2006 3:31:20 PM Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.83.0 Kaspersky Anti-Virus database last update: 26/12/2006 Kaspersky Anti-Virus database records: 254392 ——————————————————————————- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: C:\ D:\ Scan Statistics: Total number of scanned objects: 46174 Number of viruses found: 2 Number of infected objects: 1 / 0 Number of suspicious objects: 2 Duration of the scan process: 01:23:03 Infected Object Name / Virus Name / Last Action C:\Documents and Settings\Admin\Application Data\Adobe\Acrobat\Whapi\CreatePDFWinColor.ico Object is locked skipped C:\Documents and Settings\Admin\Application Data\Adobe\Acrobat\Whapi\CreatePDFWinGray.ico Object is locked skipped C:\Documents and Settings\Admin\Application Data\Adobe\Acrobat\Whapi\SearchPDFWinColor.ico Object is locked skipped C:\Documents and Settings\Admin\Application Data\Adobe\Acrobat\Whapi\SearchPDFWinGray.ico Object is locked skipped C:\Documents and Settings\Admin\Application Data\Adobe\Acrobat\Whapi\WHAppList.xml Object is locked skipped C:\Documents and Settings\Admin\Application Data\desktop.ini Object is locked skipped C:\Documents and Settings\Admin\Application Data\Microsoft\CryptnetUrlCache\Content\60E31627FDA0A46932B0E5948949F2A5 Object is locked skipped C:\Documents and Settings\Admin\Application Data\Microsoft\CryptnetUrlCache\Content\A8FABA189DB7D25FBA7CAC806625FD30 Object is locked skipped C:\Documents and Settings\Admin\Application Data\Microsoft\CryptnetUrlCache\MetaData\60E31627FDA0A46932B0E5948949F2A5 Object is locked skipped C:\Documents and Settings\Admin\Application Data\Microsoft\CryptnetUrlCache\MetaData\A8FABA189DB7D25FBA7CAC806625FD30 Object is locked skipped C:\Documents and Settings\Admin\Application Data\Microsoft\HTML Help\hh.dat Object is locked skipped C:\Documents and Settings\Admin\Application Data\Microsoft\Internet Explorer\brndlog.bak Object is locked skipped C:\Documents and Settings\Admin\Application Data\Microsoft\Internet Explorer\brndlog.txt Object is locked skipped C:\Documents and Settings\Admin\Application Data\Microsoft\Internet Explorer\Desktop.htt Object is locked skipped C:\Documents and Settings\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\America Online 6.0.lnk Object is locked skipped C:\Documents and Settings\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini Object is locked skipped C:\Documents and Settings\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk Object is locked skipped C:\Documents and Settings\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf Object is locked skipped C:\Documents and Settings\Admin\Application Data\Microsoft\Protect\CREDHIST Object is locked skipped C:\Documents and Settings\Admin\Application Data\Microsoft\Windows\Themes\Custom.theme Object is locked skipped C:\Documents and Settings\Admin\Application Data\Symantec\Shared\MyProfile.UserProfile Object is locked skipped C:\Documents and Settings\Admin\Application Data\Symantec\Shared\Options.VcPref Object is locked skipped C:\Documents and Settings\Admin\Application Data\Symantec\Shared\Sessions\20020323134857551.liveReg Object is locked skipped C:\Documents and Settings\Admin\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Admin\Favorites\Desktop.ini Object is locked skipped C:\Documents and Settings\Admin\Favorites\Links\Customize Links.url Object is locked skipped C:\Documents and Settings\Admin\Favorites\Links\Free Hotmail.url Object is locked skipped C:\Documents and Settings\Admin\Favorites\Links\RealPlayer.url Object is locked skipped C:\Documents and Settings\Admin\Favorites\Links\Toshiba On the Web\FreedomWare.url Object is locked skipped C:\Documents and Settings\Admin\Favorites\Links\Toshiba On the Web\Toshiba Computer Accessories.url Object is locked skipped C:\Documents and Settings\Admin\Favorites\Links\Toshiba On the Web\Toshiba Product Information.url Object is locked skipped C:\Documents and Settings\Admin\Favorites\Links\Toshiba On the Web\Toshiba Solutions.url Object is locked skipped C:\Documents and Settings\Admin\Favorites\Links\Toshiba On the Web\Toshiba Warranty & Service Programs.url Object is locked skipped C:\Documents and Settings\Admin\Favorites\Links\Toshiba Support\Ask IRIS.url Object is locked skipped C:\Documents and Settings\Admin\Favorites\Links\Toshiba Support\Email Subscription.url Object is locked skipped C:\Documents and Settings\Admin\Favorites\Links\Toshiba Support\How to Get Help.url Object is locked skipped C:\Documents and Settings\Admin\Favorites\Links\Toshiba Support\Software Downloads.url Object is locked skipped C:\Documents and Settings\Admin\Favorites\Links\Toshiba Support\Software Upgrades.lnk Object is locked skipped C:\Documents and Settings\Admin\Favorites\Links\Toshiba Support\Support Bulletins.url Object is locked skipped C:\Documents and Settings\Admin\Favorites\Links\Toshiba Support\Support Information.lnk Object is locked skipped C:\Documents and Settings\Admin\Favorites\Links\Toshiba Support\Virtual Tech.url Object is locked skipped C:\Documents and Settings\Admin\Favorites\Links\Windows Marketplace.url Object is locked skipped C:\Documents and Settings\Admin\Favorites\Links\Windows Media.url Object is locked skipped C:\Documents and Settings\Admin\Favorites\Links\Windows.url Object is locked skipped C:\Documents and Settings\Admin\Favorites\Media\Real.com Radio Tuner.url Object is locked skipped C:\Documents and Settings\Admin\Favorites\Microsoft Websites\IE Add-on site.url Object is locked skipped C:\Documents and Settings\Admin\Favorites\Microsoft Websites\IE site on Microsoft.com.url Object is locked skipped C:\Documents and Settings\Admin\Favorites\Microsoft Websites\Marketplace.url Object is locked skipped C:\Documents and Settings\Admin\Favorites\Microsoft Websites\Microsoft At Home.url Object is locked skipped C:\Documents and Settings\Admin\Favorites\Microsoft Websites\Microsoft At Work.url Object is locked skipped C:\Documents and Settings\Admin\Favorites\Microsoft Websites\Welcome to IE7.url Object is locked skipped C:\Documents and Settings\Admin\Favorites\MSN.com.url Object is locked skipped C:\Documents and Settings\Admin\Favorites\Radio Station Guide.url Object is locked skipped C:\Documents and Settings\Admin\Favorites\RealPlayer Home Page.url Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Application Data\GDIPFONTCACHEV1.DAT Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Application Data\IconCache.db Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Application Data\Microsoft\Feeds\FeedsStore.feedsdb-ms Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Application Data\Microsoft\Feeds\Microsoft Feeds~\Microsoft at Home~.feed-ms Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Application Data\Microsoft\Feeds\Microsoft Feeds~\Microsoft at Work~.feed-ms Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Application Data\Microsoft\Feeds Cache\2VTD1AX6\desktop.ini Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Application Data\Microsoft\Feeds Cache\2VTD1AX6\fwlink[1] Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Application Data\Microsoft\Feeds Cache\2Z09JLO0\desktop.ini Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Application Data\Microsoft\Feeds Cache\2Z09JLO0\fwlink[1] Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Application Data\Microsoft\Feeds Cache\59F8J7PU\desktop.ini Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Application Data\Microsoft\Feeds Cache\CZ7IB7OK\desktop.ini Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Application Data\Microsoft\Feeds Cache\desktop.ini Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Application Data\Microsoft\HelpCtr\D23D0028-A543-4767-B4AA-1581D8E1CDB2_1033.xml Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Application Data\Microsoft\HelpCtr\HelpSessionHistory.dat Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Application Data\Microsoft\Internet Explorer\brndlog.txt Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Application Data\Microsoft\Internet Explorer\MSIMGSIZ.DAT Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Application Data\Microsoft\Wallpaper1.bmp Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Logs\08022006.Log Object is locked skipped C:\Documents and Settings\Admin\Local Settings\desktop.ini Object is locked skipped C:\Documents and Settings\Admin\Local Settings\History\desktop.ini Object is locked skipped C:\Documents and Settings\Admin\Local Settings\History\History.IE5\desktop.ini Object is locked skipped C:\Documents and Settings\Admin\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Admin\Local Settings\History\History.IE5\MSHist012006122620061227\index.dat Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temp\ccdist.exe Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temp\IMT1A.xml Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temp\IMT1B.xml Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temp\IMT1C.xml Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temp\INSTALL.HLP Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temp\Temporary Internet Files\Content.IE5\5OTS8LWX\desktop.ini Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temp\Temporary Internet Files\Content.IE5\8J30EG4V\desktop.ini Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temp\Temporary Internet Files\Content.IE5\BM0PH7TH\desktop.ini Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temp\Temporary Internet Files\Content.IE5\desktop.ini Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temp\Temporary Internet Files\Content.IE5\XLL881A3\desktop.ini Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temp\wintdist.exe Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temp\WZS19.tmp\Setup.exe Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temp\WZS19.tmp\WBDBV32I.DLL Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temp\{c1939820-a945-11d4-86f6-0001031e5712}\LOG Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temp\~DF10A7.tmp Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temp\~DF291.tmp Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temp\~DFE9F0.tmp Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temp\~DFEA01.tmp Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temp\~rnsetup\pncrt.dll Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temp\~rnsetup\pnrs3260.dll Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\arrow_blue_normal_shadow[1].bmp Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\arrow_green_normal[1].bmp Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\arrow_green_normal_shadow[1].bmp Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\background[1].gif Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\buttonForm[1].js Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\buttonForm[2].js Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\Class3SoftwarePublishers[1].crl Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\Common[1].js Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\Common[2].js Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\Common[3].js Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\Common[4].js Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\Common[5].js Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\content[1].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\corner_01[1].gif Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\coUA[1].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\coUA[2].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\cpwebvw[1] Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\defaultsettings[1].xml Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\desktop.ini Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\desktop_icon_02[1].bmp Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\desktop_icon_03[1].bmp Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\dialog_download[1].htm Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\dialog_eula[1].htm Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\firstpage[1].htm Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\footer[1].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\footer[1].htm Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\HHWRAPPER[1].htm Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\HomenetInfo[1].htm Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\Homepage__DESKTOP[1].js Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\Homepage__SHARED[1].js Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\images_expando_collapsed[1].gif Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\iuident[1].cab Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\logo_01[1].gif Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\mstoolbar_ms[1].gif Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\nav_00_01r[1].gif Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\nav_00_03[1].gif Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\nav_00_05r[1].gif Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\nav_00_07[1].gif Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\nusrmgr[1] Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\ping[1].htm Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\ping_tssm[1].htm Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\progbar[1].gif Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\selectable[1] Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\shared[1].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\shared[2].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\shared[3].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\shared[4].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\shared[5].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\shared[6].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\shared[7].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\s_image_02[1].gif Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\toc_expanded[1].gif Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\top[1].vbs Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\TOSH001[1].BMP Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\tosnote[1].bmp Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\tosnote[2].bmp Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\tshootText[1].js Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\TshootText[1].xml Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\tshoot_shared[1].js Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\tshoot_shared[2].js Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\Uabrand[1].gif Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\users32[1] Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\users[1] Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\watermark_300x[1].bmp Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\worldwide[1].gif Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\4JLQZ4O5\wutrack[1].bin Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\1_gray[1].gif Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\arrow_green_normal[1].bmp Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\arrow_green_normal_shadow[1].bmp Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\background[1].gif Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\Behaviors[1].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\bg_tile[1].gif Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\blank[1].htm Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\body[1] Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\buttonForm[1].js Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\Common[1].js Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\Common[2].js Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\Common[3].js Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\Common[4].js Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\Common[5].js Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\Common[6].js Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\Common[7].js Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\Common[8].js Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\coUA[1].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\desktop.ini Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\desktop_icon_03[1].bmp Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\desktop_icon_04[1].bmp Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\dialog[1].js Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\featured_01a[1].gif Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\firstpage[2].htm Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\helpdoc[1] Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\HomePage[1].htm Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\HomePage[2].htm Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\Homepage__DESKTOP[1].js Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\Homepage__SHARED[1].js Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\images_expando_expanded[1].gif Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\install[1].gif Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\iuctl[1].CAB Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\localtext[1] Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\Logo[1].bmp Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\msinfo[1].htm Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\mstoolbar[1].htm Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\mstoolbar[1].js Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\mstoolbar_icp[1].gif Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\nav_00_03r[1].gif Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\nav_00_04[1].gif Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\nav_00_06r[1].gif Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\newsblock01[1].xml Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\note[1].gif Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\note[2].gif Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\reusable[1].xml Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\searchblurb[1].htm Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\shared[10].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\shared[1].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\shared[2].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\shared[3].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\shared[4].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\shared[5].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\shared[6].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\shared[7].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\shared[8].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\shared[9].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\spacer_01[1].gif Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\status[1].htm Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\s_image_03[2].gif Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\toc[1].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\top2[1].js Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\Toshibacss[1].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\tshomenet_result[1].htm Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\tshoot_shared[1].js Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\windowsupdate[1].htm Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\N4JB41WD\wutrack[1].bin Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\00_bg_spacer[1].gif Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\alttext[1].xml Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\arrow[1].gif Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\Behaviors[1].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\chg_common[1] Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\classic[1] Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\Common[1].js Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\Common[2].js Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\Common[3].js Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\Common[4].js Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\content[1].js Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\Context[1].htm Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\coUAprint[1].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\coUA[1].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\csg_button[1].gif Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\desktop.ini Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\desktop_icon_01[1].bmp Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\desktop_icon_02[1].bmp Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\dglogs[1].htm Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\eula[1].htm Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\featured_01[1].gif Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\homenetinfo_result[1].htm Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\images_expando_endnode[1].gif Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\image_03[1].jpg Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\iuctl[1].cab Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\MiniNavBar[1].htm Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\MiniNavBar[2].xml Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\msinfo[1].xml Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\mstoolbar_curve[1].gif Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\NavBar[1].htm Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\NavBar[1].xml Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\nav_00_02[1].gif Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\nav_00_04r[1].gif Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\nav_00_06[1].gif Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\Pinger[1].htm Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\popup[1] Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\resize[1].js Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\results[1].htm Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\Search[1].xml Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\shared[1].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\shared[1].js Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\shared[2].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\shared[3].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\shared[4].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\shared[5].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\shared[6].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\shared[7].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\shared[8].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\shared[9].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\splash[1].htm Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\taskbullet[1] Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\toc_endnode[1].gif Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\top[1].js Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\toshiba[1].htm Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\tsctl[1].htm Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\tshoot[1].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\WebLinks[1].ini Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\wrapperparam[1].js Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\US4A9TAW\wutrack[1].bin Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\B22200c[1].htm Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\CodeSignPCA[1].crl Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\Common[1].js Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\Common[2].js Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\Common[3].js Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\Common[4].js Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\Context[3].htm Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\coUA[1].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\default[1].htm Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\desktop.ini Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\desktop_icon_01[1].bmp Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\desktop_icon_04[1].bmp Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\dialog[1].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\failed_icon[1].gif Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\GetConfigData[1].xml Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\guest_disabled[1] Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\hcp[1].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\image_02[1].jpg Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\Layout[1].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\Layout[2].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\Logo[1].bmp Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\mainpage2[1] Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\mstoolbar[1].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\NavBar[1].htm Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\NavBar[1].xml Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\nav_00_01[1].gif Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\nav_00_02r[1].gif Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\nav_00_05[1].gif Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\nav_00_07r[1].gif Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\newsblock02[1].xml Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\newsver[1].xml Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\nusrmgr[1] Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\nusrmgr[2] Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\Search[1].htm Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\shared[1].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\shared[2].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\shared[3].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\Shared[4].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\shared[5].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\shared[6].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\shared[7].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\shared[8].css Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\shortcutCold[1].gif Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\sp1express_22E3E78B5CBBE5DB9128B1DBA2D1B80F1BDC131B[1].exe Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\splash[1].htm Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\splash[2].htm Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\s_image_04[1].gif Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\toc[1].htm Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\toc[1].js Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\TOSH001[1].BMP Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\tsctlLoad[1].htm Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\tshomenet[1].htm Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\tshomenet_sniff[1].htm Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\usahome[1].gif Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\Content.IE5\Y7E8T9P3\worldwidesites[1].gif Object is locked skipped C:\Documents and Settings\Admin\Local Settings\Temporary Internet Files\desktop.ini Object is locked skipped C:\Documents and Settings\Admin\My Documents\desktop.ini Object is locked skipped C:\Documents and Settings\Admin\My Documents\My Music\Desktop.ini Object is locked skipped C:\Documents and Settings\Admin\My Documents\My Music\Sample Music.lnk Object is locked skipped C:\Documents and Settings\Admin\My Documents\My Pictures\Desktop.ini Object is locked skipped C:\Documents and Settings\Admin\My Documents\My Pictures\Sample Pictures.lnk Object is locked skipped C:\Documents and Settings\Admin\My Documents\My Pictures\Thumbs.db Object is locked skipped C:\Documents and Settings\Admin\ntuser.dat Object is locked skipped C:\Documents and Settings\Admin\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\Admin\ntuser.ini Object is locked skipped C:\Documents and Settings\Admin\Recent\Desktop.ini Object is locked skipped C:\Documents and Settings\Admin\Recent\SYSPREP (2).lnk Object is locked skipped C:\Documents and Settings\Admin\Recent\SYSPREP.lnk Object is locked skipped C:\Documents and Settings\Admin\SendTo\Compressed (zipped) Folder.ZFSendToTarget Object is locked skipped C:\Documents and Settings\Admin\SendTo\Desktop (create shortcut).DeskLink Object is locked skipped C:\Documents and Settings\Admin\SendTo\desktop.ini Object is locked skipped C:\Documents and Settings\Admin\SendTo\Mail Recipient.MAPIMail Object is locked skipped C:\Documents and Settings\Admin\SendTo\My Documents.mydocs Object is locked skipped C:\Documents and Settings\Admin\Start Menu\desktop.ini Object is locked skipped C:\Documents and Settings\Admin\Start Menu\Programs\Accessories\Accessibility\desktop.ini Object is locked skipped C:\Documents and Settings\Admin\Start Menu\Programs\Accessories\Accessibility\Magnifier.lnk Object is locked skipped C:\Documents and Settings\Admin\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk Object is locked skipped C:\Documents and Settings\Admin\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk Object is locked skipped C:\Documents and Settings\Admin\Start Menu\Programs\Accessories\Accessibility\Utility Manager.lnk Object is locked skipped C:\Documents and Settings\Admin\Start Menu\Programs\Accessories\Address Book.lnk Object is locked skipped C:\Documents and Settings\Admin\Start Menu\Programs\Accessories\Command Prompt.lnk Object is locked skipped C:\Documents and Settings\Admin\Start Menu\Programs\Accessories\desktop.ini Object is locked skipped C:\Documents and Settings\Admin\Start Menu\Programs\Accessories\Entertainment\desktop.ini Object is locked skipped C:\Documents and Settings\Admin\Start Menu\Programs\Accessories\Entertainment\RealPlayer.lnk Object is locked skipped C:\Documents and Settings\Admin\Start Menu\Programs\Accessories\Notepad.lnk Object is locked skipped C:\Documents and Settings\Admin\Start Menu\Programs\Accessories\Program Compatibility Wizard.lnk Object is locked skipped C:\Documents and Settings\Admin\Start Menu\Programs\Accessories\Synchronize.lnk Object is locked skipped C:\Documents and Settings\Admin\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk Object is locked skipped C:\Documents and Settings\Admin\Start Menu\Programs\Accessories\Tour Windows XP.lnk Object is locked skipped C:\Documents and Settings\Admin\Start Menu\Programs\Accessories\Windows Explorer.lnk Object is locked skipped C:\Documents and Settings\Admin\Start Menu\Programs\desktop.ini Object is locked skipped C:\Documents and Settings\Admin\Start Menu\Programs\Internet Explorer.lnk Object is locked skipped C:\Documents and Settings\Admin\Start Menu\Programs\Outlook Express.lnk Object is locked skipped C:\Documents and Settings\Admin\Start Menu\Programs\Remote Assistance.lnk Object is locked skipped C:\Documents and Settings\Admin\Start Menu\Programs\Startup\desktop.ini Object is locked skipped C:\Documents and Settings\Admin\Start Menu\Programs\Windows Media Player.lnk Object is locked skipped C:\Documents and Settings\Admin\Start Menu\Programs\Windows Messenger.lnk Object is locked skipped C:\Documents and Settings\Admin\Templates\amipro.sam Object is locked skipped C:\Documents and Settings\Admin\Templates\excel.xls Object is locked skipped C:\Documents and Settings\Admin\Templates\excel4.xls Object is locked skipped C:\Documents and Settings\Admin\Templates\lotus.wk4 Object is locked skipped C:\Documents and Settings\Admin\Templates\powerpnt.ppt Object is locked skipped C:\Documents and Settings\Admin\Templates\presenta.shw Object is locked skipped C:\Documents and Settings\Admin\Templates\quattro.wb2 O
And here is the rest of the log file: C:\Documents and Settings\Admin\Templates\quattro.wb2 Object is locked skipped C:\Documents and Settings\Admin\Templates\sndrec.wav Object is locked skipped C:\Documents and Settings\Admin\Templates\winword.doc Object is locked skipped C:\Documents and Settings\Admin\Templates\winword2.doc Object is locked skipped C:\Documents and Settings\Admin\Templates\wordpfct.wpd Object is locked skipped C:\Documents and Settings\Admin\Templates\wordpfct.wpg Object is locked skipped C:\Documents and Settings\Admin\UserData\E5APKTKV\oWindowsUpdate[1].xml Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-12192006-105705.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Windows NT\MSFax\ActivityLog\InboxLOG.txt Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Windows NT\MSFax\ActivityLog\OutboxLOG.txt Object is locked skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CallingHomebiz.zip/gbdoch.exe Suspicious: Password-protected-EXE skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CallingHomebiz.zip ZIP: suspicious - 1 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp Object is locked skipped C:\Documents and Settings\All Users\DRM\drmstore.hds Object is locked skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\Stefanie\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Stefanie\Local Settings\Application Data\Microsoft\Media Player\CurrentDatabase_360.wmdb Object is locked skipped C:\Documents and Settings\Stefanie\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Stefanie\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Stefanie\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Stefanie\Local Settings\Temp\~DF4B3F.tmp Object is locked skipped C:\Documents and Settings\Stefanie\Local Settings\Temp\~DF4BC9.tmp Object is locked skipped C:\Documents and Settings\Stefanie\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped C:\Documents and Settings\Stefanie\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Stefanie\ntuser.dat Object is locked skipped C:\Documents and Settings\Stefanie\ntuser.dat.LOG Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBConfig.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDebug.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDetect.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBNotify.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBRefr.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetDev.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetLoc.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetUsr.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStHash.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStMSI.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBValid.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPPolicy.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStart.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStop.log Object is locked skipped C:\Program Files\Symantec AntiVirus\SAVRT\0362NAV~.TMP Object is locked skipped C:\Program Files\Symantec AntiVirus\SAVRT\0773NAV~.TMP Object is locked skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{E126D0E1-B902-48D5-B5DE-630CE9695C8A}\RP1208\A0045681.dll Infected: not-a-virus:AdWare.Win32.SafeSurfing.c skipped C:\System Volume Information\_restore{E126D0E1-B902-48D5-B5DE-630CE9695C8A}\RP1216\change.log Object is locked skipped C:\WINDOWS\$NtUninstallQ307274$\spuninst\spuninst.inf Object is locked skipped C:\WINDOWS\$NtUninstallQ311345$\spuninst\spuninst.inf Object is locked skipped C:\WINDOWS\$NtUninstallQ311889$\termsrv.dll Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\ModemLog_TOSHIBA Software Modem AMR.txt Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\Internet.evt Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\wiadebug.log Object is locked skipped C:\WINDOWS\wiaservc.log Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped Scan process completed.
hi, sorry that I've been gone for a few days, a very unfortunate thing happened to our family..I was suppose to enjoy the holidays in the camp but this thing happened…

Download Gmer from here:
http://gmer.thespykiller.co.uk/gmer.zip
  • Disconnect from internet and close running programs.
  • There is a small chance this application may crash your computer so save any work you have open.
  • Double click gmer.exe
  • Let the gmer.sys driver load if asked.
  • If it gives you a warning at program start about rootkit activity and asks if you want to run scan…say Ok.
  • If no warning….
  • Click "Rootkit" tab and click "Scan"
  • Once done, click "Copy"
  • Open Notepad and hit "ctrl+v" to paste the log.
  • Reconnect to the internet and post the log back to this thread please.
Download, unzip and run 'RootkitRevealer' from Sysinternals:
http://www.sysinternals.com/Utilities/RootkitRevealer.html

Once the program has started, press Scan and let it run.
When the scan is done, use 'File' > 'Save' to place the logfile in a convenient location (such as the desktop). The default file name will be 'RootkitReveal.txt'.

Save your Log File.
Copy/Paste the contents of that logfile into your next reply.

DO NOT touch the PC at ALL for Whatever reason/s until it has 100% completed its scan, or attempted scan in case of some error etc. !

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI