This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved]Slow Computer With Malware

23 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.1
Scan saved at 10:29:54 PM, on 8/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AT&T\AT&T Internet Security Suite\Fws.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Netopia\C3kWepN.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\BellSouth Internet Tools\blsloader.exe
C:\Program Files\AT&T\Internet Security Wizard\ISW.exe
C:\Program Files\AT&T\AT&T Internet Security Suite\Rps.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Lexmark 1300 Series\lxdcamon.exe
C:\WINDOWS\StartupMonitor.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\DvzCommon\DvzMsgr.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\Program Files\AT&T\Internet Security Wizard\ISWComHandler.exe
C:\Program Files\AT&T\AT&T Internet Security Suite\rpsupdaterR.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.bellsouth.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: BlspcHlpr Class - {15C9938F-CB96-496D-800A-B827F2E34EA1} - C:\Program Files\BellSouth Internet Tools\blspc.dll
O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\AT&T\AT&T Internet Security Suite\pkR.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O3 - Toolbar: (no name) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - (no file)
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [C2kWep] C:\Program Files\Netopia\C3kWepN.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [blspcloader] "C:\Program Files\BellSouth Internet Tools\blsloader.exe"
O4 - HKLM\..\Run: [ISW.exe] "C:\Program Files\AT&T\Internet Security Wizard\ISW.exe" /AUTORUN
O4 - HKLM\..\Run: [AT&T Internet Security Suite] "C:\Program Files\AT&T\AT&T Internet Security Suite\Rps.exe"
O4 - HKLM\..\Run: [-FreedomNeedsReboot] "C:\Program Files\AT&T\AT&T Internet Security Suite\ZkRunOnceR.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [lxdcamon] "C:\Program Files\Lexmark 1300 Series\lxdcamon.exe"
O4 - HKLM\..\Run: [LXDCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXDCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Watch2007.exe
O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Dataviz Messenger.lnk = C:\WINDOWS\DvzCommon\DvzMsgr.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {4CCA4E80-9259-11D9-AC6E-444553544200} (FixController Control) - http://h30155.www3.hp.com/ediags/dd/instal…llMgr_v01_6.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase8300.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1182308439125
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - http://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab
O16 - DPF: {7E9522CF-6B95-46D6-8E2F-7638F507313F} (BLS_SpeedOP.systemcheck) - http://www.fastaccess.drivers.bellsouth.ne…bls_speedop.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://a.download.toontown.com/sv1.0.21.10/ttinst.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Automatic LiveUpdate Scheduler - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: AT&T Internet Security Suite Service (RPSUpdaterR) - AT&T - C:\Program Files\AT&T\AT&T Internet Security Suite\rpsupdaterR.exe
O23 - Service: AT&T Internet Security Suite AT&T Firewall (RP_FWS) - AT&T - C:\Program Files\AT&T\AT&T Internet Security Suite\Fws.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Windows Live OneCare (winss) - Unknown owner - C:\Program Files\Microsoft Windows OneCare Live\winss.exe (file missing)

——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Saturday, August 11, 2007 10:28:44 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.0
Kaspersky Anti-Virus database last update: 12/08/2007
Kaspersky Anti-Virus database records: 378855
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 95212
Number of viruses found: 28
Number of infected objects: 91
Number of suspicious objects: 6
Duration of the scan process: 01:42:16

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\AT&T\AT&T Internet Security Suite\Logs\AT&T Firewall - Blocked Packets - 08-11-2007–19-34-12.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AT&T\AT&T Internet Security Suite\Logs\FirewallService08-11-2007–19-33-33.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AT&T\AT&T Internet Security Suite\Logs\Fw_Session.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AT&T\AT&T Internet Security Suite\Logs\SafetyConsoleLog08-11-2007–19-34-03.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AT&T\AT&T Internet Security Suite\Logs\ServiceModel08-11-2007–19-34-03.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\de943f79f3f88dab0a562f728dcb1c_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys160500c117c7cf68a1da70967d408cb_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys357e20004f869e5b52c5be6d9b39070_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys538652e34138a0800c6e7000736a640_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys96d9f9096952961a80fe0beb58ffdbc_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys9828389d87ed86598494e343dc95f59_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeysbfb26ee59d9d6390e11d0b42f3f165a_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeysc165d944d8b54553e428d375187d584_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeyse032e98c7e80f7a81acb2b7a4493571_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeyse3729625052197086219ad01dcb689c_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeysea969132993e35f7a75188d2a43688a_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeysf5759edf91e2268ea5485ec392c9d87_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1153e3ae23f0c167db682aeb0a35947a_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\11ce4023440003365b1581ec3fced6b8_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1215c37f409617b923436c383815effc_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\12dd606924510a47f08234342de97b68_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\12fc00e448358bbaa34471f6fcbb3b34_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\14be711fa2e14c82656c3eefe0b78cca_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\150842a6e37f06bfb8d535bd4835d920_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1554d8baf000e2ba480ada89ca1d2c34_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1583858e9fc4281e4398290c793b0239_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\164f981a4aff8bee9f73d224d1d0e8ca_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\192d4c2e682efcb7c4c44d4fbbe76c3e_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1932a243782e28723505f1050cb22097_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1dabd012f09c4b7051fcfa91a243cf3e_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1f53e5481a4ee115e82ad0646e76b3e2_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\228afb142837d30c78eb66f8a243a16f_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2848d1ddde751b030edda1e9f3247294_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\29df6955a6c03274e03b39b5d2b0fc9b_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2a443893e1057f1d6f2fd1a3211aab05_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2b089b445e7879b6cbbeb10574f083ab_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2e1b821de6d2d6be0626616400241732_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\30e4735106bf6751e22c04dbb91ecbc6_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3318115862b30fd8d4c31776800acf19_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\35daaa8ee3042d5a32ece011fe909ae2_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\36c8926e25de93ac962aa03e695c8448_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\37723db14c51aa50ba91b5afbf59a096_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\37d1a9be11bbecf94acbc2cc5b1f7ed7_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\387f7768ce6c15938d8bade93b195555_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\396b8bd74c173ce77af8e4a3470e5329_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\39c123ca9e9c5c00c60be0b04ebb64b3_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3c39ccab3a0d2c2dc8b67a980f717e69_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3e563c28878675689425a68d4eb33cd5_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3e7d4f8d2fd569b20eb413154b96c978_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\415e415cc5b1f1d387d3e44ad3d3cf5c_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4202dd3ae57e2f90e5bb723b0f865851_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\438b3ed343f4983f8b8e208d39e28276_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\43bb1d85581eb699404bb93eb1850eee_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\46c14532bda639fb04680104955d21bb_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\46e3a1bbf6ad94622db3101a184c620a_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\48011fd087dd98e007d1864b07c070f8_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4822c4863c2c1d661ec6996303520285_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4949e98b70e8a7f447a9a1578c6c9690_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4aa0297861d43709e6e11e9f5c9d6689_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4b38cf941fa9997a44a603b545f3d9df_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4bc73824c4b506f302f74dca6d7ba9b1_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4bf92e8d08e9952b32fdb7f7bd62a812_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4d3b412aaa9f4c49bed81e7918ddfcb5_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4d811a265b1aa08e5966ec82fa067566_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4e08b66f5474f001b903eddbf7441978_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4f9282df08a17182278d217e3d3f7818_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\52067f67cf9b67d03380965e13492437_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\520ac7c6445267de2732d86df27137e6_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5265f9ff2fafe5d3ebcb7fb14374202f_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\53dca7ca4bf1ff6d2238ebfdb0369fe2_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\542b5909fd72d83f549911deb2178ecd_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5576ab39e09e83095751c93aa480e19b_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5638f76a39ed47314ae8221a2033edea_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\57fae10a2d3a880aae85003727a60f5f_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\584a6d9d77cf98f9505cd5139439903a_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\58f8ca93d6d0972f08aa81bba5601f50_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\590e930d099569b26a58c28558385c9c_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5d53a24cceccb9f6ec816c6f0288b93c_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5ea4408d92944e9e134c8ab065dfdf7f_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\602a5560684f1ee0274dff8798088ff5_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\604824c82525debb8e4b8e02b20d1350_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\622088e1e072ad4c504aa433e4c2df8c_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\62896265c6d9136b0566b1db6e43f9ca_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\646a04d709eb69461020741618d78707_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\67481d1743967fc64c8596a091f071c0_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\681caa5f6b1cf291170541826fb22262_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\69204eec142c8d5ff57f20ede95c564b_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\69b2f1b9f30412961cd1b5cfe897cb42_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\69bc06d196d879d13abc65a18ad2a529_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\69dffa11d309d91ecc817822b17296d2_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\69e61cf068493a282f9d82aad941afbe_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6aa22ac44834aa64a0f054ec0efc19b9_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6b27cce6362f58ca66db1238c3ac6100_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6c234669a8d53a474853a2fb32c6c2dd_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6ff671bd74aa9f43c2895441873a09ea_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\70bcbb1f946c6751781ece7e2927301f_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\72ba99e287a5e62e039c592086f3b86c_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\73e134a006273c06a59beb76a7541a03_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\755ca6f278549b7ece63a2c82580815b_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\772df4159d492dd1e6f21393dcd892f5_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7955512f2f2647617d9e0c55036416ca_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\79cca2920001e8fe78862e485dc81292_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7a08ff43ecf85e5af3e1f6149862117f_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7a1f204ee773485e23951ba76976df04_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7a92e871cd96192c7013c39c45b013e8_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7ba1fbc6128430291aa1958363e503eb_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7d7c8511669eb5de39609fe48356281a_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7da25a656fe040902bb32986eec39e26_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7e016663f45daa5700b6fef67a38f751_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\81c30f896720c335ca86987b8d565c50_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\829b2539cb2b7dd340632f499bec0201_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\838c7c2b56e2b070ddb111f94baa7870_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\845fc3984a3c13bbce14aadb3730f26e_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\85ec6b71257d4bd3f0d787fb228dd530_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\86f5dc9b60e8ae9f0a1bc8d22bf268d8_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\87b63f419b2258d748521fd50359dd51_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\892ba9fbb669bff4d31894a2d88d5dea_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8c80b8d73837d45b01ca3dfe56d5fd2c_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8d15efcd7776c9f30ba9550aced4a0be_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8ea4f49199b68b0bca4f06510f24eaf0_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8fc4c58bae880543a79ef1e9433eddd3_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\91a6097f9287e72d5b140fc37e3ad173_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\920f322635d0bf46ec148b0cc34ed592_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\941801d6ebdd4f41c3af29f53d6bde41_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\94236a33126d87b529116da1b837cf0f_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\94b867280a226ef6938b41dd45a7d0df_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\96231b5480f59007ec8a16cf6dfd5cc7_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\982a50561cb0ff32eec5409c2fe3a231_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\985c8d7594878870b19f1330f7ae9076_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\99c6a5a259b45fe2fbd3e27135768469_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9a618fd5347598aa9be1118c999e9e38_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9a70bbf055524814ec12aafb02e8cbc7_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9aab3258bc85e62592ad57911eecd479_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9c2770f791cee00f9e9360569f5b49d1_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9d2defdfb64444278f7a52cc486242e1_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9f1c576414b6593913db2eaa29a4ed82_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9f68fdf886dbab8234116535d7ff92d4_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a0df2f61bd624684b0fdd17a05ccbd0b_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a1be163da85f0c61ad725b1b55203245_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a22f2b10b9edb83a3c2fa85f5bbc4791_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a2ec75e326dfbcd09861728652869962_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a3585e480e24fd2c7756cca6436a3f9d_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a4bd386a304be192d2707a9a42b96db2_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a4d871054f86520dc28dd3bc1b2cb6e1_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a5d7541f401c8687c681cd8d46bbaf9b_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a70fb7ae53f25f7393e85ec17b5ce9e3_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a799cad061de53087293363fe57909ec_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a7ef77e15280e0312bee90a925086464_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a8684a62f1597fec921d4d56548cb9fa_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ab0c3950caddc43db2d23512776a0fd9_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ab407dddf05fa514e3a81d08e64f9514_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ac4379d2bd5ecad8ab9cbd13e852921c_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ac7e64f084df33ab69e3da34dd4fc912_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\acbc68ef760fa358ad4fcac6fa2bccbe_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ad07cd9f010fcf18a68818e35a700dd6_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\aff98896a6f6dbbd24bbad238cb79b80_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b34e43956f17ed4551dcb51cedeebec5_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b47f955a5f802366859838035c37cf9e_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b728b533abd6b0792bdec1c2151a13de_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b86d50de4e9db881723dd0624cfbb5cf_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b8bc66319b02696585a70830eefc5f28_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bad361a4711b440a179fa72da5e62c45_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bb0fb65ca4c16c0076125537e2e5d494_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bc3b6a67e1db22cff61f18c66e1a0ddf_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bceee23ea2541b30f87b08dc5ac7ae28_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bd2a4cd4388e31e6676953c123e193fe_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bda504457eddb0ffcb970e4a030d24e0_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\be5c782597affc1e58aeb5362dd3870b_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\be610d830b660196a3e6c6df2b71a588_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bedf8b8b678d51b72f1cff628ce32774_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c08922be4847b9720cdd22adcbe5cc6a_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c0e0b28fdf9d0df1894cd29931708244_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c2ea3a386e8d64fd5300c7fa3e95da9b_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c333f351b99f67ded9f0d272f124ceed_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c5b2cb744d5df321f8027c8ff8123ac5_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c69d1f048f3ac1bbd32f8eda6bc7381f_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c74bebae5bcc7f2d7c4a0785eb9c361b_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c8ea8e531abfee99fc390cb8ce342397_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c9d1a6bcdbc914d9e783e3417b433627_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\c9e455ccd3713b729343fcf4dbe998c5_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cba89d5ffdbcd5f159d33af0ba408204_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cf3121b09cdb6fc80f0ad11a6b2989b5_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d26f429b9ad21dc64418842f322c747b_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d3014be91ea922862aa85cd361546b8d_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d5642debe63b34e3f7ddff171e8ea373_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d6f8bb431dd13523a9969a87438799ea_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d7b4f572261d05c03a4bb11215fee081_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d91039e9edc3a2bbcb3d29ccecbaba95_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d9d9e3c1e7c6dc0d2eabe82ad31332bf_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dac3d3564b499aad5707e7294f1464d6_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dc7e08d1183475f3feead4700f39ff0f_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dd5b18e39bab9cd13aea7028b0ec2103_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dd9be74119f1a6c95ee525ff0a7c9f0d_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e008457f1ebfd91b3185838b14173645_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e1ebec909f6b57a1080306dd388d7a82_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ea3e5b84da0d621c71f54f9dca709480_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\eb79107a058f70757ea96b70d172bf54_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ebf80bd8ecca7cc8a1931b513f51f15b_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ecdc9cdb678adefe9b03cff2ff688343_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ececf56d125be204402d81f52263bc23_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ee955d94c129830557c2b995954fce44_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\efb33089896b9e1da71b72581bf3a2b4_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f03929791ba5dba95b9e66065e5b1bc0_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f36dfb694f564b6abe0602898f20ec82_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f4825ed7ab7f67e69723ac1941cb1937_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f4ccb6d174266e43202c51082b0268cc_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f69000869031b93a6614c32c4f59c6ed_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f72250ebaa1e359089ca48b699f932a9_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f91e09671f799c188afa3a939b27c7b3_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fbd007bf62b520ce042982655d7a9f93_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ff0fddfbafe907c222624cc75355b76c_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ffed5f13e1a7ad92220ea794844f2d47_63be2f3f-748d-41f0-bc57-61b7d675750d Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle.zip/Yazzle1162OinUninstaller.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle1.zip/Yazzle1162OinUninstaller.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle1.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle2.zip/Yazzle1162OinUninstaller.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle2.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine7F630A6 Infected: not-a-virus:AdWare.Win32.WebSearch.av skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\243C12DA/systb.dll Infected: not-a-virus:AdWare.Win32.ImiBar.c skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\243C12DA/wdskctl.exe Infected: not-a-virus:AdWare.Win32.ShopNav.g skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\243C12DA CAB: infected - 2 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\243C12DA MimarSinan: infected - 2 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\243C12DA UPX: infected - 2 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\243C12DA CryptFF: infected - 2 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\25CF33C9.wma Infected: Trojan-Downloader.WMA.Wimad.d skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5ACB5CFD.wma Infected: Trojan-Downloader.WMA.Wimad.d skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\62BD5A25 Infected: Trojan-Downloader.Win32.QDown.t skipped
C:\Documents and Settings\chris\Local Settings\Temporary Internet Files\Content.IE5\78OL927E\ad-sp2-fastclick[1].swf Infected: not-virus:Hoax.SWF.Alerter.a skipped
C:\Documents and Settings\dave\Application Data\AT&T\Internet Security Wizard\client_gateway.log Object is locked skipped
C:\Documents and Settings\dave\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\dave\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\dave\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\dave\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\dave\Local Settings\Temp\~DFD1A5.tmp Object is locked skipped
C:\Documents and Settings\dave\Local Settings\Temp\~DFD1B0.tmp Object is locked skipped
C:\Documents and Settings\dave\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\dave\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\dave\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\dave\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\deb\My Documents\keygen.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.io skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Downloads\FamilyFeudSetup-dm[1].exe Infected: not-a-virus:AdWare.Win32.Trymedia.b skipped
C:\Downloads\MLBPlayballSetup-dm[1].exe Infected: not-a-virus:AdWare.Win32.Trymedia.b skipped
C:\Downloads\PedalToTheMetalSetup-dm[1].exe Infected: not-a-virus:AdWare.Win32.Trymedia.b skipped
C:\Program Files\CA\PPRT\logs\2007-08-11.csv Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsys.dll Object is locked skipped
C:\QooBox\Quarantine\C\VundoFix Backups\ampnqodb.dll.bad.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.hb skipped
C:\QooBox\Quarantine\C\VundoFix Backups\ddcbcya.dll.bad.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\QooBox\Quarantine\C\VundoFix Backups\ddcyvuu.dll.bad.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\QooBox\Quarantine\C\VundoFix Backups\dtjsgjpx.dll.bad.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.hb skipped
C:\QooBox\Quarantine\C\VundoFix Backups\gebcc.dll.bad.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.kr skipped
C:\QooBox\Quarantine\C\VundoFix Backups\iifccyy.dll.bad.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\QooBox\Quarantine\C\VundoFix Backups\pikfgvwy.dll.bad.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.lh skipped
C:\QooBox\Quarantine\C\VundoFix Backups\rqrqnll.dll.bad.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\QooBox\Quarantine\C\VundoFix Backups\wvuvwwv.dll.bad.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\QooBox\Quarantine\C\VundoFix Backups\xacoohbd.dll.bad.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.hb skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\awtspqq.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\bnodbqfh.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.kp skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\ddcdayv.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.io skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\vfovouao.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.kp skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\xaorscjd.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.kp skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP713\A0824476.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.io skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP714\A0824478.exe Infected: Trojan.Win32.Dialer.qn skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP729\A0826901.scr Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP729\A0826909.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.at skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP729\A0826911.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP729\A0826912.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP729\A0826913.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.af skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP729\A0826914.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP729\A0826915.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP729\A0826916.SCR Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP729\A0826917.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP729\A0826918.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP729\A0826919.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.a skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP729\A0826920.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.an skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP729\A0826921.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.aq skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP729\A0826922.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP729\A0826924.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP729\A0826925.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.ax skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP729\A0826927.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP729\A0826928.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.as skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP729\A0826929.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.ad skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP729\A0826931.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP729\A0826932.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP729\A0826933.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.i skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP729\A0826936.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.hb skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP729\A0826937.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.hb skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP729\A0826938.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.as skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP729\A0826939.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP729\A0826940.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.l skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP729\A0826942.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP729\A0826943.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.au skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP729\A0826944.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP729\A0826945.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP729\A0826946.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP729\A0826947.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.hb skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP729\A0826966.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP729\A0826967.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.hb skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP729\A0827036.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.hb skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP730\A0827076.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.hb skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP734\A0827266.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.kp skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP734\A0828266.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.kp skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP734\A0829277.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.kp skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP734\A0831277.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.kp skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP734\A0832277.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.kp skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP734\A0832294.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.kp skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP735\A0832348.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.kp skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP772\A0837152.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.hb skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP772\A0837156.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP772\A0837157.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP772\A0837158.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.hb skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP772\A0837159.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.kr skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP772\A0837160.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP772\A0837161.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.lh skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP772\A0837163.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP772\A0837165.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP772\A0837166.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.hb skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP773\A0837197.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP773\A0837198.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.io skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP784\A0838636.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.kp skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP784\A0838637.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.kp skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP784\A0838638.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.kp skipped
C:\System Volume Information\_restore{75311D2D-06EA-4BF3-BC1E-CE392B978CC5}\RP785\change.log Object is locked skipped
C:\WINDOWS\$NtUninstallKB824141$\user32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB824141$\win32k.sys Object is locked skipped
C:\WINDOWS\$NtUninstallKB828028$\msasn1.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828035$\msgsvc.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828035$\wkssvc.dll Object is locked skipped
C:\WINDOWS\$NtUninstallQ329048$\reg00002 Object is locked skipped
C:\WINDOWS\$NtUninstallQ329115$\reg00002 Object is locked skipped
C:\WINDOWS\$NtUninstallQ329115$\reg00003 Object is locked skipped
C:\WINDOWS\$NtUninstallQ329390$\reg00002 Object is locked skipped
C:\WINDOWS\$NtUninstallQ329834$\reg00002 Object is locked skipped
C:\WINDOWS\$NtUninstallQ828026$\msdxm.ocx Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{54B2F208-3FCC-418A-B4B4-A2ADC86408D5}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\ODiag.evt Object is locked skipped
C:\WINDOWS\system32\config\OSession.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\config\Windows_OneCare_Evt.evt Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.
ComboFix 07-08-11 - "dave" 2007-08-11 19:27:54.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.566 [GMT -4:00]
Command switches used :: C:\Documents and Settings\dave\Desktop\CFScript.txt
* Created a new restore point

FILE::
C:\WINDOWS\system32\VundoFixSVC.exe


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Program Files\Lexmark Toolbar
C:\Program Files\Lexmark Toolbar\EzPrintLite\custmuiL.dll
C:\Program Files\Lexmark Toolbar\EzPrintLite\epfunctL.dll
C:\Program Files\Lexmark Toolbar\EzPrintLite\epoemL.dll
C:\Program Files\Lexmark Toolbar\EzPrintLite\epstrL.dll
C:\Program Files\Lexmark Toolbar\EzPrintLite\EPUtilL.dll
C:\Program Files\Lexmark Toolbar\EzPrintLite\epwizrdL.dll
C:\Program Files\Lexmark Toolbar\EzPrintLite\epwzrcL.dll
C:\Program Files\Lexmark Toolbar\EzPrintLite\ezprintL.EXE
C:\Program Files\Lexmark Toolbar\EzPrintLite\fplthelp.chm
C:\Program Files\Lexmark Toolbar\EzPrintLite\imgutilL.dll
C:\Program Files\Lexmark Toolbar\EzPrintLite\iptk.dll
C:\Program Files\Lexmark Toolbar\EzPrintLite\lfbmp13n.dll
C:\Program Files\Lexmark Toolbar\EzPrintLite\lfcmp13n.dll
C:\Program Files\Lexmark Toolbar\EzPrintLite\lfgif13n.dll
C:\Program Files\Lexmark Toolbar\EzPrintLite\lfpng13n.dll
C:\Program Files\Lexmark Toolbar\EzPrintLite\ltdis13n.dll
C:\Program Files\Lexmark Toolbar\EzPrintLite\ltefx13n.dll
C:\Program Files\Lexmark Toolbar\EzPrintLite\ltfil13n.dll
C:\Program Files\Lexmark Toolbar\EzPrintLite\ltimg13n.dll
C:\Program Files\Lexmark Toolbar\EzPrintLite\ltkrn13n.dll
C:\Program Files\Lexmark Toolbar\EzPrintLite\ltwvc13n.dll
C:\Program Files\Lexmark Toolbar\resource.dll
C:\Program Files\Lexmark Toolbar\toolband.chm
C:\Program Files\Lexmark Toolbar\toolband.dll
C:\Program Files\Shareaza
C:\Program Files\Shareaza\Incomplete\6QECFRN5ZB3ZFHIK7HPQVT7ZLX7V5BKA Kanye West - Gold Digger ft. Jamie Foxx as Ray Charles.mp3
C:\Program Files\Shareaza\Incomplete\AA4GOZMCCUQGRA4V62NVVDYA42DROIRS Senses Fail - Bloody Romance.mp3
C:\Program Files\Shareaza\Incomplete\AA4GOZMCCUQGRA4V62NVVDYA42DROIRS Senses Fail - Bloody Romance.mp3.sd
C:\Program Files\Shareaza\Incomplete\adding to the noise 32.wma
C:\Program Files\Shareaza\Incomplete\HHCNM6UA6V32Q3HFTIMZWB6JMA6J53JO 06 Ride the Lightning [Live].wma
C:\Program Files\Shareaza\Incomplete\HHCNM6UA6V32Q3HFTIMZWB6JMA6J53JO 06 Ride the Lightning [Live].wma.sd
C:\Program Files\Shareaza\Incomplete\HOGZDO2DQPAQJOGLWOXH5O2GL4YJJC5O Sidewalks.mp3
C:\Program Files\Shareaza\Incomplete\HOGZDO2DQPAQJOGLWOXH5O2GL4YJJC5O Sidewalks.mp3.sd
C:\Program Files\Shareaza\Incomplete\Y2NFHMWSI44N36NGICUCOHSYBONLSKEK Metallica - Wherever I May Roam.mp3.sd
C:\Program Files\Viewpoint
C:\Program Files\Viewpoint\Viewpoint Media Player\AxMetaStream.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\AxMetaStream_.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\AxMetaStream_0302021C.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\AxMetaStream_0302021C_.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\AxMetaStream_0303001D.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\AxMetaStream_0305000D.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\ClassIDs.ini
C:\Program Files\Viewpoint\Viewpoint Media Player\ComponentMgr_0305000D.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\ComponentRegistry.ini
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\AOLUserShell.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\Cursors.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\JpegReader.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\Mts3Reader.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\SceneComponent.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\SreeDMMX.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\SWFView.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\VectorView.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\VMgr.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\VMPSpeech.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\VMPVideo.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\VMPVideo2.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\WaveletReader.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\DownLoadHist.ini
C:\Program Files\Viewpoint\Viewpoint Media Player\HostRegistry.ini
C:\Program Files\Viewpoint\Viewpoint Media Player\MetaStreamConfig.ini
C:\Program Files\Viewpoint\Viewpoint Media Player\MetaStreamID.ini
C:\Program Files\Viewpoint\Viewpoint Media Player\MtsAxInstaller.exe
C:\Program Files\Viewpoint\Viewpoint Media Player\MTSDownloadSites.txt
C:\temp
C:\VundoFix Backups
C:\VundoFix Backups\addmorefiles.txt
C:\VundoFix Backups\ampnqodb.dll.bad
C:\VundoFix Backups\bdoqnpma.ini.bad
C:\VundoFix Backups\ccbeg.bak1.bad
C:\VundoFix Backups\ccbeg.bak2.bad
C:\VundoFix Backups\ccbeg.ini.bad
C:\VundoFix Backups\ccbeg.ini2.bad
C:\VundoFix Backups\ccbeg.tmp.bad
C:\VundoFix Backups\dbhoocax.ini.bad
C:\VundoFix Backups\ddcbcya.dll.bad
C:\VundoFix Backups\ddcyvuu.dll.bad
C:\VundoFix Backups\dtjsgjpx.dll.bad
C:\VundoFix Backups\gebcc.dll.bad
C:\VundoFix Backups\iifccyy.dll.bad
C:\VundoFix Backups\pikfgvwy.dll.bad
C:\VundoFix Backups\rqniwfki.dll.bad
C:\VundoFix Backups\rqrqnll.dll.bad
C:\VundoFix Backups\whudsycg.dll.bad
C:\VundoFix Backups\wvuvwwv.dll.bad
C:\VundoFix Backups\xacoohbd.dll.bad
C:\VundoFix Backups\xpjgsjtd.ini.bad
C:\VundoFix Backups\ywvgfkip.ini.bad
C:\WINDOWS\system32\VundoFixSVC.exe


((((((((((((((((((((((((( Files Created from 2007-07-11 to 2007-08-11 )))))))))))))))))))))))))))))))


2007-08-11 00:45 55,296 –a—— C:\WINDOWS\system32\drivers\rp_skt32.sys
2007-08-11 00:45 48,384 –a—— C:\WINDOWS\system32\drivers\rp_pkt32.sys
2007-08-10 20:44 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-09 20:56 d——– C:\Program Files\InterMute
2007-08-07 22:03 3,968 –a—— C:\WINDOWS\system32\drivers\AvgArCln.sys
2007-08-07 21:13 d——– C:\DOCUME~1\dave\APPLIC~1\Lexmark Imaging Studio
2007-08-07 14:37 d——– C:\DOCUME~1\deb\APPLIC~1\Lexmark Imaging Studio
2007-08-07 14:34 d——– C:\logs
2007-08-07 14:31 d——– C:\Program Files\Lexmark 1300 Series
2007-07-31 21:49 d——– C:\WINDOWS\AiOTemp
2007-07-29 12:03 d——– C:\DOCUME~1\dave\APPLIC~1\Share-to-Web Upload Folder
2007-07-28 21:08 d——– C:\Program Files\Raxco
2007-07-28 21:08 d——– C:\Program Files\Common Files\Authentium
2007-07-28 21:08 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Raxco
2007-07-28 21:07 d——– C:\Program Files\Common Files\Scanner
2007-07-28 21:07 d——– C:\Program Files\CA
2007-07-28 21:04 d——– C:\Program Files\AT&T
2007-07-28 21:03 d——– C:\DOCUME~1\dave\APPLIC~1\InstallShield
2007-07-28 20:22 70 –ah—– C:\aaw7boot.cmd
2007-07-27 22:24 d-a—— C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
2007-07-27 21:18 d——– C:\Program Files\WebCyberCoach
2007-07-27 16:48 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-07-26 22:19 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-07-23 23:23 d——– C:\DOCUME~1\dave\APPLIC~1\Arcsoft
2007-07-23 23:13 d——– C:\WINDOWS\DvzCommon
2007-07-23 23:13 d——– C:\Program Files\Documents To Go
2007-07-23 22:36 d——– C:\Program Files\Palm
2007-07-20 20:49 d——– C:\DOCUME~1\ryan\APPLIC~1\Google
2007-07-16 21:55 d——– C:\Program Files\Call of Duty Game of the Year Edition
2007-07-15 17:19 d——– C:\Program Files\Common Files\SupportSoft


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-11 19:34 ——— d——– C:\Program Files\BellSouth Internet Tools
2007-07-29 17:07 ——— d——– C:\Program Files\Hewlett-Packard
2007-07-29 16:29 ——— d——– C:\Program Files\Google
2007-07-29 12:08 ——— d——– C:\Program Files\Microsoft AntiSpyware
2007-07-28 21:04 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-07-27 23:59 ——— d——– C:\Program Files\Windows Live Safety Center
2007-07-27 21:55 ——— d——– C:\Program Files\BroadJump
2007-07-27 21:53 ——— d——– C:\Program Files\AIM
2007-07-27 21:52 ——— d——– C:\Program Files\Signature Colors Virtual Painter
2007-07-27 21:52 ——— d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-07-27 21:52 ——— d——– C:\DOCUME~1\dave\APPLIC~1\Aim
2007-07-27 17:09 ——— d——– C:\Program Files\Free Offers from Freeze.com
2007-07-26 22:19 ——— d——– C:\Program Files\Lavasoft
2007-07-21 15:17 ——— d——– C:\Program Files\Frets on Fire
2007-07-15 17:19 ——— d——– C:\Program Files\BellSouth
2007-06-28 22:03 ——— d——– C:\DOCUME~1\dave\APPLIC~1\AT&T
2007-06-19 15:25 ——— d–h—– C:\Program Files\WindowsUpdate
2007-05-16 11:12 86528 —–c— C:\WINDOWS\system32\dllcache\directdb.dll
2007-05-16 11:12 85504 —–c— C:\WINDOWS\system32\dllcache\wabimp.dll
2007-05-16 11:12 683520 –a—— C:\WINDOWS\system32\inetcomm.dll
2007-05-16 11:12 683520 —–c— C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-05-16 11:12 510976 —–c— C:\WINDOWS\system32\dllcache\wab32.dll
2007-05-16 11:12 1314816 —–c— C:\WINDOWS\system32\dllcache\msoe.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 05:59 C:\WINDOWS\BCMSMMSG.exe]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2003-04-24 17:58]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-03-27 22:17]
"C2kWep"="C:\Program Files\Netopia\C3kWepN.exe" [2004-03-24 13:46]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 15:42]
"blspcloader"="C:\Program Files\BellSouth Internet Tools\blsloader.exe" [2007-06-28 18:53]
"ISW.exe"="C:\Program Files\AT&T\Internet Security Wizard\ISW.exe" [2007-05-03 13:12]
"AT&T Internet Security Suite"="C:\Program Files\AT&T\AT&T Internet Security Suite\Rps.exe" [2007-06-28 16:09]
"-FreedomNeedsReboot"="C:\Program Files\AT&T\AT&T Internet Security Suite\ZkRunOnceR.exe" [2007-06-28 16:09]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]
"Share-to-Web Namespace Daemon"="C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2001-07-03 09:11]
"lxdcamon"="C:\Program Files\Lexmark 1300 Series\lxdcamon.exe" [2007-02-05 19:32]
"LXDCCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXDCtime.dll" [2007-01-22 18:05]
"Ad-Watch"="C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Watch2007.exe" [2007-07-26 22:49]
"Run StartupMonitor"="StartupMonitor.exe" [2000-05-20 17:23 C:\WINDOWS\StartupMonitor.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"NvMediaCenter"=RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
"ALUAlert"=C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Dataviz Messenger.lnk - C:\WINDOWS\DvzCommon\DvzMsgr.exe [2003-07-01 21:16:46]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoViewOnDrive"=0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Works Calendar Reminders.lnk]
backup=C:\WINDOWS\pss\Microsoft Works Calendar Reminders.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RunDLL]

R1 StarOpen;StarOpen;C:\WINDOWS\system32\drivers\StarOpen.sys
R2 CSS DVP;Dynamic Virus Protection;C:\WINDOWS\system32\DRIVERS\css-dvp.sys
R3 BCMModem;BCM V.92 56K Modem;C:\WINDOWS\system32\DRIVERS\BCMSM.sys
R3 SWLD23U;Netopia 802.11b WLAN USB Adapter;C:\WINDOWS\system32\DRIVERS\SWLD23U.sys
S3 JL2005;JL2005A Toy Camera;C:\WINDOWS\system32\Drivers\toywdm.sys
S3 Radialpoint Security Services;AT&T Internet Security Suite;C:\WINDOWS\system32\dllhost.exe /Processid:{80098F68-1220-4F43-80A8-15C7395B8874}
S3 swlubtl;WLAN USB Boot Device;C:\WINDOWS\system32\Drivers\swlubtl.sys

*Newly Created Service* - AD-WATCH_REGISTRY_FILTER

Contents of the 'Scheduled Tasks' folder
2007-08-09 21:44:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
2007-06-07 15:28:22 C:\WINDOWS\Tasks\MP Scheduled Quick Scan.job - C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MpCmdRun.exe

**************************************************************************

disk not found C:\

scanning hidden processes …

scanning hidden autostart entries …

**************************************************************************

Completion time: 2007-08-11 19:36:51 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-08-11 19:36
C:\ComboFix2.txt … 2007-08-11 00:21
C:\ComboFix3.txt … 2007-08-10 20:56

— E O F —
Wow that was a lot of homework I gave you to do and you did it all very well :thumbup:

I have a few questions for you as well as a few comments to make before I can continue:

First:

1. I see that you are now using mostly ATT Security Products. Am I correct?

2. I also see that there is listing in your logs for CA which is Computer Associates and a maker of Security Products. Do you still use their services?

3. There is also an entry for Symantec in your HJT log. Doo you still use their services?

The reason why I am asking is that more than 1 firewall and 1 Antivirus program on the same machine usually spells trouble which shows up in a huge degradation of performance and the possibility of a greater likelihood of infection due to conflicts between the competing programs.


Second:

Most of the malware detected in the scans is in your system restore cache and we will be dealing with that during the final cleanup procedures.


If you could get back to me as soon as possible with an answer to the above questions, I will be able to provide you with another solution before retiring.

Regards,

Trevuren

Please UNINSTALL Microsoft AntiSpyware as it has not been supported by Microsoft for over a year and is useless.
Trevuren..thanks for being patient with me..i am a dad and don't have alot ofcomputer time to carve out…anyways, i am running at&t security, recently i switched to this from windows live one care as i thought one care wasn't giving me adequate protection. before one care i had norton. i don't believe i had any of them running simultaneously,but, couldn't say 100%. computer associates doesn't ring a bell, and don't believe it is currently in use. hope this info helps, and thanks again for hanging in there with me and my slow responses!!dave
trevuren…just thought of this…when i set up my computer for wireless from at&t i think as part of the installation cd i have netopia wireless security running. i think it's a firewall program, but am unsure..i do know it loads on startup and is running
A. 1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\Documents and Settings\deb\My Documents\keygen.exe
C:\Downloads\FamilyFeudSetup-dm[1].exe
C:\Downloads\MLBPlayballSetup-dm[1].exe
C:\Downloads\PedalToTheMetalSetup-dm[1].exe
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle.zip

Folder::
C:\Program Files\Microsoft AntiSpyware
C:\Program Files\Common Files\Symantec
C:\Documents and Settings\All Users\Application Data\Symantec
C:\Program Files\Netopia

Driver::
Symantec Core LC 

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"C2kWep"=-


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.

B. Now please tell me how your system is running. If everything is OK, just give me the OK and we will start the final cleanup procedures.

Trevuren
ComboFix 07-08-11 - "dave" 2007-08-12 16:52:17.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.641 [GMT -4:00]
Command switches used :: C:\Documents and Settings\dave\Desktop\CFScript.txt
* Created a new restore point

FILE::
C:\Documents and Settings\deb\My Documents\keygen.exe
C:\Downloads\FamilyFeudSetup-dm[1].exe
C:\Downloads\MLBPlayballSetup-dm[1].exe
C:\Downloads\PedalToTheMetalSetup-dm[1].exe
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle.zip
Trvuren..computer seems to be improved,

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle.zip
C:\Documents and Settings\All Users\Application Data\Symantec
C:\Documents and Settings\All Users\Application Data\Symantec\ErrLogs\{1F76ACFA-22FE-49F6-BC05-F4EC835F48CC}20efc8e4.zip
C:\Documents and Settings\All Users\Application Data\Symantec\ErrLogs\{1F76ACFA-22FE-49F6-BC05-F4EC835F48CC}c7507cda.zip
C:\Documents and Settings\All Users\Application Data\Symantec\LiveSubscribe\Catalog.LiveSubscribe
C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Product.Inventory.LiveUpdate
C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Settings.LiveUpdate
C:\Documents and Settings\deb\My Documents\keygen.exe
C:\Downloads\FamilyFeudSetup-dm[1].exe
C:\Downloads\MLBPlayballSetup-dm[1].exe
C:\Downloads\PedalToTheMetalSetup-dm[1].exe
C:\Program Files\Microsoft AntiSpyware
C:\Program Files\Microsoft AntiSpyware\cleaner.log
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems679C2CD-9E84-461A-8F27-7EE245.asq
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\142BE34C-E1CD-483D-AF51-CB882B.asq
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\59136017-3B5B-42B5-9856-22D138.asq
C:\Program Files\Microsoft AntiSpyware\errors.log
C:\Program Files\Microsoft AntiSpyware\gcAgentsData.gcd
C:\Program Files\Microsoft AntiSpyware\gcAgentsDataStoreData.gcd
C:\Program Files\Microsoft AntiSpyware\gcDeterminationDataUser.gcd
C:\Program Files\Microsoft AntiSpyware\gcEventsData.gcd
C:\Program Files\Microsoft AntiSpyware\gcExplorersData.gcd
C:\Program Files\Microsoft AntiSpyware\gcThreatAuditIgnoredThreatsData.gcd
C:\Program Files\Microsoft AntiSpyware\gcThreatAuditQuarantineData.gcd
C:\Program Files\Microsoft AntiSpyware\gcThreatAuditScanHistoryData.gcd
C:\Program Files\Microsoft AntiSpyware\gcThreatAuditSettingsData.gcd
C:\Program Files\Microsoft AntiSpyware\gcUserData.gcd
C:\Program Files\Microsoft AntiSpyware\softwareupdates.log
C:\Program Files\Microsoft AntiSpyware\tracksEraser.log
C:\Program Files\Netopia
C:\Program Files\Netopia\C3kWepN.exe


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


——-\LEGACY_SYMANTEC_CORE_LC
——-\Symantec Core LC


((((((((((((((((((((((((( Files Created from 2007-07-12 to 2007-08-12 )))))))))))))))))))))))))))))))


2007-08-11 19:43 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-08-11 19:43 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
2007-08-11 00:45 55,296 –a—— C:\WINDOWS\system32\drivers\rp_skt32.sys
2007-08-11 00:45 48,384 –a—— C:\WINDOWS\system32\drivers\rp_pkt32.sys
2007-08-10 20:44 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-09 20:56 d——– C:\Program Files\InterMute
2007-08-07 22:03 3,968 –a—— C:\WINDOWS\system32\drivers\AvgArCln.sys
2007-08-07 21:13 d——– C:\DOCUME~1\dave\APPLIC~1\Lexmark Imaging Studio
2007-08-07 14:37 d——– C:\DOCUME~1\deb\APPLIC~1\Lexmark Imaging Studio
2007-08-07 14:34 d——– C:\logs
2007-08-07 14:31 d——– C:\Program Files\Lexmark 1300 Series
2007-07-31 21:49 d——– C:\WINDOWS\AiOTemp
2007-07-29 12:03 d——– C:\DOCUME~1\dave\APPLIC~1\Share-to-Web Upload Folder
2007-07-28 21:08 d——– C:\Program Files\Raxco
2007-07-28 21:08 d——– C:\Program Files\Common Files\Authentium
2007-07-28 21:08 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Raxco
2007-07-28 21:07 d——– C:\Program Files\Common Files\Scanner
2007-07-28 21:07 d——– C:\Program Files\CA
2007-07-28 21:04 d——– C:\Program Files\AT&T
2007-07-28 21:03 d——– C:\DOCUME~1\dave\APPLIC~1\InstallShield
2007-07-28 20:22 70 –ah—– C:\aaw7boot.cmd
2007-07-27 22:24 d-a—— C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
2007-07-27 21:18 d——– C:\Program Files\WebCyberCoach
2007-07-27 16:48 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-07-26 22:19 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-07-23 23:23 d——– C:\DOCUME~1\dave\APPLIC~1\Arcsoft
2007-07-23 23:13 d——– C:\WINDOWS\DvzCommon
2007-07-23 23:13 d——– C:\Program Files\Documents To Go
2007-07-23 22:36 d——– C:\Program Files\Palm
2007-07-20 20:49 d——– C:\DOCUME~1\ryan\APPLIC~1\Google
2007-07-16 21:55 d——– C:\Program Files\Call of Duty Game of the Year Edition
2007-07-15 17:19 d——– C:\Program Files\Common Files\SupportSoft


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-12 16:59 ——— d——– C:\Program Files\BellSouth Internet Tools
2007-08-12 10:21 ——— d——– C:\Program Files\Hewlett-Packard
2007-07-29 16:29 ——— d——– C:\Program Files\Google
2007-07-28 21:04 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-07-27 23:59 ——— d——– C:\Program Files\Windows Live Safety Center
2007-07-27 21:55 ——— d——– C:\Program Files\BroadJump
2007-07-27 21:53 ——— d——– C:\Program Files\AIM
2007-07-27 21:52 ——— d——– C:\Program Files\Signature Colors Virtual Painter
2007-07-27 21:52 ——— d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-07-27 21:52 ——— d——– C:\DOCUME~1\dave\APPLIC~1\Aim
2007-07-27 17:09 ——— d——– C:\Program Files\Free Offers from Freeze.com
2007-07-26 22:19 ——— d——– C:\Program Files\Lavasoft
2007-07-21 15:17 ——— d——– C:\Program Files\Frets on Fire
2007-07-15 17:19 ——— d——– C:\Program Files\BellSouth
2007-06-28 22:03 ——— d——– C:\DOCUME~1\dave\APPLIC~1\AT&T
2007-06-19 15:25 ——— d–h—– C:\Program Files\WindowsUpdate
2007-05-16 11:12 86528 —–c— C:\WINDOWS\system32\dllcache\directdb.dll
2007-05-16 11:12 85504 —–c— C:\WINDOWS\system32\dllcache\wabimp.dll
2007-05-16 11:12 683520 –a—— C:\WINDOWS\system32\inetcomm.dll
2007-05-16 11:12 683520 —–c— C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-05-16 11:12 510976 —–c— C:\WINDOWS\system32\dllcache\wab32.dll
2007-05-16 11:12 1314816 —–c— C:\WINDOWS\system32\dllcache\msoe.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 05:59 C:\WINDOWS\BCMSMMSG.exe]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2003-04-24 17:58]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-03-27 22:17]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 15:42]
"blspcloader"="C:\Program Files\BellSouth Internet Tools\blsloader.exe" [2007-06-28 18:53]
"ISW.exe"="C:\Program Files\AT&T\Internet Security Wizard\ISW.exe" [2007-05-03 13:12]
"AT&T Internet Security Suite"="C:\Program Files\AT&T\AT&T Internet Security Suite\Rps.exe" [2007-06-28 16:09]
"-FreedomNeedsReboot"="C:\Program Files\AT&T\AT&T Internet Security Suite\ZkRunOnceR.exe" [2007-06-28 16:09]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]
"Share-to-Web Namespace Daemon"="C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2001-07-03 09:11]
"lxdcamon"="C:\Program Files\Lexmark 1300 Series\lxdcamon.exe" [2007-02-05 19:32]
"LXDCCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXDCtime.dll" [2007-01-22 18:05]
"Run StartupMonitor"="StartupMonitor.exe" [2000-05-20 17:23 C:\WINDOWS\StartupMonitor.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"NvMediaCenter"=RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
"ALUAlert"=C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Dataviz Messenger.lnk - C:\WINDOWS\DvzCommon\DvzMsgr.exe [2003-07-01 21:16:46]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoViewOnDrive"=0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Works Calendar Reminders.lnk]
backup=C:\WINDOWS\pss\Microsoft Works Calendar Reminders.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RunDLL]

R1 StarOpen;StarOpen;C:\WINDOWS\system32\drivers\StarOpen.sys
R2 CSS DVP;Dynamic Virus Protection;C:\WINDOWS\system32\DRIVERS\css-dvp.sys
R3 BCMModem;BCM V.92 56K Modem;C:\WINDOWS\system32\DRIVERS\BCMSM.sys
R3 SWLD23U;Netopia 802.11b WLAN USB Adapter;C:\WINDOWS\system32\DRIVERS\SWLD23U.sys
S3 JL2005;JL2005A Toy Camera;C:\WINDOWS\system32\Drivers\toywdm.sys
S3 Radialpoint Security Services;AT&T Internet Security Suite;C:\WINDOWS\system32\dllhost.exe /Processid:{80098F68-1220-4F43-80A8-15C7395B8874}
S3 swlubtl;WLAN USB Boot Device;C:\WINDOWS\system32\Drivers\swlubtl.sys


Contents of the 'Scheduled Tasks' folder
2007-08-09 21:44:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
2007-06-07 15:28:22 C:\WINDOWS\Tasks\MP Scheduled Quick Scan.job - C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MpCmdRun.exe

**************************************************************************

disk not found C:\

scanning hidden processes …

scanning hidden autostart entries …

**************************************************************************

Completion time: 2007-08-12 17:01:41 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-08-12 17:01
C:\ComboFix2.txt … 2007-08-11 19:36
C:\ComboFix3.txt … 2007-08-11 00:21

— E O F —
Logfile of HijackThis v1.99.1
Scan saved at 5:12:11 PM, on 8/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AT&T\AT&T Internet Security Suite\Fws.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\BellSouth Internet Tools\blsloader.exe
C:\Program Files\AT&T\Internet Security Wizard\ISW.exe
C:\Program Files\AT&T\AT&T Internet Security Suite\Rps.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Lexmark 1300 Series\lxdcamon.exe
C:\WINDOWS\StartupMonitor.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\DvzCommon\DvzMsgr.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\Program Files\AT&T\Internet Security Wizard\ISWComHandler.exe
C:\Program Files\AT&T\AT&T Internet Security Suite\rpsupdaterR.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.bellsouth.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: BlspcHlpr Class - {15C9938F-CB96-496D-800A-B827F2E34EA1} - C:\Program Files\BellSouth Internet Tools\blspc.dll
O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\AT&T\AT&T Internet Security Suite\pkR.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O3 - Toolbar: (no name) - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - (no file)
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [blspcloader] "C:\Program Files\BellSouth Internet Tools\blsloader.exe"
O4 - HKLM\..\Run: [ISW.exe] "C:\Program Files\AT&T\Internet Security Wizard\ISW.exe" /AUTORUN
O4 - HKLM\..\Run: [AT&T Internet Security Suite] "C:\Program Files\AT&T\AT&T Internet Security Suite\Rps.exe"
O4 - HKLM\..\Run: [-FreedomNeedsReboot] "C:\Program Files\AT&T\AT&T Internet Security Suite\ZkRunOnceR.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [lxdcamon] "C:\Program Files\Lexmark 1300 Series\lxdcamon.exe"
O4 - HKLM\..\Run: [LXDCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXDCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Dataviz Messenger.lnk = C:\WINDOWS\DvzCommon\DvzMsgr.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {4CCA4E80-9259-11D9-AC6E-444553544200} - http://h30155.www3.hp.com/ediags/dd/instal…llMgr_v01_6.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase8300.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1182308439125
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - http://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab
O16 - DPF: {7E9522CF-6B95-46D6-8E2F-7638F507313F} (BLS_SpeedOP.systemcheck) - http://www.fastaccess.drivers.bellsouth.ne…bls_speedop.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://a.download.toontown.com/sv1.0.21.10/ttinst.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Automatic LiveUpdate Scheduler - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: AT&T Internet Security Suite Service (RPSUpdaterR) - AT&T - C:\Program Files\AT&T\AT&T Internet Security Suite\rpsupdaterR.exe
O23 - Service: AT&T Internet Security Suite AT&T Firewall (RP_FWS) - AT&T - C:\Program Files\AT&T\AT&T Internet Security Suite\Fws.exe
O23 - Service: Windows Live OneCare (winss) - Unknown owner - C:\Program Files\Microsoft Windows OneCare Live\winss.exe (file missing)

trevuren..computer seems to be improved..i note on line 023 of hijack log that windows live one care is still listed..is it worth noting?
1. Go to Start->Run and type in notepad and hit OK.

2. Then copy and paste the content of the following codebox into Notepad:

sc stop winss
sc delete winss
del delete.bat

3. Save the file as "delete.bat". Make sure to save it with the quotes. It should look like this: [external image: Posted Image]

4. Double click delete.bat.

B. Now please tell me how your system is running. If everything is OK, just give me the OK and we will start the final cleanup procedure

Congratulations, your log looks CLEAN

There are a few things you must do once you are completely clean:

1. Time for some housekeeping

Please download the OTMoveIt by OldTimer
  • Save it to your desktop.
  • Run the tool by clicking on the icon.
  • Click the Cleanup button.
  • The tools that we used as well as this one will be removed from your system.

2. Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 onlyDouble-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

3. Now Set a New Restore Point to prevent possible reinfection from an old one. Some of the malware you picked up could have been saved in System Restore. Since System Restore is a protected directory, your tools can not access it to delete these bad files which sometimes can reinfect your system. Setting a new restore point AFTER cleaning your system will help prevent this and enable your computer to "roll-back" to a clean working state.

The easiest and safest way to do this is:
  • Go to Start > Programs > Accessories > System Tools and click "System Restore".
  • Choose the radio button marked "Create a Restore Point" on the first screen then click "Next". Give the R.P. a name then click "Create". The new point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
  • Then go to Start > Run and type: Cleanmgr
  • Click "OK".
  • Click the "More Options" Tab.
  • Click "Clean Up" in the System Restore section to remove all previous restore points except the newly created one.
Here are some tips to reduce the potential for spyware infection in the future:

Make sure you keep your Windows OS current by visiting Windows update
regularly to download and install any critical updates and service packs. With out these you are leaving the backdoor open.

I strongly recommend installing the following applications:
  • Spywareblaster <= SpywareBlaster will prevent spyware from being installed.
  • Spywareguard <= SpywareGuard offers realtime protection from spyware installation attempts.
  • How to use Ad-Aware to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Ad-Aware.
  • How to use Spybot to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Spybot. Similar to Ad-Aware, I strongly recommend both to catch most spyware.
To protect yourself further:
  • Spyad <= IE/Spyad places over 4000 websites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (Cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • MVPS Hosts file <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your coputer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
  • Google Toolbar <= Get the free google toolbar to help stop pop up windows.
And also see TonyKlein's good advice
So how did I get infected in the first place?

Regards,

Trevuren
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance.

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI