This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

My Pc And Me Need Help Por Favor

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have ran ad-aware and spybot multiple times and it always finds stuff. Avg finds viruses everyday and I think theyre all gone and then bam, back again. PC runs slow and I cannot seem to get rid of this problem. Logfile of HijackThis v1.99.1 Scan saved at 4:23:17 PM, on 7/12/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\ibmpmsvc.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Sygate\SPF\smc.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\Explorer.EXE C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe C:\Program Files\AVIRA Desktop\AVESVC.EXE C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe C:\Program Files\AVIRA Desktop\AVGUARD.EXE C:\Program Files\AVIRA Desktop\AVWUPSRV.EXE C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe C:\Program Files\Network Associates\Common Framework\FrameworkService.exe C:\WINDOWS\system32\ltmsg.exe C:\WINDOWS\system32\tp4serv.exe C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Picasa2\PicasaMediaDetector.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe C:\PROGRA~1\Grisoft\AVG7\avgcc.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\System32\QCONSVC.EXE C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\BitTorrent\bittorrent.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\TpKmpSVC.exe C:\Program Files\AVIRA Desktop\AVMAILC.EXE C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Hijackthis\HijackThis.exe O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll O3 - Toolbar: SecurityToolbar - {736b5468-bdad-41be-92d0-22ae2ddf7bcb} - C:\Program Files\Security Toolbar\Security Toolbar.dll (file missing) O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey O4 - HKLM\..\Run: [LTWinModem1] ltmsg.exe 9 O4 - HKLM\..\Run: [TrackPointSrv] tp4serv.exe O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe O4 - HKLM\..\Run: [Microsoft Task Scheduler] C:\WINDOWS\system32\dlha\mstask32.com O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O10 - Broken Internet access because of LSP provider 'avsda.dll' missing O18 - Protocol: bw+0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw+0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw-0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw-0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw00 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw00s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw10 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw10s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw20 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw20s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw30 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw30s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw40 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw40s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw50 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw50s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw60 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw60s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw70 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw70s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw80 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw80s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw90 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw90s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwa0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwa0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwb0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwb0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwc0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwc0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwd0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwd0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwe0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwe0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwf0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwf0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll O18 - Protocol: bwg0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwg0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwh0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwh0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwi0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwi0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwj0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwj0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwk0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwk0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwl0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwl0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwm0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwm0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwn0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwn0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwo0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwo0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwp0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwp0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwq0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwq0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwr0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwr0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bws0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bws0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwt0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwt0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwu0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwu0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwv0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwv0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bww0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bww0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwx0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwx0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwy0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwy0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwz0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwz0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O18 - Protocol: offline-8876480 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll O20 - Winlogon Notify: tpfnf2 - C:\WINDOWS\SYSTEM32\notifyf2.dll O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe O23 - Service: AVE Service (AVEService) - AVIRA GmbH - C:\Program Files\AVIRA Desktop\AVESVC.EXE O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: AVIRA Mail Security Service (AVIRAMailService) - AVIRA GmbH - C:\Program Files\AVIRA Desktop\AVMAILC.EXE O23 - Service: AVIRA Service (AVIRAService) - AVIRA GmbH - C:\Program Files\AVIRA Desktop\AVGUARD.EXE O23 - Service: AVIRA Update (AVWUpSrv) - AVIRA GmbH - C:\Program Files\AVIRA Desktop\AVWUPSRV.EXE O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe O23 - Service: QCONSVC - Lenovo - C:\WINDOWS\System32\QCONSVC.EXE O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
Hi straightjacked,

Sorry to tell you this, but your computer appears to have been infected by a backdoor trojan. These programs have the ability to steal passwords and other information from your system. If you use your computer for sensitive purposes such as internet banking then I recommend you take the following steps immediately:
  • Use another, uninfected computer to change all your internet passwords, especially ones with financial implications such as banks, paypal, ebay, etc. You should also change the passwords for any other site you use.
  • Call your bank(s), credit card company or any other institution which may be affected and advise them that your login/password or credit card information may have been stolen and ask what steps to take with regard to your account.
  • Consider what other private information could possibly have been taken from your computer and take appropriate steps
This infection can almost certainly be cleaned, but as the malware could be configured to run any program a remote attacker requires, it will be impossible to be 100% sure that the machine is clean, if this is unacceptable to you then you should consider reformatting the system partition and reinstalling Windows as this is the only 100% sure answer.

If you wish to reformat then please let me know in your next response, I'll now continue with instructions for cleaning.

It appears that you have two antivirus programs running - Avira and AVG. Running one antivirus program is essential, but having two can cause conflicts, slow your system down and even cause stability problems, and will not improve your security. You should use just one antivirus program and use an online scanner like Kaspersky's to get a '2nd opinion'.

Before proceeding, please check and if you have two antivirus programs operating, remove one of them.
If you have any problems, please stop and let me know before proceeding further.

Next, download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
Then, download SmitfraudFix (by S!Ri) to your Desktop.
http://siri.urz.free.fr/Fix/SmitfraudFix.exe

Double-click SmitfraudFix.exe
Select option #1 - Search by typing 1 and press Enter
This program will scan large amounts of files on your computer for known patterns so please be patient while it works. When it is done, the results of the scan will be displayed and it will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed.

IMPORTANT: Do NOT run any other options until you are asked to do so!

If the tool fails to launch from the Desktop, please move SmitfraudFix.exe directly to the root of the system drive (usually C: ), and launch from there.

Note: process.exe is detected by some antivirus programs as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user. Further info is available here.

Once complete, please post the SDFix report, the Smitfraudfix report and a new HijackThis log.
SDFIX Report


SDFix: Version 1.90

Run by [removed] on Fri 07/13/2007 at 06:12 AM

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting…


Normal Mode:
Checking Files:

No Trojan Files Found




Removing Temp Files…

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

Remaining Services:
——————



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"="C:\\Program Files\\Google\\Google Talk\\googletalk.exe:*:Enabled:Google Talk"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:MSN Messenger 7.5"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Disabled:Logitech Desktop Messenger"
"C:\\WINDOWS\\system32\\LEXPPS.EXE"="C:\\WINDOWS\\system32\\LEXPPS.EXE:*:Disabled:LEXPPS.EXE"
"C:\\Program Files\\Ares\\Ares.exe"="C:\\Program Files\\Ares\\Ares.exe:*:Enabled:Ares"
"C:\\Program Files\\TurboTax\\Basic 2006\\32bit\\ttax.exe"="C:\\Program Files\\TurboTax\\Basic 2006\\32bit\\ttax.exe:LocalSubNet:Enabled:TurboTax"
"C:\\Program Files\\TurboTax\\Basic 2006\\32bit\\updatemgr.exe"="C:\\Program Files\\TurboTax\\Basic 2006\\32bit\\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Enabled:IE6"
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG7\\avginet.exe:*:Enabled:avginet.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe:*:Enabled:avgamsvr.exe"
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe:*:Enabled:avgcc.exe"
"C:\\WINDOWS\\system32\\ZoneLabs\\avsys\\ScanningProcess.exe"="C:\\WINDOWS\\system32\\ZoneLabs\\avsys\\ScanningProcess.exe:*:Enabled:Kaspersky AV Scanner"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:MSN Messenger 7.5"
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"

Remaining Files:
—————


Files with Hidden Attributes:

C:\Program Files\Common Files\Adobe\ESD\DLMCleanup.exe
C:\Program Files\Picasa2\setup.exe
C:\WINDOWS\system32\config\default.tmp.LOG
C:\WINDOWS\system32\config\software.tmp.LOG
C:\WINDOWS\system32\config\system.tmp.LOG

Finished




SmitFraudFix v2.204

Scan done at 6:26:52.99, Fri 07/13/2007
Run from C:\Documents and Settings\MH PRO\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» Process

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\QCONSVC.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\WINDOWS\system32\ltmsg.exe
C:\WINDOWS\system32\tp4serv.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\BitTorrent\bittorrent.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\cmd.exe

»»»»»»»»»»»»»»»»»»»»»»»» hosts


»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

C:\WINDOWS\system32\ot.ico FOUND !
C:\WINDOWS\system32\stdole3.tlb FOUND !
C:\WINDOWS\system32\ts.ico FOUND !
C:\WINDOWS\system32\1024\ FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\MH PRO


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\MH PRO\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Start Menu

C:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url FOUND !
C:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\MHPRO~1\FAVORI~1


»»»»»»»»»»»»»»»»»»»»»»»» Desktop


»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

C:\Program Files\Security Toolbar\ FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"


»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{89aef01d-d237-49c7-84dc-4e1904c1fd31}"="AutoDisc Ware"



»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Rustock



»»»»»»»»»»»»»»»»»»»»»»»» DNS

Description: Wireless-B Notebook Adapter - Packet Scheduler Miniport
DNS Server Search Order: 68.116.46.115
DNS Server Search Order: 68.185.34.67
DNS Server Search Order: 68.116.46.70

HKLM\SYSTEM\CCS\Services\Tcpip\..\{0A9D9AB8-8FB7-4A34-A5B3-F2D5AA41369B}: DhcpNameServer=[removed] [removed] [removed]
HKLM\SYSTEM\CS1\Services\Tcpip\..\{0A9D9AB8-8FB7-4A34-A5B3-F2D5AA41369B}: DhcpNameServer=[removed] [removed] [removed]
HKLM\SYSTEM\CS3\Services\Tcpip\..\{0A9D9AB8-8FB7-4A34-A5B3-F2D5AA41369B}: DhcpNameServer=[removed] [removed] [removed]
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] [removed]
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] [removed]
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] [removed]


»»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End





Logfile of HijackThis v1.99.1
Scan saved at 6:28:02 AM, on 7/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\QCONSVC.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\WINDOWS\system32\ltmsg.exe
C:\WINDOWS\system32\tp4serv.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\BitTorrent\bittorrent.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\notepad.exe
C:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: SecurityToolbar - {736b5468-bdad-41be-92d0-22ae2ddf7bcb} - C:\Program Files\Security Toolbar\Security Toolbar.dll (file missing)
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [LTWinModem1] ltmsg.exe 9
O4 - HKLM\..\Run: [TrackPointSrv] tp4serv.exe
O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: bw+0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Protocol: offline-8876480 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll
O20 - Winlogon Notify: tpfnf2 - C:\WINDOWS\SYSTEM32\notifyf2.dll
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: QCONSVC - Lenovo - C:\WINDOWS\System32\QCONSVC.EXE
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
Hi straightjacked,

Please print/save a copy of these instructions because we will be using Safe Mode again, during which time you won't have access to the internet.

Make hidden/system files and folders visible:
Click Start -> My Computer
Select the Tools menu, click Folder Options and select the View tab
Under the Hidden files and folders heading SELECT Show hidden files and folders
UNCHECK the Hide protected operating system files (recommended) option
Click Yes to confirm and press OK

Then reboot your computer in Safe Mode again by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.
Use Windows Explorer to find and delete the following file (if present):
C:\WINDOWS\system32\dlha\mstask32.com

Next, double-click on SmitfraudFix.exe
Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.

You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.

The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".

The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart it into Normal Windows.
A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply.
The report can also be found at the root of the system drive, usually at C:\rapport.txt

Warning : running option #2 on a non infected computer will remove your Desktop background.

Once your machine has rebooted, open HijackThis and select Open the Misc Tools section
Press the Open Uninstall Manager… button, then press Save list…
Save the Uninstall log to your deskop and include a copy in your next response.
Now press Back and Scan and then Save log to create and save a new HijackThis log.

Once complete, please post the new Smitfraudfix log, the uninstall list and a new HijackThis log. Also, please tell me if mstask32.com was present and if you deleted it OK.
MStask 32.com was NOT present

SmitFraudFix v2.204

Scan done at 8:17:39.22, Fri 07/13/2007
Run from C:\Documents and Settings\MH PRO\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{89aef01d-d237-49c7-84dc-4e1904c1fd31}"="AutoDisc Ware"


»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» hosts

127.0.0.1 localhost

»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

C:\WINDOWS\system32\ot.ico Deleted
C:\WINDOWS\system32\stdole3.tlb Deleted
C:\WINDOWS\system32\ts.ico Deleted
C:\WINDOWS\system32\1024\ Deleted
C:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url Deleted
C:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url Deleted
C:\Program Files\Security Toolbar\ Deleted

»»»»»»»»»»»»»»»»»»»»»»»» DNS

HKLM\SYSTEM\CCS\Services\Tcpip\..\{0A9D9AB8-8FB7-4A34-A5B3-F2D5AA41369B}: DhcpNameServer=[removed] [removed] [removed]
HKLM\SYSTEM\CS1\Services\Tcpip\..\{0A9D9AB8-8FB7-4A34-A5B3-F2D5AA41369B}: DhcpNameServer=[removed] [removed] [removed]
HKLM\SYSTEM\CS3\Services\Tcpip\..\{0A9D9AB8-8FB7-4A34-A5B3-F2D5AA41369B}: DhcpNameServer=[removed] [removed] [removed]
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] [removed]
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] [removed]
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] [removed]


»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End




UNINSTALL LIST


ABBYY FineReader 5.0 Sprint
Ad-Aware 2007
Adobe Download Manager 2.0 (Remove Only)
Adobe Flash Player ActiveX
Adobe Reader 7.0.7
Adobe® Photoshop® Album Starter Edition 3.0
Ares 1.9.0
AVG 7.5
BitTorrent 5.0.7
Dell AIO Printer A920
DivX Codec
FaxTools
Google Talk (remove only)
Google Toolbar for Internet Explorer
Hijackthis 1.99.1
HijackThis 1.99.1
IBM ThinkPad Battery MaxiMiser and Power Management Features
Intel® PRO Network Adapters and Drivers
Intel® PROSet
iTunes
J2SE Runtime Environment 5.0 Update 6
LimeWire 4.12.15
Logitech Desktop Messenger
Logitech Print Service
Logitech QuickCam Software
Logitech® Camera Driver
Lucent Win Modem
Microsoft Office XP Standard
Mozilla Firefox (2.0.0.4)
MSN Messenger 7.5
MSN Music Assistant
MSXML 4.0 SP2 (KB927978)
Pencil-Pal Kindergarten
Picasa 2
QuickTime
S3Display
S3Gamma2
S3Info2
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Software Installer
SuperSavage and Utilities
Sygate Personal Firewall
ThinkPad Configuration
ThinkPad EasyEject Utility
ThinkPad Keyboard Customizer Utility
ThinkPad Power Management Driver
ThinkPad Presentation Director
ThinkPad TrackPoint Driver
ThinkVantage Access Connections
TrackPoint Accessibility Features
TurboTax Basic 2005
TurboTax Basic 2006
TurboTax ItsDeductible 2005
TurboTax ItsDeductible 2006
Update for Windows XP (KB894391)
Update for Windows XP (KB900485)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
WexTech AnswerWorks
Windows Installer 3.1 (KB893803)
Windows Media Format Runtime
Windows Media Player 10
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB885884
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
WinRAR archiver




Logfile of HijackThis v1.99.1
Scan saved at 8:31:00 AM, on 7/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\WINDOWS\system32\ltmsg.exe
C:\WINDOWS\system32\tp4serv.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\BitTorrent\bittorrent.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\QCONSVC.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\WINDOWS\system32\notepad.exe

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [LTWinModem1] ltmsg.exe 9
O4 - HKLM\..\Run: [TrackPointSrv] tp4serv.exe
O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: bw+0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Protocol: offline-8876480 - {A8F92228-A677-4323-B2DA-FA54183A4926} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll
O20 - Winlogon Notify: tpfnf2 - C:\WINDOWS\SYSTEM32\notifyf2.dll
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: QCONSVC - Lenovo - C:\WINDOWS\System32\QCONSVC.EXE
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
Hi straightjacked,

MStask 32.com was NOT present

:thumbup:


Download FixSF.reg to your Desktop, double-click it and say Yes to the prompt.

Reboot your computer, then use Windows Explorer to delete the following file (if present):
C:\Windows\System32\sbnudh.dll
Let me know in your next response if this file was present and if you deleted it OK.

Next, some uninstalls to consider:

Your Java is outdated and is now a security risk
Go to Start » Control Panel » Add/Remove Programs
Find and remove this entry:
J2SE Runtime Environment 5.0 Update 6
Download and install the newest version of Java Runtime Environment (JRE), from here:
http://java.sun.com/javase/downloads/index.jsp

You have Logitech Desktop Messenger installed on your system. This is a background process which can access the internet without your knowledge or consent. Although it can assist in providing software updates for your Logitech hardware, it uses resources on your machine and the fact that it accesses the internet without your approval is potentially dangerous. I recommend you remove this program, to do so, open Start->Control Panel->Add/Remove Programs find Logitech Desktop Messenger and select Remove

You have LimeWire and Bittorrent, P2P file sharing programs installed on your computer. These programs do not come bundled with malware as some similar programs do, but P2P file sharing networks are one of the biggest sources of malware we see. Anything downloaded from them cannot be trusted to be clean, because even if the file appears to be what it claims to be, it can have malware embedded in it.
I recommend you remove it, but of course the choice is yours.
You can remove these programs via Add/Remove Programs.

Next please do an online scan with Kaspersky:

Open Kaspersky Online Scanner in Internet Explorer

You will be prompted to install an ActiveX component from Kaspersky,
Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT and then Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • The program will start to scan your system.
  • Once the scan is complete, click on the Save as Text button and save the file to your desktop
Once complete, please post the Kaspersky log and a new HijackThis log, also let me know about sbnudh.dll
sbnudh.dll was NOT present

——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Saturday, July 14, 2007 2:51:44 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.0
Kaspersky Anti-Virus database last update: 14/07/2007
Kaspersky Anti-Virus database records: 362226
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\

Scan Statistics:
Total number of scanned objects: 41388
Number of viruses found: 2
Number of infected objects: 5
Number of suspicious objects: 0
Duration of the scan process: 01:16:39

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Network Associates\Common Framework\Db\Agent_001WW187.log Object is locked skipped
C:\Documents and Settings\B\Application Data\Adobe\Acrobat\7.0\AdobeCMapFnt07.lst Object is locked skipped
C:\Documents and Settings\B\Application Data\Adobe\Acrobat\7.0\AdobeSysFnt07.lst Object is locked skipped
C:\Documents and Settings\B\Application Data\Adobe\Acrobat\7.0\Collab\RSS Object is locked skipped
C:\Documents and Settings\B\Application Data\Adobe\Acrobat\7.0\JavaScripts\glob.settings.js Object is locked skipped
C:\Documents and Settings\B\Application Data\Adobe\Acrobat\7.0\JSADM.exv Object is locked skipped
C:\Documents and Settings\B\Application Data\Adobe\Acrobat\7.0\Preferences\AutoFillDefaults.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Adobe\Acrobat\7.0\Preferences\defaultHeuristics.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Adobe\Acrobat\7.0\Updater\udlog.txt Object is locked skipped
C:\Documents and Settings\B\Application Data\Adobe\Acrobat\7.0\Updater\udstore.js Object is locked skipped
C:\Documents and Settings\B\Application Data\Adobe\Acrobat\7.0\UserCache.bin Object is locked skipped
C:\Documents and Settings\B\Application Data\Adobe\Photoshop Album\3.0\jpegviewer.xml Object is locked skipped
C:\Documents and Settings\B\Application Data\AVG7\log.idx Object is locked skipped
C:\Documents and Settings\B\Application Data\AVG7\sched-0001.cfg Object is locked skipped
C:\Documents and Settings\B\Application Data\AVG7\sched-0002.cfg Object is locked skipped
C:\Documents and Settings\B\Application Data\AVG7\user-0000.cfg Object is locked skipped
C:\Documents and Settings\B\Application Data\desktop.ini Object is locked skipped
C:\Documents and Settings\B\Application Data\Google\Local Search History\google%2Eweb.w Object is locked skipped
C:\Documents and Settings\B\Application Data\Macromedia\Flash Player\#SharedObjects\7WH8SVX8\static.userplane.com\presence\m\presence.swf\presence.sol Object is locked skipped
C:\Documents and Settings\B\Application Data\Macromedia\Flash Player\#SharedObjects\7WH8SVX8\www.youtube.com\soundData.sol Object is locked skipped
C:\Documents and Settings\B\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#static.userplane.com\settings.sol Object is locked skipped
C:\Documents and Settings\B\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.youtube.com\settings.sol Object is locked skipped
C:\Documents and Settings\B\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\CryptnetUrlCache\Content\2BF68F4714092295550497DD56F57004 Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\CryptnetUrlCache\Content\303572DF538EDD8B1D606185F1D559B8 Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\CryptnetUrlCache\Content\33ECCD4EC2899E5F6A7E306662596E0F Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\CryptnetUrlCache\Content\60E31627FDA0A46932B0E5948949F2A5 Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\CryptnetUrlCache\Content\696F3DE637E6DE85B458996D49D759AD Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\CryptnetUrlCache\Content\71644221AC231DBD2359C18EBB2118DC Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\CryptnetUrlCache\Content\79841F8EF00FBA86D33CC5A47696F165 Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015 Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\CryptnetUrlCache\Content\A44F4E7CB3133FF765C39A53AD8FCFDD Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\CryptnetUrlCache\Content\A8FABA189DB7D25FBA7CAC806625FD30 Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\CryptnetUrlCache\Content\C571B417AAF1F617555A0486AB3F5361 Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\CryptnetUrlCache\Content\E6024EAC88E6B6165D49FE3C95ADD735 Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\CryptnetUrlCache\Content\F482C95F83F1B59228F1B1E720F2EDF1 Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\CryptnetUrlCache\MetaData\2BF68F4714092295550497DD56F57004 Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\CryptnetUrlCache\MetaData\303572DF538EDD8B1D606185F1D559B8 Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\CryptnetUrlCache\MetaData\33ECCD4EC2899E5F6A7E306662596E0F Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\CryptnetUrlCache\MetaData\60E31627FDA0A46932B0E5948949F2A5 Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\CryptnetUrlCache\MetaData\696F3DE637E6DE85B458996D49D759AD Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\CryptnetUrlCache\MetaData\71644221AC231DBD2359C18EBB2118DC Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\CryptnetUrlCache\MetaData\79841F8EF00FBA86D33CC5A47696F165 Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015 Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\CryptnetUrlCache\MetaData\A44F4E7CB3133FF765C39A53AD8FCFDD Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\CryptnetUrlCache\MetaData\A8FABA189DB7D25FBA7CAC806625FD30 Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\CryptnetUrlCache\MetaData\C571B417AAF1F617555A0486AB3F5361 Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\CryptnetUrlCache\MetaData\E6024EAC88E6B6165D49FE3C95ADD735 Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\CryptnetUrlCache\MetaData\F482C95F83F1B59228F1B1E720F2EDF1 Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\Crypto\RSA\S-1-5-21-1957994488-2146954627-1343024091-1006\608f8ebf2ce922e73930d87eb41a5916_3aeec26a-dd68-43a0-8a17-a5c8fcf1f774 Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\HTML Help\hh.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\IdentityCRL\ppcrlconfig.dll Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\Internet Explorer\brndlog.bak Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\Internet Explorer\brndlog.txt Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\Internet Explorer\Desktop.htt Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\Internet Explorer\Quick Launch\Remote Desktop Connection.lnk Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\Media Player\05D154.wpl Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\MSN Messenger\2132572276\Backgrounds\map.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\MSN Messenger\2132572276\Backgrounds\TFR52.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\MSN Messenger\2132572276\Backgrounds\TFR53.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\MSN Messenger\2132572276\Backgrounds\TFR54.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\MSN Messenger\2132572276\Backgrounds\TFR55.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\MSN Messenger\2132572276\Backgrounds\TFR56.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\MSN Messenger\2132572276\DynamicBackgrounds\map.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\MSN Messenger\2132572276\DynamicBackgrounds\TFR5A.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\MSN Messenger\2132572276\DynamicBackgrounds\TFR65.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\MSN Messenger\2132572276\DynamicBackgrounds\TFR70.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\MSN Messenger\2132572276\DynamicBackgrounds\TFR7B.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\MSN Messenger\2132572276\ListCache.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\MSN Messenger\2132572276\MapFile\TFR26.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\MSN Messenger\2132572276\MapFile\TFR83.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\MSN Messenger\2132572276\MapFile\TFR84.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\MSN Messenger\2132572276\MapFile\TFRA3.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\MSN Messenger\2132572276\sqmdata00.sqm Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\MSN Messenger\2132572276\sqmdata01.sqm Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\MSN Messenger\2132572276\sqmdata02.sqm Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\MSN Messenger\2132572276\UserTile\map.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\MSN Messenger\2132572276\UserTile\TFR25.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\MSN Messenger\2132572276\UserTile\TFR46.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\MSN Messenger\2132572276\UserTile\TFR47.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\MSN Messenger\2132572276\UserTile\TFR48.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\MSN Messenger\2132572276\UserTile\TFR49.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\MSN Messenger\2132572276\UserTile\TFR4A.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\MSN Messenger\2132572276\UserTile\TFR4B.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\MSN Messenger\2132572276\UserTile\TFR4C.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\MSN Messenger\2132572276\UserTile\TFR4D.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\MSN Messenger\2132572276\UserTile\TFR4E.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\MSN Messenger\2132572276\UserTile\TFR4F.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\MSN Messenger\2132572276\UserTile\TFR50.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\MSN Messenger\2132572276\Winks3\map.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\MSN Messenger\2132572276\Winks3\TFR86.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\MSN Messenger\2132572276\Winks3\TFR88.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\MSN Messenger\2132572276\Winks3\TFR8A.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\MSN Messenger\2132572276\Winks3\TFR8C.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\MSN Messenger\2132572276\Winks3\TFR8E.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\MSN Messenger\2132572276\Winks3\TFR90.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\MSN Messenger\2132572276\Winks3\TFR92.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\MSN Messenger\2132572276\Winks3\TFR94.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\MSN Messenger\2132572276\Winks3\TFR96.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\MSN Messenger\2132572276\Winks3\TFR98.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\MSN Messenger\2132572276\Winks3\TFR9A.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\MSN Messenger\2132572276\Winks3\TFR9C.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\MSN Messenger\2132572276\Winks3\TFR9E.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\MSN Messenger\2132572276\Winks3\TFRA0.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\MSN Messenger\2132572276\Winks3\TFRA2.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\Office\MSO1033.acl Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\Office\MSOut10.pip Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\Office\Recent\AHT7MCPS.LNK Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\Office\Recent\Bryan Shollenberger Offer Letter.doc.LNK Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\Office\Recent\Bryan Shollenberger Offer Letter[1].doc.LNK Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\Office\Recent\Caci.LNK Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\Office\Recent\CoverLetter-Bryan-wwps.doc.LNK Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\Office\Recent\CoverLetter-Bryan.doc.LNK Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\Office\Recent\Desktop.LNK Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\Office\Recent\Direct Deposit.doc.LNK Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\Office\Recent\index.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\Office\Recent\Pat's Documents.LNK Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\Office\Word10.pip Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\Outlook\Outlook.NK2 Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\Proof\CUSTOM.DIC Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\Protect\CREDHIST Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\Protect\S-1-5-21-1957994488-2146954627-1343024091-1006\4143043e-df04-403e-8a1b-5dc67dd8ec5d Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\Protect\S-1-5-21-1957994488-2146954627-1343024091-1006\ab9e3ccf-7dc7-4a24-b9cc-4e5a5eb94c2d Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\Protect\S-1-5-21-1957994488-2146954627-1343024091-1006\Preferred Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\Speech\Files\UserLexicons\SP_FF851E8EF65A43BABDF366C07BF8A3CF.dat Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\Templates\Normal.dot Object is locked skipped
C:\Documents and Settings\B\Application Data\Microsoft\Windows\Themes\Custom.theme Object is locked skipped
C:\Documents and Settings\B\Cookies\anyuser@browsep2p[1].txt Object is locked skipped
C:\Documents and Settings\B\Cookies\[removed][1].txt Object is locked skipped
C:\Documents and Settings\B\Cookies\b@accounts[1].txt Object is locked skipped
C:\Documents and Settings\B\Cookies\b@accounts[2].txt Object is locked skipped
C:\Documents and Settings\B\Cookies\b@accounts[3].txt Object is locked skipped
C:\Documents and Settings\B\Cookies\[removed][2].txt Object is locked skipped
C:\Documents and Settings\B\Cookies\b@ad[1].txt Object is locked skipped
C:\Documents and Settings\B\Cookies\b@ask[1].txt Object is locked skipped
C:\Documents and Settings\B\Cookies\b@belnk[1].txt Object is locked skipped
C:\Documents and Settings\B\Cookies\[removed][2].txt Object is locked skipped
C:\Documents and Settings\B\Cookies\[removed][1].txt Object is locked skipped
C:\Documents and Settings\B\Cookies\b@com[1].txt Object is locked skipped
C:\Documents and Settings\B\Cookies\[removed][1].txt Object is locked skipped
C:\Documents and Settings\B\Cookies\[removed][1].txt Object is locked skipped
C:\Documents and Settings\B\Cookies\[removed][1].txt Object is locked skipped
C:\Documents and Settings\B\Cookies\[removed][2].txt Object is locked skipped
C:\Documents and Settings\B\Cookies\[removed][1].txt Object is locked skipped
C:\Documents and Settings\B\Cookies\[removed][2].txt Object is locked skipped
C:\Documents and Settings\B\Cookies\[removed][2].txt Object is locked skipped
C:\Documents and Settings\B\Cookies\b@discovercard[1].txt Object is locked skipped
C:\Documents and Settings\B\Cookies\[removed][2].txt Object is locked skipped
C:\Documents and Settings\B\Cookies\b@download[1].txt Object is locked skipped
C:\Documents and Settings\B\Cookies\b@google[1].txt Object is locked skipped
C:\Documents and Settings\B\Cookies\[removed][1].txt Object is locked skipped
C:\Documents and Settings\B\Cookies\[removed][1].txt Object is locked skipped
C:\Documents and Settings\B\Cookies\b@livedigital[1].txt Object is locked skipped
C:\Documents and Settings\B\Cookies\b@live[1].txt Object is locked skipped
C:\Documents and Settings\B\Cookies\[removed][2].txt Object is locked skipped
C:\Documents and Settings\B\Cookies\b@mail[1].txt Object is locked skipped
C:\Documents and Settings\B\Cookies\b@mail[3].txt Object is locked skipped
C:\Documents and Settings\B\Cookies\[removed][1].txt Object is locked skipped
C:\Documents and Settings\B\Cookies\b@msn[1].txt Object is locked skipped
C:\Documents and Settings\B\Cookies\b@myspace[1].txt Object is locked skipped
C:\Documents and Settings\B\Cookies\b@piczo[1].txt Object is locked skipped
C:\Documents and Settings\B\Cookies\[removed][2].txt Object is locked skipped
C:\Documents and Settings\B\Cookies\[removed][2].txt Object is locked skipped
C:\Documents and Settings\B\Cookies\[removed][2].txt Object is locked skipped
C:\Documents and Settings\B\Cookies\b@serviceswitching[1].txt Object is locked skipped
C:\Documents and Settings\B\Cookies\b@sourceforge[1].txt Object is locked skipped
C:\Documents and Settings\B\Cookies\[removed][1].txt Object is locked skipped
C:\Documents and Settings\B\Cookies\[removed][1].txt Object is locked skipped
C:\Documents and Settings\B\Cookies\[removed][2].txt Object is locked skipped
C:\Documents and Settings\B\Cookies\[removed][1].txt Object is locked skipped
C:\Documents and Settings\B\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\B\Cookies\system@browsep2p[1].txt Object is locked skipped
C:\Documents and Settings\B\Cookies\system@inm2006[1].txt Object is locked skipped
C:\Documents and Settings\B\Cookies\system@npmhosting[1].txt Object is locked skipped
C:\Documents and Settings\B\Desktop\Ares.lnk Object is locked skipped
C:\Documents and Settings\B\Desktop\attachments.zip Object is locked skipped
C:\Documents and Settings\B\Desktop\Bryan Shollenberger Offer Letter.doc Object is locked skipped
C:\Documents and Settings\B\Desktop\Bryan Shollenberger-stateapp.doc Object is locked skipped
C:\Documents and Settings\B\Desktop\CoverLetter-Bryan-wwps.doc Object is locked skipped
C:\Documents and Settings\B\Desktop\CoverLetter-Bryan.doc Object is locked skipped
C:\Documents and Settings\B\Desktop\DC\P1010038.JPG Object is locked skipped
C:\Documents and Settings\B\Desktop\DC\P1010039.JPG Object is locked skipped
C:\Documents and Settings\B\Desktop\DC\P1010040.JPG Object is locked skipped
C:\Documents and Settings\B\Desktop\DC\P1010041.JPG Object is locked skipped
C:\Documents and Settings\B\Desktop\DC\P1010042.JPG Object is locked skipped
C:\Documents and Settings\B\Desktop\pic\P1010001.JPG Object is locked skipped
C:\Documents and Settings\B\Desktop\pic\P1010002.JPG Object is locked skipped
C:\Documents and Settings\B\Desktop\pic\P1010003.JPG Object is locked skipped
C:\Documents and Settings\B\Desktop\pic\P1010005.JPG Object is locked skipped
C:\Documents and Settings\B\Desktop\pic\P1010030.JPG Object is locked skipped
C:\Documents and Settings\B\Desktop\pic\Thumbs.db Object is locked skipped
C:\Documents and Settings\B\Desktop\Remote Desktop Connection.lnk Object is locked skipped
C:\Documents and Settings\B\Desktop\Resume-Bryan Shollenberger.doc Object is locked skipped
C:\Documents and Settings\B\Favorites\Desktop.ini Object is locked skipped
C:\Documents and Settings\B\Favorites\Links\Customize Links.url Object is locked skipped
C:\Documents and Settings\B\Favorites\Links\Free Hotmail.url Object is locked skipped
C:\Documents and Settings\B\Favorites\Links\Windows Marketplace.url Object is locked skipped
C:\Documents and Settings\B\Favorites\Links\Windows Media.url Object is locked skipped
C:\Documents and Settings\B\Favorites\Links\Windows.url Object is locked skipped
C:\Documents and Settings\B\Favorites\MSN.com.url Object is locked skipped
C:\Documents and Settings\B\Favorites\Radio Station Guide.url Object is locked skipped
C:\Documents and Settings\B\Favorites\VA online app.url Object is locked skipped
C:\Documents and Settings\B\Local Settings\Application Data\Adobe\Acrobat\7.0\Cache\AcroFnt07.lst Object is locked skipped
C:\Documents and Settings\B\Local Settings\Application Data\Adobe\Color\ACECache4.lst Object is locked skipped
C:\Documents and Settings\B\Local Settings\Application Data\Ares\Data\CNodes.dat Object is locked skipped
C:\Documents and Settings\B\Local Settings\Application Data\Ares\Data\default.m3u Object is locked skipped
C:\Documents and Settings\B\Local Settings\Application Data\Ares\Data\DHTnodes.dat Object is locked skipped
C:\Documents and Settings\B\Local Settings\Application Data\Ares\Data\FailedSNodes.dat Object is locked skipped
C:\Documents and Settings\B\Local Settings\Application Data\Ares\Data\PHashIdx.dat Object is locked skipped
C:\Documents and Settings\B\Local Settings\Application Data\Ares\Data\ShareH.dat Object is locked skipped
C:\Documents and Settings\B\Local Settings\Application Data\Ares\Data\ShareL.dat Object is locked skipped
C:\Documents and Settings\B\Local Settings\Application Data\Ares\Data\SNodes.dat Object is locked skipped
C:\Documents and Settings\B\Local Settings\Application Data\Ares\My Shared Folder6-nickelback-far_away.mp3 Object is locked skipped
C:\Documents and Settings\B\Local Settings\Application Data\Ares\My Shared Folder\12-yung_joc-i_know_you_see_it.mp3 Object is locked skipped
C:\Documents and Settings\B\Local Settings\Application Data\Ares\My Shared Folder\michael buble - home.mp3 Object is locked skipped
C:\Documents and Settings\B\Local Settings\Application Data\Ares\My Shared Folder\micheal buble - home382.mp3 Object is locked skipped
C:\Documents and Settings\B\Local Settings\Application Data\Ares\My Shared Folder\the guess who - american women - no sugar tonight.mp3 Object is locked skipped
C:\Documents and Settings\B\Local Settings\Application Data\IconCache.db Object is locked skipped
C:\Documents and Settings\B\Local Settings\Application Data\Microsoft\FORMS\FRMCACHE.DAT Object is locked skipped
C:\Documents and Settings\B\Local Settings\Application Data\Microsoft\Internet Explorer\MSIMGSIZ.DAT Object is locked skipped
C:\Documents and Settings\B\Local Settings\Application Data\Microsoft\Media Player\CurrentDatabase_219.wmdb Object is locked skipped
C:\Documents and Settings\B\Local Settings\Application Data\Microsoft\Media Player\CurrentDatabase_59R.wmdb Object is locked skipped
C:\Documents and Settings\B\Local Settings\Application Data\Microsoft\Media Player\wmpfolders.wmdb Object is locked skipped
C:\Documents and Settings\B\Local Settings\Application Data\Microsoft\Outlook\extend.dat Object is locked skipped
C:\Documents and Settings\B\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst Object is locked skipped
C:\Documents and Settings\B\Local Settings\Application Data\Microsoft\Terminal Server Client\Cache\bcache22.bmc Object is locked skipped
C:\Documents and Settings\B\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\B\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\B\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNS.DTD Object is locked skipped
C:\Documents and Settings\B\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNS.XML Object is locked skipped
C:\Documents and Settings\B\Local Settings\Application Data\Microsoft\Windows Media\9.0\WMSDKNS.DTD Object is locked skipped
C:\Documents and Settings\B\Local Settings\Application Data\Microsoft\Windows Media\9.0\WMSDKNS.XML Object is locked skipped
C:\Documents and Settings\B\Local Settings\desktop.ini Object is locked skipped
C:\Documents and Settings\B\Local Settings\History\desktop.ini Object is locked skipped
C:\Documents and Settings\B\Local Settings\History\History.IE5\desktop.ini Object is locked skipped
C:\Documents and Settings\B\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\B\Local Settings\History\History.IE5\MSHist012007070120070702\index.dat Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\control.xml Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\IMT20.xml Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\IMT21.xml Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\IMT22.xml Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\IMT5.xml Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\IMT6.xml Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\IMT7.xml Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\IMT8.xml Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\IMT9.xml Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\IMTA.xml Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\IMTB.xml Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\IMTC.xml Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\IMTD.xml Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\lastscan.JPG Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\msninst.inf Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\msnmusax.ocx Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\MsnMusic.exe Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\MsnWmpPl.dll Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\rtdrvmon.exe Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\setb0.tmp Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\setb1.tmp Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\setb2.tmp Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\setb3.tmp Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\setb4.tmp Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\setb5.tmp Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\setb6.tmp Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\setb7.tmp Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\setup_wm.exe Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\temp.frF278 Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\TFR11.tmp Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\TFR14.tmp Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\TFR15.tmp Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\TFR5.tmp Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\TFR7.tmp Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\TFR8.tmp Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\TFRC.tmp Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\TFRE.tmp Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\unicows.dll Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\wmv3.tmp Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\wmv6.tmp Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\[removed] Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\[removed] Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\[removed] Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\[removed] Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\[removed] Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\[removed] Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\[removed] Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\[removed] Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\[removed] Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\[removed] Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\[removed] Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\[removed] Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\[removed] Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\[removed] Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\[removed] Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\[removed] Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\[removed] Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\[removed] Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\[removed] Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\[removed] Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\[removed] Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\[removed] Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\[removed] Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\[removed] Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\[removed] Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\[removed] Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\[removed] Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\[removed] Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\[removed] Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\[removed] Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\~DF8FB9.tmp Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\~DF9A16.tmp Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\~DF9CF4.tmp Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\~DFD4B.tmp Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temp\~DFF0AD.tmp Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE51K345OP\164C13C5E27A34283F53E5895C785[1].jpg Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE51K345OP\angry[1].png Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE51K345OP\available_white1[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE51K345OP\B1909321[1].htm Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE51K345OP\card_left_new[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE51K345OP\card_right2_new[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE51K345OP\card_top_new[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE51K345OP\cleardot[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE51K345OP\cry[1].png Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE51K345OP\dap[1].js Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE51K345OP\desktop.ini Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE51K345OP\equal_sad[1].png Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE51K345OP\expo_tab_icon[1].png Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE51K345OP\logo[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE51K345OP\mail[1] Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE51K345OP\mail[1].htm Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE51K345OP\mail[5] Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE51K345OP\mail[6] Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE51K345OP\mail[7] Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE51K345OP\menuarwopen[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE51K345OP\mgou[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE51K345OP\mobile_j2me_micro[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE51K345OP\MsgrConfig[1].xml Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE51K345OP\msgr_tab_icon[1].png Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE51K345OP\nav_logo3[1].png Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE51K345OP\nose_grin[1].png Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE51K345OP\nutrisystem_amandabikalt2_234x60[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE51K345OP\officeLive[1].png Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE51K345OP\paperclip[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE51K345OP\print_icon[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE51K345OP\reply_all[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE51K345OP\rockout[1].png Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE51K345OP\siteopt[2].js Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE51K345OP\slant[1].png Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE51K345OP\smile[1].png Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE51K345OP\talk_bubbles_small[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE51K345OP\tearoff_icon[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE51K345OP\topbuttons[1].xml Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5LUV8DYV1[1].htm Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5LUV8DYV\300x250_10-24_acqui_RAZR_v3m_FreeAct[1].swf Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5LUV8DYV\available_ltblue1[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5LUV8DYV\BEAD259C202AFE841BD41CAABB52B[1].jpg Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5LUV8DYV\CAAV4TU3.bin Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5LUV8DYV\card_bot_new[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5LUV8DYV\card_button_hl[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5LUV8DYV\card_button_m[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5LUV8DYV\card_left2_new[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5LUV8DYV\checkmark[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5LUV8DYV\cleardot[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5LUV8DYV\conversion[2].js Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5LUV8DYV\corner_br[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5LUV8DYV\cp2403_Summer_001[1].png Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5LUV8DYV\desktop.ini Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5LUV8DYV\devil[1].png Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5LUV8DYV\em_wink_smile_end_26x36[1].png Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5LUV8DYV\envopen[2].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5LUV8DYV\equal_grin[1].png Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5LUV8DYV\google[1].htm Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5LUV8DYV\grin[1].png Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5LUV8DYV\heart[1].png Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5LUV8DYV\liljewel[1].png Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5LUV8DYV\load[1].htm Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5LUV8DYV\mail[1].htm Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5LUV8DYV\mail[2].htm Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5LUV8DYV\mail[3].htm Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5LUV8DYV\mail[5] Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5LUV8DYV\mail[7] Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5LUV8DYV\mail[9] Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5LUV8DYV\messengerTab_shoppingBag[1].png Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5LUV8DYV\nose_smile[1].png Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5LUV8DYV\opentriangle[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5LUV8DYV\reply[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5LUV8DYV\siteopt[2].js Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5LUV8DYV\star_off_2[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5LUV8DYV\star_off_sm_2[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5LUV8DYV\straight_face[1].png Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5LUV8DYV\today_en-us[2].js Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5LUV8DYV\tongue[1].png Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5LUV8DYV\version_en_win_ax[1].xml Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\8RABCVEX205_009_R_180150_A[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\8RABCVEX\bookmarks[1].xml Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\8RABCVEX\card_bl_new[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\8RABCVEX\card_button_hm[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\8RABCVEX\card_button_l[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\8RABCVEX\card_right_new[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\8RABCVEX\chat_bubble_nav[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\8RABCVEX\chevron[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\8RABCVEX\cool[1].png Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\8RABCVEX\cowbell[1].png Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\8RABCVEX\c[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\8RABCVEX\D1C7F0FEF3435D7CC7683F4DF312B6[1].jpg Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\8RABCVEX\D3376108E1F2EF5AE731279BDEDE2[1].jpg Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\8RABCVEX\desktop.ini Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\8RABCVEX\equal_tongue[1].png Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\8RABCVEX\flashwrite_1_2[1].js Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\8RABCVEX\forward[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\8RABCVEX\frown[1].png Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\8RABCVEX\fs_tab_on[1].png Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\8RABCVEX\getaccountinfo[1].htm Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\8RABCVEX\google_transparent[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\8RABCVEX\im[1].png Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\8RABCVEX\logo1[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\8RABCVEX\mail[1].htm Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\8RABCVEX\mail[2] Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\8RABCVEX\mail[2].htm Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\8RABCVEX\mail[3].htm Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\8RABCVEX\mail[4].htm Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\8RABCVEX\mail[5] Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\8RABCVEX\mymsn[1].js Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\8RABCVEX\nose_sad[1].png Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\8RABCVEX\nose_tongue[1].png Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\8RABCVEX\offline_white1[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\8RABCVEX\rhapsody_messenger_tab[1].png Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\8RABCVEX\sbtnbk[2].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\8RABCVEX\shocked[1].png Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\8RABCVEX\smlnopresence[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\8RABCVEX\today[1].css Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\8RABCVEX\toolbar1[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\UZU7URSF\30[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\UZU7URSF\3CD3986AE5EBE0DC2EEA9F121C8F5[1].jpg Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\UZU7URSF\434469CEBF32D75DCD6C539A2A5B2B[1].jpg Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\UZU7URSF\B1909321[1].20;sz=300x250;ord=1375813786 Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\UZU7URSF\bottab-icon[1].png Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\UZU7URSF\busy_white1[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\UZU7URSF\card_br_new[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\UZU7URSF\card_button_d[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\UZU7URSF\card_button_hs[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\UZU7URSF\card_button_s[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\UZU7URSF\card_tl_new[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\UZU7URSF\corner_bl[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\UZU7URSF\corner_tl[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\UZU7URSF\corner_tr[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\UZU7URSF\desktop.ini Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\UZU7URSF\ebay_messenger_logo_32x36_PNG[1].png Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\UZU7URSF\envclosed[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\UZU7URSF\equal_slant[1].png Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\UZU7URSF\equal_smile[1].png Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\UZU7URSF\logo[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\UZU7URSF\mail[1] Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\UZU7URSF\mail[1].htm Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\UZU7URSF\mail[2] Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\UZU7URSF\mail[2].htm Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\UZU7URSF\mail[3] Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\UZU7URSF\mail[5] Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\UZU7URSF\mail[6] Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\UZU7URSF\monkey[1].png Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\UZU7URSF\nose_big_wink[1].png Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\UZU7URSF\nose_wink[1].png Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\UZU7URSF\offline_ltblue1[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\UZU7URSF\sound[1].swf Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\UZU7URSF\star_on_sm_2[1].gif Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\UZU7URSF\Tabicon[1].png Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\UZU7URSF\tab_icon[1].png Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\UZU7URSF\urchin_beta[2].js Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\UZU7URSF\wince[1].png Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\Content.IE5\UZU7URSF\wink[1].png Object is locked skipped
C:\Documents and Settings\B\Local Settings\Temporary Internet Files\desktop.ini Object is locked skipped
C:\Documents and Settings\B\My Documents\Default.rdp Object is locked skipped
C:\Documents and Settings\B\My Documents\desktop.ini Object is locked skipped
C:\Documents and Settings\B\My Documents\My Music\Desktop.ini Object is locked skipped
C:\Documents and Settings\B\My Documents\My Music\Sample Music.lnk Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 001.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 002.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 003.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 004.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 005.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 006.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 007.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 008.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 009.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 010.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 011.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 012.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 013.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 014.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 015.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 016.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 017.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 018.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 019.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 020.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 021.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 022.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 023.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 024.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 025.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 026.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 027.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 028.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 029.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 030.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 031.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 032.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 033.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 034.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 035.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 036.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 037.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 038.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 039.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 040.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 041.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 042.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 043.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 044.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 045.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 046.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 047.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 048.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Bryan phone 7_07 049.jpg Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Bryan phone 7_07\Thumbs.db Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Desktop.ini Object is locked skipped
C:\Documents and Settings\B\My Documents\My Pictures\Sample Pictures.lnk Object is locked skipped
C:\Documents and Settings\B\My Documents\My Videos\Desktop.ini Object is locked skipped
C:\Documents and Settings\B\NetHood\c on Mom (001ww187)\Desktop.ini Object is locked skipped
C:\Documents and Settings\B\NetHood\c on Mom (001ww187)\target.lnk Object is locked skipped
C:\Documents and Settings\B\NetHood\SharedDocs on Mom (001ww187)\Desktop.ini Object is locked skipped
C:\Documents and Settings\B\NetHood\SharedDocs on Mom (001ww187)\target.lnk Object is locked skipped
C:\Documents and Settings\B\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\B\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\B\ntuser.ini Object is locked skipped
C:\Documents and Settings\B\Recent\100OLYMP.lnk Object is locked skipped
C:\Documents and Settings\B\Recent\attachments.zip.lnk Object is locked skipped
C:\Documents and Settings\B\Recent\Bryan phone 7_07 025.jpg.lnk Object is locked skipped
C:\Documents and Settings\B\Recent\Bryan phone 7_07 026.jpg.lnk Object is locked skipped
C:\Documents and Settings\B\Recent\Bryan phone 7_07 035.jpg.lnk Object is locked skipped
C:\Documents and Settings\B\Recent\Bryan phone 7_07 042.jpg.lnk Object is locked skipped
C:\Documents and Settings\B\Recent\Bryan phone 7_07.lnk Object is locked skipped
C:\Documents and Settings\B\Recent\Bryan Shollenberger Offer Letter.doc.lnk Object is locked skipped
C:\Documents and Settings\B\Recent\Caci.lnk Object is locked skipped
C:\Documents and Settings\B\Recent\CoverLetter-Bryan-wwps.doc.lnk Object is locked skipped
C:\Documents and Settings\B\Recent\CoverLetter-Bryan.doc.lnk Object is locked skipped
C:\Documents and Settings\B\Recent\Direct Deposit.doc.lnk Object is locked skipped
C:\Documents and Settings\B\Recent\EmploymAppli2_06-2004.pdf.lnk Object is locked skipped
C:\Documents and Settings\B\Recent\fw4.pdf.lnk Object is locked skipped
C:\Documents and Settings\B\Recent\i-9.pdf.lnk Object is locked skipped
C:\Documents and Settings\B\Recent\P1010047.JPG.lnk Object is locked skipped
C:\Documents and Settings\B\Recent\P1010048.JPG.lnk Object is locked skipped
C:\Documents and Settings\B\Recent\P1010075.JPG.lnk Object is locked skipped
C:\Documents and Settings\B\Recent\P1010132.JPG.lnk Object is locked skipped
C:\Documents and Settings\B\Recent\P1010161.JPG.lnk Object is locked skipped
C:\Documents and Settings\B\Recent\P1010165.JPG.lnk Object is locked skipped
C:\Documents and Settings\B\Recent\P1010166.JPG.lnk Object is locked skipped
C:\Documents and Settings\B\Recent\P1010167.JPG.lnk Object is locked skipped
C:\Documents and Settings\B\Recent\P1010168.JPG.lnk Object is locked skipped
C:\Documents and Settings\B\Recent\P1010169.JPG.lnk Object is locked skipped
C:\Documents and Settings\B\Recent\Pat's Documents.lnk Object is locked skipped
C:\Documents and Settings\B\Recent\pic.lnk Object is locked skipped
C:\Documents and Settings\B\Recent\Resume-Bryan Shollenberger.doc.lnk Object is locked skipped
C:\Documents and Settings\B\SendTo\Compressed (zipped) Folder.ZFSendToTarget Object is locked skipped
C:\Documents and Settings\B\SendTo\Desktop (create shortcut).DeskLink Object is locked skipped
C:\Documents and Settings\B\SendTo\desktop.ini Object is locked skipped
C:\Documents and Settings\B\SendTo\Mail Recipient.MAPIMail Object is locked skipped
C:\Documents and Settings\B\SendTo\My Documents.mydocs Object is locked skipped
C:\Documents and Settings\B\Start Menu\desktop.ini Object is locked skipped
C:\Documents and Settings\B\Start Menu\Programs\Accessories\Accessibility\desktop.ini Object is locked skipped
C:\Documents and Settings\B\Start Menu\Programs\Accessories\Accessibility\Magnifier.lnk Object is locked skipped
C:\Documents and Settings\B\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk Object is locked skipped
C:\Documents and Settings\B\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk Object is locked skipped
C:\Documents and Settings\B\Start Menu\Programs\Accessories\Accessibility\Utility Manager.lnk Object is locked skipped
C:\Documents and Settings\B\Start Menu\Programs\Accessories\Address Book.lnk Object is locked skipped
C:\Documents and Settings\B\Start Menu\Programs\Accessories\Command Prompt.lnk Object is locked skipped
C:\Documents and Settings\B\Start Menu\Programs\Accessories\desktop.ini Object is locked skipped
C:\Documents and Settings\B\Start Menu\Programs\Accessories\Entertainment\desktop.ini Object is locked skipped
C:\Documents and Settings\B\Start Menu\Programs\Accessories\Entertainment\Windows Media Player.lnk Object is locked skipped
C:\Documents and Settings\B\Start Menu\Programs\Accessories\Notepad.lnk Object is locked skipped
C:\Documents and Settings\B\Start Menu\Programs\Accessories\Program Compatibility Wizard.lnk Object is locked skipped
C:\Documents and Settings\B\Start Menu\Programs\Accessories\Synchronize.lnk Object is locked skipped
C:\Documents and Settings\B\Start Menu\Programs\Accessories\Tour Windows XP.lnk Object is locked skipped
C:\Documents and Settings\B\Start Menu\Programs\Accessories\Windows Explorer.lnk Object is locked skipped
C:\Documents and Settings\B\Start Menu\Programs\Ares\Ares.lnk Object is locked skipped
C:\Documents and Settings\B\Start Menu\Programs\Ares\Uninstall.lnk Object is locked skipped
C:\Documents and Settings\B\Start Menu\Programs\desktop.ini Object is locked skipped
C:\Documents and Settings\B\Start Menu\Programs\Internet Explorer.lnk Object is locked skipped
C:\Documents and Settings\B\Start Menu\Programs\Outlook Express.lnk Object is locked skipped
C:\Documents and Settings\B\Start Menu\Programs\Remote Assistance.lnk Object is locked skipped
C:\Documents and Settings\B\Start Menu\Programs\Startup\desktop.ini Object is locked skipped
C:\Documents and Settings\B\Start Menu\Programs\Windows Media Player.lnk Object is locked skipped
C:\Documents and Settings\B\Templates\amipro.sam Object is locked skipped
C:\Documents and Settings\B\Templates\excel.xls Object is locked skipped
C:\Documents and Settings\B\Templates\excel4.xls Object is locked skipped
C:\Documents and Settings\B\Templates\lotus.wk4 Object is locked skipped
C:\Documents and Settings\B\Templates\powerpnt.ppt Object is locked skipped
C:\Documents and Settings\B\Templates\presenta.shw Object is locked skipped
C:\Documents and Settings\B\Templates\quattro.wb2 Object is locked skipped
C:\Documents and Settings\B\Templates\sndrec.wav Object is locked skipped
C:\Documents and Settings\B\Templates\winword.doc Object is locked skipped
C:\Documents and Settings\B\Templates\winword2.doc Object is locked skipped
C:\Documents and Settings\B\Templates\wordpfct.wpd Object is locked skipped
C:\Documents and Settings\B\Templates\wordpfct.wpg Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\MH PRO\Application Data\BitTorrent\bittorrent.log Object is locked skipped
C:\Documents and Settings\MH PRO\Application Data\Mozilla\Firefox\Profiles\c18e7nmq.default\cert8.db Object is locked skipped
C:\Documents and Settings\MH PRO\Application Data\Mozilla\Firefox\Profiles\c18e7nmq.default\flashgot.log Object is locked skipped
C:\Documents and Settings\MH PRO\Application Data\Mozilla\Firefox\Profiles\c18e7nmq.default\formhistory.dat Object is locked skipped
C:\Documents and Settings\MH PRO\Application Data\Mozilla\Firefox\Profiles\c18e7nmq.default\history.dat Object is locked skipped
C:\Documents and Settings\MH PRO\Application Data\Mozilla\Firefox\Profiles\c18e7nmq.default\key3.db Object is locked skipped
C:\Documents and Settings\MH PRO\Application Data\Mozilla\Firefox\Profiles\c18e7nmq.default\parent.lock Object is locked skipped
C:\Documents and Settings\MH PRO\Application Data\Mozilla\Firefox\Profiles\c18e7nmq.default\search.sqlite Object is locked skipped
C:\Documents and Settings\MH PRO\Application Data\Mozilla\Firefox\Profiles\c18e7nmq.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\MH PRO\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\MH PRO\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\MH PRO\Desktop\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\MH PRO\Desktop\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\MH PRO\Desktop\SmitfraudFix.exe RarSFX: infected - 2 skipped
C:\Documents and Settings\MH PRO\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\MH PRO\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\MH PRO\Local Settings\Application Data\Mozilla\Firefox\Profiles\c18e7nmq.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\MH PRO\Local Settings\Application Data\Mozilla\Firefox\Profiles\c18e7nmq.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\MH PRO\Local Settings\Application Data\Mozilla\Firefox\Profiles\c18e7nmq.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\MH PRO\Local Settings\Application Data\Mozilla\Firefox\Profiles\c18e7nmq.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\MH PRO\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\MH PRO\Local Settings\History\History.IE5\MSHist012007071420070715\index.dat Object is locked skipped
C:\Documents and Settings\MH PRO\Local Settings\Temp\~DF5CAD.tmp Object is locked skipped
C:\Documents and Settings\MH PRO\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\MH PRO\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\MH PRO\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Pat\Local Settings\Temp\systelmn32.exe Object is locked skipped
C:\Program Files\Sygate\SPF\debug.log Object is locked skipped
C:\Program Files\Sygate\SPF\rawlog.log Object is locked skipped
C:\Program Files\Sygate\SPF\seclog.log Object is locked skipped
C:\Program Files\Sygate\SPF\syslog.log Object is locked skipped
C:\Program Files\Sygate\SPF\tralog.log Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP42\A0004730.dll Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP42\A0004731.dll Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP42\A0004733.com Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP43\A0004738.com Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP43\A0004746.dll Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP43\A0004747.dll Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP43\A0004750.com Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP43\A0004758.dll Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP43\A0004759.dll Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP43\A0004763.com Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP43\A0004770.dll Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP43\A0004771.dll Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP43\A0004774.com Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP43\A0004779.dll Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP43\A0004780.dll Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP43\A0004783.com Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP44\A0004798.com Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP44\A0004808.dll Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP44\A0004809.dll Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP44\A0004811.com Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP44\A0004816.dll Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP44\A0004817.dll Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP44\A0004820.com Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP44\A0004907.dll Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP44\A0004908.dll Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP44\A0004909.com Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP45\A0004913.com Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP46\A0004916.com Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP46\A0005907.dll Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP46\A0005908.dll Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP46\A0005910.com Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP47\A0005913.com Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP47\A0005923.dll Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP47\A0005924.dll Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP47\A0005927.com Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP47\A0005937.dll Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP47\A0005938.dll Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP47\A0005941.com Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP47\A0005951.dll Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP47\A0005952.dll Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP47\A0005955.com Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP48\A0005967.dll Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP48\A0005968.dll Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP48\A0005971.com Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP49\A0005982.dll Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP49\A0005983.dll Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP49\A0005986.com Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP50\A0005995.com Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP51\A0006006.dll Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP51\A0006007.dll Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP51\A0006008.dll Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP51\A0006009.dll Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP51\A0006013.com Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP51\A0006027.dll Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP51\A0006028.dll Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP51\A0006029.dll Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP51\A0006030.dll Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP51\A0006033.com Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP51\A0006037.exe Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP52\A0006038.com Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP52\A0006046.dll Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP52\A0006047.dll Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP52\A0006048.dll Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP52\A0006049.dll Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP52\A0006052.com Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP52\A0006056.exe Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP55\A0006194.dll Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP55\A0006195.dll Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP55\A0006197.com Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP56\A0006213.com Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP57\A0006230.com Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP57\A0006289.dll Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP57\A0006290.dll Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP57\A0006292.com Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP57\A0006294.dll Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP57\A0006392.exe Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP57\A0006396.com Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP57\A0006397.dll Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP57\A0006398.dll Object is locked skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP58\A0006478.tlb Infected: Trojan-Downloader.Win32.Zlob.pv skipped
C:\System Volume Information\_restore{3C7F2AF4-0644-4AD8-BE16-C09B6A433267}\RP69\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.



Logfile of HijackThis v1.99.1
Scan saved at 2:55:12 AM, on 7/14/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\QCONSVC.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\WINDOWS\system32\ltmsg.exe
C:\WINDOWS\system32\tp4serv.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\BitTorrent\bittorrent.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\SPOOL\DRIVERS\W32X86\3\DLBKPSWX.EXE
C:\WINDOWS\system32\SPOOL\DRIVERS\W32X86\3\DLBKJSWX.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [LTWinModem1] ltmsg.exe 9
O4 - HKLM\..\Run: [TrackPointSrv] tp4serv.exe
O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll
O20 - Winlogon Notify: tpfnf2 - C:\WINDOWS\SYSTEM32\notifyf2.dll
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: QCONSVC - Lenovo - C:\WINDOWS\System32\QCONSVC.EXE
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
The computer is running a little quicker however Kaspersky said it found two viruses and now I am scanning with AVG FREE and it has found a Trojan horse downloader in the first five minutes of scanning. Am I officially screwed by this virus? I am more than willing to continue troubleshooting. Thanks for everything.
Hi straightjacked,

Kaspersky found an infected System Restore Point, as well as files associated with Smitfraudfix, none of which you need to worry about as they will all be deleted before we are through.

Please post the detection details (virus name and filename/path e.g. C:\windows\virus.exe) from AVG Free for me to check.
AVG Description of infected file: Trojan Horse Downloader.Generic5.DAW File Path of Infected File: C:\RECYCLER\S-1-5-21-1957994488-2146954627-1343024091-1007\Dc4.exe AVG said that it automatically deleted the entry but it keeps coming back. Thanks again.
Hi straightjacked,

Ok that's the recycle bin so again it's not a problem, we'll take care of the leftovers now.

First please delete SDFix.exe, SmitFraudfix.exe, the SmitFraudfix folder and FixSF.reg from your Desktop.

Then delete this folder:
C:\SDFix

Next, please empty your Recycle Bin

Then, create a new, clean System Restore point which you can use in case of future system problems:
Press Start->All Programs->Accessories->System Tools->System Restore
Select Create a restore point, then Next, type a name like clean then press the Create button and once it's done press Close

Now remove old, infected System Restore points:
Next click Start->Run and type cleanmgr in the box and press OK
Ensure the boxes for Temporary Files and Temporary Internet Files are checked, you can choose to check other boxes if you wish but they are not required.
Select the More Options tab, under System Restore press Clean up… and say Yes to the prompt
Press OK and Yes to confirm

Re-hide hidden/system files and folders:
Click Start -> My Computer
Select the Tools menu, click Folder Options and select the View tab
Under the Hidden files and folders heading SELECT Do not show hidden files and folders
CHECK the Hide protected operating system files (recommended) option
Press OK

Once complete, please let me know if everything went OK, you can scan again with AVG or Kaspersky if you wish to double-check.
Hi, Do you still need help with your machine? If the instructions are unclear or something isn't working, please let me know before proceeding.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI