Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93105 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

Search Results Hijacking


  • Please log in to reply
14 replies to this topic

#1 jesskristn

jesskristn

    New Member

  • Authentic Member
  • Pip
  • 10 posts

Posted 18 May 2007 - 08:08 PM

in explorer 6.0 (or 7) when doing searches I get the search results displayed. But when I select one of the result items, rather than going to that site, I get directed to other sites like ebay, or some advertising site. have run adaware registry smart mcafee. nothing seems to change it. when i run the same searches on firefox actions are normal. I have included spybot search results

Logfile of HijackThis v1.99.1
Scan saved at 7:41:49 PM, on 5/18/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Common Files\AOL\1143409849\ee\AOLSoftware.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Maxtor\Maxtor Quick Start\maxbackservice.exe
C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe
C:\Program Files\Maxtor\Maxtor Quick Start\msssort.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\John\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O3 - Toolbar: (no name) - {860c2f6b-ca82-4282-9187-beccbb66f0af} - (no file)
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [Apoint] "C:\Program Files\Apoint\Apoint.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [HostManager] "C:\Program Files\Common Files\AOL\1143409849\ee\AOLSoftware.exe"
O4 - HKLM\..\Run: [TrueImageMonitor.exe] "C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe"
O4 - HKLM\..\Run: [AcronisTimounterMonitor] "C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe"
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [DeviceDiscovery] "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe"
O4 - HKLM\..\Run: [IPHSend] "C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe"
O4 - HKLM\..\Run: [MaxBackSchedule] "C:\Program Files\Maxtor\Maxtor Quick Start\maxbackservice.exe"
O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
O4 - HKLM\..\Run: [mssSort] "C:\Program Files\Maxtor\Maxtor Quick Start\msssort.exe"
O4 - HKLM\..\Run: [Dell QuickSet] "C:\Program Files\Dell\QuickSet\quickset.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [RegistrySmart] "C:\Program Files\RegistrySmart\RegistrySmart.exe" -boot
O4 - HKLM\..\Run: [AdwareAlert] "C:\Program Files\AdwareAlert\AdwareAlert.exe" -boot
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] "C:\Program Files\Windows Media Player\WMPNSCFG.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - https://support.dell...iler/SysPro.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcaf...01/mcinsctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1142476845270
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symant...ex/symdlmgr.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1142478409543
O16 - DPF: {E856B973-45FD-4559-8F82-EAB539144667} (Dell PC Checkup Installer Control) - http://pccheckup.del...ll/gtdownde.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A93F7BC0-205C-4B1F-A995-6225EE993B33}: NameServer = 85.255.116.171,85.255.112.228
O17 - HKLM\System\CCS\Services\Tcpip\..\{DF44ECED-9ABA-4B35-A091-3AFB89B1DEC9}: NameServer = 85.255.116.171,85.255.112.228
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.171 85.255.112.228
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.116.171 85.255.112.228
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.171 85.255.112.228
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\Nortel Networks\Extranet_serv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

    Advertisements

Register to Remove


#2 tim s

tim s

    MRU Emeritus

  • Authentic Member
  • PipPip
  • 229 posts
  • Interests:Computers

Posted 19 May 2007 - 06:25 PM

Hi jesskristn,

Welcome to the Tomcoyote forum! I'll be glad to help you with your computer problems.
HijackThis logs can take some time to research, so please be patient with me. I know that you need
your computer working as quickly as possible, and I will work hard to help see that happens.

In order to help me help you, please observe the following while we work:
  • If you don't know, stop and ask! Don't continue, we don't want to start all over again!
  • Understand that cleaning your computer can sometimes take multiple passes/posts,
    and it's important to follow the steps as listed including re-running scans as listed
  • Please reply to this thread, do not start another.

If you can do those three things, everything should go smoothly

-------------------------------------------------------------

Ok your log shows your are infected.

First from the looks of your log you are running HiJackThis.exe directly from your desktop. It should be running from inside of a folder to save backups.
Just right click on any open area on desktop screen and from menu choose > New > then Folder and name it HJT.
Now put HiJackThis.exe into that folder(HJT).
Now right-click on HijackThis.exe icon > and choose Send to > Choose Desktop( create a shortcut)
Very important This has to be done first.

-------------------------------------------------------------

Please disable SpySweeper, as it may hinder the removal of some entries. You can re-enable it after you're clean.
To disable SpySweeper:
  • Open it click >Options over to the left then >program options >Uncheck "load at windows startup".
  • Over to the left click "shields" and uncheck everything there.
  • Uncheck "home page shield".
  • Uncheck "automatically restore default without notification".
  • Exit the program.
-------------------------------------------------------------

You may want to print out these instructions for reference, since you will have to restart your computer during the fix.

Please download FixWareout from one of these two links:
http://www.bleepingc.../Fixwareout.exe
http://downloads.sub.../Fixwareout.exe
  • Save it to your desktop and run it. Click Next, then Install, make sure Run fixit is checked and click Finish.
  • The fix will begin; follow the prompts.
  • You will be asked to reboot your computer; please do so.
  • Your system may take longer than usual to load; this is normal.
  • Once the desktop loads, post the text that will open (report.txt) in next reply to this thread.

Run HijackThis. Click "Do a System Scan Only", and place a check next to the following items (if found):

O3 - Toolbar: (no name) - {860c2f6b-ca82-4282-9187-beccbb66f0af} - (no file)
O17 - HKLM\System\CCS\Services\Tcpip\..\{A93F7BC0-205C-4B1F-A995-6225EE993B33}: NameServer = 85.255.116.171,85.255.112.228
O17 - HKLM\System\CCS\Services\Tcpip\..\{DF44ECED-9ABA-4B35-A091-3AFB89B1DEC9}: NameServer = 85.255.116.171,85.255.112.228
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.171 85.255.112.228
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.116.171 85.255.112.228
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.171 85.255.112.228


Close all windows other than HJT and then click FIX CHECKED. Close HijackThis.

Now lets check some settings on your system.
(2000/XP) Only

Please go to Start -> Control Panel, and choose Network Connections. Then right click on your default connection, usually Local Area Connection, or Dial-up Connection if you are using Dial-up, and left click on properties. Double-click on the Internet Protocol (TCP/IP) item and select the radio button that says Obtain DNS servers automatically. Click OK twice, and restart your computer.

Next Go start run type cmd and hit OK
type
ipconfig /flushdns
then hit enter, type exit hit enter
(that space between g and / is needed)

Reboot computer here.
-----------------------------------------------------------------------------

Please do an online scan with Kaspersky Online Scanner

Notice!
A new version of Kaspersky Virus Scanner has been released on August 8, 2006. If you have installed a previous version, you must unistall that program first before installing the new version. To uninstall, please go to the computer control panel and select "Add/Remove Programs." Close all Internet Explorer windows before uninstalling the Kaspersky Online Scanner.
Note* You must use Internet Explorer for the scan not Firefox if you use it.

Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
      • Extended (If available otherwise Standard)
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
  • Click OK
  • Now under select a target to scan select My Computer
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Now click on the Save Report As button:
    • Save the file to your desktop.
    • File Type: Text file (*.txt).
    • Name: Kav.txt for example
  • Copy and paste that information in your next post.

Post these logs in your next reply to this thread:
Fixwareout report.txt
kaspersky scan report
New HJT log

Posted Image

Honors Graduate of MalWare Removal University - A Cooperative Effort with WhattheTech

#3 jesskristn

jesskristn

    New Member

  • Authentic Member
  • Pip
  • 10 posts

Posted 21 May 2007 - 12:21 AM

Fixwareout Last edited 5/15/2007
Post this report in the forums please
...
»»»»»Prerun check
HKLM\SOFTWARE\~\Winlogon\ "System"="kdedc.exe"

»»»»»

»»»»» Postrun check
HKLM\SOFTWARE\~\Winlogon\ "system"=""
....
....
»»»»» Misc files.
....
»»»»» Checking for older varients.
....

Search five digit cs, dm, kd, jb, other, files.
The following files NEED TO BE SUBMITTED to one of the following URL'S for further inspection.


Click browse, find the file then click submit.
http://www.virustota...h/index_en.html
Or http://virusscan.jotti.org/

»»»»» Other

»»»»» Current runs
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0_01\\bin\\jusched.exe\""
"ATIPTA"="\"C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe\""
"Apoint"="\"C:\\Program Files\\Apoint\\Apoint.exe\""
"Adobe Photo Downloader"="\"C:\\Program Files\\Adobe\\Photoshop Album Starter Edition\\3.0\\Apps\\apdproxy.exe\""
"HostManager"="\"C:\\Program Files\\Common Files\\AOL\\1143409849\\ee\\AOLSoftware.exe\""
"TrueImageMonitor.exe"="\"C:\\Program Files\\Acronis\\TrueImageHome\\TrueImageMonitor.exe\""
"AcronisTimounterMonitor"="\"C:\\Program Files\\Acronis\\TrueImageHome\\TimounterMonitor.exe\""
"Acronis Scheduler2 Service"="\"C:\\Program Files\\Common Files\\Acronis\\Schedule2\\schedhlp.exe\""
"DeviceDiscovery"="\"C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpotdd01.exe\""
"IPHSend"="\"C:\\Program Files\\Common Files\\AOL\\IPHSend\\IPHSend.exe\""
"MaxBackSchedule"="\"C:\\Program Files\\Maxtor\\Maxtor Quick Start\\maxbackservice.exe\""
"mxomssmenu"="\"C:\\Program Files\\Maxtor\\OneTouch Status\\maxmenumgr.exe\""
"mssSort"="\"C:\\Program Files\\Maxtor\\Maxtor Quick Start\\msssort.exe\""
"Dell QuickSet"="\"C:\\Program Files\\Dell\\QuickSet\\quickset.exe\""
"HPDJ Taskbar Utility"="C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\hpztsb09.exe"
"Broadcom Wireless Manager UI"="C:\\WINDOWS\\system32\\WLTRAY.exe"
"RegistrySmart"="\"C:\\Program Files\\RegistrySmart\\RegistrySmart.exe\" -boot"
"AdwareAlert"="\"C:\\Program Files\\AdwareAlert\\AdwareAlert.exe\" -boot"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="\"C:\\Program Files\\DellSupport\\DSAgnt.exe\" /startup"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"WMPNSCFG"="\"C:\\Program Files\\Windows Media Player\\WMPNSCFG.exe\""
....
Hosts file was reset, If you use a custom hosts file please replace it
»»»»» End report »»»»»

#4 jesskristn

jesskristn

    New Member

  • Authentic Member
  • Pip
  • 10 posts

Posted 21 May 2007 - 12:28 AM

had to split report into two replies KASPERSKY ONLINE SCANNER REPORT Monday, May 21, 2007 12:00:54 AM Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.83.0 Kaspersky Anti-Virus database last update: 21/05/2007 Kaspersky Anti-Virus database records: 325163 Scan Settings Scan using the following antivirus database extended Scan Archives true Scan Mail Bases true Scan Target My Computer C:\ D:\ Scan Statistics Total number of scanned objects 60764 Number of viruses found 1 Number of infected objects 1 / 0 Number of suspicious objects 0 Duration of the scan process 00:59:35 Infected Object Name Virus Name Last Action C:\bf4f1a5704dbda0c75e630b226511093\%temp%dd_msxml_retMSI.txt Object is locked skipped C:\Documents and Settings\All Users\Application Data\Maxtor\MSS\MaxBackConfig_tmp.txt Object is locked skipped C:\Documents and Settings\All Users\Application Data\McAfee\MNA\NAData Object is locked skipped C:\Documents and Settings\All Users\Application Data\McAfee\MPF\data\log.edb Object is locked skipped C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\Events.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\McAfee\MSC\McUsers.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Logs\OAS.Log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys257e161d4c31aab7f62f97ad247874_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys5f2bcac62e2b0e4dec01b3d70183cb_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys9a934a610eca6ab1a59fd8366a8484_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys10e47fbadd5b2ade24819b2be9ed369_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys1156d3203c273db3b65e6aa6e335469_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys129ac883d8d931720914cb40440b1d7_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys19917f95d1f0d32dcfba573d16ccc38_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys1ea1792e8f5c10c566d91ad18604c45_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys30724373c13b4afdff3cb5bed3b6bc7_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys35fcaa093a754a514460710f7f64ce0_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys3cac59eac1df1b3068f31bf615879e0_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys3cbf87790968470b8ddf708f929cd52_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys4c51e1e3038f96f8b0fe8db4201d9cd_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys50266c68681b2f7cdfd5da253009907_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys53930e477df391687a54b827d548f80_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys53a281eaaee1b195a3824661b6c290b_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys5ae5b7dfbc8bd7e2ca940097dcf4030_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys5ddc0f6cb69b10275ff7066144d5b9c_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys5df7378f44a490d944fd976f603be5b_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys6e8939b59e307897a0fa71ce218be2d_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys7eb7482e2657a9d2d5df19f61982f39_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys86b1837e4e70101fae663abce4f25cc_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys8cce19ee0ac08f807d7c32db5ba8b37_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys90466d7482602d9c100772cab9c438f_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeysa9a656822611483a2cca841cccbdb3f_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeysb22a2307a99694aefd1d0bfd038f4cc_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeysb2ea6302b08533b5d221cbc3718d3f7_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeysbe00d0b2f6559a2c8b6ab19b9c679cb_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeysc4e4edeb088f53825be154dd65a3055_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeysc5e1f9053c76b79c9893222c811bb40_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeysd136ea72fd6111d134a1d48dc17efa8_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeysd3a3d4a8832c22ae8d66ccd2d3e1f46_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeyse8a5b99b772b03eb35a0759bc3136e4_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeyseb740cb2a95ee6c51fba118367d99ff_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeysee2aa1ffb7d21114ba16724547ccb25_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeysfa662d133ebca8570f3c412652497e8_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeysfed88f6896c549f315009f1504774f6_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\105fd610ee355f2a5c2eaa8ab935f9bc_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\11092cdf2bfad96744aa302a9be60c07_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\112cebde57bb3623994ae05bd59287eb_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\12be28c486699ee2f542f8228d2f6997_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\13a6054519f2baaded205a65d6bd3f54_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1406c79a3bbb44679bea8f55408e0cbc_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1417d192457e41620b7dcf4751f03c5b_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\14feaac9bba59cccda3b57157e6659cd_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\155be986846bb6818ea441bd11e321a4_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\15f188267882b72176bd15cca4680b2f_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1a507d7373437854a558d67bf1897ecc_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1a9932396815629aae6a91a8ccb9982c_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1aff12dceb82623279356923176ea2ec_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1b3bd389fa48a27cfe5c832020e07567_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1b6f1c289a83111ecedf1b06a05206b4_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1c6366b4ea957b267b016280a86097bf_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1d2a41fad244693f403c859b90ff0226_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1da7354bdb0fc60b5960519ca591e608_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1dfbb72aebc5968ff0aedc0cb652ce50_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1eb0abce5bcc104832c63b4b944721f2_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1eec042c7aa4b24759f3d7147bb9d245_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1fb4bb5d99e66a36e8fb490066f8ae16_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\20511698d2192f8b20234cf70024b3c2_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\22e2f7372799a1ccc773d44ffa340c66_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\232220b72f7f88a0978b50bda94b73c3_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2333a7c1d92ff993e2b714cdb9927e11_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2380a2a7d83aa912301fd091bff658c1_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\23970f20a8b1b960774adced8ccbf3ba_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\23f50b8012030552c36301823f74bd9a_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\247cace6a8d4bc5210e31120cc854408_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\24d8abd92b345c0224384f4352448150_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\25052d239364199692e95fc1ee57e63d_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\25534d4700d10e6701d8c9442c5807f2_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\255369309c204de6774ed45e1acaaa89_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\25883c4b8c19363d6059536fca6eb276_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2696f97b8b51b6eddfd580db17e1d803_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2702a2c1371fcbb51920904a150af814_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\281e984346b5e6838c19fc54545d9b90_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\293a50729d537f279220ea64eb61bacb_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\29624ed288df1fe384acd16a4073b9f9_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\297ea09792ccc6e4b2ed69e50568aaa0_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2aa071881502bc929fc24cfb6b0843ab_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2b78323602850bf4a8d9de7871b943ae_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2c33fd500a35bffa83337a67ceaff602_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2cad87b3f2ac5734d9d99d4e9bf4f296_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2cfcc2617b6a1dcfbfdbdbf5383c8daf_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2d4250d77a21d965f6ee3b219bf71c52_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2d9a8d59bc8a48bc4369367272ad3356_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2dbeabdc1ab0cdb1a7c6e47bdd36a219_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2e11d447a301625d6fecb1d989f41630_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2e5d84c82e53559a02bbfb00b59bffe7_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2ed63524f37f3987ee6323f9f5cfd8af_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2ee860dee702c8fc7c75d3915a8c0df2_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2f160cd89363aa65412c2ae1dab1b7a2_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2fa2db596dcad252909376ee766d6ce1_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2fa9a8b4a647734115b22c2ae732b6a4_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2fb011218197e3f44c5f549a5df7304d_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2ff85c6ee761cd568a64a239d281c703_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3047d209bb18efe3eecc6058f4521334_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\30adfdd1a3aa90923bb051c76b29f7c3_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\30b69efa83be361182880c33ed00a047_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3193566aaa5d5262c8a763286319751b_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\31dac128f52d548a8648ae0021069506_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\31f557898f631891cf9b58d23f31f483_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3430518bd913264747a10224582ded98_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\34d1ef982f7ccff30b9063e7282e14c1_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3620dfd302312b15060a6bed0944134d_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\365548244c4dab3ee150903c88859277_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\367dc4ca75e0f0512f03f5154588e116_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\37376e5f871774326b71bd098393ccf6_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\37814fd25b0b7a71e9bcb96f9276ad37_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\38327971c1fed1497fd42d817ec7044b_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3897009a03a89443b2e224b8f61799f6_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3b6beef6c425af2b1cd4e1ca1f8658d0_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3c23b6d826793a09708037032a94901c_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3c48408385a4ae82ace224a6fc4698eb_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3e7b0bbfad3e02cbfa007f768086b3f5_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3f63222b9a2848a6891031b3e46fcd0b_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3ff3ccf8fce858499190d168c5218e42_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\409064fb71783ba7514f5a6ba6be6b6b_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4264a977e8efb755acbac0dbc3325d69_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\42865e2b2f02d11b137855a1d57cfd23_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4319351ed0a99cb312e785ca687012e0_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4381a81584e98d176495ce1c27ad7df1_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\444386d486d2e8d71d09f24cfadbe7d5_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\44bddee0c0e447558e973a6c73f84419_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\44d68b68b5b14090d0b1eca15ea74d55_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\451fb1f5f6c7c5d72f4b995b8ce983c5_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\45cbcb02aa73b3c8d1181149fe1f8cba_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\47393e2120b4c352fb9fc41831d0d4a2_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\478eaba17e1eeb4a5fa376542f0e6f94_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\486e411ff0baa99eb1f003f8817bd9f5_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\48d04508cd341f546eaa0b47e1cd2c50_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4b34f715474421dd1f3e6ff7979a2870_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4b9ae6fb2732544cce59c826f91d4ef8_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4bd55e001daaaeca25ce784720262639_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4e159d92e8ee7e3e26c6136b5f2ff86e_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4e8fdf80c5c75e74ed6f4c98c3fbe209_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4ecf39f147f0a9f74e695fc7e49cd30c_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4f65de840e1d6fb5544b4e2c714575c0_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\504d71bab9145a6e8641d5dfff2404f2_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\50a7ab825e9de9d0e6af184e43658167_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\510591efbea086cb10e97819c93ba7bf_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\521971e111a97ec0701b7603081c4295_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\529792edaf50643b15985b6b169302f4_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\539d67d06d0e1849590960f9849dd855_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5438eb21a17286832cec9d2a6da55948_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5474c8aeb8931f79721241fa51bc43cc_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\55051e6cf3963c085acbb9e7da369e4a_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\56272b3e2fa16c2d3c677d0817430e34_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\562c4c8975f08afa3230c4ad9f067058_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\56cac02d35df74459c7a6f840651ca35_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\57206fc550394c41dfc0f191c6b94f4e_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\57c39358da6338ac450f15c74b1fb0f7_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\580871feb27b987ea2f23da24da0469a_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\587293448babe467b563e9a70c8c0058_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\58a9b5563401d94b5fd57d530c4a08a7_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\590e4cfe43e0a41994d5ba823177b0b5_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5931428fbdf262d6dc9b18ff1cd764d4_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\59673a4641763a5629dc2be16d2842b8_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\59c13f9feba55c5b7aecc998db158d44_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5a1ef456a33e7c8ec62f407568a6cd2a_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5a59b9934451a98ffe3eb95782e2b2c7_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5aaa28067a5d99cf34ae0baaed502cd3_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5ab06cc673755c53b3e429446bca0346_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5abfe1ee6016648efb19623ad45668c3_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5ad24b325ada625131eace85603c051c_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5b723373724f9f27d2e9087abb580e0e_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5bcbbd25581f4c925a6599d29c74d6ec_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5c137e7d209157137858c1ba65f9c8fc_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5c607140f7cf66953a4eade1fc69c6c1_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5c692c93f750239fc675928c8b9690ef_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5c6f44eee00139c7f11e1bc0cd3dbcb7_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5cb227126c48206ced0a888a98037ff5_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5d06bc9e0c75f39d0a3b0e846cfb177c_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5d5b9cae49aaf71d249ea034a4525b6c_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5de737ae43db7433863b8d0c952b14fe_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5ffff28fbc1451419f73ba6aede4c5b4_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6126afb27e5f036fceb8ef161bc8441d_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6191c2dedd75b40603a5088448657105_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\63d136740b0afbe508602137eefdb6fd_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6421b8bcd679d0ee6ff71c845a52ec04_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\64821d3efbb2c71b692c39df4dbd9f75_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6565c19a1f557f91b2a1247b01d55085_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\65db779e1baecf073d8e6496b30ba074_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\65fe39e967589cb3a522e06473774f48_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\66d7d1a8f3df9ec3190b929df3bb8e9d_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6714a59b5d532f463823777c62ba078e_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\672c4fc378dbffe6bd94c6744d8ff623_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\67ad468ccdd6440631708c72e4027dec_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\695e283d9966250e592a043e630ea536_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6960e413b8d79e3ff40b05fc4619c1b1_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6a12c7d71005d05f1e9306150820e22d_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6a48d0019d2042d424512c557e05bf6f_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6aaf065639567307bf0a55049c9432fd_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6b32d6e9ab76d9f2de873c93da8d8336_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6badbb52ac25439e5f87da6c47ea0f19_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6be3c48284593f901e1c745911e2ddcd_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6cda716c190bdfc555cd17a7c6e393b9_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6d1c2e138c654b04525a4b4418e074a4_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6d25817cc0fad1c3791fc2ac17ea723b_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6d98dc9ad3cfe89e7b60ea7faa5bb118_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6ddb31140857a08373ad4eaad2bd3ff7_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6e1964add2854569c9e883999d36445d_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6e3234b246caea349460532ca68aa5e3_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6eadf50c391278121bbc123d8201b010_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6ebff1215471400824c0a8b88e37600b_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6f100a5a916947aaacd26b04a3a088d4_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6f94e41fc2e17931929dac456ccc0184_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\70242cdf662143137b0816342aee69c6_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\70406bdc577c541560bcb37c4fc4a334_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\70e5c136ecbf27e53f4b38ebaa6963b2_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\711307317e8fca4ec0acf0f0bf5ac829_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7299078d3dbb2148e61575a2022eb9a5_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\72de464d7aaa56ad91c7c52975a15e6a_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\73b298eadf9e34cd82f96f5cbcec14ad_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\73b9ccca8ff473ff354776509973d167_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\73c43cb6b5da6a468c005c6586484474_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\73cc0f6c4c94432a5023808863e6ae09_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\73f662a402b2bdfbb001f7a71356d879_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7464eed137713a357c3c902f8b5afcca_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\75ff145a6cb8fc165e07426bfba49a45_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\76a179e0d07eac6bc3d72377a443efd5_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\76ae26aadbf876f7315ce8520a2bd3b8_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\76dc68a03d1db6ffd51939f5f446504c_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\78e7c6c97223c59ea3900fcf44d2101f_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7a855d7a8ca8225ff619c46ce08bc85e_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7ae7e31c76115d9a87a4b5c6905c1a74_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7bcd88344ffd07df025e373548dc4159_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7bf752c77a8395792005987c64423a8d_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7c5c2760dddffe5fa31a821ba058ecfb_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7c90402aec5181a9bbd9990a92f4632a_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7d1cb3ae9288adef647e2a4501dba766_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7d7b4b8239fb970fe1cbcd44e36a0f00_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7fc8956ac4cd37aa97051a6a9e1c1764_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\819124e810904290bd04f3767e8879c1_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\819e065de3b2827f59ee755cd7c09424_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\81b9429187d4b7eaf78a26a39ed87adf_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\81c9b3cd4b4dc7362da7ac5564b9e2d4_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8349714cf0c41777bfdbe772554f9df8_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8390f5d75c31e53831cad447bfa1b465_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\83a809abf9e8c233a4f9519f6cf55753_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\843ebad2fa2d861f14c5c9ef1541eb03_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\84d5ef1b2e3372b5ca09be6484edd990_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\84e171e55f21a34ca043f4b84d19be60_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\84e7c16ac8c4c88e9e7107225b8ab752_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\858e67dbc713ea19f949cc31f6b2fb7b_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8623df8ed63c7ac32165129a2d651366_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\86254e36ccb2dde9dc7c84f23f0f3c2a_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8648d5193ff695bfb5295aa7ab3d622d_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped

#5 jesskristn

jesskristn

    New Member

  • Authentic Member
  • Pip
  • 10 posts

Posted 21 May 2007 - 12:29 AM

2nd part of kaspersky scan report C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\86a17bc52be2e5e6ded6dc97e157b2f1_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\876c1b5c105e3f2f3804b33a12b9db17_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\88932886cddda254c90ac00ba3ea21d1_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8965a2f669d7eafa1460c25d584d0331_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\89f6f17f735dea8c182b2d342671e18a_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8a5dc98f90d362bbff318bd3bdd9001e_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8b4e70800f4380f85984b08aab5b338d_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8b9ffec470e0d2a47e96a0f3cc2f37d6_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8bb694b5819b02d6af1ad8e2733d40fb_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8bc0a6a2c509df628dd85b0519cc8e83_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8bf5e8c67b42127982502576fe43f255_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8c18601cddd1fa13b2af64befb6c545c_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8c195feb85d8869401bf9af8cf882dc2_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8cb0938dcc2d1deaffe84dbdef22a1fd_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8e1aa260980adc37c887e40855b7fec7_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8e5cd12cb5f7c99fda2c0668b4aa97a8_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8e67b3d6f3313ea28dd2998b129e0d04_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8e865456bd81f0292632f554e3a8ac74_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8ecc1defe78a4f0ed6fef51fbf317f1b_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8f7d1a2b780b565cc181b7a423203308_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8fc5ce38155d750dfc88b98822883c66_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8fea2cb8af5efbef11ad1dbf2e83544a_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\91076e1fb202b6f0ced1b5b12f45b1be_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\911e753040fd8c0bbeaf1aeaf7beed2b_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\91465534d6469aa600b137f6fc4f66ec_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\92008e933602c7911c699490c94853c0_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\924d1ae3d5cd6d21f79fdc7e2b1a8515_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\92a9be78a7c917c85ea104f9739ac6bb_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\93162d0cc24cb5557a5610b2c4015c34_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\93dea35da0821d7525114d7b1d52c30e_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\943307a35271d52903606bcee50b62f7_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\947172a0d644ee41656c8ee65011c381_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\94cc5b24693e23087fc693cef90b2dee_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\94ff7e66110dffe8140aa2e016ad8675_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9686bb55e2fb335aaca9aac83b43c025_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\96a00129bb4ccb91a876d15c6aaea679_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\96bd7165b683a3f7044a3d0636343ba4_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\96e0eb2ea9b96e4a0fd4d13eec2f6ca3_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9713ada30251dd2e3be4111280877e3f_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\97e586bb9d8c12727bbab476e715f6c4_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\980d55bc1e4947c8e07fd5e8a65805eb_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\985b9582b0b8aaed6ae6aaa4338262fe_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\988e9501f95cbf80863468e9fe6757f4_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\993b2758601ac7fa62cdf04b77e27852_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\99c0e6b8dc5b596fddd0d374ed19d19f_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9a4b89d2eb7cbc572366fd48b1ba6f7c_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9bb0bcd87d9ea9446c1fcc7b1d477f91_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9c2ec6dfcf4595ec19b6a3e137074dc0_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9d2f6f97390823aa33ac6985975bbdc0_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9f00e5cdf7ec1be937b66adef6eb45af_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9f3ffa01ffad7373e49b16769be39d84_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a124535e9285a167c5be555f143629ea_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a17b69cc3a0e386656081847b8c62dd2_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a1d45049246289ee0439d375d1c0292a_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a1f637708db128fbd190e3bfaa77db22_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a1fd4b5fae230d8c6e3e5d894e472e31_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a211fb0f025e0f51f28ca8d9dbbe9c01_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a2d2c731403154295ccc65939e9724ff_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a33e9f6d315c3729485e8f2be1389aac_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a41495a60c2e0b0542a9c978b239f5c2_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a4471c333f014900a8f1e427fd7c0785_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a4bc2eca1e97e2fc93f16c0526056545_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a51c8dc416733c5bc825e675c7542298_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a588fbb483b907165035c41aaeb9fbf4_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a6f0ac7418e33997e4868ba6de68fe5b_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a7a5dffce7d94b40a7832e0526c4b204_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a84c9e85448f45b81eb54d71a41a42a3_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a8ebfeb40ce17494ba6ece9926705047_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a8f63c64352d4bc1dd08f1ccf8caa04f_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a9504f2654931ec08701545e594cad10_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\aaca80cb9e5afe3fecf24723cc6b56dc_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ab0157636a84661512e5e6898e87a527_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ab567b25c7948498aeea883a824e19e4_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\aca7998d38179b121472b402e1e35d66_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ace64b0f2ee3329cfe9d8cc6f8604c61_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ad64ea51044f8b5fd8483d56c9aae977_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\aee95ac98f1c1656b1ca2b97f6017bb0_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\aefb99404bdbd1b7b244c4f6f3c56f88_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\aefc1882a46e1ff59a05c3e8f05910e4_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\af11544a30cc43bf7b76698047eca204_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\af6d0c973e27649d72029f3e39a29bc8_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\af8146ae9ab96fe8843a70cc4a1e19d6_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\afc0210b5031187b74612f3c191609b7_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\afe7715419f793c828f4c46bbd9e339a_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b0d42b5e4925354562c93b4cf2977107_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b1ad2b95c2edb39da57ed2cdef62eda6_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b1ad880fa7456a6d99617bb108640d2e_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b23b2dcb56230836feb7eb97fc38d05e_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b27774a2aed4fe26b79c50abf6ec07bb_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b3b2b0c548f553ec100db47fcca62edc_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b4612e8dd5ce042c2d297be9d7203931_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b4725aa3d4ef80275022bd9a66cd2576_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b4cbfd450d30413fd245d7ec97931461_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b55127324d496fceb883ee83d1ccac76_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b583082f38e6b0a8300ba1b383f635d7_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b65978c1ce2706a6a5e8b34b32cea847_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b6aaaa0dd526377d88d99012d48a65b1_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b6f931b4db62dae7f413017652864e66_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b73a762cdc46c1b636a4b43a7eb05ea9_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b780da0f5cd203ccef56c26f972cefa2_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b948795350e76383f6d40a67ebfc756b_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b98a6c97153f4f2bdf74f9d27165d14d_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b9fd8061d6d5aa2be35d9ef901252264_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ba0c4cb1e73631a7e7beb69981aeec57_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ba184eec4ca2fe867f190e67f21712ff_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ba1d5f91612495073633914bc78d4090_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\baf6b5c4fce5d736e7117dedf1319039_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bbd6de33bb0c81d6e279331f2d45a613_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bc51aa2277cb5405cd6ca3a55e8bb8ae_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bc72e24bb3748cd9cc61bf80c6e2b823_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bc79894e448543b5fdc4a7a2b73484b0_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bca378812c05d2ed741621b1329734c9_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\be80518b5bf9ffd44520da55c9a06df6_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bec77a35eafbf4bbaebc611abbb0559d_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bf1dd1a1eb65e11e896a77c8805cbf7b_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bf62d445481369a2e9e3611f2469508c_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c02e2f80ab574c868c0407de557ecb2e_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c08ea7d8687e6c68d4df4f4ca817f995_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c2db6eb853b409b6daed37b0c92c3851_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c2e1d844e1f40ed8798f6ffe01ac679b_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c3a83f737e0232502a923de379771bde_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c44c821ba4670c6b3d40211bbac76030_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c480180b297fa5dfd4895248c31cd91a_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c4b441492be7f57291f4e1fd99f9b649_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c4c8dbb4bd35b13df737fc3df8118bb4_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c504f7c56e76794919c297ac1109bbbc_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c5b226e3713740679dd6024b927c8d7b_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c5c211cfc0fbb47c0139bcf7ee8c4382_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c764e8b69ef8c50decab6718e5df0aba_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c7dce8e76e0cb3b8a2028c173a0b879e_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c805856b563e3037650caed541c8389c_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c82d5c4052a2fe720702bc37185a43d3_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c8a960a1bb064a0100ca1ef9f20d03a1_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c90314de71d619cb0a55fc114ef5d85e_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c95c3b8172ea1377272d241f7241ab3e_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c990b80dd769e46065b9304509da390a_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c9a49c9fc5fa9888311a0f142a4a5be7_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ca0a331efa72cbb79056eb024f627ef4_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\caa06ff3241b4c1645bcfee55bce9699_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cb2b3056dc5e8818707e75c41647c70e_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cb2e5eb82fa89557de7fc3aab41f7696_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cb6685aaab7cd5efb8be16ed9b82b4d8_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cc41482d42b32557ec258a668bbd24b9_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cc4d2c02368ae3c7b4fcb2f1e7b7ae8a_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cc70c678c4c42913557e77ce4655ae6e_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cc89769c2325e4a48ee9f28efb1ce720_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cca11f7a82feb78edbabbae6f40037c9_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cdee583e73c7a5399abc99ddcf0f4a82_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ce490080e748a1526a5f082ed7aa65e3_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cf0a17870321c52fd609a40e27e93dec_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cfbab7528d5605327a74884b58df7284_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d0292044027cbdf2831a1c2e9ae07cfd_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d051ab40587e416ae3fb9d1eed27069b_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d0b4a5558032b4ab5f852e20b31348ec_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d1cce99bcabad0e9b204ed1a1b4961fc_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d2322554f6b45eb81031bf6e22553f8f_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d241459f2b3216dc1d95cffc1ca47f85_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d3425cfd7351ad7a228c1c88886e55a0_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d3607a419ea8469ba4b6f1b9352e4e14_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d3f20f057183c3f7ad094a69ccb5b279_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d47d7ac189f25df12b9ab485ad40bbaa_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d4b6afb9c386bd8b40219bad0146f9bd_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d520d3cfb6245d2c6a66bb95e725a373_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d5c535658abd3d86a4eb779ed171cc81_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d7354463454b78887ce49a9252cc17b0_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d9e1dc6bb35954f0f350f487c9408fc5_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\da503d8994495bf0004f08133e05606c_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dab634d201d68276c52d694c9ef21fd7_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\db439108ff64a80a902d849d04de9d41_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dbf322be250691c3cea6a683f296a428_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dc18d25cfa6b89ddbef6f4f11a9b9a28_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dd4423d0bf7b323d9f6922d38f6ed072_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dd86fbe52d282d8ff52321662f8935aa_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\df8ec7f6a0ce8ed09b71ed87ced18681_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e01ad8987c53be831685d3a33b32761d_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e02caa452d7bbd331039799a39f4755a_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e05b38773d5e744d4e2da15dae424e09_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e08bb3c43953c3aa15428212c7a09ecd_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e13e53b6ac2cc2d0d4eaf0d4c65217ff_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e16ec90ab4191d3b72e7465dbf32b28a_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e19436a1d7eddb044d2f81bd585788b9_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e2064359e7ff92a23fe124977c7841f7_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e222af227c3964e41fee160519a918d5_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e253190838fe7dcfe0dcacac3b76e3aa_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e33967334829050d599c4791014c3d0c_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e3454284030583283eadf6c0eb457196_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e350cecbe1ead025fbed36f349c36bf3_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e373a26f0dc23efae59247c05bfdbf04_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e3863ef12d25e94c862cc84a2ea39eff_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e3cb7189aa3e5b53f9cdfff699fe7963_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e44445bacf7351e6acddc1cdee54523a_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e472e850952ef5abdff5c660bbe49a5c_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e567054dc50b8b26d606957e7094ccce_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e57744059314fd494e3352f910360e10_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e597c71dd875c36195e5ae5185deaf9c_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e6ffee2da5775437293e9ab7a32d3b43_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e7d7b134e76a783bbe845188570c6060_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e967562ea7cfcba11dc45dd0f8c7a409_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\eaf1197dd70cfa239f89663f66b11ffe_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\eb3bf1503088e8f2700152003add5c08_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\eb710a4814713e3a00a72df593d13b7d_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\eb859e5c66101511779943b578e24bce_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ebef9caf2d479569d6563186541a5306_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ec1f1a5b3d90fb373defb4eaa97d440a_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ec58354aa6754fcff2276661d262d3e8_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ecb7a0f8549cb1648ae0df040c4ac0c1_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ecfaf200cd1f466c0ba123681c196d64_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ed4321529f4ef70b657556cd89622e1e_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ed7c84b55abd9859da69a81a07fedd3d_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\eddf895ae797f493ca14b6ef044bc394_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ee433eb460a2c1c72e1613ad95674347_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ee4a65e464694b9a0508e9d71404600f_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\eed936cc35b57918424aeeba07ab1dc2_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ef15d5c670dc42f5509b4781d4bf7f4b_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ef4b2d23c3b8a9437812d86c972fe913_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f085cae60074dbf640c64017a373248f_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f1af296ca7b46cc19fbc6ef4b6f3f5e7_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f1b8adb4d3ffebcd32ce1e3993c7d799_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f24810f294d932186ddd88dc96cb5a5f_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f2598a3136f2d67d55a3eaa0e526959b_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f28bf9d02c3dee61c808d47e7e5ba400_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f3642f020e8b962983ce206b9c113dfa_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f5273eaf5dcfd7ef1cbad486d0095c03_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f7382767e21a819ea6ac6f43572dc4c4_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f79097a0e47f3f01c036046ca516293c_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f8496919c61c0c7b1d7a476cd2a402e3_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f956ff0460b18e4e78a1a6d829c6dffe_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fad7df3682fba88802a673327eb79253_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fbb919aa8f23e9e79ef41584ebff3c27_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fc98296474801de8d1e278532f929b9f_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fd12624f636ab11eff1151b34b2651f5_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fd2973591b67f6961126bc7a48c799f3_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fdb64acbff978ee5b2e4aade2303bb58_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fdba9d08b019ab44ceb6301ca0033fc0_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fe058a2ba099cae08956cf4e946e1aa2_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fecd3716b7b9d6adb2f99ae2d6b46e42_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ff5f9021017e9ca1223f87318c6c9cd3_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ff73a70eb96f352e1f545d3469eef86c_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ffb053b74d71de8d204c90aab2fde4a3_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fff008c8ee0b726ad75e42564e652cad_23483023-0dac-471f-97cc-84cf9a247bbe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare Object is locked skipped C:\Documents and Settings\John\Application Data\GTek\GTUpdate\AUpdate\DellSupport\DSAgnt.log Object is locked skipped C:\Documents and Settings\John\Application Data\GTek\GTUpdate\AUpdate\DellSupport\DSAgnt_GTActions.log Object is locked skipped C:\Documents and Settings\John\Application Data\GTek\GTUpdate\AUpdate\DellSupport\gdql_d_DSAgnt.log Object is locked skipped C:\Documents and Settings\John\Application Data\GTek\GTUpdate\AUpdate\DellSupport\glog.log Object is locked skipped C:\Documents and Settings\John\Application Data\Microsoft\Outlook\Outlook.srs Object is locked skipped C:\Documents and Settings\John\Application Data\Microsoft\Templates\Normal.dot Object is locked skipped C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\frs2d8ja.default\cert8.db Object is locked skipped C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\frs2d8ja.default\history.dat Object is locked skipped C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\frs2d8ja.default\key3.db Object is locked skipped C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\frs2d8ja.default\parent.lock Object is locked skipped C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\frs2d8ja.default\search.sqlite Object is locked skipped C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\frs2d8ja.default\urlclassifier2.sqlite Object is locked skipped C:\Documents and Settings\John\Application Data\QSWWShare Object is locked skipped C:\Documents and Settings\John\Cookies\index.dat Object is locked skipped C:\Documents and Settings\John\Local Settings\Application Data\AOL\UserProfiles\All Users\cls\common.cls Object is locked skipped C:\Documents and Settings\John\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst Object is locked skipped C:\Documents and Settings\John\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\John\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\John\Local Settings\Application Data\Mozilla\Firefox\Profiles\frs2d8ja.default\Cache\_CACHE_001_ Object is locked skipped C:\Documents and Settings\John\Local Settings\Application Data\Mozilla\Firefox\Profiles\frs2d8ja.default\Cache\_CACHE_002_ Object is locked skipped C:\Documents and Settings\John\Local Settings\Application Data\Mozilla\Firefox\Profiles\frs2d8ja.default\Cache\_CACHE_003_ Object is locked skipped C:\Documents and Settings\John\Local Settings\Application Data\Mozilla\Firefox\Profiles\frs2d8ja.default\Cache\_CACHE_MAP_ Object is locked skipped C:\Documents and Settings\John\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\John\Local Settings\History\History.IE5\MSHist012007052020070521\index.dat Object is locked skipped C:\Documents and Settings\John\Local Settings\Temp\~DF859F.tmp Object is locked skipped C:\Documents and Settings\John\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\John\NTUSER.DAT Object is locked skipped C:\Documents and Settings\John\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Data\settings.dat Object is locked skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Program Files\Webroot\Spy Sweeper\Masters\masters.bak Object is locked skipped C:\Program Files\Webroot\Spy Sweeper\Masters\Masters.const Object is locked skipped C:\Program Files\Webroot\Spy Sweeper\Masters\masters.mst Object is locked skipped C:\Program Files\Webroot\Spy Sweeper\Masters.base Object is locked skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{EDB56365-2E96-4035-9BC4-AEE0FC0E20BE}\RP161\A0171902.exe Infected: Trojan.Win32.DNSChanger.ih skipped C:\System Volume Information\_restore{EDB56365-2E96-4035-9BC4-AEE0FC0E20BE}\RP161\change.log Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\Internet.evt Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\Temp\mcafee_OH3vbaWEAxbsxS4 Object is locked skipped C:\WINDOWS\Temp\mcmsc_brfGLzZcofrHObV Object is locked skipped C:\WINDOWS\Temp\mcmsc_PxBTUrDNUJlRaJv Object is locked skipped C:\WINDOWS\Temp\mcmsc_sZoSIO77vXQOMed Object is locked skipped C:\WINDOWS\wiadebug.log Object is locked skipped C:\WINDOWS\wiaservc.log Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped Scan process completed.

#6 jesskristn

jesskristn

    New Member

  • Authentic Member
  • Pip
  • 10 posts

Posted 21 May 2007 - 12:42 AM

new HJT log
Logfile of HijackThis v1.99.1
Scan saved at 12:02:10 AM, on 5/21/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Common Files\AOL\1143409849\ee\AOLSoftware.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Maxtor\Maxtor Quick Start\maxbackservice.exe
C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe
C:\Program Files\Maxtor\Maxtor Quick Start\msssort.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
c:\program files\mcafee\msc\mcuimgr.exe
C:\Documents and Settings\John\Desktop\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [Apoint] "C:\Program Files\Apoint\Apoint.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [HostManager] "C:\Program Files\Common Files\AOL\1143409849\ee\AOLSoftware.exe"
O4 - HKLM\..\Run: [TrueImageMonitor.exe] "C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe"
O4 - HKLM\..\Run: [AcronisTimounterMonitor] "C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe"
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [DeviceDiscovery] "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe"
O4 - HKLM\..\Run: [IPHSend] "C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe"
O4 - HKLM\..\Run: [MaxBackSchedule] "C:\Program Files\Maxtor\Maxtor Quick Start\maxbackservice.exe"
O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
O4 - HKLM\..\Run: [mssSort] "C:\Program Files\Maxtor\Maxtor Quick Start\msssort.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [RegistrySmart] "C:\Program Files\RegistrySmart\RegistrySmart.exe" -boot
O4 - HKLM\..\Run: [AdwareAlert] "C:\Program Files\AdwareAlert\AdwareAlert.exe" -boot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] "C:\Program Files\Windows Media Player\WMPNSCFG.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - https://support.dell...iler/SysPro.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcaf...01/mcinsctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1142476845270
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symant...ex/symdlmgr.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1142478409543
O16 - DPF: {E856B973-45FD-4559-8F82-EAB539144667} (Dell PC Checkup Installer Control) - http://pccheckup.del...ll/gtdownde.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\Nortel Networks\Extranet_serv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

#7 tim s

tim s

    MRU Emeritus

  • Authentic Member
  • PipPip
  • 229 posts
  • Interests:Computers

Posted 21 May 2007 - 06:02 PM

Hi jesskristn,

Thanks for posting logs.

I see a leftover of norton in your log, maybe from and uninstall. Norton is bad for that. Please do the following.

To uninstall Norton go to HERE downloading the Removal Tool to your computer.
Follow Step 1 and 2.

Make sure to use the one for windows XP.


----------------------------------------------------

I will need to see results from this tool.


Go to Try F-Secure BlackLight
  • Click on I Accept button.
  • Choose Download Blacklight Beta graphical user interface version to download Blacklight to your Desktop
  • Double-click fsbl.exe then accept the agreement
  • Click Scan. Let F-Secure BlackLight scan system.
  • When done You'll see a list of all items found or it will say (No hidden items found).
  • Close program Do Not click next we do not want step 2. run yet! I need to see scan results first
  • There will also be a log on your desktop with the name fsbl.xxxxxxxxxxxxxx.log (the xxxxxxxxxxxxxx stand for numbers).
  • Copy and Paste this log in your next reply.
---------------------------------------------------

Please post these in next reply.
fsbl.xxxxxxxxxxxxxx.log (the xxxxxxxxxxxxxx stand for numbers).
New HJT log.
Posted Image

Honors Graduate of MalWare Removal University - A Cooperative Effort with WhattheTech

#8 jesskristn

jesskristn

    New Member

  • Authentic Member
  • Pip
  • 10 posts

Posted 21 May 2007 - 09:44 PM

05/21/07 21:29:33 [Info]: BlackLight Engine 1.0.61 initialized 05/21/07 21:29:33 [Info]: OS: 5.1 build 2600 (Service Pack 2) 05/21/07 21:29:34 [Note]: 7019 4 05/21/07 21:29:34 [Note]: 7005 0 05/21/07 21:29:46 [Note]: 7006 0 05/21/07 21:29:46 [Note]: 7011 2312 05/21/07 21:29:46 [Note]: 7026 0 05/21/07 21:29:46 [Note]: 7026 0 05/21/07 21:29:49 [Note]: FSRAW library version 1.7.1021 05/21/07 21:40:37 [Note]: 7007 0

#9 jesskristn

jesskristn

    New Member

  • Authentic Member
  • Pip
  • 10 posts

Posted 21 May 2007 - 09:53 PM

Logfile of HijackThis v1.99.1
Scan saved at 9:46:55 PM, on 5/21/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Common Files\AOL\1143409849\ee\AOLSoftware.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Maxtor\Maxtor Quick Start\maxbackservice.exe
C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe
C:\Program Files\Maxtor\Maxtor Quick Start\msssort.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
c:\program files\mcafee\msc\mcuimgr.exe
C:\Documents and Settings\John\Desktop\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [Apoint] "C:\Program Files\Apoint\Apoint.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [HostManager] "C:\Program Files\Common Files\AOL\1143409849\ee\AOLSoftware.exe"
O4 - HKLM\..\Run: [TrueImageMonitor.exe] "C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe"
O4 - HKLM\..\Run: [AcronisTimounterMonitor] "C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe"
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [DeviceDiscovery] "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe"
O4 - HKLM\..\Run: [IPHSend] "C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe"
O4 - HKLM\..\Run: [MaxBackSchedule] "C:\Program Files\Maxtor\Maxtor Quick Start\maxbackservice.exe"
O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
O4 - HKLM\..\Run: [mssSort] "C:\Program Files\Maxtor\Maxtor Quick Start\msssort.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [RegistrySmart] "C:\Program Files\RegistrySmart\RegistrySmart.exe" -boot
O4 - HKLM\..\Run: [AdwareAlert] "C:\Program Files\AdwareAlert\AdwareAlert.exe" -boot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] "C:\Program Files\Windows Media Player\WMPNSCFG.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - https://support.dell...iler/SysPro.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcaf...01/mcinsctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1142476845270
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symant...ex/symdlmgr.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1142478409543
O16 - DPF: {E856B973-45FD-4559-8F82-EAB539144667} (Dell PC Checkup Installer Control) - http://pccheckup.del...ll/gtdownde.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\Nortel Networks\Extranet_serv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

#10 tim s

tim s

    MRU Emeritus

  • Authentic Member
  • PipPip
  • 229 posts
  • Interests:Computers

Posted 21 May 2007 - 10:54 PM

Hi jesskristn,

Thanks for posting logs. Good job.

Now we checking for leftovers of infection.

*NOTE* CCleaner deletes EVERYTHING out of temp/temporary folders. If you have anything in a temp folder, back it up or move it to a permanent folder prior to running CCleaner!

Download CCleaner from here It will start to download automatically. If ask if you want to download let it. Save to your Desktop.
Note: If you get and Error page from this link.
Try again you will see this message Your download of CCleaner will automatically start in 5 seconds. Click here if it does not do not wait go ahead and click on it.
  • Double click on the file to start the installation of the program.
  • Select your language and click OK, then next.
  • Follow prompts to install finish to complete installation.
  • Double click the CCleaner shortcut on the desktop to start the program.
  • On the Windows tab, under Internet Explorer,
  • All Boxes should have a check mark. (You will need to re-enter your passwords at all sites where a cookie is used to recognize you when you visit).
  • On the Windows tab, under Windows Explorer,
  • All Boxes should have a check mark.
  • On the Windows tab, under System,
  • All Boxes should have a check mark.
  • On the Windows tab, under Advanced,
  • NO check marks
[*]If you use either the Firefox or Mozilla browsers, the box to put check in for "Cookies" is on the Applications tab, under Firefox/Mozilla. If already checked move to next step.
[*]Click on the "Options" icon at the left side of the window, then click on "Advanced."
deselect "Only delete files in Windows Temp folders older than 48 hours."

[*]Click on the "Cleaner" icon on the left side of the window, then click Run Cleaner to run the program.
[*]Caution: It is not recommended that you use the "Issues" feature unless you are very familiar with the registry as it has been known to find legitimate items.
[*]After CCleaner has completed its process, click Exit.
[*] You will need to reboot here if not ask to do so.
[/list]_______________________________

Please print out or copy these instructions/tutorial to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes.

Here we are going to just make sure this tool is setup correctly Do not run scan yet.
Please download AVG Anti-Spyware to your Desktop or to your usual Download Folder.
  • Install AVG Anti-Spyware by double clicking the installer.
  • Follow the prompts. Make sure that Launch AVG Anti-Spyware is checked.
  • On the main screen under Your Computer's security.
    • Click on Change state next to Resident shield. It should now change to inactive.
    • Click on Change state next to Automatic updates. It should now change to inactive.
    • Next to the words Last Update, click on Update now. (You will need an active internet connection to perform this)
    • Wait until you see the Update succesfull message.
    • Click on Scanner on the toolbar at top of this screen.
    • Click on the Settings tab.
      • Under How to act?
      • Click on Recommended Action and choose Quarantine from the popup menu.
    • Under How to scan?
      • All checkboxes should be ticked.
    • Under Possibly unwanted software:
      • All checkboxes should be ticked.
    • Under Reports:
      • Select Automatically generate report after every scan and uncheck Only if threats were found.
    • Under What to scan?
      • Select Scan every file.
  • Close AVG Anti-Spyware without running yet.
Now disable (turn off AVG Anti-Spyware)
  • Right-click the AVG Anti-Spyware Tray Icon (Bottom right corner of computer screen near clock) and uncheck Start with Windows.
  • Right-click the AVG Anti-Spyware Tray Icon again and select Exit. Confirm by clicking Yes.
If you are having problems with the updater, you can use this link to manually update AVG Anti-Spyware.
AVG Anti-Spyware manual updates.
Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that AVG Anti-Spyware is closed before installing the update.
______________________________

Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
______________________________


Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
Note: If AVG Anti-Spyware screen does not fit your monitor screen Hold down the Alt button on keyboard then tap spacebar, menu should pop up then choose maximize. AVG Anti-Spyware screen should fix screen a little better.
  • Click on the Scan tab.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan the machine.
  • When the scan has finished, follow the instructions below.
Posted Image

IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
  • Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
  • At the bottom of the window click on the Apply all Actions button.(3)
  • When done, click the Save Scan Report button. (4)
    • Click the Save Report as button.
    • Save the report to your Desktop. I will need you to post this in your next reply.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
Reboot in Normal Mode.

-----------------------------------------------------

Please post theses in your next reply
AVG Scan report
New HJT log


Let me know how your computer is running now?
Posted Image

Honors Graduate of MalWare Removal University - A Cooperative Effort with WhattheTech

#11 jesskristn

jesskristn

    New Member

  • Authentic Member
  • Pip
  • 10 posts

Posted 23 May 2007 - 10:26 PM

Logfile of HijackThis v1.99.1
Scan saved at 10:22:14 PM, on 5/23/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Common Files\AOL\1143409849\ee\AOLSoftware.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Maxtor\Maxtor Quick Start\maxbackservice.exe
C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe
C:\Program Files\Maxtor\Maxtor Quick Start\msssort.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe
C:\Documents and Settings\John\Desktop\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [Apoint] "C:\Program Files\Apoint\Apoint.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [HostManager] "C:\Program Files\Common Files\AOL\1143409849\ee\AOLSoftware.exe"
O4 - HKLM\..\Run: [TrueImageMonitor.exe] "C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe"
O4 - HKLM\..\Run: [AcronisTimounterMonitor] "C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe"
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [DeviceDiscovery] "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe"
O4 - HKLM\..\Run: [IPHSend] "C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe"
O4 - HKLM\..\Run: [MaxBackSchedule] "C:\Program Files\Maxtor\Maxtor Quick Start\maxbackservice.exe"
O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
O4 - HKLM\..\Run: [mssSort] "C:\Program Files\Maxtor\Maxtor Quick Start\msssort.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [RegistrySmart] "C:\Program Files\RegistrySmart\RegistrySmart.exe" -boot
O4 - HKLM\..\Run: [AdwareAlert] "C:\Program Files\AdwareAlert\AdwareAlert.exe" -boot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] "C:\Program Files\Windows Media Player\WMPNSCFG.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - https://support.dell...iler/SysPro.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcaf...01/mcinsctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1142476845270
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symant...ex/symdlmgr.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1142478409543
O16 - DPF: {E856B973-45FD-4559-8F82-EAB539144667} (Dell PC Checkup Installer Control) - http://pccheckup.del...ll/gtdownde.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\Nortel Networks\Extranet_serv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

#12 jesskristn

jesskristn

    New Member

  • Authentic Member
  • Pip
  • 10 posts

Posted 23 May 2007 - 10:28 PM

--------------------------------------------------------- AVG Anti-Spyware - Scan Report --------------------------------------------------------- + Created at: 10:13:11 PM 5/23/2007 + Scan result: :mozilla.35:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.36:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.391:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.40:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.91:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.93:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\John\Application Data\AdwareAlert\Quarantine8-05-2007-21-09-33\10006.qit -> TrackingCookie.2o7 : Cleaned. :mozilla.134:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.159:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.17:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.18:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.19:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.440:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.755:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.768:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.769:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.95:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. C:\Documents and Settings\Jessica\Cookies\jessica@ads.adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.150:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.151:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.152:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.153:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.154:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.155:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.34:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.36:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.37:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.37:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.38:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.39:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.39:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.40:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.158:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned. :mozilla.23:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned. :mozilla.730:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned. C:\Documents and Settings\John\Application Data\AdwareAlert\Quarantine8-05-2007-21-09-33\10000.qit -> TrackingCookie.Bridgetrack : Cleaned. :mozilla.24:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.25:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.26:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.27:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.28:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.29:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.30:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.31:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.751:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned. :mozilla.756:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Cnn : Cleaned. :mozilla.100:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned. :mozilla.101:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned. :mozilla.102:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned. :mozilla.103:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned. :mozilla.646:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned. :mozilla.647:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned. :mozilla.648:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned. :mozilla.649:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned. C:\Documents and Settings\Jessica\Cookies\jessica@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned. :mozilla.35:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned. :mozilla.38:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned. C:\Documents and Settings\John\Application Data\AdwareAlert\Quarantine8-05-2007-21-09-33\10001.qit -> TrackingCookie.Doubleclick : Cleaned. C:\Documents and Settings\John\Application Data\AdwareAlert\Quarantine\12-05-2007-22-10-02\10000.qit -> TrackingCookie.Doubleclick : Cleaned. :mozilla.752:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned. :mozilla.15:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.16:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.20:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.32:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. C:\Documents and Settings\John\Application Data\AdwareAlert\Quarantine8-05-2007-21-09-33\10002.qit -> TrackingCookie.Fastclick : Cleaned. :mozilla.145:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.146:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.147:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.144:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Hotlog : Cleaned. :mozilla.321:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Live : Cleaned. :mozilla.322:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Live : Cleaned. :mozilla.323:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Live : Cleaned. :mozilla.229:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.567:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.568:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.764:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.765:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.700:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Masterstats : Cleaned. :mozilla.43:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned. :mozilla.610:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned. :mozilla.611:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned. :mozilla.10:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Msn : Cleaned. :mozilla.17:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Msn : Cleaned. :mozilla.18:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Msn : Cleaned. :mozilla.21:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Msn : Cleaned. :mozilla.7:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Msn : Cleaned. C:\Documents and Settings\Jessica\Cookies\jessica@search.msn[2].txt -> TrackingCookie.Msn : Cleaned. :mozilla.84:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Overture : Cleaned. C:\Documents and Settings\John\Application Data\AdwareAlert\Quarantine8-05-2007-21-09-33\10004.qit -> TrackingCookie.Overture : Cleaned. :mozilla.180:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Paypal : Cleaned. :mozilla.231:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.233:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.44:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.45:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.156:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned. :mozilla.157:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned. :mozilla.257:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.258:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.259:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.260:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.261:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.262:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.263:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.264:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.465:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.466:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.467:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.468:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.469:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.470:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.471:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.472:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.473:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.474:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.475:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.476:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.477:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.478:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.479:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.480:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.481:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.482:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.483:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.484:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.78:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned. :mozilla.459:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned. :mozilla.104:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned. :mozilla.105:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned. :mozilla.106:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned. :mozilla.107:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned. :mozilla.404:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.405:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.406:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.407:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.9:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\frs2d8ja.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned. :mozilla.67:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Valuead : Cleaned. :mozilla.71:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Valuead : Cleaned. :mozilla.72:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Valuead : Cleaned. :mozilla.73:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Valuead : Cleaned. :mozilla.74:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Valuead : Cleaned. :mozilla.75:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Valuead : Cleaned. :mozilla.518:C:\Documents and Settings\Jessica\Application Data\Netscape\NSB\Profiles\6azax664.default\cookies.txt -> TrackingCookie.Webtrends : Cleaned. C:\Documents and Settings\Jessica\Cookies\jessica@m.webtrends[1].txt -> TrackingCookie.Webtrends : Cleaned. C:\Documents and Settings\John\Application Data\AdwareAlert\Quarantine8-05-2007-21-09-33\10005.qit -> TrackingCookie.Webtrends : Cleaned. :mozilla.97:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.98:C:\Documents and Settings\Jessica\Application Data\Mozilla\Firefox\Profiles\gmgwn1jn.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. C:\System Volume Information\_restore{EDB56365-2E96-4035-9BC4-AEE0FC0E20BE}\RP161\A0171902.exe -> Trojan.DNSChanger.ih : Cleaned with backup (quarantined). ::Report end

#13 tim s

tim s

    MRU Emeritus

  • Authentic Member
  • PipPip
  • 229 posts
  • Interests:Computers

Posted 24 May 2007 - 05:35 PM

Hi jesskristn,

Good job. Let me know how your computer is running now.

These tools I had you download are of no longer any use as they update so frequently that fresh copies have to be downloaded when needed.

Delete tools:
fsbl.exe
Fixwareout



This is my normal post for when you are clear - which you now are - or seem to be. Please advise of any problems you still have :-

Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
  • Disable and Enable System Restore. - You are using Windows XP then you should disable and re-enable system restore to make sure there are no infected files found in a restore point.
    You can find instructions on how to enable and re enable system restore here:

    Windows XP System Restore Guide
    re-enable system restore with instructions from tutorial above
  • Make your Internet Explorer more secure - This can be done by following these simple instructions:
    • From within Internet Explorer click on the Tools menu and then click on Options.
    • Click once on the Security tab
    • Click once on the Internet icon so it becomes highlighted.
    • Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialise and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub-frames across different domains to Prompt
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Use an Anti Virus Software - It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future. See this link for a listing of some on line & their stand-alone anti virus programs:
    Computer Safety On line - Anti-Virus
  • Update your Anti Virus Software - It is imperitive that you update your Anti virus software at least once a week (Even more if you wish). If you do not update your anti virus software then it will not be able to catch any of the new variants that may come out.
  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. For an article on Firewalls and a listing of some available ones see the link below:
    Computer Safety On line - Software Firewalls
  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
  • Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option.
    This will provide real-time spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an anti virus software. A tutorial on installing & using this product can be found here:
    Instructions for - Spybot S & D and Ad-aware
  • Install Ad-Aware - Install and download Ad-Aware. You should also scan your computer with the program on a regular basis just as you would an anti virus software in conjunction with Spybot. A tutorial on installing & using this product can be found here:
    Instructions for - Spybot S & D and Ad-aware
  • Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs. A article on anti-malware products with links for this program and others can be found here:
    Computer Safety on line - Anti-Malware
  • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.

Stand up and be Counted.

NOW is the time you can start to hit back at the people who infected you.
Posted Image
Please take the time to go and complain - that forum has a topic for your infection which is Wareout please post as a reply, you will need to register to do so. It will also have a list of other places you can go to to register your complaint, depending on the country you are resident in. Please read the topics and complain, it is only with such complaints to goverment or government agances that something will get done.



May your God go with you..
Tim s
Posted Image

Honors Graduate of MalWare Removal University - A Cooperative Effort with WhattheTech

#14 jesskristn

jesskristn

    New Member

  • Authentic Member
  • Pip
  • 10 posts

Posted 26 May 2007 - 07:59 AM

Thanks for your help everythings seems back to normal. the hijacking appears to have stopped. Thanks again!

#15 tim s

tim s

    MRU Emeritus

  • Authentic Member
  • PipPip
  • 229 posts
  • Interests:Computers

Posted 26 May 2007 - 05:23 PM

Hi jesskristn, You are welcome glad we could help. :)
Posted Image

Honors Graduate of MalWare Removal University - A Cooperative Effort with WhattheTech

Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users