Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 92333 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Definitely some malware but cannot find it


  • This topic is locked This topic is locked
11 replies to this topic

#1 Guest_san01_*

Guest_san01_*
  • Guests

Posted 19 March 2007 - 04:13 PM

I KNOW my browser has been hijacked but for the life of me I cannot find the source. I use Firefox but my partner who occasionally uses the computer, uses IE and there is the problem. I don't know how long the problem has been on the computer but he only told me about it this week and I have spent all weekend running scans and I have spybot and adware loaded on. When I google in something and click on a web site I want to visit, another search box pops up advertising porn and other bad things, Please help. I've looked at the log from hijack this but I don't know enough about what is good or not. Thanks in advance..

Logfile of HijackThis v1.99.1
Scan saved at 21:23:37, on 19/03/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware Pro\aawservice.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Executive Software\DiskeeperLite\DKService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
c:\program files\lenovo\system update\suservice.exe
C:\WINDOWS\System32\TPHDEXLG.EXE
C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\System32\wltray.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\TP98TRAY.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\TrojanHunter 4.6\THGuard.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\ThinkPad\UltraNav Wizard\UNavTray.EXE
C:\Program Files\NETGEAR\WPN111\wpn111.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\san\Desktop\Downloads\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ie/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ie/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: IEPlugin Class - {CF7C3CF0-4B15-11D1-ABED-709549C10000} - C:\Program Files\Advanced System Optimizer\IEHelper.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [wltray.exe] C:\WINDOWS\System32\wltray.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [TPTRAY] C:\PROGRA~1\ThinkPad\UTILIT~1\TP98TRAY.EXE
O4 - HKLM\..\Run: [IMJPMIG9.0] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMJP9\IMJPMIG.EXE /Preload /Migration32
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE
O4 - HKLM\..\Run: [BMMMONWND] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.6\THGuard.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: NETGEAR WPN111 Smart Wizard.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akama...ex/qtplugin.cab
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=58813
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewi...oOnlineScan.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.t...ivex/hcImpl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1159050386710
O16 - DPF: {74FFE28D-2378-11D5-990C-006094235084} (IBM Access Support) - http://www-307.ibm.c...rt/IbmEgath.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/s...nfo/webscan.cab
O16 - DPF: {9C024426-7859-4B2D-AB4C-B1E370AE7549} - http://us.mcafee.com...ScannerCtrl.cab
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadbl...ivex/sabspx.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0DFAD8A3-B147-4CF6-98C9-F8872322A951}: NameServer = 85.255.116.101,85.255.112.184
O17 - HKLM\System\CCS\Services\Tcpip\..\{15B1749C-2B06-432E-8070-2D91F581FF79}: NameServer = 85.255.116.101,85.255.112.184
O17 - HKLM\System\CCS\Services\Tcpip\..\{649C7725-FD9B-4497-9A0D-C09E31FE8A69}: NameServer = 85.255.116.101,85.255.112.184
O17 - HKLM\System\CCS\Services\Tcpip\..\{98CBDCA4-7EEB-4E2F-B63F-57BE0CE33767}: NameServer = 85.255.116.101,85.255.112.184
O17 - HKLM\System\CCS\Services\Tcpip\..\{D3F9EE0D-2177-4240-A6B0-75684AA03398}: NameServer = 85.255.116.101,85.255.112.184
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = europa.rbsgrp.net,asia.rbsgrp.net,americas.rbsgrp.net,rbsres01.net,rbs01.rbsgretail.net,nwb01.rbsgretail.net,nwb02.rbsgretail.net,nwb03.rbsgretail.net
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.101 85.255.112.184
O17 - HKLM\System\CS1\Services\Tcpip\..\{0DFAD8A3-B147-4CF6-98C9-F8872322A951}: NameServer = 85.255.116.101,85.255.112.184
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = europa.rbsgrp.net,asia.rbsgrp.net,americas.rbsgrp.net,rbsres01.net,rbs01.rbsgretail.net,nwb01.rbsgretail.net,nwb02.rbsgretail.net,nwb03.rbsgretail.net
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.101 85.255.112.184
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware Pro\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\DiskeeperLite\DKService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Oracleora817ClientCache - Unknown owner - C:\ORA817\BIN\ONRSD.EXE
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: System Update (SUService) - - c:\program files\lenovo\system update\suservice.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.EXE
O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe

    Advertisements

Register to Remove


#2 IndiGenus

IndiGenus

    Teacher Emeritus

  • Authentic Member
  • PipPipPipPipPipPip
  • 5,251 posts
  • Interests:Computer Security, Music, Sports

Posted 20 March 2007 - 08:55 AM

Hello san01 and welcome to the forums here at Tom Coyote.

You appear to have a Wareout infection.

I recommend you print out these instructions for reference, since you will have to restart your computer during the fix.

Run HijackThis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

O17 - HKLM\System\CCS\Services\Tcpip\..\{0DFAD8A3-B147-4CF6-98C9-F8872322A951}: NameServer = 85.255.116.101,85.255.112.184
O17 - HKLM\System\CCS\Services\Tcpip\..\{15B1749C-2B06-432E-8070-2D91F581FF79}: NameServer = 85.255.116.101,85.255.112.184
O17 - HKLM\System\CCS\Services\Tcpip\..\{649C7725-FD9B-4497-9A0D-C09E31FE8A69}: NameServer = 85.255.116.101,85.255.112.184
O17 - HKLM\System\CCS\Services\Tcpip\..\{98CBDCA4-7EEB-4E2F-B63F-57BE0CE33767}: NameServer = 85.255.116.101,85.255.112.184
O17 - HKLM\System\CCS\Services\Tcpip\..\{D3F9EE0D-2177-4240-A6B0-75684AA03398}: NameServer = 85.255.116.101,85.255.112.184
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = europa.rbsgrp.net,asia.rbsgrp.net,americas.rbsgrp.net,rbsres01.net,rbs01.rbsgretail.net,nwb01.rbsgretail.net,nwb02.rbsgretail.net,nwb03.rbsgretail.net
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.101 85.255.112.184
O17 - HKLM\System\CS1\Services\Tcpip\..\{0DFAD8A3-B147-4CF6-98C9-F8872322A951}: NameServer = 85.255.116.101,85.255.112.184
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = europa.rbsgrp.net,asia.rbsgrp.net,americas.rbsgrp.net,rbsres01.net,rbs01.rbsgretail.net,nwb01.rbsgretail.net,nwb02.rbsgretail.net,nwb03.rbsgretail.net
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.101 85.255.112.184

Then close all windows except this one and press Fix checked.

Please download FixWareout from one of these sites:
http://downloads.sub.../Fixwareout.exe
http://www.bleepingc.../Fixwareout.exe

Save it to your desktop and run it. Click Next, then Install, make sure "Run fixit" is checked and click Finish.
The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so. Your system may take longer than usual to load; this is normal.

Once the desktop loads please post the text that will open (report.txt) and a new HijackThis log.

Now lets check some settings on your system.
(2000/XP) Only
In the windows control panel. If you are using Windows XP's Category View, select the Network and Internet Connections category otherwise double click on Network Connections. Then right click on your default connection, usually local area connection for cable and dsl, and left click on properties. Click the Networking tab. Double-click on the Internet Protocol (TCP/IP) item and select the radio dial that says Obtain DNS servers automatically
Press OK twice to get out of the properties screen and reboot if it asks.
That option might not be avaiable on some systems
Next Go start run type cmd and hit OK
type
ipconfig /flushdns
then hit enter, type exit hit enter
(that space between g and / is needed)

Regards,
Dave
IndiGenus

The help you receive here is free, but if you would like to help me continue the fight against Malware then Posted Image

Logs will be closed if you haven't replied within 5 days



Proud Graduate of TC/WTT Classroom



"To find perfect composure in the midst of change is to find ourselves in nirvana."

Suzuki Roshi


#3 Guest_san01_*

Guest_san01_*
  • Guests

Posted 20 March 2007 - 10:09 AM

WOW! thanks for prompt reply - have followed all instructions, and am reposting the fixwareout log and HJT log..
ta very much - San


Fixwareout Last edited 2/11/2007
Post this report in the forums please
...
╗╗╗╗╗Prerun check

╗╗╗╗╗ System restarted

╗╗╗╗╗ Postrun check
HKLM\SOFTWARE\~\Winlogon\ "System"=""
....
....
╗╗╗╗╗ Misc files.
....
╗╗╗╗╗ Checking for older varients.
....

Search five digit cs, dm, kd, jb, other, files.
The following files NEED TO BE SUBMITTED to one of the following URL'S for further inspection.


Click browse, find the file then click submit.
http://www.virustota...h/index_en.html
Or http://virusscan.jotti.org/

╗╗╗╗╗ Other

╗╗╗╗╗ Current runs
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"wltray.exe"="C:\\WINDOWS\\System32\\wltray.exe"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"TPTRAY"="C:\\PROGRA~1\\ThinkPad\\UTILIT~1\\TP98TRAY.EXE"
"IMJPMIG9.0"="C:\\PROGRA~1\\COMMON~1\\MICROS~1\\IME\\IMJP9\\IMJPMIG.EXE /Preload /Migration32"
"Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
"BMMGAG"="RunDll32 C:\\PROGRA~1\\ThinkPad\\UTILIT~1\\pwrmonit.dll,StartPwrMonitor"
"BMMLREF"="C:\\Program Files\\ThinkPad\\Utilities\\BMMLREF.EXE"
"BMMMONWND"="rundll32.exe C:\\PROGRA~1\\ThinkPad\\UTILIT~1\\BatInfEx.dll,BMMAutonomicMonitor"
"THGuard"="\"C:\\Program Files\\TrojanHunter 4.6\\THGuard.exe\""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Disabled]
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
"SUPERAntiSpyware"="C:\\Program Files\\SUPERAntiSpyware\\SUPERAntiSpyware.exe"
....
Hosts file was reset, If you use a custom hosts file please replace it
╗╗╗╗╗ End report ╗╗╗╗╗
-----------------------------------------------------------------------------------

Logfile of HijackThis v1.99.1
Scan saved at 16:00:53, on 20/03/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware Pro\aawservice.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Executive Software\DiskeeperLite\DKService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
c:\program files\lenovo\system update\suservice.exe
C:\WINDOWS\System32\TPHDEXLG.EXE
C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\System32\wltray.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\TP98TRAY.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\TrojanHunter 4.6\THGuard.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\ThinkPad\UltraNav Wizard\UNavTray.EXE
C:\Program Files\NETGEAR\WPN111\wpn111.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Documents and Settings\san\Desktop\Downloads\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ie/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ie/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: IEPlugin Class - {CF7C3CF0-4B15-11D1-ABED-709549C10000} - C:\Program Files\Advanced System Optimizer\IEHelper.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [wltray.exe] C:\WINDOWS\System32\wltray.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [TPTRAY] C:\PROGRA~1\ThinkPad\UTILIT~1\TP98TRAY.EXE
O4 - HKLM\..\Run: [IMJPMIG9.0] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMJP9\IMJPMIG.EXE /Preload /Migration32
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE
O4 - HKLM\..\Run: [BMMMONWND] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.6\THGuard.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: NETGEAR WPN111 Smart Wizard.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akama...ex/qtplugin.cab
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=58813
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewi...oOnlineScan.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.t...ivex/hcImpl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1159050386710
O16 - DPF: {74FFE28D-2378-11D5-990C-006094235084} (IBM Access Support) - http://www-307.ibm.c...rt/IbmEgath.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/s...nfo/webscan.cab
O16 - DPF: {9C024426-7859-4B2D-AB4C-B1E370AE7549} - http://us.mcafee.com...ScannerCtrl.cab
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadbl...ivex/sabspx.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware Pro\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\DiskeeperLite\DKService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Oracleora817ClientCache - Unknown owner - C:\ORA817\BIN\ONRSD.EXE
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: System Update (SUService) - - c:\program files\lenovo\system update\suservice.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.EXE
O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe

#4 IndiGenus

IndiGenus

    Teacher Emeritus

  • Authentic Member
  • PipPipPipPipPipPip
  • 5,251 posts
  • Interests:Computer Security, Music, Sports

Posted 20 March 2007 - 10:48 AM

I recommend some clean up and an online virus scan at this point.

Download ATF (Atribune Temp File) Cleanerę by Atribune to your desktop.

Double-click ATF Cleaner.exe to open it.

Under Main select the following:
Under Main choose: Select All
Click the Empty Selected button.

If you use Firefox:
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

-------------------------------------------------------------------------------------------------

Using Internet Explorer, click on Kaspersky Online Scanner * You will be prompted to install an ActiveX component from Kaspersky, Click 'Yes'.
* The program will launch and then start to download the latest definition files.
* Once the scanner is installed and the definitions downloaded, click 'Next'.
* Now click on 'Scan Settings'
* In the scan settings make sure that the following are selected:
o Scan using the following Anti-Virus database: 'Extended' (If available, otherwise 'Standard')
o Scan Options: 'Scan Archives' and 'Scan Mail Bases'
* Click 'OK'
* Now under 'Select a target to scan' select 'My Computer'
* The scan will take a while, so be patient and let it run. Once the scan is complete, it will display whether your system has been infected.
* Now click on the 'Save as Text' button:
* Save the file to your desktop.
Please post the Kaspersky report and a new HijackThis log.

Regards,
Dave
IndiGenus

The help you receive here is free, but if you would like to help me continue the fight against Malware then Posted Image

Logs will be closed if you haven't replied within 5 days



Proud Graduate of TC/WTT Classroom



"To find perfect composure in the midst of change is to find ourselves in nirvana."

Suzuki Roshi


#5 Guest_san01_*

Guest_san01_*
  • Guests

Posted 20 March 2007 - 01:23 PM

hmm- it wont' let me post the full virus scan log, and the HJT logs together (too many characters) but i have it saved...




----------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Tuesday, March 20, 2007 7:00:13 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 20/03/2007
Kaspersky Anti-Virus database records: 283674
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\

Scan Statistics:
Total number of scanned objects: 48186
Number of viruses found: 1
Number of infected objects: 5 / 0
Number of suspicious objects: 0
Duration of the scan process: 00:49:49



Logfile of HijackThis v1.99.1
Scan saved at 19:04:33, on 20/03/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware Pro\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Executive Software\DiskeeperLite\DKService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
c:\program files\lenovo\system update\suservice.exe
C:\WINDOWS\System32\TPHDEXLG.EXE
C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\System32\wltray.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\TP98TRAY.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\TrojanHunter 4.6\THGuard.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ThinkPad\UltraNav Wizard\UNavTray.EXE
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\NETGEAR\WPN111\wpn111.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Documents and Settings\san\Desktop\Downloads\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ie/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ie/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: IEPlugin Class - {CF7C3CF0-4B15-11D1-ABED-709549C10000} - C:\Program Files\Advanced System Optimizer\IEHelper.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [wltray.exe] C:\WINDOWS\System32\wltray.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [TPTRAY] C:\PROGRA~1\ThinkPad\UTILIT~1\TP98TRAY.EXE
O4 - HKLM\..\Run: [IMJPMIG9.0] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMJP9\IMJPMIG.EXE /Preload /Migration32
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE
O4 - HKLM\..\Run: [BMMMONWND] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.6\THGuard.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: NETGEAR WPN111 Smart Wizard.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akama...ex/qtplugin.cab
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=58813
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewi...oOnlineScan.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.t...ivex/hcImpl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1159050386710
O16 - DPF: {74FFE28D-2378-11D5-990C-006094235084} (IBM Access Support) - http://www-307.ibm.c...rt/IbmEgath.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/s...nfo/webscan.cab
O16 - DPF: {9C024426-7859-4B2D-AB4C-B1E370AE7549} - http://us.mcafee.com...ScannerCtrl.cab
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadbl...ivex/sabspx.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware Pro\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\DiskeeperLite\DKService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Oracleora817ClientCache - Unknown owner - C:\ORA817\BIN\ONRSD.EXE
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: System Update (SUService) - - c:\program files\lenovo\system update\suservice.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.EXE
O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe

#6 IndiGenus

IndiGenus

    Teacher Emeritus

  • Authentic Member
  • PipPipPipPipPipPip
  • 5,251 posts
  • Interests:Computer Security, Music, Sports

Posted 21 March 2007 - 07:09 AM

Hi san01, Yes, sorry I should have mentioned that you may need a couple of posts to fit the whole log. I would like to see it please. Thanks, Dave
IndiGenus

The help you receive here is free, but if you would like to help me continue the fight against Malware then Posted Image

Logs will be closed if you haven't replied within 5 days



Proud Graduate of TC/WTT Classroom



"To find perfect composure in the midst of change is to find ourselves in nirvana."

Suzuki Roshi


#7 Guest_san01_*

Guest_san01_*
  • Guests

Posted 21 March 2007 - 07:54 AM

Cool! part 1 ------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER REPORT Tuesday, March 20, 2007 7:00:13 PM Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.83.0 Kaspersky Anti-Virus database last update: 20/03/2007 Kaspersky Anti-Virus database records: 283674 ------------------------------------------------------------------------------- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: C:\ Scan Statistics: Total number of scanned objects: 48186 Number of viruses found: 1 Number of infected objects: 5 / 0 Number of suspicious objects: 0 Duration of the scan process: 00:49:49 Infected Object Name / Virus Name / Last Action C:\Documents and Settings\Administrator\Application Data\desktop.ini Object is locked skipped C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\brndlog.bak Object is locked skipped C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\brndlog.txt Object is locked skipped C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Desktop.htt Object is locked skipped C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini Object is locked skipped C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk Object is locked skipped C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Excel 2003.lnk Object is locked skipped C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office PowerPoint 2003.lnk Object is locked skipped C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Word 2003.lnk Object is locked skipped C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf Object is locked skipped C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk Object is locked skipped C:\Documents and Settings\Administrator\Application Data\Microsoft\Media Player\000422F1.wpl Object is locked skipped C:\Documents and Settings\Administrator\Application Data\Microsoft\Office\MSO2057.acl Object is locked skipped C:\Documents and Settings\Administrator\Application Data\Microsoft\Office\MSOut11.pip Object is locked skipped C:\Documents and Settings\Administrator\Application Data\Microsoft\Office\Recent\CV All.LNK Object is locked skipped C:\Documents and Settings\Administrator\Application Data\Microsoft\Office\Recent\Docs.LNK Object is locked skipped C:\Documents and Settings\Administrator\Application Data\Microsoft\Office\Recent\index.dat Object is locked skipped C:\Documents and Settings\Administrator\Application Data\Microsoft\Office\Recent\PeteCV2.LNK Object is locked skipped C:\Documents and Settings\Administrator\Application Data\Microsoft\Office\Recent\sleepyhead.LNK Object is locked skipped C:\Documents and Settings\Administrator\Application Data\Microsoft\Office\Recent\Templates.LNK Object is locked skipped C:\Documents and Settings\Administrator\Application Data\Microsoft\Office\Word11.pip Object is locked skipped C:\Documents and Settings\Administrator\Application Data\Microsoft\Outlook\Default Outlook Profile.xml Object is locked skipped C:\Documents and Settings\Administrator\Application Data\Microsoft\Proof\CUSTOM.DIC Object is locked skipped C:\Documents and Settings\Administrator\Application Data\Microsoft\Protect\CREDHIST Object is locked skipped C:\Documents and Settings\Administrator\Application Data\Microsoft\Templates\Normal.dot Object is locked skipped C:\Documents and Settings\Administrator\Application Data\Microsoft\Windows\Themes\Custom.theme Object is locked skipped C:\Documents and Settings\Administrator\Favorites\Desktop.ini Object is locked skipped C:\Documents and Settings\Administrator\Favorites\Links\Customize Links.url Object is locked skipped C:\Documents and Settings\Administrator\Favorites\Links\Free Hotmail.url Object is locked skipped C:\Documents and Settings\Administrator\Favorites\Links\Windows Media.url Object is locked skipped C:\Documents and Settings\Administrator\Favorites\Links\Windows.url Object is locked skipped C:\Documents and Settings\Administrator\Favorites\MSN.com.url Object is locked skipped C:\Documents and Settings\Administrator\Favorites\Radio Station Guide.url Object is locked skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini Object is locked skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\IconCache.db Object is locked skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\FORMS\FRMCACHE.DAT Object is locked skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\HelpCtr\HelpSessionHistory.dat Object is locked skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Internet Explorer\MSIMGSIZ.DAT Object is locked skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Media Player\CurrentDatabase_59R.wmdb Object is locked skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Media Player\wmpfolders.wmdb Object is locked skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Outlook\extend.dat Object is locked skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp Object is locked skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows Media\9.0\WMSDKNS.DTD Object is locked skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows Media\9.0\WMSDKNS.XML Object is locked skipped C:\Documents and Settings\Administrator\Local Settings\desktop.ini Object is locked skipped C:\Documents and Settings\Administrator\Local Settings\History\desktop.ini Object is locked skipped C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\desktop.ini Object is locked skipped C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\MSHist012006092020060921\index.dat Object is locked skipped C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\MSHist012006092120060922\index.dat Object is locked skipped C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\MSHist012006092220060923\index.dat Object is locked skipped C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\MSHist012006092320060924\index.dat Object is locked skipped C:\Documents and Settings\Administrator\Local Settings\Temp\Office 11 Maintenance(0000).TXT Object is locked skipped C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\desktop.ini Object is locked skipped C:\Documents and Settings\Administrator\My Documents\desktop.ini Object is locked skipped C:\Documents and Settings\Administrator\My Documents\Docs\CV All\cv cover.doc Object is locked skipped C:\Documents and Settings\Administrator\My Documents\Docs\CV All\CV Template.doc Object is locked skipped C:\Documents and Settings\Administrator\My Documents\Docs\CV All\jake cv1.doc Object is locked skipped C:\Documents and Settings\Administrator\My Documents\Docs\CV All\james cv2.doc Object is locked skipped C:\Documents and Settings\Administrator\My Documents\Docs\CV All\james cv2.odt Object is locked skipped C:\Documents and Settings\Administrator\My Documents\Docs\CV All\new pete cv.odt Object is locked skipped C:\Documents and Settings\Administrator\My Documents\Docs\CV All\PeteCV2.doc Object is locked skipped C:\Documents and Settings\Administrator\My Documents\Docs\Misc\adoptionform[1].doc Object is locked skipped C:\Documents and Settings\Administrator\My Documents\Docs\Misc\Behan.doc Object is locked skipped C:\Documents and Settings\Administrator\My Documents\Docs\Misc\Pet humour.doc Object is locked skipped C:\Documents and Settings\Administrator\My Documents\Docs\Misc\Revenue.doc Object is locked skipped C:\Documents and Settings\Administrator\My Documents\Docs\Misc\The Max Factor.doc Object is locked skipped C:\Documents and Settings\Administrator\My Documents\Docs\Site Info\A Moon Poem poe.doc Object is locked skipped C:\Documents and Settings\Administrator\My Documents\Docs\Site Info\Celt\an tain bo cuailgne.doc Object is locked skipped C:\Documents and Settings\Administrator\My Documents\Docs\Site Info\Celt\Celtic Goddesss.doc Object is locked skipped C:\Documents and Settings\Administrator\My Documents\Docs\Site Info\Celt\Cuchulainn.doc Object is locked skipped C:\Documents and Settings\Administrator\My Documents\Docs\Site Info\Celt\Fairy forts.doc Object is locked skipped C:\Documents and Settings\Administrator\My Documents\Docs\Site Info\Celt\Finn Mc Cool.doc Object is locked skipped C:\Documents and Settings\Administrator\My Documents\Docs\Site Info\Celt\Name.doc Object is locked skipped C:\Documents and Settings\Administrator\My Documents\Docs\Site Info\Celt\Song of Amergin.doc Object is locked skipped C:\Documents and Settings\Administrator\My Documents\Docs\Site Info\Celt\The Fianna was a warrior band.doc Object is locked skipped C:\Documents and Settings\Administrator\My Documents\Docs\Site Info\Celt\The Irish mythological cycle can be divided into four major .doc Object is locked skipped C:\Documents and Settings\Administrator\My Documents\Docs\Site Info\Celt\THE RANN.doc Object is locked skipped C:\Documents and Settings\Administrator\My Documents\Docs\Site Info\Celt\Tuatha.doc Object is locked skipped C:\Documents and Settings\Administrator\My Documents\Docs\Site Info\FLY NOT YET moore.doc Object is locked skipped C:\Documents and Settings\Administrator\My Documents\Docs\Site Info\FULL MOON dn.doc Object is locked skipped C:\Documents and Settings\Administrator\My Documents\Docs\Site Info\Is the moon tired dn.doc Object is locked skipped C:\Documents and Settings\Administrator\My Documents\Docs\Site Info\Moon names.doc Object is locked skipped C:\Documents and Settings\Administrator\My Documents\Docs\Site Info\MOON WORSHIP BY PAGANS.doc Object is locked skipped C:\Documents and Settings\Administrator\My Documents\Docs\Site Info\ods and ends\Names given to Moon Goddesses.doc Object is locked skipped C:\Documents and Settings\Administrator\My Documents\Docs\Site Info\ods and ends\rune name.doc Object is locked skipped C:\Documents and Settings\Administrator\My Documents\Docs\Site Info\ods and ends\Site description.doc Object is locked skipped C:\Documents and Settings\Administrator\My Documents\Docs\Site Info\sleepyhead.doc Object is locked skipped C:\Documents and Settings\Administrator\My Documents\Docs\Site Info\THE CRAZED MOON.doc Object is locked skipped C:\Documents and Settings\Administrator\My Documents\Docs\Site Info\The Moo1 emily.doc Object is locked skipped C:\Documents and Settings\Administrator\My Documents\Docs\Site Info\Under the Moon.doc Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Desktop.ini Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\My Documents.lnk Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Sample Music.lnk Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (20-09-2006 20-57-42)\01 Track 1.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (20-09-2006 20-57-42)\02 Track 2.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (20-09-2006 20-57-42)\03 Track 3.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (20-09-2006 20-57-42)\04 Track 4.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (20-09-2006 20-57-42)\05 Track 5.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (20-09-2006 20-57-42)\06 Track 6.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (20-09-2006 20-57-42)\07 Track 7.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (20-09-2006 20-57-42)\08 Track 8.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (20-09-2006 20-57-42)\09 Track 9.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (20-09-2006 20-57-42)\10 Track 10.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (20-09-2006 20-57-42)\11 Track 11.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (20-09-2006 20-57-42)\12 Track 12.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (21-09-2006 15-46-38)\01 Track 1.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (21-09-2006 15-46-38)\02 Track 2.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (21-09-2006 15-46-38)\03 Track 3.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (21-09-2006 15-46-38)\04 Track 4.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (21-09-2006 15-46-38)\05 Track 5.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (21-09-2006 15-46-38)\06 Track 6.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (21-09-2006 15-46-38)\07 Track 7.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (21-09-2006 15-46-38)\08 Track 8.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (21-09-2006 15-46-38)\09 Track 9.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (21-09-2006 15-46-38)\10 Track 10.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (21-09-2006 15-46-38)\11 Track 11.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (21-09-2006 15-46-38)\12 Track 12.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (21-09-2006 15-46-38)\13 Track 13.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (21-09-2006 15-46-38)\14 Track 14.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (21-09-2006 15-46-38)\15 Track 15.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (21-09-2006 15-46-38)\16 Track 16.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (21-09-2006 15-46-38)\17 Track 17.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (21-09-2006 15-46-38)\18 Track 18.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (21-09-2006 15-46-38)\19 Track 19.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (21-09-2006 15-46-38)\20 Track 20.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (21-09-2006 15-46-38)\21 Track 21.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (21-09-2006 15-46-38)\22 Track 22.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (21-09-2006 19-02-59)\01 Track 1.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (21-09-2006 19-02-59)\04 Track 4.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (21-09-2006 19-02-59)\05 Track 5.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (21-09-2006 19-02-59)\06 Track 6.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (21-09-2006 19-02-59)\07 Track 7.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (21-09-2006 19-02-59)\08 Track 8.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (21-09-2006 19-02-59)\09 Track 9.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (21-09-2006 19-02-59)\10 Track 10.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (21-09-2006 19-02-59)\11 Track 11.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (21-09-2006 19-02-59)\12 Track 12.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (21-09-2006 19-02-59)\13 Track 13.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (21-09-2006 19-02-59)\14 Track 14.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (21-09-2006 19-02-59)\15 Track 15.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (21-09-2006 19-02-59)\16 Track 16.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (21-09-2006 19-02-59)\17 Track 17.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (21-09-2006 19-02-59)\18 Track 18.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (21-09-2006 19-02-59)\19 Track 19.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (21-09-2006 19-02-59)\20 Track 20.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Music\Unknown Artist\Unknown Album (21-09-2006 19-02-59)\21 Track 21.wma Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Desktop.ini Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Aragorn\Pictures 031.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Aragorn\Pictures 032.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Aragorn\Pictures 033.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Aragorn\Pictures 034.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Aragorn\Pictures 035.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Aragorn\Pictures 036.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Aragorn\Pictures 037.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Aragorn\Pictures 038.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Aragorn\Pictures 219.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Aragorn\Pictures 305.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Aragorn\Thumbs.db Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Funny Pics\Pictures 056.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Funny Pics\Pictures 057.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Funny Pics\Pictures 058.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Funny Pics\Pictures 059.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Funny Pics\Pictures 060.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Funny Pics\Pictures 061.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Funny Pics\Pictures 062.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Funny Pics\Pictures 063.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Funny Pics\Pictures 064.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Funny Pics\Thumbs.db Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Jose\Pictures 300.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Jose\Pictures 302.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Jose\Pictures 306.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Jose\Pictures 423.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Jose\Pictures 424.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Jose\Pictures 425.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Jose\Pictures 426.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Jose\Pictures 427.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Jose\Pictures 428.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Jose\Pictures 429.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Jose\Pictures 430.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Jose\Pictures 431.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Jose\Thumbs.db Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 017.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 019.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 020.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 021.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 022.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 023.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 024.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 025.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 029.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 030.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 164.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 166.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 173.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 175.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 176.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 177.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 178.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 179.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 181.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 182.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 183.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 184.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 185.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 186.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 187.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 188.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 189.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 190.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 191.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 192.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 193.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 194.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 195.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 196.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 197.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 198.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 199.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 201.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 203.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 206.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 208.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 237.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 241.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 242.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 248.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 254.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 255.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 259.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 260.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 261.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 262.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 263.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 264.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 266.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 267.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 268.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 269.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 270.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 271.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 272.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 273.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 274.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 275.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 276.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 277.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 278.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 279.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 280.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 282.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 284.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 287.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 288.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 290.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 291.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 292.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 296.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 298.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 340.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 389.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 432.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 434.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 435.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 436.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 437.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 438.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 439.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 440.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 441.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 442.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 443.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 444.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 445.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 446.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 447.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 448.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 449.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 450.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 451.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 455.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 456.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 458.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 459.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 460.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 461.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 462.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 463.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 464.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 465.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 466.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 469.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 470.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 471.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 472.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 473.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 474.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 476.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 477.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 478.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 479.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 480.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 481.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 482.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 483.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 484.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 485.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 486.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 491.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 493.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 495.avi Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 531.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 532.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 534.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 535.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 536.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 537.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 538.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 541.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 543.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 547.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 548.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 552.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 553.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 554.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 556.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Pictures 584.avi Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\Max\Thumbs.db Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 026.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 039.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 040.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 041.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 042.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 043.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 044.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 045.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 046.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 047.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 048.gif Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 049.gif Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 050.gif Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 051.gif Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 052.gif Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 053.gif Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 054.gif Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 055.gif Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 065.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 101.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 102.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 103.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 104.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 105.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 106.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 107.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 108.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 109.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 110.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 111.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 112.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 113.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 114.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 115.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 116.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 117.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 118.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 119.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 120.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 121.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 122.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 123.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 124.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 125.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 126.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 127.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 128.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 129.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 130.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 131.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 132.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 133.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 134.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 135.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 136.gif Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 137.gif Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 138.bmp Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures\My Space & Goddess\Pictures 146.jpg Object is locked skipped C:\Documents and Settings\Administrator\My Documents\My Pictures\Pictures�

#8 Guest_san01_*

Guest_san01_*
  • Guests

Posted 21 March 2007 - 07:56 AM

Part 2 - thanks..



---------------------------------------------------------------------------------
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware Pro\Logs\Ad-Aware event.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-11292006-234557.log Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT.LOG Object is locked skipped
C:\Documents and Settings\san\Application Data\Mozilla\Firefox\Profiles\a0tweu3k.default\cert8.db Object is locked skipped
C:\Documents and Settings\san\Application Data\Mozilla\Firefox\Profiles\a0tweu3k.default\formhistory.dat Object is locked skipped
C:\Documents and Settings\san\Application Data\Mozilla\Firefox\Profiles\a0tweu3k.default\history.dat Object is locked skipped
C:\Documents and Settings\san\Application Data\Mozilla\Firefox\Profiles\a0tweu3k.default\key3.db Object is locked skipped
C:\Documents and Settings\san\Application Data\Mozilla\Firefox\Profiles\a0tweu3k.default\parent.lock Object is locked skipped
C:\Documents and Settings\san\Application Data\Mozilla\Firefox\Profiles\a0tweu3k.default\search.sqlite Object is locked skipped
C:\Documents and Settings\san\Application Data\Mozilla\Firefox\Profiles\a0tweu3k.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\san\Application Data\Mozilla\Firefox\Profiles\a0tweu3k.default\webappsstore.sqlite Object is locked skipped
C:\Documents and Settings\san\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SUPERANTISPYWARE.LOG Object is locked skipped
C:\Documents and Settings\san\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\san\Desktop\Downloads\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\san\Desktop\Downloads\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\san\Desktop\Downloads\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\san\Desktop\Downloads\SmitfraudFix.exe RarSFX: infected - 2 skipped
C:\Documents and Settings\san\Desktop\Downloads\SmitfraudFix.exe PE_Patch.UPX: infected - 2 skipped
C:\Documents and Settings\san\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\san\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\san\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{41234425-B76C-450D-BB40-C8382B7FA4FA} Object is locked skipped
C:\Documents and Settings\san\Local Settings\Application Data\Mozilla\Firefox\Profiles\a0tweu3k.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\san\Local Settings\Application Data\Mozilla\Firefox\Profiles\a0tweu3k.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\san\Local Settings\Application Data\Mozilla\Firefox\Profiles\a0tweu3k.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\san\Local Settings\Application Data\Mozilla\Firefox\Profiles\a0tweu3k.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\san\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\san\Local Settings\Temp\~DFC346.tmp Object is locked skipped
C:\Documents and Settings\san\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\san\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\san\ntuser.dat Object is locked skipped
C:\Documents and Settings\san\NTUSER.DAT.LOG Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\WINDOWS\$NtUninstallKB321936$\cscdll.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB321936$\mrxsmb.sys Object is locked skipped
C:\WINDOWS\$NtUninstallKB321936$\rdbss.sys Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\accwiz.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\crypt32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\cryptsvc.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\hh.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\hhctrl.ocx Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\hhsetup.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\html32.cnv Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\itircl.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\itss.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\locator.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\magnify.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\migwiz.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\narrator.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\newdev.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\ntdll.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\ntkrnlpa.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\ntoskrnl.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\ole32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\osk.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\pchshell.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\raspptp.sys Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\rpcrt4.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\rpcss.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\shmedia.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\srrstr.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\srv.sys Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\user32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\win32k.sys Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\winsrv.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB826939$\zipfldr.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828028$\msasn1.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828035$\msgsvc.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828035$\wkssvc.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\catsrv.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\catsrvut.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\clbcatex.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\clbcatq.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\colbact.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\comadmin.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\comrepl.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\comsvcs.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\comuid.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\es.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\migregdb.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\msdtcprx.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\msdtctm.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\msdtcuiu.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\mtxclu.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\mtxoci.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\ole32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\rpcrt4.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\rpcss.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\txflog.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB829558$\dao360.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB829558$\expsrv.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB829558$\msexch40.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB829558$\msexcl40.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB829558$\msjet40.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB829558$\msjetol1.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB829558$\msjetoledb40.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB829558$\msjint40.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB829558$\msjter40.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB829558$\msjtes40.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB829558$\msltus40.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB829558$\mspbde40.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB829558$\msrd2x40.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB829558$\msrd3x40.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB829558$\msrepl40.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB829558$\mstext40.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB829558$\mswdat10.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB829558$\mswstr10.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB829558$\msxbde40.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB829558$\vbajet32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB833407$\bssym7.ttf Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\callcont.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\cmdevtgprov.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\evtgprov.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\gdi32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\h323.tsp Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\h323msp.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\helpctr.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\ipnathlp.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\lsasrv.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\mf3216.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\msasn1.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\msgina.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\mst120.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\netapi32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\nmcom.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\rtcdll.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\schannel.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\xpsp2res.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB837001$\dao360.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB837001$\msexcl40.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB837001$\msjet40.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB837001$\msjetol1.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB837001$\msjetoledb40.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB837001$\msjtes40.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB839645$\fldrclnr.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB839645$\shell32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB839645$\sxs.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB839645$\xpsp2res.dll Object is locked skipped
C:\WINDOWS\CSC\00000001 Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped



C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.




HIJACK THIS LOG

Logfile of HijackThis v1.99.1
Scan saved at 19:04:33, on 20/03/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware Pro\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Executive Software\DiskeeperLite\DKService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
c:\program files\lenovo\system update\suservice.exe
C:\WINDOWS\System32\TPHDEXLG.EXE
C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\System32\wltray.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\TP98TRAY.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\TrojanHunter 4.6\THGuard.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ThinkPad\UltraNav Wizard\UNavTray.EXE
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\NETGEAR\WPN111\wpn111.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Documents and Settings\san\Desktop\Downloads\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ie/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ie/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: IEPlugin Class - {CF7C3CF0-4B15-11D1-ABED-709549C10000} - C:\Program Files\Advanced System Optimizer\IEHelper.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [wltray.exe] C:\WINDOWS\System32\wltray.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [TPTRAY] C:\PROGRA~1\ThinkPad\UTILIT~1\TP98TRAY.EXE
O4 - HKLM\..\Run: [IMJPMIG9.0] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMJP9\IMJPMIG.EXE /Preload /Migration32
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE
O4 - HKLM\..\Run: [BMMMONWND] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.6\THGuard.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: NETGEAR WPN111 Smart Wizard.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akama...ex/qtplugin.cab
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=58813
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewi...oOnlineScan.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.t...ivex/hcImpl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1159050386710
O16 - DPF: {74FFE28D-2378-11D5-990C-006094235084} (IBM Access Support) - http://www-307.ibm.c...rt/IbmEgath.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/s...nfo/webscan.cab
O16 - DPF: {9C024426-7859-4B2D-AB4C-B1E370AE7549} - http://us.mcafee.com...ScannerCtrl.cab
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadbl...ivex/sabspx.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware Pro\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\DiskeeperLite\DKService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Oracleora817ClientCache - Unknown owner - C:\ORA817\BIN\ONRSD.EXE
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: System Update (SUService) - - c:\program files\lenovo\system update\suservice.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.EXE
O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe

#9 IndiGenus

IndiGenus

    Teacher Emeritus

  • Authentic Member
  • PipPipPipPipPipPip
  • 5,251 posts
  • Interests:Computer Security, Music, Sports

Posted 21 March 2007 - 08:05 AM

Ah it appears you downloaded and ran the Smitfraud tool at an earlier point. That's what Kaspersky is finding. Not a problem. You can delete the tool at this point as you should not need it (and if you did you would want to download the latest version anyway).

Everything else looks good. How is it running?

If all is well I recommend you clear out your restore points.

Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: (You will lose all previous restore points which may be infected anyway).

Click Start>Help and Support>Undo changes to your computer with System Restore
Select Create A Restore Point then click Next. Give it a name it and then click Create

Click Start>Run and type Cleanmgr
Click the More Options Tab.
Click Clean Up in the System Restore section.

Regards,
Dave
IndiGenus

The help you receive here is free, but if you would like to help me continue the fight against Malware then Posted Image

Logs will be closed if you haven't replied within 5 days



Proud Graduate of TC/WTT Classroom



"To find perfect composure in the midst of change is to find ourselves in nirvana."

Suzuki Roshi


#10 Guest_san01_*

Guest_san01_*
  • Guests

Posted 21 March 2007 - 09:55 AM

Great- well done, I think that's it! Seems to be running fine, did loads of IE scarches and so far so go...I pride myself on keeping a 'clean' computer, but you just don't know do ya? Ta very much!!XXXXX

#11 IndiGenus

IndiGenus

    Teacher Emeritus

  • Authentic Member
  • PipPipPipPipPipPip
  • 5,251 posts
  • Interests:Computer Security, Music, Sports

Posted 21 March 2007 - 10:15 AM

That's great san01 :thumbup:

In addition to updating and running your current protection you may want to consider adding the following:

Install Spybot - Search and Destroy - Spybot: Search And Destroy with its TeaTimer option. This will provide realtime spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an antivirus software.
A tutorial on installing & using this product can be found here:
Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers

Install Ad-Aware - Ad-Aware SE You should also scan your computer with program on a regular basis just as you would an antivirus software in conjunction with Spybot.
A tutorial on installing & using this product can be found here:
Using Ad-aware to remove Spyware, Malware, & Hijackers from Your Computer

Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.
A tutorial on installing & using this product can be found here:
Using SpywareBlaster to protect your computer from Spyware and Malware

Install SpywareGuard - SpywareGuard provides a real-time protection solution against spyware that is a great addition to SpywareBlaster's protection method.
A tutorial on installing & using this product can be found here:
Using SpywareGuard to protect your computer from Spyware and Malware

Update all of your Anti-Malware programs regularly - Make sure you update all the programs I have listed and the ones you are currently running regularly. Without regular updates you Will Not be protected when new malicious programs are released.

Here is a great link to a post here on securing your PC after an attack.
http://forums.tomcoy...mp;#entry257163

Follow this list and your potential for being infected again will reduce dramatically.

Glad I was able to help.

Dave
IndiGenus

The help you receive here is free, but if you would like to help me continue the fight against Malware then Posted Image

Logs will be closed if you haven't replied within 5 days



Proud Graduate of TC/WTT Classroom



"To find perfect composure in the midst of change is to find ourselves in nirvana."

Suzuki Roshi


#12 little eagle

little eagle

    spyware hawk

  • Visiting Fellow
  • PipPipPipPipPipPip
  • 8,968 posts
  • Interests:spyware

Posted 24 March 2007 - 09:07 AM

Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoy...showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users