This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Cannot Enter Safe Mode; Hangs On Shut Down

31 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hi,

I have a Compaq Presario R3145 (thats an R3000 series), 80gb hard-drive partitioned with XP sp2 on the d: drive. 756mb RAM.

I have been trying to defrag the d: drive. XP's defrag (as well as other defrag programs) can not complete the defrag. I read that defrag can sometimes complete if XP is run in safe mode. However, I cannot enter safe mode. I don't know how long this has been the case, as I rarely use it. I can select F8 and choose safe mode on bootup, it then shows all the drivers loading on screen, but stops as it gets to multi(0)disk(0)partition(2)\WINDOWS\SYSTEM32\DRIVERS\BTHidmgr.sys

The computer also hangs on shut down, as the logoff screen changes to 'Windows is now shutting down'. It will stay on this screen for 10mins+ before shutting down and sometimes just doesn't shut down at all and stays on this screen for hours.

On top of this the laptop is used for pro audio, and used to be able to record 5 tracks simultaneously, and it couldn't do this recently - so it seems sick. i read that it could be viruses/malware that can stop me entering safe mode, so though i would see if a hijackthis log could help. can anyone help me please?


Logfile of HijackThis v1.99.1
Scan saved at 20:47:54, on 17/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\ZoneLabs\vsmon.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\System32\wltrysvc.exe
D:\WINDOWS\System32\bcmwltry.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\system32\acs.exe
D:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
D:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
D:\WINDOWS\System32\cisvc.exe
D:\WINDOWS\system32\HPZipm12.exe
D:\Program Files\CyberLink\Shared files\RichVideo.exe
D:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\AGRSMMSG.exe
D:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
D:\Program Files\Apoint2K\Apoint.exe
D:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
D:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe
D:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
D:\WINDOWS\CTHELPER.EXE
D:\Program Files\Apoint2K\Apntex.exe
D:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
D:\WINDOWS\system32\bcmntray.exe
D:\WINDOWS\system32\rundll32.exe
D:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
D:\Program Files\iTunes\iTunesHelper.exe
D:\Program Files\iPod\bin\iPodService.exe
D:\Program Files\Opera\Opera.exe
D:\WINDOWS\system32\cidaemon.exe
D:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.incredimail.com/english
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [eabconfg.cpl] D:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Apoint] D:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG7_CC] D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [EPSON Stylus Photo R240 Series] D:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAHE.EXE /P30 "EPSON Stylus Photo R240 Series" /O6 "USB001" /M "Stylus Photo R240"
O4 - HKLM\..\Run: [HydraVisionDesktopManager] D:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe
O4 - HKLM\..\Run: [ATIPTA] D:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] D:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [NapsterShell] D:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [ZoneAlarm Client] "D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "D:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] D:\WINDOWS\system32\bcmntray
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "D:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SRS Audio Sandbox] "D:\Program Files\SRS Labs\Audio Sandbox\SRSSSC.exe" /hideme
O8 - Extra context menu item: Download Link Using Mega Manager… - D:\Program Files\Megaupload\Mega Manager\mm_file.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: D:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - D:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {60EFC337-15C2-4369-B2A0-3429B071D8B8} (Hewlett-Packard Printer Diagnostics) - http://h50203.www5.hp.com/HPISWeb/Customer…SWebManager.CAB
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotion…anner371020.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1A9EA759-DFEE-480D-80B3-725CDBC06F74}: NameServer = 202.102.199.68
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: !SASWinLogon - D:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: ssqpp - D:\WINDOWS\
O20 - Winlogon Notify: WgaLogon - WgaLogon.dll (file missing)
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - D:\WINDOWS\system32\acs.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - D:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - D:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - D:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - D:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - D:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - D:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - D:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - D:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - D:\WINDOWS\System32\wltrysvc.exe
There are a couple of leftover entries in your log , which we will remove slightly later, but they are almost certainly not causing your problems

First of all, you are using an older version of HijackThis. Please do the following to download and install the latest version of HijackThis v2.0.2:

CLICK HERE to download the HijackThis Installer:
  • Save HJTInstall.exe to your desktop.
  • Double-click on HJTInstall.exe to run the program.
  • By default it will install to C:\Program Files\Trend Micro\HijackThis.
  • Accept the license agreement by clicking the "I Accept" button.
  • Click on the "Do a system scan and save a log file" button. It will scan and then ask you to save the log.
  • Click "Save log" to save the log file and then the log will open in Notepad.
  • Click on "Edit -> Select All" then click on "Edit -> Copy" to copy the entire contents of the log.
  • Come back here to this thread and paste the log in your next reply.
  • Do NOT have HijackThis fix anything yet! Most of what it finds will be harmless or even required.
You may delete the older version once you have successfully downloaded and installed the latest version of HijackThis v2.0.2.

Download Deckard's System Scanner (DSS) to your Desktop. Note: You must be logged onto an account with administrator privileges.
  • Close all applications and windows.
  • Double-click on dss.exe to run it, and follow the prompts.
  • When the scan is complete, two text files will open - main.txt <- this one will be maximized and extra.txt<-this one will be minimized
  • Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of main.txt and the extra.txt to your post. in your reply
hi

thanks for taking the time to reply. i installed hijackthis 2.02, here is my latest log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:58:18, on 31/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\wltrysvc.exe
D:\WINDOWS\System32\bcmwltry.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\system32\acs.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
D:\Program Files\Bonjour\mDNSResponder.exe
D:\WINDOWS\System32\cisvc.exe
D:\WINDOWS\system32\HPZipm12.exe
D:\Program Files\CyberLink\Shared files\RichVideo.exe
D:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\AGRSMMSG.exe
D:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
D:\Program Files\Apoint2K\Apoint.exe
D:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
D:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe
D:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
D:\WINDOWS\CTHELPER.EXE
D:\Program Files\Apoint2K\Apntex.exe
D:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
D:\WINDOWS\system32\bcmntray.exe
D:\Program Files\iTunes\iTunesHelper.exe
D:\Program Files\iPod\bin\iPodService.exe
D:\WINDOWS\system32\cidaemon.exe
D:\Program Files\Common Files\Teleca Shared\Generic.exe
D:\Program Files\Sony Ericsson\Mobile\Mobile Phone Monitor\epmworker.exe
D:\WINDOWS\system32\ZoneLabs\vsmon.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\wuauclt.exe
D:\Program Files\Opera\Opera.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.incredimail.com/english
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [eabconfg.cpl] D:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Apoint] D:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG7_CC] D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [EPSON Stylus Photo R240 Series] D:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAHE.EXE /P30 "EPSON Stylus Photo R240 Series" /O6 "USB001" /M "Stylus Photo R240"
O4 - HKLM\..\Run: [HydraVisionDesktopManager] D:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe
O4 - HKLM\..\Run: [ATIPTA] D:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] D:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [NapsterShell] D:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [ZoneAlarm Client] "D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "D:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] D:\WINDOWS\system32\bcmntray
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "D:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SRS Audio Sandbox] "D:\Program Files\SRS Labs\Audio Sandbox\SRSSSC.exe" /hideme
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] D:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Download Link Using Mega Manager… - D:\Program Files\Megaupload\Mega Manager\mm_file.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: D:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - D:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {60EFC337-15C2-4369-B2A0-3429B071D8B8} (Hewlett-Packard Printer Diagnostics) - http://h50203.www5.hp.com/HPISWeb/Customer…SWebManager.CAB
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotion…anner371020.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1A9EA759-DFEE-480D-80B3-725CDBC06F74}: NameServer = 202.102.199.68
O20 - Winlogon Notify: !SASWinLogon - D:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: ssqpp - D:\WINDOWS\
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - D:\WINDOWS\system32\acs.exe
O23 - Service: Ati HotKey Poller - Unknown owner - D:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - D:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - D:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - D:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - D:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - D:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - D:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - D:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - D:\WINDOWS\System32\wltrysvc.exe

–
End of file - 8682 bytes


here are my deckard results:

Deckard's System Scanner v20070729.57
Run by [removed] on 2007-07-31 at 22:00:37
Computer is in Normal Mode.
——————————————————————————–

– System Restore ————————————————————–

Successfully created a Deckard's System Scanner Restore Point.


– Last 5 Restore Point(s) –
14: 2007-07-31 21:01:04 UTC - RP352 - Deckard's System Scanner Restore Point
13: 2007-07-30 23:18:05 UTC - RP351 - System Checkpoint
12: 2007-07-29 22:32:06 UTC - RP350 - System Checkpoint
11: 2007-07-26 21:30:23 UTC - RP349 - System Checkpoint
10: 2007-07-25 18:09:30 UTC - RP348 - System Checkpoint


– First Restore Point –
1: 2007-07-11 09:43:27 UTC - RP339 - System Checkpoint


Backed up registry hives.

Performed disk cleanup.


– HijackThis (run as Collen.exe) ———————————————-

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:02:38, on 31/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\wltrysvc.exe
D:\WINDOWS\System32\bcmwltry.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\system32\acs.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
D:\Program Files\Bonjour\mDNSResponder.exe
D:\WINDOWS\System32\cisvc.exe
D:\WINDOWS\system32\HPZipm12.exe
D:\Program Files\CyberLink\Shared files\RichVideo.exe
D:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\AGRSMMSG.exe
D:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
D:\Program Files\Apoint2K\Apoint.exe
D:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
D:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe
D:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
D:\WINDOWS\CTHELPER.EXE
D:\Program Files\Apoint2K\Apntex.exe
D:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
D:\WINDOWS\system32\bcmntray.exe
D:\Program Files\iTunes\iTunesHelper.exe
D:\Program Files\iPod\bin\iPodService.exe
D:\WINDOWS\system32\cidaemon.exe
D:\Program Files\Common Files\Teleca Shared\Generic.exe
D:\Program Files\Sony Ericsson\Mobile\Mobile Phone Monitor\epmworker.exe
D:\WINDOWS\system32\ZoneLabs\vsmon.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Opera\Opera.exe
D:\Documents and Settings\Collen\Application Data\Opera\Opera\profile\cache4\temporary_download\dss.exe
D:\PROGRA~1\TRENDM~1\HIJACK~1\Collen.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.incredimail.com/english
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [eabconfg.cpl] D:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Apoint] D:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG7_CC] D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [EPSON Stylus Photo R240 Series] D:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAHE.EXE /P30 "EPSON Stylus Photo R240 Series" /O6 "USB001" /M "Stylus Photo R240"
O4 - HKLM\..\Run: [HydraVisionDesktopManager] D:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe
O4 - HKLM\..\Run: [ATIPTA] D:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] D:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [NapsterShell] D:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [ZoneAlarm Client] "D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "D:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] D:\WINDOWS\system32\bcmntray
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "D:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SRS Audio Sandbox] "D:\Program Files\SRS Labs\Audio Sandbox\SRSSSC.exe" /hideme
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] D:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Download Link Using Mega Manager… - D:\Program Files\Megaupload\Mega Manager\mm_file.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: D:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - D:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {60EFC337-15C2-4369-B2A0-3429B071D8B8} (Hewlett-Packard Printer Diagnostics) - http://h50203.www5.hp.com/HPISWeb/Customer…SWebManager.CAB
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotion…anner371020.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1A9EA759-DFEE-480D-80B3-725CDBC06F74}: NameServer = 202.102.199.68
O20 - Winlogon Notify: !SASWinLogon - D:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: ssqpp - D:\WINDOWS\
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - D:\WINDOWS\system32\acs.exe
O23 - Service: Ati HotKey Poller - Unknown owner - D:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - D:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - D:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - D:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - D:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - D:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - D:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - D:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - D:\WINDOWS\System32\wltrysvc.exe

–
End of file - 8740 bytes

– File Associations ———————————————————–

All associations okay.


– Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ———————

R0 BTHidMgr (Bluetooth HID Manager Service) - d:\windows\system32\drivers\bthidmgr.sys
You are running a P2P filesharing programme.
  • Many of these programmes come with unwanted components bundled with them.
  • If you wish to find out whether the one you're using does click here.

Please note: Even if you are using a "safe" P2P programme, it is only the programme that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.


My recommendation is you uninstall it.

Go to Start> Control Panel> Add or Remove Programs.

Remove the following programs, if they are present.
J2SE Runtime Environment 5.0 Update 10
J2SE Runtime Environment 5.0 Update 11
J2SE Runtime Environment 5.0 Update 9
They are outdated versions of Java & vulnerable to exploitation

Run HijackThis
Click on do a system scan only
Place a checkmark next to these lines(if still present)

J2SE Runtime Environment 5.0 Update 10
J2SE Runtime Environment 5.0 Update 11
J2SE Runtime Environment 5.0 Update 9

Then close all windows except HijackThis and click Fix Checked

Go here to run an online scannner from Kaspersky.
  • Click on "Kaspersky Online Scanner"
  • A new smaller window will pop up. Press on "Accept". After reading the contents.
  • Now Kaspersky will update the anti-virus database. Let it run.
  • Click on "Next">"Scan Settings", and make sure the database is set to "extended". And check both the scan options. Then click OK.
  • Then click on "My Computer", and the scan will start.
  • Once finished, save the log as "KAV.txt" to the desktop.
Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.

Post back with the Kaspersky log, a new HijackThis log & let me know of any remaining problems
hi Thanks for your help, I really appreciate it. I know I'm running filesharing P2P, I need to run Soulseek and uTorrent, which are both on the safe list. If there's any others present or running, please let me know so I can get rid of them. There are no others present in Add/Remove programs. I unistalled all three instances of J2SE. I ran hijackthis but there were no references to them anymore. Here's my Kaspersky and latest hijackthis logs: KASPERSKY ONLINE SCANNER REPORT Friday, August 03, 2007 7:05:13 AM Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.83.0 Kaspersky Anti-Virus database last update: 2/08/2007 Kaspersky Anti-Virus database records: 371310 Scan Settings Scan using the following antivirus database extended Scan Archives true Scan Mail Bases true Scan Target My Computer A:\ C:\ D:\ E:\ F:\ G:\ Scan Statistics Total number of scanned objects 187610 Number of viruses found 9 Number of infected objects 201 / 0 Number of suspicious objects 0 Duration of the scan process 06:07:17 Infected Object Name Virus Name Last Action C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\75b7ff72e954b2efe761be6c0ed985c6_ba4e625e-9b95-4368-b7be-33e42dc9d8a8 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped C:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{2E691DF1-09B8-4013-B63D-80257490E4BF}\Message Store\Attachments\ATT47.eml/[From "Kw" ][Date Tue, 19 Sep 2006 16:12:09 -0600]/WE_SHIP_WORLDWIDE_RX_GENERIC_MEDS.html Infected: Trojan.JS.Redirector.b skipped C:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{2E691DF1-09B8-4013-B63D-80257490E4BF}\Message Store\Attachments\ATT47.eml Mail: infected - 1 skipped C:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{2E691DF1-09B8-4013-B63D-80257490E4BF}\Message Store\Attachments\ATT49.eml/[From "Kw" ][Date Tue, 19 Sep 2006 16:12:09 -0600]/WE_SHIP_WORLDWIDE_RX_GENERIC_MEDS.html Infected: Trojan.JS.Redirector.b skipped C:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{2E691DF1-09B8-4013-B63D-80257490E4BF}\Message Store\Attachments\ATT49.eml Mail: infected - 1 skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{300650BC-C760-45E8-9FE4-E36B99FD4590}\RP8\A0005528.EXE Infected: not-a-virus:RiskTool.Win32.HideWindows skipped D:\!KillBox\Ultimate Cleaner\app.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.d skipped D:\!KillBox\Ultimate Cleaner\IeSafe.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.36042 skipped D:\!KillBox\Ultimate Cleaner\Uninstall.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.f skipped D:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped D:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped D:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3775184272b9ebdb8337f8a8509b7611_982a7054-df1e-4c59-995e-5d98be1a8576 Object is locked skipped D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9fd4610d37e43c7be8e11c56a82b5a5b_982a7054-df1e-4c59-995e-5d98be1a8576 Object is locked skipped D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ab4167498db5135aa9ac8131a96c89d8_982a7054-df1e-4c59-995e-5d98be1a8576 Object is locked skipped D:\Documents and Settings\Collen\Application Data\Opera\Opera\mail\indexer\indexer.dat Object is locked skipped D:\Documents and Settings\Collen\Application Data\Opera\Opera\mail\indexer\indexer_1024.dat Object is locked skipped D:\Documents and Settings\Collen\Application Data\Opera\Opera\mail\indexer\indexer_16384.dat Object is locked skipped D:\Documents and Settings\Collen\Application Data\Opera\Opera\mail\indexer\indexer_65536.dat Object is locked skipped D:\Documents and Settings\Collen\Application Data\Opera\Opera\mail\lexicon\lexicon.dat Object is locked skipped D:\Documents and Settings\Collen\Application Data\Opera\Opera\mail\mailbase.dat Object is locked skipped D:\Documents and Settings\Collen\Cookies\index.dat Object is locked skipped D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\Attachments\Benfica76_click-EXPLODING-ORGASMS.htm Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\Attachments\Bjminnich_10POUNDSIN10DAYSDIET.HTML Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\Attachments\BUY_HERBALVIAGRA.HTM Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\Attachments\BUY_LAST_LONGER.HTML Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\Attachments\BUY_PERMANENTENLARG.HTM Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\Attachments\BUY_PERMANENTGROWTH.HTML Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\Attachments\BUY_SPERMCOUNT.HTML Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\Attachments\BUY_YOURSPERMCOUNT.HTML Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\Attachments\Caliboosh-Lose-10poundsIn10days.htm Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\Attachments\Chilena512_click-PERMANENTENLARGER.htm Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\Attachments\Chin_Buy_PermanentEnlarger.HTML Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\Attachments\click-HERBALVIAGRA.htm Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\Attachments\Dhankins22_10POUNDSIN10DAYSDIET.HTML Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\Attachments\Frtrus.htm Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\Attachments\Fuzzy2087_click-EXPLODING-ORGASMS.htm Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\Attachments\Horrible9_BUY_PHARMACY.HTML Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\Attachments\Horriblymoody_BUY_PHARMACY.HTML Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\Attachments\Horrid2_BUY_PHARMACY.HTML Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\Attachments\Horridreview_10POUNDSIN10DAYSDIET.HTML Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\Attachments\Jcb159_10POUNDSIN10DAYSDIET.HTML Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\Attachments\Jcb159_click-PERMANENTENLARGER.htm Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\Attachments\Kim_Buy_PermanentEnlarger.HTML Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\Attachments\Leti47_click-PERMANENTENLARGER.htm Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\Attachments\Lezginka_click-PERMANENTENLARGER.htm Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\Attachments\Logan_Buy_PermanentEnlarger.HTML Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\Attachments\Louis_Buy_HERBALVIAGRA.HTML Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\Attachments\Makowskibr_10POUNDSIN10DAYSDIET.HTML Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\Attachments\Nosfe666_10POUNDSIN10DAYSDIET.HTML Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\Attachments\Nosfe666_click-PERMANENTENLARGER.htm Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\Attachments\Stratton_Buy_PermanentEnlarger.HTML Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\Attachments\Watzup_doc_stay_cool_click-PERMANENTENLARGER.htm Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\Attachments\Wtawil_click-NONSCRIPTMEDShtm.htm Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\Attachments\{1A344B30-E95A-44C7-AC1C-DAD1E42BB324}\BUY_SPERMCOUNT.HTML Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\Attachments\{23392F38-0F28-49C6-B52A-48D1C02190C3}\Dhankins22_10POUNDSIN10DAYSDIET.HTML Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\Attachments\{25FA3A0B-1243-459F-866F-3F4089A2C05D}\BUY_PERMANENTENLARG.HTM Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\Attachments\{3995888F-81D2-4EBB-90DA-16C7696662BC}\Horrid2_BUY_PHARMACY.HTML Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\Attachments\{839D6FF0-F66B-4283-B0D2-ECDDD2B8D2FA}\BUY_PERMANENTENLARG.HTM Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\Attachments\{8A71EFC4-2AB2-464D-9160-55D9218BEA70}\BUY_HERBALVIAGRA.HTM Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\Attachments\{8FD199B6-0CE1-45A3-9B98-13295855F1D1}\BUY_PERMANENTENLARG.HTM Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\Attachments\{98DA6A92-95B6-4A63-AE99-43742C9DDF8B}\Kim_Buy_PermanentEnlarger.HTML Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\Attachments\{B9EC6E28-38F9-4CB0-B60B-9F9521BB4645}\Kim_Buy_PermanentEnlarger.HTML Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\Attachments\{C823AE80-3340-4976-AF21-A27F870A8907}\Lezginka_click-PERMANENTENLARGER.htm Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\Attachments\{F8713576-735A-4731-9D6F-0033E309929E}\BUY_YOURSPERMCOUNT.HTML Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Incrediconvert\Inbox\20070716190551453697.eml/[From MAXLOADS1 ][Date Fri, 24 Nov 2006 06:46:04 -0800 (EST)]/Sunny8153_click-BIGGERLOADS.htm Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Incrediconvert\Inbox\20070716190551453697.eml Mail: infected - 1 skipped D:\Documents and Settings\Collen\Desktop\Incrediconvert\Inbox\20070716190607859108.eml/[From RX_Online ][Date Sat, 03 Feb 2007 01:55:17 +0900 (EST)]/Kecia1310_click-onlineRX.htm Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Incrediconvert\Inbox\20070716190607859108.eml Mail: infected - 1 skipped D:\Documents and Settings\Collen\Desktop\Incrediconvert\Inbox\20070716190614515143.eml/[From PharmaShop ][Date Wed, 14 Mar 2007 05:06:10 +0900]/BUY_online_RX.HTML Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Incrediconvert\Inbox\20070716190614515143.eml Mail: infected - 1 skipped D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\20070716190725953260.eml/[From MAXLOADS1 ][Date Fri, 24 Nov 2006 06:46:04 -0800 (EST)]/Sunny8153_click-BIGGERLOADS.htm Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\20070716190725953260.eml Mail: infected - 1 skipped D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\20070716190725953676.eml/[From MAXLOADS1 ][Date Fri, 24 Nov 2006 06:46:04 -0800 (EST)]/Sunny8153_click-BIGGERLOADS.htm Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\20070716190725953676.eml Mail: infected - 1 skipped D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\20070716190725953730.eml/[From MAXLOADS1 ][Date Fri, 24 Nov 2006 06:46:04 -0800 (EST)]/Sunny8153_click-BIGGERLOADS.htm Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\20070716190725953730.eml Mail: infected - 1 skipped D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\2007071619074315611.eml/[From RX_Online ][Date Sat, 03 Feb 2007 01:55:17 +0900 (EST)]/Kecia1310_click-onlineRX.htm Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\2007071619074315611.eml Mail: infected - 1 skipped D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\20070716190743203767.eml/[From RX_Online ][Date Sat, 03 Feb 2007 01:55:17 +0900 (EST)]/Kecia1310_click-onlineRX.htm Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\20070716190743203767.eml Mail: infected - 1 skipped D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\20070716190743250684.eml/[From RX_Online ][Date Sun, 04 Feb 2007 20:00:59 +0900 (EST)]/Bearyouth_click-onlineRX.htm Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\20070716190743250684.eml Mail: infected - 1 skipped D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\20070716190743328888.eml/[From RX_Online ][Date Sun, 04 Feb 2007 20:00:59 +0900 (EST)]/Bearyouth_click-onlineRX.htm Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\20070716190743328888.eml Mail: infected - 1 skipped D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\20070716190744734395.eml/[From RX_Online ][Date Fri, 16 Feb 2007 17:06:44 +0900 (EST)]/Osbornmelinda_click-onlineRX.htm Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\20070716190744734395.eml Mail: infected - 1 skipped D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\20070716190744859471.eml/[From RX_Online ][Date Fri, 16 Feb 2007 17:06:44 +0900 (EST)]/Osbornmelinda_click-onlineRX.htm Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\20070716190744859471.eml Mail: infected - 1 skipped D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\20070716190745140979.eml/[From MEDICATIONS DELIVERED][Date 19 Feb 2007 12:42:05 -0800]/Buy_Rx_Here.html Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\20070716190745140979.eml Mail: infected - 1 skipped D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\2007071619074562614.eml/[From MEDICATIONS DELIVERED][Date 19 Feb 2007 12:42:05 -0800]/Buy_Rx_Here.html Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\2007071619074562614.eml Mail: infected - 1 skipped D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\20070716190752250916.eml/[From PharmaShop ][Date Wed, 14 Mar 2007 05:06:10 +0900]/BUY_online_RX.HTML Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\20070716190752250916.eml Mail: infected - 1 skipped D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\20070716190752359545.eml/[From PharmaShop ][Date Wed, 14 Mar 2007 05:06:10 +0900]/BUY_online_RX.HTML Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\20070716190752359545.eml Mail: infected - 1 skipped D:\Documents and Settings\Collen\Desktop\Incrediconvert\Outbox\20070716191139750558.eml/[From [removed]][Date Thu, 23 Nov 2006 18:18:06 +0000 (GMT Standard Time)]/Re_/[From QualityRXSh:-[removed]][Date Wed, 22 Nov 2006 16:53:03 -0400 (PST)]/HOLIDAY_MED_PACKAGES_EQUAL_HUGE_SAVINGS_SEE_HERE.htm Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Incrediconvert\Outbox\20070716191139750558.eml/[From [removed]][Date Thu, 23 Nov 2006 18:18:06 +0000 (GMT Standard Time)]/Re_ Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Incrediconvert\Outbox\20070716191139750558.eml Mail: infected - 2 skipped D:\Documents and Settings\Collen\Desktop\Incrediconvert\Outbox\2007071619113981273.eml/[From [removed]][Date Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/0.eml/[From MAXLOADS1 ][Date Fri, 24 Nov 2006 06:46:04 -0800 (EST)]/Sunny8153_click-BIGGERLOADS.htm Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Incrediconvert\Outbox\2007071619113981273.eml/[From [removed]][Date Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/0.eml Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Incrediconvert\Outbox\2007071619113981273.eml Mail: infected - 2 skipped D:\Documents and Settings\Collen\Desktop\Incrediconvert\Outbox\20070716191143953798.eml/[From [removed]][Date Thu, 28 Dec 2006 21:25:13 +0000 (GMT Standard Time)]/0.eml/[From MEDS HERE][Date 26 Dec 2006 13:24:50 -0800]/BUY-MEDS-HERE.htm Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Incrediconvert\Outbox\20070716191143953798.eml/[From [removed]][Date Thu, 28 Dec 2006 21:25:13 +0000 (GMT Standard Time)]/0.eml Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Incrediconvert\Outbox\20070716191143953798.eml Mail: infected - 2 skipped D:\Documents and Settings\Collen\Desktop\Incrediconvert\Outbox\2007071619114431366.eml/[From [removed]][Date Fri, 5 Jan 2007 20:18:23 +0000 (GMT Standard Time)]/Delivery/[From "Medication-Refills" ][Date Fri, 05 Jan 2007 17:08:08 -0200]/GO_HERE_PHARMA_SHOP_RX_SALE.htm Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Incrediconvert\Outbox\2007071619114431366.eml/[From [removed]][Date Fri, 5 Jan 2007 20:18:23 +0000 (GMT Standard Time)]/Delivery Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Incrediconvert\Outbox\2007071619114431366.eml Mail: infected - 2 skipped D:\Documents and Settings\Collen\Desktop\Incrediconvert\Outbox\20070716191205375777.eml/[From [removed]][Date Mon, 19 Mar 2007 19:53:15 +0000 (GMT Standard Time)]/Re_0.eml/[From Online_RX ][Date Tue, 20 Mar 2007 04:47:35 +0900 (EST)]/C_eldert_click-Online_RX.htm Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Incrediconvert\Outbox\20070716191205375777.eml/[From [removed]][Date Mon, 19 Mar 2007 19:53:15 +0000 (GMT Standard Time)]/Re_0.eml Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Incrediconvert\Outbox\20070716191205375777.eml Mail: infected - 2 skipped D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From [removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From … /[F … /[From … /[From "Alice French" ][Date Tue, 11 Apr 2006 09:43:06 -0800]/html Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From [removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From … /[F … /[From 10lbs'lo .. … /[From [removed]][Date Mon, 10 Apr 2006 19:05:23 +0000]/text Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From [removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From … /[F … /[From 10lbs'lo … /[From [removed]][Date Mon, 10 Apr 2006 23:06:43 +0000]/text Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From [removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From … /[F … /[From 10lbs'lossin10-days ][Date Mon, 10 Apr 2006 15:42:11 -0800]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From [removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From … /[F … /[From Home_Loan_Source ][Date Mon, 10 Apr 2006 21:41:08 -0800]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From [removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From "MySpace Friend Reque … /[From ][Date Thu, 13 Apr 2006 22:52:27 -080 … /html Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From [removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From "MySpace Friend Reque … /[From ][Date Thu, 13 Apr 2006 22:52:27 -0800]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From [removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From "MySpace Friend Request" ][Date Fri, 14 Apr 2006 13:09:30 GMT]/text Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From [removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From … /[From "S … /[From "Kenton or Deborah" ][Date Thur, 6 Apr 2006 14:35:14 -0600]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From [removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From … /[From "S … … /[From me . … /[From [removed]][Date Wed, 05 Apr 2006 03:01:53 -0600]/text Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From [removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From … /[From "S … … /[From me … /[From eBay ][Date Wed, 5 Apr 2006 04:22:55 PDT]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From [removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From … /[From "S … … /[From men'z enlarger ][Date Tue, 04 Apr 2006 10:31:48 -0800]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From [removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From … /[From "S … … /[From " … /[From eBay ][Date Tue, 4 Apr 2006 08:00:13 PDT]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From [removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From … /[From "S … … /[From " … /[Fro … /[From [removed]][Date Sun, 02 Apr 2006 19:52:00 -0800]/text Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From [removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From … /[From "S … … /[From " … /[From TOURISTE ][Date Mon, 3 Apr 2006 07:35:14 +0100]/text Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From [removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From … /[From "S … … /[From " … /[From [removed]][Date Sat, 1 Apr 2006 19:42:39 +0000]/text Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From [removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From … /[From "S … … /[From "male'enla-rger" ][Date Sat, 01 Apr 2006 13:34:02 -0800]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From [removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From … /[From "S … /[From "safetydietin_tendays" ][Date Sun, 02 Apr 2006 01:58:40 -0800]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From [removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From … /[From "S- … /[From "enlarg … /[From [removed]][Date Fri, 31 Mar 2006 23:54:22 +0000]/text Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From [removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From … /[From "S- … /[From "enlarger-team" ][Date Fri, 31 Mar 2006 19:52:43 -0800]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From [removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From … /[From "S-OMA-VAL … … … /[From [removed]][Date Thu, 30 Mar 2006 22:39:31 +0000]/text Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From [removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From … /[From "S-OMA-VAL … … /[From [removed]][Date Mon, 27 Mar 2006 22:16:40 +0000]/text Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From [removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From … /[From "S-OMA-VAL … /[From "MENSGROWTH" ][Date Mon, 27 Mar 2006 14:14:40 -0800]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From [removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From … /[From "S-OMA-VAL-IUM" ][Date Mon, 20 Mar 2006 19:36:08 -0600]/html Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From [removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From … /[From "S-OMA-VAL-IUM" ][Date Tue, 21 Mar 2006 08:35:44 -0700]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From [removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From The Trainline ][Date Tue, 21 Mar 2006 00:33:03 +0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From [removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement andviag ][Date Sun, 19 Mar 2006 20:45:49 -0800 (EST)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From [removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From [removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From "Nicole Miller" ][Date Sun, 6 Aug 2006 15:23:14 +0200]/UNNAMED/[From Medications Warehouse ][Date Sat, 4 Feb 2006 17:41:51 -0000]/html Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From "Nicole Miller" ][Date Sun, 6 Aug 2006 15:23:14 +0200]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From Prospects.ac.uk][Date 3 Aug 2006 03:19:53 GMT]/UNNAMED/[From [removed]][Date Wed, 02 Aug 2006 13:46:49 -0800]/UNNAMED/UNNAMED/UNNAMED/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From Prospects.ac.uk][Date 3 Aug 2006 03:19:53 GMT]/UNNAMED/[From [removed]][Date Wed, 02 Aug 2006 13:46:49 -0800]/UNNAMED/UNNAMED/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From Prospects.ac.uk][Date 3 Aug 2006 03:19:53 GMT]/UNNAMED/[From [removed]][Date Wed, 02 Aug 2006 13:46:49 -0800]/UNNAMED/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From Prospects.ac.uk][Date 3 Aug 2006 03:19:53 GMT]/UNNAMED/[From [removed]][Date Wed, 02 Aug 2006 13:46:49 -0800]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From Prospects.ac.uk][Date 3 Aug 2006 03:19:53 GMT]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From "Nicole Miller" ][Date Sun, 6 Aug 2006 15:23:14 +0200]/UNNAMED/[From Medications Warehouse ][Date Sat, 4 Feb 2006 17:41:51 -0000]/html Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From "Nicole Miller" ][Date Sun, 6 Aug 2006 15:23:14 +0200]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From Prospects.ac.uk][Date 3 Aug 2006 03:19:53 GMT]/UNNAMED/[From [removed]][Date Wed, 02 Aug 2006 13:46:49 -0800]/UNNAMED/UNNAMED/UNNAMED/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From Prospects.ac.uk][Date 3 Aug 2006 03:19:53 GMT]/UNNAMED/[From [removed]][Date Wed, 02 Aug 2006 13:46:49 -0800]/UNNAMED/UNNAMED/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From Prospects.ac.uk][Date 3 Aug 2006 03:19:53 GMT]/UNNAMED/[From [removed]][Date Wed, 02 Aug 2006 13:46:49 -0800]/UNNAMED/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From Prospects.ac.uk][Date 3 Aug 2006 03:19:53 GMT]/UNNAMED/[From [removed]][Date Wed, 02 Aug 2006 13:46:49 -0800]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From Prospects.ac.uk][Date 3 Aug 2006 03:19:53 GMT]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message Store\JunkMail.imm Mail: infected - 44 skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Attachments\Bearyouth_click-onlineRX.htm Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Attachments\BUY_online_RX.HTML Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Attachments\Buy_Rx_Here063.html Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Attachments\Kecia1310_click-onlineRX.htm Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Attachments\Osbornmelinda_click-onlineRX.htm Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Attachments\Sexonthebeach0_click_PERMANENTGrowth.htm Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Attachments\Sunny8153_click-BIGGERLOADS.htm Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Attachments\{06A7E24E-20CC-49E8-BAFD-A0F022E0C375}\Sexonthebeach0_click_PERMANENTGrowth.htm Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Attachments\{65E167B3-EF4D-4BEE-BBC2-9ECE4F7B927D}\Clairey2k1023_click-PERMANENTENLARGER.htm Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:06 +0000 (GMT Standard Time)]/Re_/[From QualityRXSh:-[removed]][Date Wed, 22 Nov 2006 16:53:03 -0400 (PST)]/HOLIDAY_MED_PACKAGES_EQUAL_HUGE_SAVINGS_SEE_HERE.htm Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:06 +0000 (GMT Standard Time)]/Re_ Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18 +0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov 2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/0.eml/[From MAXLOADS1 ][Date Fri, 24 Nov 2006 06:46:04 -0800 (EST)]/Sunny8153_click-BIGGERLOADS.htm Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18 +0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov 2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/0.eml Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18 +0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov 2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date … /[From Re: Busi … /[From "Collen … /[From MEDS HERE][Date 26 Dec 2006 13:24:50 -0800]/BUY-MEDS-HERE.htm Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18 +0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov 2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date … /[From Re: Busi … /[From "Collen Ch … /[From [removed]][Date Thu, 28 Dec 2006 21:25:13 +0000 (GMT Standard Time)]/0.eml Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18 +0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov 2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date … /[F … … /[From "Medication-Refills" ][Date Fri, 05 Jan 2007 17:08:08 -0200]/GO_HERE_PHARMA_SHOP_RX_SALE.htm Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18 +0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov 2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date … /[F … /[From Re: Message from eBa … /[From [removed]][Date Fri, 5 Jan 2007 20:18:23 +0000 (GMT Standard Time)]/Delivery Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18 +0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov 2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date … /[F … /[From … … /[From Online_RX ][Date Tue, 20 Mar 2007 04:47:35 +0900 (EST)]/C_eldert_click-Online_RX.htm Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18 +0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov 2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date … /[F … /[From … /[From "Collen … /[From [removed]][Date Mon, 19 Mar 2007 19:53:15 +0000 (GMT Standard Time)]/Re_0.eml Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18 +0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov 2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date … /[F … /[From … /[From "Collen Chandler" ][Date Mon, 19 Mar 2007 12:47:36 +0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18 +0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov 2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date … /[F … /[From … /[From "Collen … /[From [removed]][Date Sun, 11 Mar 2007 23:07:11 +0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18 +0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov 2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date … /[F … /[From … /[From "Collen Chandler" ][Date Sun, 11 Mar 2007 17:57:43 +0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18 +0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov 2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date … /[F … /[From … /[From "Collen Chandler" ][Date Thu, 8 Mar 2007 18:08:45 +0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18 +0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov 2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date … /[F … /[From … /[From "Collen Chandler" ][Date Thu, 1 Mar 2007 13:51:37 +0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18 +0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov 2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date … /[F … /[From … /[From "Collen Chandler" ][Date Wed, 28 Feb 2007 23:45:28 +0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18 +0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov 2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date … /[F … /[From … /[From "Collen Chandler" ][Date Mon, 26 Feb 2007 20:36:53 +0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18 +0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov 2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date … /[F … /[From … /[From "Collen … /[From [removed]][Date Mon, 26 Feb 2007 20:24:14 +0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18 +0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov 2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date … /[F … /[From … /[From "Collen Chandler" ][Date Sun, 25 Feb 2007 22:25:20 +0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18 +0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov 2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date … /[F … /[From … /[From "Collen Chandler" ][Date Fri, 23 Feb 2007 22:01:07 +0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18 +0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov 2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date … /[F … /[From … /[From "Collen Chandler" ][Date Fri, 23 Feb 2007 21:59:30 +0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18 +0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov 2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date … /[F … /[From … /[From "Collen Chandler" ][Date Fri, 23 Feb 2007 21:08:02 +0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18 +0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov 2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date … /[F … /[From … /[From "Collen Chandler" ][Date Fri, 23 Feb 2007 18:28:40 +0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18 +0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov 2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date … /[F … /[From … /[From "Collen Chandler" ][Date Tue, 30 Jan 2007 21:55:38 +0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18 +0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov 2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date … /[F … /[From … /[From "Collen Chandler" ][Date Mon, 29 Jan 2007 10:52:21 +0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18 +0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov 2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date … /[F … /[From … /[From "Collen Chandler" ][Date Tue, 23 Jan 2007 21:54:28 +0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18 +0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov 2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date … /[F … /[From … /[From "Collen Chandler" ][Date Wed, 10 Jan 2007 22:05:42 +0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18 +0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov 2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date … /[F … /[From Re: Message from eBay … /[From [removed]][Date Sun, 7 Jan 2007 20:48:28 +0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18 +0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov 2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date … /[F … /[From Re: Message from eBay Member Regarding Item #140067725707][Date Fri, 5 Jan 2007 20:06:40 +0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18 +0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov 2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date … /[From Re: Busi … /[From "Collen Chandler" ][Date Sat, 30 Dec 2006 14:01:25 +0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18 +0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov 2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date … /[From Re: Busi … /[From "Collen Chandler" ][Date Fri, 15 Dec 2006 14:30:26 +0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18 +0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov 2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date … /[From Re: Busi … /[From "Collen Chandler" ][Date Fri, 15 Dec 2006 13:36:09 +0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18 +0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov 2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date … /[From Re: Business Enquiry for Work at Home Online from FreeIndex.co.uk][Date Thu, 7 Dec 2006 13:48:39 +0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18 +0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov 2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date … /[From Re: Business Enquiry for Work at Home Online from FreeIndex.co.uk][Date Thu, 7 Dec 2006 13:37:31 +0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18 +0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov 2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date Fri, 24 Nov 2006 14 … /[From "Collen Chandler" ][Date Thu, 7 Dec 2006 12:46:06 +0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18 +0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov 2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date Fri, 24 Nov 2006 14 … /[From "Collen Chandler" ][Date Tue, 28 Nov 2006 16:28:22 +0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18 +0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov 2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date Fri, 24 Nov 2006 14 … /[From "Collen Chandler" ][Date Fri, 24 Nov 2006 21:04:48 +0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18 +0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov 2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date Fri, 24 Nov 2006 14:50:11 +0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18 +0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov 2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18 +0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov 2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18 +0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message Store\Outbox.imm Mail: infected - 41 skipped D:\Documents and Settings\Collen\Local Settings\Application Data\Last.fm\Client\container.log Object is locked skipped D:\Documents and Settings\Collen\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped D:\Documents and Settings\Collen\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped D:\Documents and Settings\Collen\Local Settings\History\History.IE5\index.dat Object is locked skipped D:\Documents and Settings\Collen\Local Settings\Temp\~DF26DA.tmp Object is locked skipped D:\Documents and Settings\Collen\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped D:\Documents and Settings\Collen\ntuser.dat Object is locked skipped D:\Documents and Settings\Collen\ntuser.dat.LOG Object is locked skipped D:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped D:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped D:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped D:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped D:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped D:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped D:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped D:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped D:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped D:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped D:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped D:\Documents and Settings\Rachel\Local Settings\Temp\tinst26.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.d skipped D:\Documents and Settings\Rachel\Local Settings\Temporary Internet Files\Content.IE5\SH6RSL2V\ucleaner_FOYGq2JV9B[1].exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.d skipped D:\Program Files\Mozilla Firefox\plugins\NPMyGlSh.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.i skipped D:\Program Files\MyGlobalSearch\bar\1.bin\M9PLUGIN.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.l skipped D:\Program Files\MyGlobalSearch\bar\1.bin\NPMYGLSH.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.i skipped D:\Program Files\Smitfraud\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped D:\System Volume Information\catalog.wci\000002.ps1 Object is locked skipped D:\System Volume Information\catalog.wci\000002.ps2 Object is locked skipped D:\System Volume Information\catalog.wci\010014.ci Object is locked skipped D:\System Volume Information\catalog.wci\cicat.fid Object is locked skipped D:\System Volume Information\catalog.wci\cicat.hsh Object is locked skipped D:\System Volume Information\catalog.wci\CiCL0001.000 Object is locked skipped D:\System Volume Information\catalog.wci\CiP10000.000 Object is locked skipped D:\System Volume Information\catalog.wci\CiP20000.000 Object is locked skipped D:\System Volume Information\catalog.wci\CiPT0000.000 Object is locked skipped D:\System Volume Information\catalog.wci\CiSL0001.000 Object is locked skipped D:\System Volume Information\catalog.wci\CiSP0000.000 Object is locked skipped D:\System Volume Information\catalog.wci\CiST0000.000 Object is locked skipped D:\System Volume Information\catalog.wci\CiVP0000.000 Object is locked skipped D:\System Volume Information\catalog.wci\INDEX.000 Object is locked skipped D:\System Volume Information\catalog.wci\propstor.bk1 Object is locked skipped D:\System Volume Information\catalog.wci\propstor.bk2 Object is locked skipped D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped D:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped D:\WINDOWS\Internet Logs\COLRACH.ldb Object is locked skipped D:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped D:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped D:\WINDOWS\SchedLgU.Txt Object is locked skipped D:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped D:\WINDOWS\Sti_Trace.log Object is locked skipped D:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped D:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped D:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped D:\WINDOWS\system32\config\default Object is locked skipped D:\WINDOWS\system32\config\default.LOG Object is locked skipped D:\WINDOWS\system32\config\SAM Object is locked skipped D:\WINDOWS\system32\config\SAM.LOG Object is locked skipped D:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped D:\WINDOWS\system32\config\SECURITY Object is locked skipped D:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped D:\WINDOWS\system32\config\software Object is locked skipped D:\WINDOWS\system32\config\software.LOG Object is locked skipped D:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped D:\WINDOWS\system32\config\system Object is locked skipped D:\WINDOWS\system32\config\system.LOG Object is locked skipped D:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped D:\WINDOWS\system32\h323log.txt Object is locked skipped D:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped D:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped D:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped D:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped D:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped D:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped D:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped D:\WINDOWS\system32\yhmckhvn.exe Infected: not-a-virus:AdWare.Win32.Searchcolor.a skipped D:\WINDOWS\Temp\ZLT05e1a.TMP Object is locked skipped D:\WINDOWS\Temp\ZLT05e37.TMP Object is locked skipped D:\WINDOWS\wiadebug.log Object is locked skipped D:\WINDOWS\wiaservc.log Object is locked skipped D:\WINDOWS\WindowsUpdate.log Object is locked skipped F:\RECYCLER\S-1-5-21-484763869-152049171-854245398-1004\Dc41.jpg Object is locked skipped F:\RECYCLER\S-1-5-21-484763869-152049171-854245398-1004\Dc51\photies 001.jpg Object is locked skipped F:\RECYCLER\S-1-5-21-484763869-152049171-854245398-1004\Dc51\photies 002.jpg Object is locked skipped F:\RECYCLER\S-1-5-21-484763869-152049171-854245398-1004\Dc51\photies 003.jpg Object is locked skipped F:\RECYCLER\S-1-5-21-484763869-152049171-854245398-1004\Dc51\photies 004.jpg Object is locked skip
hi

Thanks for your help, I really appreciate it.

I know I'm running filesharing P2P, I need to run Soulseek and uTorrent, which are both on the safe list. If there's any others present or running, please let me know so I can get rid of them. There are no others present in Add/Remove programs.

I unistalled all three instances of J2SE. I ran hijackthis but there were no references to them anymore.

Here's my Kaspersky and latest hijackthis logs:

KASPERSKY ONLINE SCANNER REPORT
Friday, August 03, 2007 7:05:13 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 2/08/2007
Kaspersky Anti-Virus database records: 371310
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
A:\
C:\
D:\
E:\
F:\
G:\
Scan Statistics
Total number of scanned objects 187610
Number of viruses found 9
Number of infected objects 201 / 0
Number of suspicious objects 0
Duration of the scan process 06:07:17

Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\75b7ff72e954b2efe761be6c0ed985c6_ba4e625e-9b95-4368-b7be-33e42dc9d8a8
Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp
Object is locked skipped
C:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{2E691DF1-09B8-4013-B63D-80257490E4BF}\Message
Store\Attachments\ATT47.eml/[From "Kw" ][Date Tue, 19 Sep 2006 16:12:09 -0600]/WE_SHIP_WORLDWIDE_RX_GENERIC_MEDS.html
Infected: Trojan.JS.Redirector.b skipped
C:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{2E691DF1-09B8-4013-B63D-80257490E4BF}\Message
Store\Attachments\ATT47.eml Mail: infected - 1 skipped
C:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{2E691DF1-09B8-4013-B63D-80257490E4BF}\Message
Store\Attachments\ATT49.eml/[From "Kw" ][Date Tue, 19 Sep 2006 16:12:09 -0600]/WE_SHIP_WORLDWIDE_RX_GENERIC_MEDS.html
Infected: Trojan.JS.Redirector.b skipped
C:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{2E691DF1-09B8-4013-B63D-80257490E4BF}\Message
Store\Attachments\ATT49.eml Mail: infected - 1 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked
skipped
C:\System Volume Information\_restore{300650BC-C760-45E8-9FE4-E36B99FD4590}\RP8\A0005528.EXE
Infected: not-a-virus:RiskTool.Win32.HideWindows skipped
D:\!KillBox\Ultimate Cleaner\app.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.d
skipped
D:\!KillBox\Ultimate Cleaner\IeSafe.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.36042
skipped
D:\!KillBox\Ultimate Cleaner\Uninstall.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.f
skipped
D:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is
locked skipped
D:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log
Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck
Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3775184272b9ebdb8337f8a8509b7611_982a7054-df1e-4c59-995e-5d98be1a8576
Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9fd4610d37e43c7be8e11c56a82b5a5b_982a7054-df1e-4c59-995e-5d98be1a8576
Object is locked skipped
D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ab4167498db5135aa9ac8131a96c89d8_982a7054-df1e-4c59-995e-5d98be1a8576
Object is locked skipped
D:\Documents and Settings\Collen\Application Data\Opera\Opera\mail\indexer\indexer.dat
Object is locked skipped
D:\Documents and Settings\Collen\Application Data\Opera\Opera\mail\indexer\indexer_1024.dat
Object is locked skipped
D:\Documents and Settings\Collen\Application Data\Opera\Opera\mail\indexer\indexer_16384.dat
Object is locked skipped
D:\Documents and Settings\Collen\Application Data\Opera\Opera\mail\indexer\indexer_65536.dat
Object is locked skipped
D:\Documents and Settings\Collen\Application Data\Opera\Opera\mail\lexicon\lexicon.dat
Object is locked skipped
D:\Documents and Settings\Collen\Application Data\Opera\Opera\mail\mailbase.dat
Object is locked skipped
D:\Documents and Settings\Collen\Cookies\index.dat Object is locked skipped
D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\Attachments\Benfica76_click-EXPLODING-ORGASMS.htm Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\Attachments\Bjminnich_10POUNDSIN10DAYSDIET.HTML Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\Attachments\BUY_HERBALVIAGRA.HTM Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\Attachments\BUY_LAST_LONGER.HTML Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\Attachments\BUY_PERMANENTENLARG.HTM Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\Attachments\BUY_PERMANENTGROWTH.HTML Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\Attachments\BUY_SPERMCOUNT.HTML Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\Attachments\BUY_YOURSPERMCOUNT.HTML Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\Attachments\Caliboosh-Lose-10poundsIn10days.htm Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\Attachments\Chilena512_click-PERMANENTENLARGER.htm Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\Attachments\Chin_Buy_PermanentEnlarger.HTML Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\Attachments\click-HERBALVIAGRA.htm Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\Attachments\Dhankins22_10POUNDSIN10DAYSDIET.HTML Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\Attachments\Frtrus.htm Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\Attachments\Fuzzy2087_click-EXPLODING-ORGASMS.htm Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\Attachments\Horrible9_BUY_PHARMACY.HTML Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\Attachments\Horriblymoody_BUY_PHARMACY.HTML Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\Attachments\Horrid2_BUY_PHARMACY.HTML Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\Attachments\Horridreview_10POUNDSIN10DAYSDIET.HTML Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\Attachments\Jcb159_10POUNDSIN10DAYSDIET.HTML Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\Attachments\Jcb159_click-PERMANENTENLARGER.htm Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\Attachments\Kim_Buy_PermanentEnlarger.HTML Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\Attachments\Leti47_click-PERMANENTENLARGER.htm Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\Attachments\Lezginka_click-PERMANENTENLARGER.htm Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\Attachments\Logan_Buy_PermanentEnlarger.HTML Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\Attachments\Louis_Buy_HERBALVIAGRA.HTML Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\Attachments\Makowskibr_10POUNDSIN10DAYSDIET.HTML Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\Attachments\Nosfe666_10POUNDSIN10DAYSDIET.HTML Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\Attachments\Nosfe666_click-PERMANENTENLARGER.htm Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\Attachments\Stratton_Buy_PermanentEnlarger.HTML Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\Attachments\Watzup_doc_stay_cool_click-PERMANENTENLARGER.htm Infected:
Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\Attachments\Wtawil_click-NONSCRIPTMEDShtm.htm Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\Attachments\{1A344B30-E95A-44C7-AC1C-DAD1E42BB324}\BUY_SPERMCOUNT.HTML
Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\Attachments\{23392F38-0F28-49C6-B52A-48D1C02190C3}\Dhankins22_10POUNDSIN10DAYSDIET.HTML
Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\Attachments\{25FA3A0B-1243-459F-866F-3F4089A2C05D}\BUY_PERMANENTENLARG.HTM
Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\Attachments\{3995888F-81D2-4EBB-90DA-16C7696662BC}\Horrid2_BUY_PHARMACY.HTML
Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\Attachments\{839D6FF0-F66B-4283-B0D2-ECDDD2B8D2FA}\BUY_PERMANENTENLARG.HTM
Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\Attachments\{8A71EFC4-2AB2-464D-9160-55D9218BEA70}\BUY_HERBALVIAGRA.HTM
Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\Attachments\{8FD199B6-0CE1-45A3-9B98-13295855F1D1}\BUY_PERMANENTENLARG.HTM
Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\Attachments\{98DA6A92-95B6-4A63-AE99-43742C9DDF8B}\Kim_Buy_PermanentEnlarger.HTML
Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\Attachments\{B9EC6E28-38F9-4CB0-B60B-9F9521BB4645}\Kim_Buy_PermanentEnlarger.HTML
Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\Attachments\{C823AE80-3340-4976-AF21-A27F870A8907}\Lezginka_click-PERMANENTENLARGER.htm
Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Homemade MP3s\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\Attachments\{F8713576-735A-4731-9D6F-0033E309929E}\BUY_YOURSPERMCOUNT.HTML
Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Incrediconvert\Inbox\20070716190551453697.eml/[From
MAXLOADS1 ][Date Fri, 24 Nov 2006 06:46:04 -0800 (EST)]/Sunny8153_click-BIGGERLOADS.htm
Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Incrediconvert\Inbox\20070716190551453697.eml
Mail: infected - 1 skipped
D:\Documents and Settings\Collen\Desktop\Incrediconvert\Inbox\20070716190607859108.eml/[From
RX_Online ][Date Sat, 03 Feb 2007 01:55:17 +0900 (EST)]/Kecia1310_click-onlineRX.htm
Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Incrediconvert\Inbox\20070716190607859108.eml
Mail: infected - 1 skipped
D:\Documents and Settings\Collen\Desktop\Incrediconvert\Inbox\20070716190614515143.eml/[From
PharmaShop ][Date Wed, 14 Mar 2007 05:06:10 +0900]/BUY_online_RX.HTML Infected:
Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Incrediconvert\Inbox\20070716190614515143.eml
Mail: infected - 1 skipped
D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\20070716190725953260.eml/[From
MAXLOADS1 ][Date Fri, 24 Nov 2006 06:46:04 -0800 (EST)]/Sunny8153_click-BIGGERLOADS.htm
Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\20070716190725953260.eml
Mail: infected - 1 skipped
D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\20070716190725953676.eml/[From
MAXLOADS1 ][Date Fri, 24 Nov 2006 06:46:04 -0800 (EST)]/Sunny8153_click-BIGGERLOADS.htm
Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\20070716190725953676.eml
Mail: infected - 1 skipped
D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\20070716190725953730.eml/[From
MAXLOADS1 ][Date Fri, 24 Nov 2006 06:46:04 -0800 (EST)]/Sunny8153_click-BIGGERLOADS.htm
Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\20070716190725953730.eml
Mail: infected - 1 skipped
D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\2007071619074315611.eml/[From
RX_Online ][Date Sat, 03 Feb 2007 01:55:17 +0900 (EST)]/Kecia1310_click-onlineRX.htm
Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\2007071619074315611.eml
Mail: infected - 1 skipped
D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\20070716190743203767.eml/[From
RX_Online ][Date Sat, 03 Feb 2007 01:55:17 +0900 (EST)]/Kecia1310_click-onlineRX.htm
Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\20070716190743203767.eml
Mail: infected - 1 skipped
D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\20070716190743250684.eml/[From
RX_Online ][Date Sun, 04 Feb 2007 20:00:59 +0900 (EST)]/Bearyouth_click-onlineRX.htm
Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\20070716190743250684.eml
Mail: infected - 1 skipped
D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\20070716190743328888.eml/[From
RX_Online ][Date Sun, 04 Feb 2007 20:00:59 +0900 (EST)]/Bearyouth_click-onlineRX.htm
Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\20070716190743328888.eml
Mail: infected - 1 skipped
D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\20070716190744734395.eml/[From
RX_Online ][Date Fri, 16 Feb 2007 17:06:44 +0900 (EST)]/Osbornmelinda_click-onlineRX.htm
Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\20070716190744734395.eml
Mail: infected - 1 skipped
D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\20070716190744859471.eml/[From
RX_Online ][Date Fri, 16 Feb 2007 17:06:44 +0900 (EST)]/Osbornmelinda_click-onlineRX.htm
Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\20070716190744859471.eml
Mail: infected - 1 skipped
D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\20070716190745140979.eml/[From
MEDICATIONS DELIVERED][Date 19 Feb 2007 12:42:05 -0800]/Buy_Rx_Here.html
Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\20070716190745140979.eml
Mail: infected - 1 skipped
D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\2007071619074562614.eml/[From
MEDICATIONS DELIVERED][Date 19 Feb 2007 12:42:05 -0800]/Buy_Rx_Here.html
Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\2007071619074562614.eml
Mail: infected - 1 skipped
D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\20070716190752250916.eml/[From
PharmaShop ][Date Wed, 14 Mar 2007 05:06:10 +0900]/BUY_online_RX.HTML Infected:
Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\20070716190752250916.eml
Mail: infected - 1 skipped
D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\20070716190752359545.eml/[From
PharmaShop ][Date Wed, 14 Mar 2007 05:06:10 +0900]/BUY_online_RX.HTML Infected:
Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Incrediconvert\JunkMail\20070716190752359545.eml
Mail: infected - 1 skipped
D:\Documents and Settings\Collen\Desktop\Incrediconvert\Outbox\20070716191139750558.eml/[From
[removed]][Date Thu, 23 Nov 2006 18:18:06 +0000 (GMT Standard
Time)]/Re_/[From QualityRXSh:-[removed]][Date Wed, 22 Nov 2006 16:53:03
-0400 (PST)]/HOLIDAY_MED_PACKAGES_EQUAL_HUGE_SAVINGS_SEE_HERE.htm Infected:
Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Incrediconvert\Outbox\20070716191139750558.eml/[From
[removed]][Date Thu, 23 Nov 2006 18:18:06 +0000 (GMT Standard
Time)]/Re_ Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Incrediconvert\Outbox\20070716191139750558.eml
Mail: infected - 2 skipped
D:\Documents and Settings\Collen\Desktop\Incrediconvert\Outbox\2007071619113981273.eml/[From
[removed]][Date Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard
Time)]/0.eml/[From MAXLOADS1 ][Date Fri, 24 Nov 2006 06:46:04 -0800 (EST)]/Sunny8153_click-BIGGERLOADS.htm
Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Incrediconvert\Outbox\2007071619113981273.eml/[From
[removed]][Date Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard
Time)]/0.eml Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Incrediconvert\Outbox\2007071619113981273.eml
Mail: infected - 2 skipped
D:\Documents and Settings\Collen\Desktop\Incrediconvert\Outbox\20070716191143953798.eml/[From
[removed]][Date Thu, 28 Dec 2006 21:25:13 +0000 (GMT Standard
Time)]/0.eml/[From MEDS HERE][Date 26 Dec 2006 13:24:50 -0800]/BUY-MEDS-HERE.htm
Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Incrediconvert\Outbox\20070716191143953798.eml/[From
[removed]][Date Thu, 28 Dec 2006 21:25:13 +0000 (GMT Standard
Time)]/0.eml Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Incrediconvert\Outbox\20070716191143953798.eml
Mail: infected - 2 skipped
D:\Documents and Settings\Collen\Desktop\Incrediconvert\Outbox\2007071619114431366.eml/[From
[removed]][Date Fri, 5 Jan 2007 20:18:23 +0000 (GMT Standard Time)]/Delivery/[From
"Medication-Refills" ][Date Fri, 05 Jan 2007 17:08:08 -0200]/GO_HERE_PHARMA_SHOP_RX_SALE.htm
Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Incrediconvert\Outbox\2007071619114431366.eml/[From
[removed]][Date Fri, 5 Jan 2007 20:18:23 +0000 (GMT Standard Time)]/Delivery
Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Incrediconvert\Outbox\2007071619114431366.eml
Mail: infected - 2 skipped
D:\Documents and Settings\Collen\Desktop\Incrediconvert\Outbox\20070716191205375777.eml/[From
[removed]][Date Mon, 19 Mar 2007 19:53:15 +0000 (GMT Standard
Time)]/Re_0.eml/[From Online_RX ][Date Tue, 20 Mar 2007 04:47:35 +0900 (EST)]/C_eldert_click-Online_RX.htm
Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Incrediconvert\Outbox\20070716191205375777.eml/[From
[removed]][Date Mon, 19 Mar 2007 19:53:15 +0000 (GMT Standard
Time)]/Re_0.eml Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Incrediconvert\Outbox\20070716191205375777.eml
Mail: infected - 2 skipped
D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From
[removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET
N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement
andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From … /[F … /[From … /[From
"Alice French" ][Date Tue, 11 Apr 2006 09:43:06 -0800]/html Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From
[removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET
N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement
andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From … /[F … /[From 10lbs'lo
.. … /[From [removed]][Date Mon, 10 Apr 2006 19:05:23 +0000]/text
Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From
[removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET
N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement
andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From … /[F … /[From 10lbs'lo
… /[From [removed]][Date Mon, 10 Apr 2006 23:06:43 +0000]/text
Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From
[removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET
N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement
andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From … /[F … /[From 10lbs'lossin10-days
][Date Mon, 10 Apr 2006 15:42:11 -0800]/UNNAMED Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From
[removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET
N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement
andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From … /[F … /[From Home_Loan_Source
][Date Mon, 10 Apr 2006 21:41:08 -0800]/UNNAMED Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From
[removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET
N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement
andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From "MySpace Friend Reque …
/[From ][Date Thu, 13 Apr 2006 22:52:27 -080 … /html Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From
[removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET
N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement
andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From "MySpace Friend Reque …
/[From ][Date Thu, 13 Apr 2006 22:52:27 -0800]/UNNAMED Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From
[removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET
N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement
andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From "MySpace Friend Request"
][Date Fri, 14 Apr 2006 13:09:30 GMT]/text Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From
[removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET
N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement
andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From … /[From "S … /[From
"Kenton or Deborah" ][Date Thur, 6 Apr 2006 14:35:14 -0600]/UNNAMED Infected:
Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From
[removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET
N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement
andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From … /[From "S … … /[From
me . … /[From [removed]][Date Wed, 05 Apr 2006 03:01:53 -0600]/text
Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From
[removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET
N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement
andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From … /[From "S … … /[From
me … /[From eBay ][Date Wed, 5 Apr 2006 04:22:55 PDT]/UNNAMED Infected:
Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From
[removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET
N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement
andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From … /[From "S … … /[From
men'z enlarger ][Date Tue, 04 Apr 2006 10:31:48 -0800]/UNNAMED Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From
[removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET
N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement
andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From … /[From "S … … /[From
" … /[From eBay ][Date Tue, 4 Apr 2006 08:00:13 PDT]/UNNAMED Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From
[removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET
N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement
andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From … /[From "S … … /[From
" … /[Fro … /[From [removed]][Date Sun, 02 Apr 2006 19:52:00 -0800]/text
Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From
[removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET
N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement
andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From … /[From "S … … /[From
" … /[From TOURISTE ][Date Mon, 3 Apr 2006 07:35:14 +0100]/text Infected:
Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From
[removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET
N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement
andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From … /[From "S … … /[From
" … /[From [removed]][Date Sat, 1 Apr 2006 19:42:39 +0000]/text
Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From
[removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET
N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement
andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From … /[From "S … … /[From
"male'enla-rger" ][Date Sat, 01 Apr 2006 13:34:02 -0800]/UNNAMED Infected:
Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From
[removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET
N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement
andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From … /[From "S … /[From
"safetydietin_tendays" ][Date Sun, 02 Apr 2006 01:58:40 -0800]/UNNAMED Infected:
Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From
[removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET
N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement
andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From … /[From "S- … /[From
"enlarg … /[From [removed]][Date Fri, 31 Mar 2006 23:54:22 +0000]/text
Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From
[removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET
N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement
andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From … /[From "S- … /[From
"enlarger-team" ][Date Fri, 31 Mar 2006 19:52:43 -0800]/UNNAMED Infected:
Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From
[removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET
N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement
andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From … /[From "S-OMA-VAL …
… … /[From [removed]][Date Thu, 30 Mar 2006 22:39:31 +0000]/text
Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From
[removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET
N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement
andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From … /[From "S-OMA-VAL …
… /[From [removed]][Date Mon, 27 Mar 2006 22:16:40 +0000]/text
Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From
[removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET
N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement
andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From … /[From "S-OMA-VAL …
/[From "MENSGROWTH" ][Date Mon, 27 Mar 2006 14:14:40 -0800]/UNNAMED Infected:
Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From
[removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET
N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement
andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From … /[From "S-OMA-VAL-IUM"
][Date Mon, 20 Mar 2006 19:36:08 -0600]/html Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From
[removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET
N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement
andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From … /[From "S-OMA-VAL-IUM"
][Date Tue, 21 Mar 2006 08:35:44 -0700]/UNNAMED Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From
[removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET
N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement
andviag ][Date Sun, 19 Mar 2006 20:45:49 -08 … /[From The Trainline ][Date Tue,
21 Mar 2006 00:33:03 +0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From
[removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET
N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text/[From enlargement
andviag ][Date Sun, 19 Mar 2006 20:45:49 -0800 (EST)]/UNNAMED Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From
[removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED/[From "GARNET
N Nevada " ][Date Thu, 16 Mar 2006 19:37:34 -0600]/text Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From
[removed]][Date Thu, 16 Mar 2006 16:15:33 -0700]/UNNAMED Infected:
Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From
"Nicole Miller" ][Date Sun, 6 Aug 2006 15:23:14 +0200]/UNNAMED/[From Medications
Warehouse ][Date Sat, 4 Feb 2006 17:41:51 -0000]/html Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From
"Nicole Miller" ][Date Sun, 6 Aug 2006 15:23:14 +0200]/UNNAMED Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From
Prospects.ac.uk][Date 3 Aug 2006 03:19:53 GMT]/UNNAMED/[From [removed]][Date
Wed, 02 Aug 2006 13:46:49 -0800]/UNNAMED/UNNAMED/UNNAMED/UNNAMED Infected:
Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From
Prospects.ac.uk][Date 3 Aug 2006 03:19:53 GMT]/UNNAMED/[From [removed]][Date
Wed, 02 Aug 2006 13:46:49 -0800]/UNNAMED/UNNAMED/UNNAMED Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From
Prospects.ac.uk][Date 3 Aug 2006 03:19:53 GMT]/UNNAMED/[From [removed]][Date
Wed, 02 Aug 2006 13:46:49 -0800]/UNNAMED/UNNAMED Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From
Prospects.ac.uk][Date 3 Aug 2006 03:19:53 GMT]/UNNAMED/[From [removed]][Date
Wed, 02 Aug 2006 13:46:49 -0800]/UNNAMED Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From
Prospects.ac.uk][Date 3 Aug 2006 03:19:53 GMT]/UNNAMED Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From
"Nicole Miller" ][Date Sun, 6 Aug 2006 15:23:14 +0200]/UNNAMED/[From Medications
Warehouse ][Date Sat, 4 Feb 2006 17:41:51 -0000]/html Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From
"Nicole Miller" ][Date Sun, 6 Aug 2006 15:23:14 +0200]/UNNAMED Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From
Prospects.ac.uk][Date 3 Aug 2006 03:19:53 GMT]/UNNAMED/[From [removed]][Date
Wed, 02 Aug 2006 13:46:49 -0800]/UNNAMED/UNNAMED/UNNAMED/UNNAMED Infected:
Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From
Prospects.ac.uk][Date 3 Aug 2006 03:19:53 GMT]/UNNAMED/[From [removed]][Date
Wed, 02 Aug 2006 13:46:49 -0800]/UNNAMED/UNNAMED/UNNAMED Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From
Prospects.ac.uk][Date 3 Aug 2006 03:19:53 GMT]/UNNAMED/[From [removed]][Date
Wed, 02 Aug 2006 13:46:49 -0800]/UNNAMED/UNNAMED Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From
Prospects.ac.uk][Date 3 Aug 2006 03:19:53 GMT]/UNNAMED/[From [removed]][Date
Wed, 02 Aug 2006 13:46:49 -0800]/UNNAMED Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text/[From
Prospects.ac.uk][Date 3 Aug 2006 03:19:53 GMT]/UNNAMED Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\JunkMail.imm/[From "MySpace Events" ][Date Thu, 16 Mar 2006 19:36:49 GMT]/text
Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Desktop\Unused Desktop Shortcuts\{7F6C5280-55A4-45A2-8E17-A5F220295715}\Message
Store\JunkMail.imm Mail: infected - 44 skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Attachments\Bearyouth_click-onlineRX.htm Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Attachments\BUY_online_RX.HTML Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Attachments\Buy_Rx_Here063.html Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Attachments\Kecia1310_click-onlineRX.htm Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Attachments\Osbornmelinda_click-onlineRX.htm Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Attachments\Sexonthebeach0_click_PERMANENTGrowth.htm Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Attachments\Sunny8153_click-BIGGERLOADS.htm Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Attachments\{06A7E24E-20CC-49E8-BAFD-A0F022E0C375}\Sexonthebeach0_click_PERMANENTGrowth.htm
Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Attachments\{65E167B3-EF4D-4BEE-BBC2-9ECE4F7B927D}\Clairey2k1023_click-PERMANENTENLARGER.htm
Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:06
+0000 (GMT Standard Time)]/Re_/[From QualityRXSh:-[removed]][Date Wed,
22 Nov 2006 16:53:03 -0400 (PST)]/HOLIDAY_MED_PACKAGES_EQUAL_HUGE_SAVINGS_SEE_HERE.htm
Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:06
+0000 (GMT Standard Time)]/Re_ Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18
+0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov
2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/0.eml/[From
MAXLOADS1 ][Date Fri, 24 Nov 2006 06:46:04 -0800 (EST)]/Sunny8153_click-BIGGERLOADS.htm
Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18
+0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov
2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/0.eml Infected:
Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18
+0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov
2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
… /[From Re: Busi … /[From "Collen … /[From MEDS HERE][Date 26 Dec 2006 13:24:50
-0800]/BUY-MEDS-HERE.htm Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18
+0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov
2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
… /[From Re: Busi … /[From "Collen Ch … /[From [removed]][Date
Thu, 28 Dec 2006 21:25:13 +0000 (GMT Standard Time)]/0.eml Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18
+0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov
2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
… /[F … … /[From "Medication-Refills" ][Date Fri, 05 Jan 2007 17:08:08 -0200]/GO_HERE_PHARMA_SHOP_RX_SALE.htm
Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18
+0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov
2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
… /[F … /[From Re: Message from eBa … /[From [removed]][Date
Fri, 5 Jan 2007 20:18:23 +0000 (GMT Standard Time)]/Delivery Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18
+0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov
2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
… /[F … /[From … … /[From Online_RX ][Date Tue, 20 Mar 2007 04:47:35 +0900
(EST)]/C_eldert_click-Online_RX.htm Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18
+0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov
2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
… /[F … /[From … /[From "Collen … /[From [removed]][Date
Mon, 19 Mar 2007 19:53:15 +0000 (GMT Standard Time)]/Re_0.eml Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18
+0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov
2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
… /[F … /[From … /[From "Collen Chandler" ][Date Mon, 19 Mar 2007 12:47:36
+0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18
+0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov
2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
… /[F … /[From … /[From "Collen … /[From [removed]][Date
Sun, 11 Mar 2007 23:07:11 +0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18
+0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov
2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
… /[F … /[From … /[From "Collen Chandler" ][Date Sun, 11 Mar 2007 17:57:43
+0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18
+0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov
2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
… /[F … /[From … /[From "Collen Chandler" ][Date Thu, 8 Mar 2007 18:08:45
+0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18
+0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov
2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
… /[F … /[From … /[From "Collen Chandler" ][Date Thu, 1 Mar 2007 13:51:37
+0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18
+0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov
2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
… /[F … /[From … /[From "Collen Chandler" ][Date Wed, 28 Feb 2007 23:45:28
+0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18
+0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov
2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
… /[F … /[From … /[From "Collen Chandler" ][Date Mon, 26 Feb 2007 20:36:53
+0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18
+0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov
2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
… /[F … /[From … /[From "Collen … /[From [removed]][Date
Mon, 26 Feb 2007 20:24:14 +0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18
+0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov
2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
… /[F … /[From … /[From "Collen Chandler" ][Date Sun, 25 Feb 2007 22:25:20
+0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18
+0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov
2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
… /[F … /[From … /[From "Collen Chandler" ][Date Fri, 23 Feb 2007 22:01:07
+0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18
+0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov
2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
… /[F … /[From … /[From "Collen Chandler" ][Date Fri, 23 Feb 2007 21:59:30
+0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18
+0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov
2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
… /[F … /[From … /[From "Collen Chandler" ][Date Fri, 23 Feb 2007 21:08:02
+0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18
+0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov
2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
… /[F … /[From … /[From "Collen Chandler" ][Date Fri, 23 Feb 2007 18:28:40
+0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18
+0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov
2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
… /[F … /[From … /[From "Collen Chandler" ][Date Tue, 30 Jan 2007 21:55:38
+0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18
+0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov
2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
… /[F … /[From … /[From "Collen Chandler" ][Date Mon, 29 Jan 2007 10:52:21
+0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18
+0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov
2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
… /[F … /[From … /[From "Collen Chandler" ][Date Tue, 23 Jan 2007 21:54:28
+0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18
+0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov
2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
… /[F … /[From … /[From "Collen Chandler" ][Date Wed, 10 Jan 2007 22:05:42
+0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18
+0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov
2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
… /[F … /[From Re: Message from eBay … /[From [removed]][Date
Sun, 7 Jan 2007 20:48:28 +0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18
+0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov
2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
… /[F … /[From Re: Message from eBay Member Regarding Item #140067725707][Date
Fri, 5 Jan 2007 20:06:40 +0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18
+0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov
2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
… /[From Re: Busi … /[From "Collen Chandler" ][Date Sat, 30 Dec 2006 14:01:25
+0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18
+0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov
2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
… /[From Re: Busi … /[From "Collen Chandler" ][Date Fri, 15 Dec 2006 14:30:26
+0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18
+0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov
2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
… /[From Re: Busi … /[From "Collen Chandler" ][Date Fri, 15 Dec 2006 13:36:09
+0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18
+0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov
2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
… /[From Re: Business Enquiry for Work at Home Online from FreeIndex.co.uk][Date
Thu, 7 Dec 2006 13:48:39 +0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18
+0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov
2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
… /[From Re: Business Enquiry for Work at Home Online from FreeIndex.co.uk][Date
Thu, 7 Dec 2006 13:37:31 +0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18
+0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov
2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
Fri, 24 Nov 2006 14 … /[From "Collen Chandler" ][Date Thu, 7 Dec 2006 12:46:06
+0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18
+0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov
2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
Fri, 24 Nov 2006 14 … /[From "Collen Chandler" ][Date Tue, 28 Nov 2006 16:28:22
+0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18
+0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov
2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
Fri, 24 Nov 2006 14 … /[From "Collen Chandler" ][Date Fri, 24 Nov 2006 21:04:48
+0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18
+0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov
2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
Fri, 24 Nov 2006 14:50:11 +0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18
+0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov
2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED/[From [removed]][Date
Fri, 24 Nov 2006 14:50:09 +0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18
+0000 (GMT Standard Time)]/UNNAMED/[From "Collen Chandler" ][Date Thu, 23 Nov
2006 19:49:00 +0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b
skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Outbox.imm/[From [removed]][Date Thu, 23 Nov 2006 18:18:18
+0000 (GMT Standard Time)]/UNNAMED Infected: Trojan.JS.Redirector.b skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\IM\Identities\{8B48DB2D-EA0D-445A-8AEA-2461D67E28E3}\Message
Store\Outbox.imm Mail: infected - 41 skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\Last.fm\Client\container.log
Object is locked skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat
Object is locked skipped
D:\Documents and Settings\Collen\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG
Object is locked skipped
D:\Documents and Settings\Collen\Local Settings\History\History.IE5\index.dat
Object is locked skipped
D:\Documents and Settings\Collen\Local Settings\Temp\~DF26DA.tmp Object is
locked skipped
D:\Documents and Settings\Collen\Local Settings\Temporary Internet Files\Content.IE5\index.dat
Object is locked skipped
D:\Documents and Settings\Collen\ntuser.dat Object is locked skipped
D:\Documents and Settings\Collen\ntuser.dat.LOG Object is locked skipped
D:\Documents and Settings\LocalService\Cookies\index.dat Object is locked
skipped
D:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat
Object is locked skipped
D:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG
Object is locked skipped
D:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat
Object is locked skipped
D:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat
Object is locked skipped
D:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
D:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
D:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat
Object is locked skipped
D:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG
Object is locked skipped
D:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
D:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked
skipped
D:\Documents and Settings\Rachel\Local Settings\Temp\tinst26.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.d
skipped
D:\Documents and Settings\Rachel\Local Settings\Temporary Internet Files\Content.IE5\SH6RSL2V\ucleaner_FOYGq2JV9B[1].exe
Infected: not-a-virus:FraudTool.Win32.UltimateDefender.d skipped
D:\Program Files\Mozilla Firefox\plugins\NPMyGlSh.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.i
skipped
D:\Program Files\MyGlobalSearch\bar\1.bin\M9PLUGIN.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.l
skipped
D:\Program Files\MyGlobalSearch\bar\1.bin\NPMYGLSH.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.i
skipped
D:\Program Files\Smitfraud\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f
skipped
D:\System Volume Information\catalog.wci\000002.ps1 Object is locked skipped
D:\System Volume Information\catalog.wci\000002.ps2 Object is locked skipped
D:\System Volume Information\catalog.wci\010014.ci Object is locked skipped
D:\System Volume Information\catalog.wci\cicat.fid Object is locked skipped
D:\System Volume Information\catalog.wci\cicat.hsh Object is locked skipped
D:\System Volume Information\catalog.wci\CiCL0001.000 Object is locked skipped
D:\System Volume Information\catalog.wci\CiP10000.000 Object is locked skipped
D:\System Volume Information\catalog.wci\CiP20000.000 Object is locked skipped
D:\System Volume Information\catalog.wci\CiPT0000.000 Object is locked skipped
D:\System Volume Information\catalog.wci\CiSL0001.000 Object is locked skipped
D:\System Volume Information\catalog.wci\CiSP0000.000 Object is locked skipped
D:\System Volume Information\catalog.wci\CiST0000.000 Object is locked skipped
D:\System Volume Information\catalog.wci\CiVP0000.000 Object is locked skipped
D:\System Volume Information\catalog.wci\INDEX.000 Object is locked skipped
D:\System Volume Information\catalog.wci\propstor.bk1 Object is locked skipped
D:\System Volume Information\catalog.wci\propstor.bk2 Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked
skipped
D:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
D:\WINDOWS\Internet Logs\COLRACH.ldb Object is locked skipped
D:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped
D:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped
D:\WINDOWS\SchedLgU.Txt Object is locked skipped
D:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
D:\WINDOWS\Sti_Trace.log Object is locked skipped
D:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
D:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
D:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
D:\WINDOWS\system32\config\default Object is locked skipped
D:\WINDOWS\system32\config\default.LOG Object is locked skipped
D:\WINDOWS\system32\config\SAM Object is locked skipped
D:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
D:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
D:\WINDOWS\system32\config\SECURITY Object is locked skipped
D:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
D:\WINDOWS\system32\config\software Object is locked skipped
D:\WINDOWS\system32\config\software.LOG Object is locked skipped
D:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
D:\WINDOWS\system32\config\system Object is locked skipped
D:\WINDOWS\system32\config\system.LOG Object is locked skipped
D:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
D:\WINDOWS\system32\h323log.txt Object is locked skipped
D:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
D:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
D:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
D:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
D:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
D:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
D:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
D:\WINDOWS\system32\yhmckhvn.exe Infected: not-a-virus:AdWare.Win32.Searchcolor.a
skipped
D:\WINDOWS\Temp\ZLT05e1a.TMP Object is locked skipped
D:\WINDOWS\Temp\ZLT05e37.TMP Object is locked skipped
D:\WINDOWS\wiadebug.log Object is locked skipped
D:\WINDOWS\wiaservc.log Object is locked skipped
D:\WINDOWS\WindowsUpdate.log Object is locked skipped
F:\RECYCLER\S-1-5-21-484763869-152049171-854245398-1004\Dc41.jpg Object is
locked skipped
F:\RECYCLER\S-1-5-21-484763869-152049171-854245398-1004\Dc51\photies 001.jpg
Object is locked skipped
F:\RECYCLER\S-1-5-21-484763869-152049171-854245398-1004\Dc51\photies 002.jpg
Object is locked skipped
F:\RECYCLER\S-1-5-21-484763869-152049171-854245398-1004\Dc51\photies 003.jpg
Object is locked skipped
F:\RECYCLER\S-1-5-21-484763869-152049171-854245398-1004\Dc51\photies 004.jpg
Object is locked skipped
F:\RECYCLER\S-1-5-21-484763869-152049171-854245398-1004\Dc51\photies 005.jpg
Object is locked skipped
F:\RECYCLER\S-1-5-21-484763869-152049171-854245398-1004\Dc51\photies 006.jpg
Object is locked skipped
F:\RECYCLER\S-1-5-21-484763869-152049171-854245398-1004\Dc51\photies 007.jpg
Object is locked skipped
F:\RECYCLER\S-1-5-21-484763869-152049171-854245398-1004\Dc51\photies 008.jpg
Object is locked skipped
F:\RECYCLER\S-1-5-21-484763869-152049171-854245398-1004\Dc51\photies 009.jpg
Object is locked skipped
F:\RECYCLER\S-1-5-21-484763869-152049171-854245398-1004\Dc51\photies 010.jpg
Object is locked skipped
F:\RECYCLER\S-1-5-21-484763869-152049171-854245398-1004\Dc51\photies 011.jpg
Object is locked skipped
F:\RECYCLER\S-1-5-21-484763869-152049171-854245398-1004\Dc51\photies 012.jpg
Object is locked skipped
F:\RECYCLER\S-1-5-21-484763869-152049171-854245398-1004\Dc51\photies 013.jpg
Object is locked skipped
F:\RECYCLER\S-1-5-21-484763869-152049171-854245398-1004\Dc51\photies 014.jpg
Object is locked skipped
F:\RECYCLER\S-1-5-21-484763869-152049171-854245398-1004\Dc51\photies 015.jpg
Object is locked skipped
F:\RECYCLER\S-1-5-21-484763869-152049171-854245398-1004\Dc51\photies 016.jpg
Object is locked skipped
F:\RECYCLER\S-1-5-21-484763869-152049171-854245398-1004\Dc51\photies 017.jpg
Object is locked skipped
F:\RECYCLER\S-1-5-21-484763869-152049171-854245398-1004\Dc51\photies 018.jpg
Object is locked skipped
F:\RECYCLER\S-1-5-21-484763869-152049171-854245398-1004\Dc51\photies 019.jpg
Object is locked skipped
F:\RECYCLER\S-1-5-21-484763869-152049171-854245398-1004\Dc51\photies 020.jpg
Object is locked skipped
F:\RECYCLER\S-1-5-21-484763869-152049171-854245398-1004\Dc51\photies 021.jpg
Object is locked skipped
F:\RECYCLER\S-1-5-21-484763869-152049171-854245398-1004\Dc51\photies 022.jpg
Object is locked skipped
F:\RECYCLER\S-1-5-21-484763869-152049171-854245398-1004\Dc51\photies 024.jpg
Object is locked skipped
F:\RECYCLER\S-1-5-21-484763869-152049171-854245398-1004\Dc51\photies 025.jpg
Object is locked skipped
F:\RECYCLER\S-1-5-21-484763869-152049171-854245398-1004\Dc51\photies 026.jpg
Object is locked skipped
F:\RECYCLER\S-1-5-21-484763869-152049171-854245398-1004\Dc51\photies 027.jpg
Object is locked skipped
F:\RECYCLER\S-1-5-21-484763869-152049171-854245398-1004\Dc51\Thumbs.db Object
is locked skipped
F:\System Volume Information\MountPointManagerRemoteDatabase Object is locked
skipped
Scan process completed.




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:45:11, on 03/08/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\ZoneLabs\vsmon.exe
D:\WINDOWS\System32\wltrysvc.exe
D:\WINDOWS\System32\bcmwltry.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\system32\acs.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
D:\Program Files\Bonjour\mDNSResponder.exe
D:\WINDOWS\System32\cisvc.exe
D:\WINDOWS\system32\HPZipm12.exe
D:\Program Files\CyberLink\Shared files\RichVideo.exe
D:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\AGRSMMSG.exe
D:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
D:\Program Files\Apoint2K\Apoint.exe
D:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
D:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe
D:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
D:\Program Files\Apoint2K\Apntex.exe
D:\WINDOWS\CTHELPER.EXE
D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
D:\WINDOWS\system32\bcmntray.exe
D:\Program Files\iTunes\iTunesHelper.exe
D:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
D:\Program Files\iPod\bin\iPodService.exe
D:\Program Files\Opera\Opera.exe
D:\WINDOWS\system32\cidaemon.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.incredimail.com/english
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [eabconfg.cpl] D:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Apoint] D:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG7_CC] D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [EPSON Stylus Photo R240 Series] D:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAHE.EXE /P30 "EPSON Stylus Photo R240 Series" /O6 "USB001" /M "Stylus Photo R240"
O4 - HKLM\..\Run: [HydraVisionDesktopManager] D:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe
O4 - HKLM\..\Run: [ATIPTA] D:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] D:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [NapsterShell] D:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [ZoneAlarm Client] "D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "D:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] D:\WINDOWS\system32\bcmntray
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "D:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SRS Audio Sandbox] "D:\Program Files\SRS Labs\Audio Sandbox\SRSSSC.exe" /hideme
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] D:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Download Link Using Mega Manager… - D:\Program Files\Megaupload\Mega Manager\mm_file.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: D:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - D:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {60EFC337-15C2-4369-B2A0-3429B071D8B8} (Hewlett-Packard Printer Diagnostics) - http://h50203.www5.hp.com/HPISWeb/Customer…SWebManager.CAB
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotion…anner371020.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1A9EA759-DFEE-480D-80B3-725CDBC06F74}: NameServer = 202.102.199.68
O17 - HKLM\System\CCS\Services\Tcpip\..\{67F19675-7547-478C-BA87-544475DC6281}: NameServer = 149.254.201.126 149.254.192.126
O20 - Winlogon Notify: !SASWinLogon - D:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: ssqpp - D:\WINDOWS\
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - D:\WINDOWS\system32\acs.exe
O23 - Service: Ati HotKey Poller - Unknown owner - D:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - D:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - D:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - D:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - D:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - D:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - D:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - D:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - D:\WINDOWS\System32\wltrysvc.exe

–
End of file - 8662 bytes



Many thanks.
I suggest you go through and delete e-mail from unknown senders-quite a bit of it appears to be infected

Go to Start> Control Panel> Add or Remove Programs.

Remove the following program, if it is present.
My Global Search Bar
Delete this folder:

D:\Program Files\MyGlobalSearch\

And This file:
D:\WINDOWS\system32\yhmckhvn.exe

Run HijackThis
Click on do a system scan only
Place a checkmark next to these lines(if still present)

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O20 - Winlogon Notify: ssqpp - D:\WINDOWS\

Then close all windows except HijackThis and click Fix Checked

Then post a new HijackThis log and let me know if you are still experiencing problems
Hi

Thanks again for your help. Sorry it takes me so long to reply between posts as well, I am quite busy at the moment.

I have recently started getting lots of spam emails that turn up in my inbox (I use incredimail to collect from a hotmail acct). It is coming from 'Confirmations Dept', 'Beauty Dept', 'Asda Dept' etc and is supposedly confirmation of an offer I have received. I'm getting about 15-20 of these a day now. I'm considering just dumping my old hotmail address, because I can't stop receiving them. Is there any way of knowing if it is these that are the infected emails? I also keep a lot of old email, some with attachments, going back several years, and am willing to purge it if you deem it necessary, but would really wish to keep a lot of it for sentimental reasons - what do you advise I should do?

I couldnt delete MyGlobalSearch from Add/Remove Programs. It says the .dll is not present to run the module. I am pretty certain I have deleted this before, and this looks just like a dead link?

Delete this folder:

D:\Program Files\MyGlobalSearch\

And This file:
D:\WINDOWS\system32\yhmckhvn.exe

un HijackThis
Click on do a system scan only
Place a checkmark next to these lines(if still present)

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O20 - Winlogon Notify: ssqpp - D:\WINDOWS\

Then close all windows except HijackThis and click Fix Checked


Done.

I will post back with results, see if I can get into safe mode. Here is new hijackthis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:39:09, on 13/08/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\ZoneLabs\vsmon.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\System32\wltrysvc.exe
D:\WINDOWS\System32\bcmwltry.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\system32\acs.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
D:\Program Files\Bonjour\mDNSResponder.exe
D:\WINDOWS\System32\cisvc.exe
D:\Program Files\CyberLink\Shared files\RichVideo.exe
D:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\AGRSMMSG.exe
D:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
D:\Program Files\Apoint2K\Apoint.exe
D:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
D:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe
D:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
D:\WINDOWS\CTHELPER.EXE
D:\Program Files\Apoint2K\Apntex.exe
D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
D:\WINDOWS\system32\bcmntray.exe
D:\Program Files\iTunes\iTunesHelper.exe
D:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
D:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
D:\Program Files\iPod\bin\iPodService.exe
D:\WINDOWS\system32\cidaemon.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.incredimail.com/english
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [eabconfg.cpl] D:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Apoint] D:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG7_CC] D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [EPSON Stylus Photo R240 Series] D:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAHE.EXE /P30 "EPSON Stylus Photo R240 Series" /O6 "USB001" /M "Stylus Photo R240"
O4 - HKLM\..\Run: [HydraVisionDesktopManager] D:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe
O4 - HKLM\..\Run: [ATIPTA] D:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] D:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [NapsterShell] D:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [ZoneAlarm Client] "D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "D:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] D:\WINDOWS\system32\bcmntray
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "D:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SRS Audio Sandbox] "D:\Program Files\SRS Labs\Audio Sandbox\SRSSSC.exe" /hideme
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] D:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Download Link Using Mega Manager… - D:\Program Files\Megaupload\Mega Manager\mm_file.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: D:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - D:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {60EFC337-15C2-4369-B2A0-3429B071D8B8} (Hewlett-Packard Printer Diagnostics) - http://h50203.www5.hp.com/HPISWeb/Customer…SWebManager.CAB
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotion…anner371020.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1A9EA759-DFEE-480D-80B3-725CDBC06F74}: NameServer = 202.102.199.68
O17 - HKLM\System\CCS\Services\Tcpip\..\{67F19675-7547-478C-BA87-544475DC6281}: NameServer = 149.254.201.126 149.254.192.126
O20 - Winlogon Notify: !SASWinLogon - D:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - D:\WINDOWS\system32\acs.exe
O23 - Service: Ati HotKey Poller - Unknown owner - D:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - D:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - D:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - D:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - D:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - D:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - D:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - D:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - D:\WINDOWS\System32\wltrysvc.exe

–
End of file - 8447 bytes
It appears your problems are associated with your bluetooth drivers In order to solve the you would need to uninstall BlueSoleil from add/remove programs, however, that would prevent you from using any bluetooth devices until you reinstalled it
I don't think BlueSoleil is the problem - I have only installed it in the last couple of months when I got a bluetooth dongle, whereas the laptop has taken 10+mins to shut down for many months before this. Any other ideas? Many thanks.
I think some of your issues are being caused by the number of unnecessary programs you have running in the background, so we'll disable some of them

Run HijackThis
Click on do a system scan only
Place a checkmark next to these lines(if still present)

O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] D:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"

Then close all windows except HijackThis and click Fix Checked

Restart and then let me how much disabling them helped
hi

i disabled the programs you suggested with hijackthis. I also managed to get a bit further with defragging D: but it stops with about 30% fragmentation left and says the following files could not be defragmented: it then lists some files, but only about 20 files, which is not enough to fragment 30% of the drive.

I still can't log into safe mode either. again, hangs at bthidmgr.sys. shutdown time is 10 mins.

here is my latest hijackthis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:41:51, on 19/08/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\ZoneLabs\vsmon.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\System32\wltrysvc.exe
D:\WINDOWS\System32\bcmwltry.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\system32\acs.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
D:\Program Files\Bonjour\mDNSResponder.exe
D:\WINDOWS\System32\cisvc.exe
D:\WINDOWS\system32\HPZipm12.exe
D:\Program Files\CyberLink\Shared files\RichVideo.exe
D:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\AGRSMMSG.exe
D:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
D:\Program Files\Apoint2K\Apoint.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
D:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe
D:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
D:\Program Files\Apoint2K\Apntex.exe
D:\WINDOWS\system32\bcmntray.exe
D:\Program Files\iTunes\iTunesHelper.exe
D:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
D:\Program Files\IncrediMail\bin\IncMail.exe
D:\Program Files\iPod\bin\iPodService.exe
D:\PROGRA~1\INCRED~1\bin\IMApp.exe
D:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
D:\Program Files\Opera\Opera.exe
D:\WINDOWS\system32\cidaemon.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.incredimail.com/english
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [eabconfg.cpl] D:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Apoint] D:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [AVG7_CC] D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [EPSON Stylus Photo R240 Series] D:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAHE.EXE /P30 "EPSON Stylus Photo R240 Series" /O6 "USB001" /M "Stylus Photo R240"
O4 - HKLM\..\Run: [HydraVisionDesktopManager] D:\Program Files\ATI Technologies\ATI HYDRAVISION\HydraDM.exe
O4 - HKLM\..\Run: [ATIPTA] D:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [NapsterShell] D:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [ZoneAlarm Client] "D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "D:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] D:\WINDOWS\system32\bcmntray
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "D:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SRS Audio Sandbox] "D:\Program Files\SRS Labs\Audio Sandbox\SRSSSC.exe" /hideme
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] D:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Download Link Using Mega Manager… - D:\Program Files\Megaupload\Mega Manager\mm_file.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: D:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - D:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {60EFC337-15C2-4369-B2A0-3429B071D8B8} (Hewlett-Packard Printer Diagnostics) - http://h50203.www5.hp.com/HPISWeb/Customer…SWebManager.CAB
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotion…anner371020.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1A9EA759-DFEE-480D-80B3-725CDBC06F74}: NameServer = 202.102.199.68
O17 - HKLM\System\CCS\Services\Tcpip\..\{67F19675-7547-478C-BA87-544475DC6281}: NameServer = 149.254.201.126 149.254.192.126
O20 - Winlogon Notify: !SASWinLogon - D:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - D:\WINDOWS\system32\acs.exe
O23 - Service: Ati HotKey Poller - Unknown owner - D:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - D:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - D:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - D:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - D:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - D:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - D:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - D:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - D:\WINDOWS\System32\wltrysvc.exe

–
End of file - 8048 bytes

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI