This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved]Removal Of Security Toolbar 7.1 In Ie

48 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:57:40 PM, on 8/22/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\Video ActiveX Access\iesmn.exe
D:\Program Files\Video ActiveX Access\imsmain.exe
D:\PROGRA~1\Grisoft\AVG7\avgcc.exe
D:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
D:\Program Files\QuickTime\qttask.exe
D:\Program Files\Picasa2\PicasaMediaDetector.exe
D:\Program Files\Skype\Phone\Skype.exe
D:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
D:\Program Files\Video ActiveX Access\imsmn.exe
D:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
D:\Program Files\Common Files\GMT\GMT.exe
D:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
D:\Program Files\Network Associates\VirusScan\avsynmgr.exe
D:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
D:\WINDOWS\system32\cisvc.exe
D:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
D:\Program Files\Video ActiveX Access\iesmin.exe
D:\Program Files\WebSecureAlert\WebSecureAlert.exe
D:\WINDOWS\System32\CTSvcCDA.exe
D:\Program Files\Network Associates\VirusScan\VsStat.exe
D:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
D:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
D:\WINDOWS\system32\inetsrv\inetinfo.exe
D:\Program Files\Network Associates\VirusScan\Vshwin32.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Network Associates\VirusScan\Avconsol.exe
D:\Program Files\Network Associates\VirusScan\Webscanx.exe
D:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
D:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
D:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
D:\WINDOWS\system32\NOTEPAD.EXE
D:\Program Files\Internet Explorer\iexplore.exe
D:\WINDOWS\System32\mdm.exe
D:\WINDOWS\system32\cidaemon.exe
D:\WINDOWS\system32\cidaemon.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - D:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - D:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {5DDE5591-A8AB-4897-93EF-1E4E943F85A7} - D:\Program Files\Video ActiveX Access\iesplg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - D:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar3.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - D:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O3 - Toolbar: Protection Bar - {CC18AE76-7E65-4258-A193-9EA0C52DA6B8} - D:\Program Files\Video ActiveX Access\iesbpl.dll
O4 - HKLM\..\Run: [CMESys] "D:\Program Files\Common Files\CMEII\CMESys.exe"
O4 - HKLM\..\Run: [AVG7_CC] D:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] D:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Picasa Media Detector] D:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [SNM] D:\Program Files\SpyNoMore\SNM.exe /startup
O4 - HKCU\..\Run: [EPSON Stylus Photo 825] D:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /A "D:\WINDOWS\system32\E_S494.tmp"
O4 - HKCU\..\Run: [Yahoo! Pager] "D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Skype] "D:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "D:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [swg] D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKLM\..\Policies\Explorer\Run: [user32.dll] D:\Program Files\Video ActiveX Access\iesmn.exe
O4 - HKLM\..\Policies\Explorer\Run: [rare] D:\Program Files\Video ActiveX Access\imsmain.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] D:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] D:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] D:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] D:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: GStartup.lnk = D:\Program Files\Common Files\GMT\GMT.exe
O4 - Global Startup: Image Transfer.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Service Manager.lnk = D:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: WebSecureAlert.lnk = D:\Program Files\WebSecureAlert\WebSecureAlert.exe
O8 - Extra context menu item: &Yahoo! Search - file:///D:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///D:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///D:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///D:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - D:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - D:\PROGRA~1\Yahoo!\MESSEN~1\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - D:\PROGRA~1\Yahoo!\MESSEN~1\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: D:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: YExplorer1_8US.CAB - http://photos.groups.yahoo.com/ocx/us/yexplorer1_8us.cab
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - https://components.viewpoint.com/MTSInstall…l?noreloadredir
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.35mb.com/applet/applet_l.cab
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540000} (CInstall Class) - http://www.spywarestormer.com/files2/Install.cab
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540006} (CInstall Class) - http://www.errorguard.com/installation/Install.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - D:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://inotes.cwinsider.com/mailrm02/iNotes6W.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.snapfish.com/SnapfishActivia.cab
O16 - DPF: {42F2C9BA-614F-47C0-B3E3-ECFD34EED658} - http://static.35mb.com/applet/applet_y.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/09c86d4cad8ebe…ip/RdxIE601.cab
O16 - DPF: {5F8A33E7-6A32-4EE0-887A-134C627CB052} (Easy Upload Tool Combo Control) - http://sridharpatturu.myphotoalbum.com/EasyUploadTool.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1120406532343
O16 - DPF: {7114683A-020D-4D16-80FD-6ACE384B66DF} (FarPoint Spread 7.0 (OLEDB)) - https://qaive.cwinsider.com/,DanaInfo=.aahq…ava+fpspr70.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {90051A81-3018-4826-8B38-DD60B6B53F9C} (Snapfish File Upload ActiveX Control) - http://www.costcophotocenter.com/CostcoUpload.cab
O16 - DPF: {95EEE69E-27B4-4D13-BD32-766617A16909} (NDTVVideo.MPlayer) - http://www.ndtv.com/video/NDTVseekvideo.CAB
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.35mb.com/applet.cab
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O16 - DPF: {C915801D-6F00-49CD-8A9A-8DE5C11ADDC1} (Pixami Drag/Drop Upload UI Control) - http://www.photoworks.com/pixami/DragDropUploader.cab
O16 - DPF: {E2454650-4D87-11D2-B8B2-0000C00A958C} (FarPoint Spread 3.0) - https://www.cwinsider.com/cwi/spr32x30.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O22 - SharedTaskScheduler: falsism - {6e886df7-914d-48f0-86b3-a5cf24385361} - D:\WINDOWS\system32\fwrkqfl.dll (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVSync Manager (AvSynMgr) - Unknown owner - D:\Program Files\Network Associates\VirusScan\avsynmgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - D:\WINDOWS\System32\CTSvcCDA.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - D:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Google Updater Service (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McShield - Unknown owner - D:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
O23 - Service: NBService - Nero AG - D:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - D:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

–
End of file - 12113 bytes
Hi Sridhar Patturu and welcome to the forums.

NOTE: I closed your other post. Please only make one post for help and follow my instructions below for continuing this fix.

My name is Dave. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can sometimes take a while to research so please be patient and I'd be grateful if you would note the following:
  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

——————————————————-

We are going to use HJT to create a list of your currently installed programs.1. Open HijackThis and click on the Config… button in the "Other stuff" section (lower right hand corner).
2. Click on the Misc Tools button.
3. Click on the Open Uninstall Manager… button.
4. Click on the Save list… button.
5. Save the file uninstall_list.txt to a convinient location. This should open Notepad with the list.
6. Please Copy and Paste the list into your next reply.
——————————————————–

Please download SmitfraudFix (by S!Ri) to your Desktop.

Double-click SmitfraudFix.exe
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.

**If the tool fails to launch from the Desktop, please move SmitfraudFix.exe directly to the root of the system drive (usually C:), and launch from there.


Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
http://www.beyondlogic.org/consulting/proc…processutil.htm
Hi Dave, Here the list i copied and pasted from the uninstall_list.txt from the Hijack tool: and later below i also pasted the list after running the smitfraudfix file. And Also i Apologize for not posting the thread in the right forum initially. Thank you once again, and really appreciate the help and time. Adobe Acrobat 5.0 Adobe Flash Player 9 ActiveX All Sound Recorder XP 2.10 Apple Software Update ArcSoft PhotoImpression 3.0 AVG 7.5 BitTornado 0.3.7 Citrix ICA Web Client DivX DivX Content Uploader DivX Player DivX Web Player DVD Decrypter (Remove Only) DVD Shrink 3.2 EPSON Printer Software FileZilla (remove only) Gadwin PrintScreen Google Talk (remove only) Google Toolbar for Internet Explorer Google Toolbar for Internet Explorer Google Video Player HijackThis 2.0.2 HTML Guardian 7 HTMLProtector IExplorer Security Plug-in Image Transfer Intel® 82845G Graphics Driver Software Intel® PRO Ethernet Adapter and Software Internet Explorer Secure Bar iPass J2SE Runtime Environment 5.0 Update 10 J2SE Runtime Environment 5.0 Update 11 Java™ SE Runtime Environment 6 Update 1 Joost ™ 0.10.8 LiveReg (Symantec Corporation) LiveUpdate 1.6 (Symantec Corporation) Macromedia Extension Manager Macromedia Flash Player 8 Macromedia Flash Player 8 Plugin McAfee VirusScan 4.5.1 - Home Version Messenger Service Microsoft Data Access Components KB870669 Microsoft Office XP Professional with FrontPage Microsoft SQL Server 2000 Microsoft SQL Server Desktop Engine Microsoft Visual Studio 6.0 Enterprise Edition Microsoft Web Publishing Wizard 1.53 Mozilla Firefox (2.0.0.6) MSN Messenger 7.5 MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) My DSC Nero - Burning Rom Nero 7 Essentials neroxml Nortel Networks Contivity VPN Client Picasa 2 PowerDVD QuickTime RealPlayer Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 10 (KB936782) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB883939) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896422) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896424) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB896688) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899588) Security Update for Windows XP (KB899589) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB903235) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB905915) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB908531) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911567) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB912812) Security Update for Windows XP (KB912919) Security Update for Windows XP (KB913446) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB916281) Security Update for Windows XP (KB917159) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917422) Security Update for Windows XP (KB917537) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB918899) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920214) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921398) Security Update for Windows XP (KB921503) Security Update for Windows XP (KB921883) Security Update for Windows XP (KB922616) Security Update for Windows XP (KB922760) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB923694) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924191) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925454) Security Update for Windows XP (KB925486) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926255) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928090) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB929123) Security Update for Windows XP (KB929969) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931768) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB932168) Security Update for Windows XP (KB933566) Security Update for Windows XP (KB935839) Security Update for Windows XP (KB935840) Security Update for Windows XP (KB936021) Security Update for Windows XP (KB937143) Security Update for Windows XP (KB938127) Security Update for Windows XP (KB938829) Security Update for Windows XP (KB939373) Skype (BETA) SnagIt 8 Sony USB Driver Sound Blaster PCI TextPad 4.7 Update for Windows XP (KB894391) Update for Windows XP (KB896727) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB910437) Update for Windows XP (KB911280) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Update for Windows XP (KB927891) Update for Windows XP (KB929338) Update for Windows XP (KB930916) Update for Windows XP (KB931836) Update for Windows XP (KB936357) Update for Windows XP (KB938828) VideoLAN VLC media player 0.8.6a Viewpoint Manager (Remove Only) Viewpoint Media Player WebSecureAlert Windows Genuine Advantage v1.3.0254.0 Windows Installer 3.1 (KB893803) Windows Installer 3.1 (KB893803) Windows Media Format Runtime Windows Media Player 10 Windows Safety Alert Windows XP Hotfix - KB834707 Windows XP Hotfix - KB867282 Windows XP Hotfix - KB873333 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885250 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB885884 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB887742 Windows XP Hotfix - KB888113 Windows XP Hotfix - KB888240 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890047 Windows XP Hotfix - KB890175 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB890923 Windows XP Hotfix - KB891781 Windows XP Hotfix - KB893066 Windows XP Hotfix - KB893086 Windows XP Service Pack 2 WinRAR archiver WinZip WSEM Update XoftSpySE Yahoo! Browser Services Yahoo! Mail Yahoo! Messenger Yahoo! Photos Easy Upload Tool Yahoo! Photos Print-at-Home Tool ********************************** SmitFraudFix v2.215 Scan done at 18:43:09.56, Wed 08/22/2007 Run from D:\Documents and Settings\Sridhar\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in normal mode »»»»»»»»»»»»»»»»»»»»»»»» Process D:\WINDOWS\System32\smss.exe D:\WINDOWS\system32\winlogon.exe D:\WINDOWS\system32\services.exe D:\WINDOWS\system32\lsass.exe D:\WINDOWS\system32\svchost.exe D:\WINDOWS\System32\svchost.exe D:\WINDOWS\system32\spoolsv.exe D:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe D:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe D:\Program Files\Network Associates\VirusScan\avsynmgr.exe D:\WINDOWS\system32\cisvc.exe D:\WINDOWS\System32\CTSvcCDA.exe D:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe D:\WINDOWS\system32\inetsrv\inetinfo.exe D:\WINDOWS\System32\svchost.exe D:\Program Files\Network Associates\VirusScan\VsStat.exe D:\Program Files\Network Associates\VirusScan\Vshwin32.exe D:\Program Files\Common Files\Network Associates\McShield\mcshield.exe D:\Program Files\Network Associates\VirusScan\Webscanx.exe D:\Program Files\Network Associates\VirusScan\Avconsol.exe D:\WINDOWS\Explorer.EXE D:\Program Files\Video ActiveX Access\iesmn.exe D:\Program Files\Video ActiveX Access\imsmain.exe D:\PROGRA~1\Grisoft\AVG7\avgcc.exe D:\Program Files\Java\jre1.6.0_01\bin\jusched.exe D:\Program Files\QuickTime\qttask.exe D:\Program Files\Picasa2\PicasaMediaDetector.exe D:\Program Files\Video ActiveX Access\imsmn.exe D:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe D:\Program Files\Video ActiveX Access\iesmin.exe D:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe D:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe D:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe D:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe D:\WINDOWS\System32\mdm.exe D:\Program Files\Internet Explorer\iexplore.exe D:\WINDOWS\system32\cidaemon.exe D:\WINDOWS\system32\cidaemon.exe D:\WINDOWS\system32\notepad.exe D:\WINDOWS\system32\notepad.exe D:\WINDOWS\system32\cmd.exe »»»»»»»»»»»»»»»»»»»»»»»» hosts »»»»»»»»»»»»»»»»»»»»»»»» D:\ »»»»»»»»»»»»»»»»»»»»»»»» D:\WINDOWS »»»»»»»»»»»»»»»»»»»»»»»» D:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» D:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» D:\WINDOWS\system32 »»»»»»»»»»»»»»»»»»»»»»»» D:\WINDOWS\system32\LogFiles »»»»»»»»»»»»»»»»»»»»»»»» D:\Documents and Settings\Sridhar »»»»»»»»»»»»»»»»»»»»»»»» D:\Documents and Settings\Sridhar\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Start Menu D:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url FOUND ! D:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» D:\DOCUME~1\Sridhar\FAVORI~1 D:\DOCUME~1\Sridhar\FAVORI~1\Online Security Test.url FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» Desktop D:\DOCUME~1\ALLUSE~1\Desktop\Online Security Guide.url FOUND ! D:\DOCUME~1\ALLUSE~1\Desktop\Security Troubleshooting.url FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» D:\Program Files D:\Program Files\Video ActiveX Access\ FOUND ! D:\Program Files\VirusProtectPro 3.7\ FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{6e886df7-914d-48f0-86b3-a5cf24385361}"="falsism" [HKEY_CLASSES_ROOT\CLSID\{6e886df7-914d-48f0-86b3-a5cf24385361}\InProcServer32] @="D:\WINDOWS\system32\fwrkqfl.dll" [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{6e886df7-914d-48f0-86b3-a5cf24385361}\InProcServer32] @="D:\WINDOWS\system32\fwrkqfl.dll" »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="" »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» Rustock »»»»»»»»»»»»»»»»»»»»»»»» DNS Description: Intel® PRO/100 VE Network Connection - Packet Scheduler Miniport DNS Server Search Order: 66.75.164.90 DNS Server Search Order: 66.75.164.89 HKLM\SYSTEM\CCS\Services\Tcpip\..\{BA1B954C-5EF6-44E8-A003-CA3EA25D6EE1}: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS1\Services\Tcpip\..\{BA1B954C-5EF6-44E8-A003-CA3EA25D6EE1}: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS3\Services\Tcpip\..\{BA1B954C-5EF6-44E8-A003-CA3EA25D6EE1}: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End
Running the Clean
Download AVG Anti-Spyware from Here and save that file to your
desktop.
This is a 30 day trial of the program
  • Once you have downloaded AVG anti-spyware, locate the icon on the desktop
    and double-click it to launch the set up program.
  • Once the setup is complete you will need run AVG Anti-Spyware and update the definition
    files.
  • On the main screen select the icon "Update" then select the "
    Update now
    " link.
    • Next select the "Start Update" button, the update will start and a
      progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of
    the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then
    select "Delete".
  • Under "Reports"
    • Select "Do not automatically generate reports"
Close AVG Anti-Spyware, Do Not run a scan just yet, we will shortly.

______________________________

Warning: running option #2 on a non infected computer will remove your Desktop background.


Please print out or copy these instructions/tutorial to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes.

Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
______________________________

Open the SmitfraudFix Folder, then double-click smitfraudfix.cmd file to start the tool.
Select option #2 - Clean by typing 2 and press Enter.
Wait for the tool to complete and disk cleanup to finish.
You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.

[external image: Posted Image]

The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. Reboot in Safe Mode.

The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.
______________________________

Clean out your Temporary Internet files. Proceed like this:
  • Quit Internet Explorer and quit any instances of Windows Explorer.
  • Click Start, click Control Panel, and then double-click Internet Options.
  • On the General tab, click Delete Files under Temporary Internet Files.
  • In the Delete Files dialog box, tick the Delete all offline content check box , and then click OK.
  • On the General tab, click Delete Cookies under Temporary Internet Files, and then click OK.
  • Click on the Programs tab then click the Reset Web Settings button. Click Apply then OK.
  • Click OK.
Next Click Start, click Control Panel and then double-click Display. Click on the Desktop tab, then click the Customize Desktop button. Click on the Web tab. Under Web Pages you should see a checked entry called Security info or something similar. If it is there, select that entry and click the Delete button. Click Ok then Apply and Ok.

Empty the Recycle Bin by right-clicking the Recycle Bin icon on your Desktop, and then clicking Empty Recycle Bin.
______________________________

Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware, and run a full scan.
  • IMPORTANT: Do not open any other windows or
    programs while AVG Anti-Spyware is scanning, it may interfere with the scanning proccess:
  • Lauch AVG Anti-Spyware by double-clicking the icon on your desktop.
  • Select the "Scanner" icon at the top and then the "Scan" tab
    then click on "Complete System Scan".
  • AVG will now begin the scanning process, be patient this may take a little
    time.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all
    actions
    "
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the
    screen and save it as a text file on your Desktop (make sure to remember where you saved that file, this is important).
Close AVG Anti-Spyware and Reboot in Normal Mode.
______________________________

Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #3 - Delete Trusted zone by typing 3 and press Enter
Answer Yes to the question "Restore Trusted Zone ?" by typing
Y and hit Enter.

Note, if you use SpywareBlaster and/or IE-SPYAD, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE-SPYAD, run the batch file and reinstall the protection.
______________________________

Please post:
1.c:\rapport.txt
2.AVG Anti-Spyware log
3.A new HijackThis log

Your may need several replies to post the requested logs, otherwise they might get cut off.
Hi Dave, Here are the results from rapport.txt… SmitFraudFix v2.215 Scan done at 21:36:03.26, Wed 08/22/2007 Run from D:\Documents and Settings\All Users\Documents\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in safe mode »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{6e886df7-914d-48f0-86b3-a5cf24385361}"="falsism" [HKEY_CLASSES_ROOT\CLSID\{6e886df7-914d-48f0-86b3-a5cf24385361}\InProcServer32] @="D:\WINDOWS\system32\fwrkqfl.dll" [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{6e886df7-914d-48f0-86b3-a5cf24385361}\InProcServer32] @="D:\WINDOWS\system32\fwrkqfl.dll" »»»»»»»»»»»»»»»»»»»»»»»» Killing process »»»»»»»»»»»»»»»»»»»»»»»» hosts 127.0.0.1 localhost »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix GenericRenosFix by S!Ri »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files D:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url Deleted D:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url Deleted D:\DOCUME~1\ALLUSE~1\Desktop\Online Security Guide.url Deleted D:\DOCUME~1\ALLUSE~1\Desktop\Security Troubleshooting.url Deleted D:\Program Files\Video ActiveX Access\ Deleted D:\Program Files\VirusProtectPro 3.7\ Deleted »»»»»»»»»»»»»»»»»»»»»»»» DNS HKLM\SYSTEM\CCS\Services\Tcpip\..\{BA1B954C-5EF6-44E8-A003-CA3EA25D6EE1}: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS1\Services\Tcpip\..\{BA1B954C-5EF6-44E8-A003-CA3EA25D6EE1}: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS3\Services\Tcpip\..\{BA1B954C-5EF6-44E8-A003-CA3EA25D6EE1}: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning Registry Cleaning done. »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{6e886df7-914d-48f0-86b3-a5cf24385361}"="falsism" [HKEY_CLASSES_ROOT\CLSID\{6e886df7-914d-48f0-86b3-a5cf24385361}\InProcServer32] @="D:\WINDOWS\system32\fwrkqfl.dll" [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{6e886df7-914d-48f0-86b3-a5cf24385361}\InProcServer32] @="D:\WINDOWS\system32\fwrkqfl.dll" »»»»»»»»»»»»»»»»»»»»»»»» End
Hi Dave, following is the AVG spyware log: ——————————————————— AVG Anti-Spyware - Scan Report ——————————————————— + Created at: 11:30:01 PM 8/22/2007 + Scan result: C:\System Volume Information\_restore{A0F0FBCB-DA79-43B5-A72F-0F9A25988E3C}\RP1\A0000328.exe -> Heuristic.Win32.Dialer : Cleaned. D:\Program Files\iPass\iPassConnect\idialer.exe -> Heuristic.Win32.Dialer : Cleaned. ::Report end
Hi Dave, Here is the new HijackThis log: Adobe Acrobat 5.0 Adobe Flash Player 9 ActiveX All Sound Recorder XP 2.10 Apple Software Update ArcSoft PhotoImpression 3.0 AVG 7.5 AVG Anti-Spyware 7.5 BitTornado 0.3.7 Citrix ICA Web Client DivX DivX Content Uploader DivX Player DivX Web Player DVD Decrypter (Remove Only) DVD Shrink 3.2 EPSON Printer Software FileZilla (remove only) Gadwin PrintScreen Google Talk (remove only) Google Toolbar for Internet Explorer Google Toolbar for Internet Explorer Google Video Player HijackThis 2.0.2 HTML Guardian 7 HTMLProtector Image Transfer Intel® 82845G Graphics Driver Software Intel® PRO Ethernet Adapter and Software iPass J2SE Runtime Environment 5.0 Update 10 J2SE Runtime Environment 5.0 Update 11 Java™ SE Runtime Environment 6 Update 1 Joost ™ 0.10.8 LiveReg (Symantec Corporation) LiveUpdate 1.6 (Symantec Corporation) Macromedia Extension Manager Macromedia Flash Player 8 Macromedia Flash Player 8 Plugin McAfee VirusScan 4.5.1 - Home Version Microsoft Data Access Components KB870669 Microsoft Office XP Professional with FrontPage Microsoft SQL Server 2000 Microsoft SQL Server Desktop Engine Microsoft Visual Studio 6.0 Enterprise Edition Microsoft Web Publishing Wizard 1.53 Mozilla Firefox (2.0.0.6) MSN Messenger 7.5 MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) My DSC Nero - Burning Rom Nero 7 Essentials neroxml Nortel Networks Contivity VPN Client Picasa 2 PowerDVD QuickTime RealPlayer Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 10 (KB936782) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB883939) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896422) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896424) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB896688) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899588) Security Update for Windows XP (KB899589) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB903235) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB905915) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB908531) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911567) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB912812) Security Update for Windows XP (KB912919) Security Update for Windows XP (KB913446) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB916281) Security Update for Windows XP (KB917159) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917422) Security Update for Windows XP (KB917537) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB918899) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920214) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921398) Security Update for Windows XP (KB921503) Security Update for Windows XP (KB921883) Security Update for Windows XP (KB922616) Security Update for Windows XP (KB922760) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB923694) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924191) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925454) Security Update for Windows XP (KB925486) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926255) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928090) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB929123) Security Update for Windows XP (KB929969) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931768) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB932168) Security Update for Windows XP (KB933566) Security Update for Windows XP (KB935839) Security Update for Windows XP (KB935840) Security Update for Windows XP (KB936021) Security Update for Windows XP (KB937143) Security Update for Windows XP (KB938127) Security Update for Windows XP (KB938829) Security Update for Windows XP (KB939373) Skype (BETA) SnagIt 8 Sony USB Driver Sound Blaster PCI TextPad 4.7 Update for Windows XP (KB894391) Update for Windows XP (KB896727) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB910437) Update for Windows XP (KB911280) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Update for Windows XP (KB927891) Update for Windows XP (KB929338) Update for Windows XP (KB930916) Update for Windows XP (KB931836) Update for Windows XP (KB936357) Update for Windows XP (KB938828) VideoLAN VLC media player 0.8.6a Viewpoint Manager (Remove Only) Viewpoint Media Player WebSecureAlert Windows Genuine Advantage v1.3.0254.0 Windows Installer 3.1 (KB893803) Windows Installer 3.1 (KB893803) Windows Media Format Runtime Windows Media Player 10 Windows XP Hotfix - KB834707 Windows XP Hotfix - KB867282 Windows XP Hotfix - KB873333 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885250 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB885884 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB887742 Windows XP Hotfix - KB888113 Windows XP Hotfix - KB888240 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890047 Windows XP Hotfix - KB890175 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB890923 Windows XP Hotfix - KB891781 Windows XP Hotfix - KB893066 Windows XP Hotfix - KB893086 Windows XP Service Pack 2 WinRAR archiver WinZip WSEM Update XoftSpySE Yahoo! Browser Services Yahoo! Mail Yahoo! Messenger Yahoo! Photos Easy Upload Tool Yahoo! Photos Print-at-Home Tool
Hi Sridhar, Good job! The last log you gave me for HJT was the installed programs, which does not hurt, but I need the HJT log. Like the first one you initially posted.
Hi Dave,


Sorry for that, here is the scan Log file from Hijackthis…and also i did a system scan with the avg antispyware and here is the saved report file, i am pasting it after the hijackthis log file………..

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:15:02 AM, on 8/23/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
D:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
D:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
D:\Program Files\Network Associates\VirusScan\avsynmgr.exe
D:\WINDOWS\system32\cisvc.exe
D:\WINDOWS\System32\CTSvcCDA.exe
D:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
D:\WINDOWS\system32\inetsrv\inetinfo.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Network Associates\VirusScan\VsStat.exe
D:\Program Files\Network Associates\VirusScan\Vshwin32.exe
D:\Program Files\Network Associates\VirusScan\Avconsol.exe
D:\Program Files\Network Associates\VirusScan\Webscanx.exe
D:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
D:\PROGRA~1\Grisoft\AVG7\avgcc.exe
D:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
D:\Program Files\QuickTime\qttask.exe
D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
D:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
D:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
D:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
D:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
D:\WINDOWS\System32\mdm.exe
D:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
D:\WINDOWS\system32\cidaemon.exe
D:\WINDOWS\system32\cidaemon.exe
D:\PROGRA~1\Grisoft\AVG7\avgw.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - D:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - D:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - D:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar3.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - D:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O4 - HKLM\..\Run: [CMESys] "D:\Program Files\Common Files\CMEII\CMESys.exe"
O4 - HKLM\..\Run: [AVG7_CC] D:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] D:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Picasa Media Detector] D:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [EPSON Stylus Photo 825] D:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /A "D:\WINDOWS\system32\E_S494.tmp"
O4 - HKCU\..\Run: [Yahoo! Pager] "D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Skype] "D:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "D:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [swg] D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] D:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] D:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] D:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] D:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: GStartup.lnk = D:\Program Files\Common Files\GMT\GMT.exe
O4 - Global Startup: Image Transfer.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Service Manager.lnk = D:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: WebSecureAlert.lnk = D:\Program Files\WebSecureAlert\WebSecureAlert.exe
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Yahoo;! Search - file:///D:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary; - file:///D:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps; - file:///D:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS; - file:///D:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - D:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - D:\PROGRA~1\Yahoo!\MESSEN~1\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - D:\PROGRA~1\Yahoo!\MESSEN~1\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: D:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: YExplorer1_8US.CAB - http://photos.groups.yahoo.com/ocx/us/yexplorer1_8us.cab
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - https://components.viewpoint.com/MTSInstall…l?noreloadredir
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.35mb.com/applet/applet_l.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540000} (CInstall Class) - http://www.spywarestormer.com/files2/Install.cab
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540006} (CInstall Class) - http://www.errorguard.com/installation/Install.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - D:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://inotes.cwinsider.com/mailrm02/iNotes6W.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.snapfish.com/SnapfishActivia.cab
O16 - DPF: {42F2C9BA-614F-47C0-B3E3-ECFD34EED658} - http://static.35mb.com/applet/applet_y.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/09c86d4cad8ebe…ip/RdxIE601.cab
O16 - DPF: {5F8A33E7-6A32-4EE0-887A-134C627CB052} (Easy Upload Tool Combo Control) - http://sridharpatturu.myphotoalbum.com/EasyUploadTool.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1120406532343
O16 - DPF: {7114683A-020D-4D16-80FD-6ACE384B66DF} (FarPoint Spread 7.0 (OLEDB)) - https://qaive.cwinsider.com/,DanaInfo=.aahq…ava+fpspr70.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {90051A81-3018-4826-8B38-DD60B6B53F9C} (Snapfish File Upload ActiveX Control) - http://www.costcophotocenter.com/CostcoUpload.cab
O16 - DPF: {95EEE69E-27B4-4D13-BD32-766617A16909} (NDTVVideo.MPlayer) - http://www.ndtv.com/video/NDTVseekvideo.CAB
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.35mb.com/applet.cab
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O16 - DPF: {C915801D-6F00-49CD-8A9A-8DE5C11ADDC1} (Pixami Drag/Drop Upload UI Control) - http://www.photoworks.com/pixami/DragDropUploader.cab
O16 - DPF: {E2454650-4D87-11D2-B8B2-0000C00A958C} (FarPoint Spread 3.0) - https://www.cwinsider.com/cwi/spr32x30.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVSync Manager (AvSynMgr) - Unknown owner - D:\Program Files\Network Associates\VirusScan\avsynmgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - D:\WINDOWS\System32\CTSvcCDA.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - D:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Google Updater Service (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McShield - Unknown owner - D:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
O23 - Service: NBService - Nero AG - D:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - D:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

–
End of file - 10902 bytes

***********************************

AVG-Antispyware saved report….

———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 8:00:34 AM 8/23/2007

+ Scan result:



D:\Documents and Settings\Sridhar\Cookies\sridhar@advertising[1].txt -> TrackingCookie.Advertising : Cleaned.
D:\Documents and Settings\Sridhar\Cookies\sridhar@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
D:\Documents and Settings\Sridhar\Cookies\sridhar@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
D:\Documents and Settings\Sridhar\Cookies\sridhar@linksynergy[2].txt -> TrackingCookie.Linksynergy : Cleaned.
D:\Documents and Settings\Sridhar\Cookies\[removed][2].txt -> TrackingCookie.Netflame : Cleaned.


::Report end
Hi Sridhar,

OK some cleanup to do along with a note about your Antivirus software(s).

It appears you have 2 Antivirus programs running, AVG and McAfee. Is this correct? If so please read the following:

This can cause many issues including system slow down, conflicts, false positives, ect…
You can keep both installed but just use one for real-time scanning and disable the other. The disabled program can still be used for one-time scans. I would recommend uninstalling one of them if you do not intend to keep it updated.

In general you never want to run 2 Anti-Virus or Firewall programs at the same time. Other types of Spyware protection such as Spybot, SpywareBlaster, ect… are usually OK (and recommended) to have multiple programs running for layered protection.

—————————————————————–


STEP 1:

Run HijackThis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

O4 - HKLM\..\Run: [CMESys] "D:\Program Files\Common Files\CMEII\CMESys.exe"
O4 - Global Startup: GStartup.lnk = D:\Program Files\Common Files\GMT\GMT.exe
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - https://components.viewpoint.com/MTSInstall…l?noreloadredir
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.35mb.com/applet/applet_l.cab
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540000} (CInstall Class) - http://www.spywarestormer.com/files2/Install.cab
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540006} (CInstall Class) - http://www.errorguard.com/installation/Install.cab
O16 - DPF: {42F2C9BA-614F-47C0-B3E3-ECFD34EED658} - http://static.35mb.com/applet/applet_y.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/09c86d4cad8ebe…ip/RdxIE601.cab
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.35mb.com/applet.cab

Then close all windows except this one and press Fix checked.


STEP 2:

Using Windows Explorer delete the following folders:

D:\Program Files\Common Files\CMEII
D:\Program Files\Common Files\GMT


STEP 3:

Use ATF Cleaner to remove temp files,
cookies, cache, ect…

Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 onlyDouble-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.


STEP 4:

Using Internet Explorer, click on Kaspersky Online Scanner * You will be prompted to install an ActiveX component from Kaspersky, Click 'Yes'.
* The program will launch and then start to download the latest definition files.
* Once the scanner is installed and the definitions downloaded, click 'Next'.
* Now click on 'Scan Settings'
* In the scan settings make sure that the following are selected:
o Scan using the following Anti-Virus database: 'Extended' (If available, otherwise 'Standard')
o Scan Options: 'Scan Archives' and 'Scan Mail Bases'
* Click 'OK'
* Now under 'Select a target to scan' select 'My Computer'
* The scan will take a while, so be patient and let it run. Once the scan is complete, it will display whether your system has been infected.
* Now click on the 'Save as Text' button:
* Save the file to your desktop.
Please post the Kaspersky report and a new HijackThis log.
Hi Dave, Here is the kaspersky report: KASPERSKY ONLINE SCANNER REPORT Thursday, August 23, 2007 12:38:24 PM Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.93.0 Kaspersky Anti-Virus database last update: 23/08/2007 Kaspersky Anti-Virus database records: 388315 Scan Settings Scan using the following antivirus database extended Scan Archives true Scan Mail Bases true Scan Target My Computer A:\ C:\ D:\ E:\ F:\ Scan Statistics Total number of scanned objects 106045 Number of viruses found 14 Number of infected objects 39 Number of suspicious objects 2 Duration of the scan process 01:41:22 Infected Object Name Virus Name Last Action C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\511a0f3f9e960fa97de3d0b74adfc574_4527ab2a-f130-4746-b578-39d36911a6c3 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\75ea560707031c0dbf694f5898f8c4d6_4527ab2a-f130-4746-b578-39d36911a6c3 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\91efb0bef66695a1f2788ab35efd203a_4527ab2a-f130-4746-b578-39d36911a6c3 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a037f90e458ba50cddcc053baacdcfc3_4527ab2a-f130-4746-b578-39d36911a6c3 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f813be0ac1d9fe55607a32df478c2dd1_4527ab2a-f130-4746-b578-39d36911a6c3 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped C:\Documents and Settings\Shridhar\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst/Personal Folders/Inbox/19 Jun 2000 09:53 from Ramineni Praveen Kumar:Praveen here/gameofthecentury.exe Infected: not-virus:BadJoke.Win32.JepRuss skipped C:\Documents and Settings\Shridhar\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst/Personal Folders/Inbox/21 Aug 2000 04:23 from Viswanadham Mehar Surya Nagendra Sriram:T/Wow.exe Infected: not-virus:BadJoke.Win32.FakeFormat.105 skipped C:\Documents and Settings\Shridhar\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst/Personal Folders/Inbox/19 Apr 2001 08:20 from Srinivasa Rao Karanati:FW: [We2One] enjoy/YAMAHA.EXE Infected: not-virus:BadJoke.Win32.Train skipped C:\Documents and Settings\Shridhar\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst/Personal Folders/Inbox/18 Apr 2001 17:28 from Viswanadham Mehar Surya Nagendra Sriram:/yamaha.exe Infected: not-virus:BadJoke.Win32.Train skipped C:\Documents and Settings\Shridhar\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst/Personal Folders/Inbox/26 Jul 2001 09:17 from Ramprasad Venkata Inala:Guess what wood h/Cool.exe Infected: Trojan.Win32.Bingo skipped C:\Documents and Settings\Shridhar\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst/Personal Folders/Inbox/11 Apr 2002 05:57 from Sadagobane Anand: please read the note an/Haunt.zip/Haunt/Haunt.exe/hauntpc.exe Infected: not-virus:BadJoke.Win32.Hauntpc skipped C:\Documents and Settings\Shridhar\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst/Personal Folders/Inbox/11 Apr 2002 05:57 from Sadagobane Anand: please read the note an/Haunt.zip/Haunt/Haunt.exe Infected: not-virus:BadJoke.Win32.Hauntpc skipped C:\Documents and Settings\Shridhar\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst/Personal Folders/Inbox/11 Apr 2002 05:57 from Sadagobane Anand: please read the note an/Haunt.zip Infected: not-virus:BadJoke.Win32.Hauntpc skipped C:\Documents and Settings\Shridhar\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst/Personal Folders/Inbox/28 Mar 2002 04:15 from Sadagobane Anand: Good one/good-1.exe Infected: not-virus:BadJoke.Win32.Bounce skipped C:\Documents and Settings\Shridhar\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst/Personal Folders/Inbox/29 Apr 2002 11:07 from shivu9:SBI or IDBI.rtf Suspicious: Exploit.HTML.Iframe.FileDownload skipped C:\Documents and Settings\Shridhar\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst Mail MS Mail: infected - 9, suspicious - 1 skipped C:\Program Files\Comet Systems\dm\bin\dmproxy.dll Infected: not-a-virus:AdWare.Win32.Comet.e skipped C:\Program Files\Common Files\CMEII\apps\DateManager\datemanager3000.zip/InstallDateManager.exe/WISE0012.BIN Infected: not-a-virus:AdWare.Win32.Gator.3010 skipped C:\Program Files\Common Files\CMEII\apps\DateManager\datemanager3000.zip/InstallDateManager.exe Infected: not-a-virus:AdWare.Win32.Gator.3010 skipped C:\Program Files\Common Files\CMEII\apps\DateManager\datemanager3000.zip ZIP: infected - 2 skipped C:\Program Files\Common Files\GMT\EGGCEngine.dll Infected: not-a-virus:AdWare.Win32.Gator.6041 skipped C:\Program Files\mt.html Infected: not-a-virus:AdWare.Win32.MediaTickets.e skipped C:\System Volume Information\catalog.wci\000002.ps1 Object is locked skipped C:\System Volume Information\catalog.wci\000002.ps2 Object is locked skipped C:\System Volume Information\catalog.wci\01000D.ci Object is locked skipped C:\System Volume Information\catalog.wci\cicat.fid Object is locked skipped C:\System Volume Information\catalog.wci\cicat.hsh Object is locked skipped C:\System Volume Information\catalog.wci\CiCL0001.000 Object is locked skipped C:\System Volume Information\catalog.wci\CiP10000.000 Object is locked skipped C:\System Volume Information\catalog.wci\CiP20000.000 Object is locked skipped C:\System Volume Information\catalog.wci\CiPT0000.000 Object is locked skipped C:\System Volume Information\catalog.wci\CiSL0001.000 Object is locked skipped C:\System Volume Information\catalog.wci\CiSP0000.000 Object is locked skipped C:\System Volume Information\catalog.wci\CiST0000.000 Object is locked skipped C:\System Volume Information\catalog.wci\CiVP0000.000 Object is locked skipped C:\System Volume Information\catalog.wci\INDEX.000 Object is locked skipped C:\System Volume Information\catalog.wci\propstor.bk1 Object is locked skipped C:\System Volume Information\catalog.wci\propstor.bk2 Object is locked skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{A0F0FBCB-DA79-43B5-A72F-0F9A25988E3C}\RP1\A0000089.exe/WISE0012.BIN Infected: not-a-virus:AdWare.Win32.Gator.3010 skipped C:\System Volume Information\_restore{A0F0FBCB-DA79-43B5-A72F-0F9A25988E3C}\RP1\A0000089.exe WiseSFX: infected - 1 skipped C:\System Volume Information\_restore{A0F0FBCB-DA79-43B5-A72F-0F9A25988E3C}\RP1\A0000089.exe WiseSFX Dropper: infected - 1 skipped D:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped D:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys81521bec6864be434b2f6cb82208a8c_78b29fd3-19ea-45be-ac6d-826ec15a7467 Object is locked skipped D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeysa6ce8bc1c2e1e382c487ddb56ea792d_78b29fd3-19ea-45be-ac6d-826ec15a7467 Object is locked skipped D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\17afc90b1691e97a3d14dc31d294b71e_78b29fd3-19ea-45be-ac6d-826ec15a7467 Object is locked skipped D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\219d21119b94aba237d7e3ea36a00251_78b29fd3-19ea-45be-ac6d-826ec15a7467 Object is locked skipped D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2ccbda0d354015c177f42ff7d1671877_78b29fd3-19ea-45be-ac6d-826ec15a7467 Object is locked skipped D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2edad5cd861999e09c368cac15e65d37_78b29fd3-19ea-45be-ac6d-826ec15a7467 Object is locked skipped D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\34bbc3ec93312101cd2d5faeb72a180b_78b29fd3-19ea-45be-ac6d-826ec15a7467 Object is locked skipped D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3f67689972c6b87bb706bfa401a9a149_78b29fd3-19ea-45be-ac6d-826ec15a7467 Object is locked skipped D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4ea262a5e0a738c941b8877d87adbba8_78b29fd3-19ea-45be-ac6d-826ec15a7467 Object is locked skipped D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4eca6d6b145bc00b88b9cd9c6f166d18_78b29fd3-19ea-45be-ac6d-826ec15a7467 Object is locked skipped D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5983ae02be4da603d1cdd462f5fe003b_78b29fd3-19ea-45be-ac6d-826ec15a7467 Object is locked skipped D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\777fba3e0992d49582801e274b10db6b_78b29fd3-19ea-45be-ac6d-826ec15a7467 Object is locked skipped D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\77f925cac6be33ee0fe3fb37c239ae03_78b29fd3-19ea-45be-ac6d-826ec15a7467 Object is locked skipped D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8795aa893d18ed26e9d47cea9e2d7674_78b29fd3-19ea-45be-ac6d-826ec15a7467 Object is locked skipped D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bd1847994f0350e0fe02f80a9281d908_78b29fd3-19ea-45be-ac6d-826ec15a7467 Object is locked skipped D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e46eac32efc3101f65b87aa43d365f93_78b29fd3-19ea-45be-ac6d-826ec15a7467 Object is locked skipped D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e5a4f3763d5763bfc49b73de675179b6_78b29fd3-19ea-45be-ac6d-826ec15a7467 Object is locked skipped D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e648a8a9c83b01267c194c6b0b7ce02a_78b29fd3-19ea-45be-ac6d-826ec15a7467 Object is locked skipped D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\eb0a0a8e32d876b73fce31aaa6003704_78b29fd3-19ea-45be-ac6d-826ec15a7467 Object is locked skipped D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fa496b2063d1460f14ac430a4ad63709_78b29fd3-19ea-45be-ac6d-826ec15a7467 Object is locked skipped D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fc7d91f8ab4e83d98b2daa90a5311511_78b29fd3-19ea-45be-ac6d-826ec15a7467 Object is locked skipped D:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fda5630df8bb35a39c3e900e514dbb08_78b29fd3-19ea-45be-ac6d-826ec15a7467 Object is locked skipped D:\Documents and Settings\All Users\Documents\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped D:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped D:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped D:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped D:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped D:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped D:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped D:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped D:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped D:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped D:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped D:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped D:\Documents and Settings\Sridhar\Cookies\index.dat Object is locked skipped D:\Documents and Settings\Sridhar\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped D:\Documents and Settings\Sridhar\Desktop\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped D:\Documents and Settings\Sridhar\Desktop\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped D:\Documents and Settings\Sridhar\Desktop\SmitfraudFix.exe RarSFX: infected - 2 skipped D:\Documents and Settings\Sridhar\Local Settings\Application Data\Ahead\Nero Home\bl.db Object is locked skipped D:\Documents and Settings\Sridhar\Local Settings\Application Data\Ahead\Nero Home\is2.db Object is locked skipped D:\Documents and Settings\Sridhar\Local Settings\Application Data\Identities\{532A1FBD-3853-42C0-BB9E-47825D21A618}\Microsoft\Outlook Express\Folders.dbx Object is locked skipped D:\Documents and Settings\Sridhar\Local Settings\Application Data\Identities\{532A1FBD-3853-42C0-BB9E-47825D21A618}\Microsoft\Outlook Express\Offline.dbx Object is locked skipped D:\Documents and Settings\Sridhar\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped D:\Documents and Settings\Sridhar\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped D:\Documents and Settings\Sridhar\Local Settings\History\History.IE5\index.dat Object is locked skipped D:\Documents and Settings\Sridhar\Local Settings\History\History.IE5\MSHist012007082320070824\index.dat Object is locked skipped D:\Documents and Settings\Sridhar\Local Settings\Temp\Perflib_Perfdata_2ec.dat Object is locked skipped D:\Documents and Settings\Sridhar\Local Settings\Temp\Perflib_Perfdata_b08.dat Object is locked skipped D:\Documents and Settings\Sridhar\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped D:\Documents and Settings\Sridhar\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped D:\Documents and Settings\Sridhar\NTUSER.DAT Object is locked skipped D:\Documents and Settings\Sridhar\ntuser.dat.LOG Object is locked skipped D:\Inetpub\catalog.wci\000002.ps1 Object is locked skipped D:\Inetpub\catalog.wci\000002.ps2 Object is locked skipped D:\Inetpub\catalog.wci\010001.ci Object is locked skipped D:\Inetpub\catalog.wci\cicat.fid Object is locked skipped D:\Inetpub\catalog.wci\cicat.hsh Object is locked skipped D:\Inetpub\catalog.wci\CiCL0001.000 Object is locked skipped D:\Inetpub\catalog.wci\CiP10000.000 Object is locked skipped D:\Inetpub\catalog.wci\CiP20000.000 Object is locked skipped D:\Inetpub\catalog.wci\CiPT0000.000 Object is locked skipped D:\Inetpub\catalog.wci\CiSL0001.000 Object is locked skipped D:\Inetpub\catalog.wci\CiSP0000.000 Object is locked skipped D:\Inetpub\catalog.wci\CiST0000.000 Object is locked skipped D:\Inetpub\catalog.wci\CiVP0000.000 Object is locked skipped D:\Inetpub\catalog.wci\INDEX.000 Object is locked skipped D:\Inetpub\catalog.wci\propstor.bk1 Object is locked skipped D:\Inetpub\catalog.wci\propstor.bk2 Object is locked skipped D:\Kathya\Sree\outlook.pst/Personal Folders/Inbox/19 Jun 2000 09:53 from Ramineni Praveen Kumar:Praveen here/gameofthecentury.exe Infected: not-virus:BadJoke.Win32.JepRuss skipped D:\Kathya\Sree\outlook.pst/Personal Folders/Inbox/21 Aug 2000 04:23 from Viswanadham Mehar Surya Nagendra Sriram:T/Wow.exe Infected: not-virus:BadJoke.Win32.FakeFormat.105 skipped D:\Kathya\Sree\outlook.pst/Personal Folders/Inbox/29 Apr 2002 11:07 from shivu9:SBI or IDBI.rtf Suspicious: Exploit.HTML.Iframe.FileDownload skipped D:\Kathya\Sree\outlook.pst/Personal Folders/Inbox/18 Apr 2001 17:28 from Viswanadham Mehar Surya Nagendra Sriram:/yamaha.exe Infected: not-virus:BadJoke.Win32.Train skipped D:\Kathya\Sree\outlook.pst/Personal Folders/Inbox/19 Apr 2001 08:20 from Srinivasa Rao Karanati:FW: [We2One] enjoy/YAMAHA.EXE Infected: not-virus:BadJoke.Win32.Train skipped D:\Kathya\Sree\outlook.pst/Personal Folders/Inbox/26 Jul 2001 09:17 from Ramprasad Venkata Inala:Guess what wood h/Cool.exe Infected: Trojan.Win32.Bingo skipped D:\Kathya\Sree\outlook.pst/Personal Folders/Inbox/11 Apr 2002 05:57 from Sadagobane Anand: please read the note an/Haunt.zip/Haunt/Haunt.exe/hauntpc.exe Infected: not-virus:BadJoke.Win32.Hauntpc skipped D:\Kathya\Sree\outlook.pst/Personal Folders/Inbox/11 Apr 2002 05:57 from Sadagobane Anand: please read the note an/Haunt.zip/Haunt/Haunt.exe Infected: not-virus:BadJoke.Win32.Hauntpc skipped D:\Kathya\Sree\outlook.pst/Personal Folders/Inbox/11 Apr 2002 05:57 from Sadagobane Anand: please read the note an/Haunt.zip Infected: not-virus:BadJoke.Win32.Hauntpc skipped D:\Kathya\Sree\outlook.pst/Personal Folders/Inbox/28 Mar 2002 04:15 from Sadagobane Anand: Good one/good-1.exe Infected: not-virus:BadJoke.Win32.Bounce skipped D:\Kathya\Sree\outlook.pst Mail MS Mail: infected - 9, suspicious - 1 skipped D:\My Downloads\Nero-7.8.5.0_eng_update.exe/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped D:\My Downloads\Nero-7.8.5.0_eng_update.exe RAR: infected - 1 skipped D:\software\DivXPro511Adware.exe/stream/data0019 Infected: not-a-virus:AdWare.Win32.Gator.3202 skipped D:\software\DivXPro511Adware.exe/stream Infected: not-a-virus:AdWare.Win32.Gator.3202 skipped D:\software\DivXPro511Adware.exe NSIS: infected - 2 skipped D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped D:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped D:\WINDOWS\SchedLgU.Txt Object is locked skipped D:\WINDOWS\SoftwareDistribution\EventCache\{6CA41482-38C8-44F7-A599-D5EF8B66E7D2}.bin Object is locked skipped D:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped D:\WINDOWS\Sti_Trace.log Object is locked skipped D:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped D:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped D:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped D:\WINDOWS\system32\config\default Object is locked skipped D:\WINDOWS\system32\config\default.LOG Object is locked skipped D:\WINDOWS\system32\config\SAM Object is locked skipped D:\WINDOWS\system32\config\SAM.LOG Object is locked skipped D:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped D:\WINDOWS\system32\config\SECURITY Object is locked skipped D:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped D:\WINDOWS\system32\config\software Object is locked skipped D:\WINDOWS\system32\config\software.LOG Object is locked skipped D:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped D:\WINDOWS\system32\config\system Object is locked skipped D:\WINDOWS\system32\config\system.LOG Object is locked skipped D:\WINDOWS\system32\h323log.txt Object is locked skipped D:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped D:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped D:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped D:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped D:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped D:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped D:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped D:\WINDOWS\Temp\WebPoolFileFile Object is locked skipped D:\WINDOWS\wiadebug.log Object is locked skipped D:\WINDOWS\wiaservc.log Object is locked skipped D:\WINDOWS\WindowsUpdate.log Object is locked skipped Scan process completed.
hi Dave,

Below is the hijackthis log file :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:59:42 PM, on 8/23/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
D:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
D:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
D:\Program Files\Network Associates\VirusScan\avsynmgr.exe
D:\WINDOWS\system32\cisvc.exe
D:\WINDOWS\System32\CTSvcCDA.exe
D:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
D:\WINDOWS\system32\inetsrv\inetinfo.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Network Associates\VirusScan\VsStat.exe
D:\Program Files\Network Associates\VirusScan\Vshwin32.exe
D:\Program Files\Network Associates\VirusScan\Avconsol.exe
D:\Program Files\Network Associates\VirusScan\Webscanx.exe
D:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
D:\PROGRA~1\Grisoft\AVG7\avgcc.exe
D:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
D:\Program Files\QuickTime\qttask.exe
D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
D:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
D:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
D:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
D:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
D:\WINDOWS\System32\mdm.exe
D:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
D:\WINDOWS\system32\cidaemon.exe
D:\WINDOWS\system32\cidaemon.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - D:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - D:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - D:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar3.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - D:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O4 - HKLM\..\Run: [AVG7_CC] D:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] D:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Picasa Media Detector] D:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [EPSON Stylus Photo 825] D:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /A "D:\WINDOWS\system32\E_S494.tmp"
O4 - HKCU\..\Run: [Yahoo! Pager] "D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Skype] "D:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "D:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [swg] D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] D:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] D:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] D:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] D:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Image Transfer.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Service Manager.lnk = D:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: WebSecureAlert.lnk = D:\Program Files\WebSecureAlert\WebSecureAlert.exe
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Yahoo! Search - file:///D:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///D:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///D:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///D:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - D:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - D:\PROGRA~1\Yahoo!\MESSEN~1\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - D:\PROGRA~1\Yahoo!\MESSEN~1\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: D:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: YExplorer1_8US.CAB - http://photos.groups.yahoo.com/ocx/us/yexplorer1_8us.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.35mb.com/applet/applet_l.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - D:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://inotes.cwinsider.com/mailrm02/iNotes6W.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.snapfish.com/SnapfishActivia.cab
O16 - DPF: {5F8A33E7-6A32-4EE0-887A-134C627CB052} (Easy Upload Tool Combo Control) - http://sridharpatturu.myphotoalbum.com/EasyUploadTool.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1120406532343
O16 - DPF: {7114683A-020D-4D16-80FD-6ACE384B66DF} (FarPoint Spread 7.0 (OLEDB)) - https://qaive.cwinsider.com/,DanaInfo=.aahq…ava+fpspr70.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {90051A81-3018-4826-8B38-DD60B6B53F9C} (Snapfish File Upload ActiveX Control) - http://www.costcophotocenter.com/CostcoUpload.cab
O16 - DPF: {95EEE69E-27B4-4D13-BD32-766617A16909} (NDTVVideo.MPlayer) - http://www.ndtv.com/video/NDTVseekvideo.CAB
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O16 - DPF: {C915801D-6F00-49CD-8A9A-8DE5C11ADDC1} (Pixami Drag/Drop Upload UI Control) - http://www.photoworks.com/pixami/DragDropUploader.cab
O16 - DPF: {E2454650-4D87-11D2-B8B2-0000C00A958C} (FarPoint Spread 3.0) - https://www.cwinsider.com/cwi/spr32x30.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVSync Manager (AvSynMgr) - Unknown owner - D:\Program Files\Network Associates\VirusScan\avsynmgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - D:\WINDOWS\System32\CTSvcCDA.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - D:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Google Updater Service (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McShield - Unknown owner - D:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
O23 - Service: NBService - Nero AG - D:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - D:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

–
End of file - 9884 bytes
Please download the OTMoveIt by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Program Files\Comet Systems
    C:\Program Files\Common Files\CMEII
    C:\Program Files\Common Files\GMT
    C:\Program Files\mt.html
    D:\software\DivXPro511Adware.exe
  • Return to OTMoveIt, right click on the "Paste List of Files/Folders to be moved" window and choose Paste.
  • Click the red Moveit! button.
  • Copy everything on the Results window to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it on your next reply.
  • Close OTMoveIt
*If a file or folder cannot be moved immediately, you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine, choose Yes.
**If a reboot was necessary or you needed to Exit before posting the log, you will find a copy of the log at the root of the drive where OTMoveIt is installed, usually at :
C:\_OTMoveIt\MovedFiles\********_******.log
(where "********_******" is the "date_time")


Click "Exit" to close OTMoveIt.

You also have several infected emails/attachments in your Outlook inbox folder. These messages I would delete:

19 Jun 2000 09:53 from Ramineni Praveen Kumar:Praveen here/gameofthecentury.exe
21 Aug 2000 04:23 from Viswanadham Mehar Surya Nagendra Sriram:T/Wow.exe
19 Apr 2001 08:20 from Srinivasa Rao Karanati:FW: [We2One] enjoy/YAMAHA.EXE
18 Apr 2001 17:28 from Viswanadham Mehar Surya Nagendra Sriram:/yamaha.exe
26 Jul 2001 09:17 from Ramprasad Venkata Inala:Guess what wood h/Cool.exe
11 Apr 2002 05:57 from Sadagobane Anand: please read the note an/Haunt.zip
11 Apr 2002 05:57 from Sadagobane Anand: please read the note an/Haunt.zip
11 Apr 2002 05:57 from Sadagobane Anand: please read the note an/Haunt.zip
28 Mar 2002 04:15 from Sadagobane Anand: Good/good-1.exe


Other than that your HJT log appears clean. The only thing I still see is 2 Anti-virus programs running.

Post a fresh HJT log and let me know how it's running.
Hi Dave, yes i need to stop one of the anti virus, thank you….here is the log file from OTMove_IT : C:\Program Files\Comet Systems\dm\temp moved successfully. C:\Program Files\Comet Systems\dm\ready moved successfully. C:\Program Files\Comet Systems\dm\input moved successfully. C:\Program Files\Comet Systems\dm\bin moved successfully. C:\Program Files\Comet Systems\dm moved successfully. C:\Program Files\Comet Systems moved successfully. Folder move failed. C:\Program Files\Common Files\CMEII\store\core\syscfg scheduled to be moved on reboot. Folder move failed. C:\Program Files\Common Files\CMEII\store\core\svclist scheduled to be moved on reboot. Folder move failed. C:\Program Files\Common Files\CMEII\store\core\persist scheduled to be moved on reboot. Folder move failed. C:\Program Files\Common Files\CMEII\store\core\locappllist scheduled to be moved on reboot. Folder move failed. C:\Program Files\Common Files\CMEII\store\core\hfixcfg scheduled to be moved on reboot. Folder move failed. C:\Program Files\Common Files\CMEII\store\core\col scheduled to be moved on reboot. Folder move failed. C:\Program Files\Common Files\CMEII\store\core\appllist scheduled to be moved on reboot. C:\Program Files\Common Files\CMEII\store\core moved successfully. C:\Program Files\Common Files\CMEII\store\apps moved successfully. C:\Program Files\Common Files\CMEII\store moved successfully. C:\Program Files\Common Files\CMEII\gui\appmgr moved successfully. C:\Program Files\Common Files\CMEII\gui moved successfully. C:\Program Files\Common Files\CMEII\apps\PrecisionTime moved successfully. C:\Program Files\Common Files\CMEII\apps\DateManager moved successfully. C:\Program Files\Common Files\CMEII\apps moved successfully. C:\Program Files\Common Files\CMEII moved successfully. C:\Program Files\Common Files\GMT\scripts moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gg moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gd moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\9468 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\8921 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\8066 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\8065 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\7898 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\6330 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\6275 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\6271 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\5439 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\5207 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\5097 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24961 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24960 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24959 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24958 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24935 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24929 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24900 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24897 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24895 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24892 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24850 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24730 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24723 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24722 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24719 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24685 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24683 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24439 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24425 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24411 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24408 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24401 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24397 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24396 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24395 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24394 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24393 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24392 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24390 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24378 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24360 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24358 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24341 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24333 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24322 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24297 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24296 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24290 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24283 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24281 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24267 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24266 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24265 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24264 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24263 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24242 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24239 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24226 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24223 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24222 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24208 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24207 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24202 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24200 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24190 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24182 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24180 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24172 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24170 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24169 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24164 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24162 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24161 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24157 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24156 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24150 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24149 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24148 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24147 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24143 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24135 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24127 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24122 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24115 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24068 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24054 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24035 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24030 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24025 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24021 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24015 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\24006 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23995 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23983 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23977 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23973 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23972 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23964 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23936 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23932 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23927 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23916 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23915 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23902 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23889 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23880 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23879 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23877 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23872 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23856 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23855 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23851 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23843 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23825 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23818 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23771 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23768 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23730 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23728 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23724 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23722 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23718 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23708 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23698 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23615 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23610 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23609 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23608 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23599 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23587 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23576 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23555 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23551 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23518 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23517 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23511 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23498 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23478 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23476 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23470 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23464 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23462 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23428 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23427 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23426 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23411 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23409 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23373 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23372 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23365 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23357 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23356 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23355 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23353 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23323 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23306 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23298 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23289 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23287 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23264 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23247 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23237 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23235 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23218 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23200 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23192 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23181 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23176 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23174 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23152 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23143 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23133 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23130 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23096 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23063 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23056 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23037 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\23007 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22973 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22936 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22934 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22930 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22892 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22847 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22818 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22731 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22730 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22729 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22700 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22699 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22698 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22697 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22688 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22687 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22674 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22653 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22641 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22637 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22630 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22601 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22599 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22582 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22575 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22568 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22554 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22552 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22529 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22518 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22517 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22510 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22509 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22508 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22507 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22477 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22470 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22430 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22416 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22411 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22409 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22346 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22344 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22338 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22336 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22326 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22316 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22306 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22284 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22275 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22255 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22220 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22216 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22215 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22203 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22201 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22199 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22192 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22188 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22174 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22173 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22172 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22126 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22122 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22107 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22095 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22048 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22047 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22046 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\22045 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\21994 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\21977 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\21974 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\21947 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\21864 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\21820 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\21779 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\21690 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\21689 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\21656 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\21654 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\21616 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\21539 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\21532 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\21478 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\21459 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\21411 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\21410 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\21409 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\21408 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\21366 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\21298 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\21283 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\21232 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\21229 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\21158 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\21063 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\21054 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\21038 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\21033 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20927 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20899 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20897 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20875 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20873 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20871 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20852 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20816 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20804 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20790 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20779 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20768 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20640 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20623 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20620 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20601 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20594 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20570 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20569 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20567 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20564 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20558 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20555 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20553 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20552 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20540 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20539 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20488 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20479 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20465 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20454 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20409 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20406 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20402 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20372 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20333 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20301 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20298 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20280 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20226 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20196 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20173 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20118 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20107 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20105 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20096 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20093 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20072 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20070 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20069 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20055 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20041 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20019 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\20008 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\19995 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\19994 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\19991 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\19960 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\19955 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\19842 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\19817 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\19809 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\19807 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\19792 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\19789 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\19746 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\19700 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\19625 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\19624 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\19618 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\19466 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\19419 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\19334 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\19330 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\19325 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\19324 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\19276 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\19216 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\19192 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\19184 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\19164 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\19156 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\19122 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\19077 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\18988 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\18861 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\18846 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\18807 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\18688 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\18630 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\18629 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\18621 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\18620 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\18519 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\18513 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\18477 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\18460 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\18370 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\18369 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\18352 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\18351 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\18350 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\18349 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\18348 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\18347 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\18345 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\18308 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\18108 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\18095 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\18059 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\18043 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\18021 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\17998 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\17997 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\17973 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\17951 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\17840 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\17834 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\17807 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\17774 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\17668 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\17500 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\17486 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\17481 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\17428 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\17369 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\17367 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\17361 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\17321 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\17304 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\17299 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\17285 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\17275 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\17181 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\17172 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\17167 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\17075 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\16997 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\16935 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\16930 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\16928 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\16926 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\16925 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\16921 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\16911 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\16908 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\16903 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\16868 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\16835 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\16811 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\16801 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\16794 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\16777 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\16776 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\16770 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\16768 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\16767 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\16761 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\16759 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\16746 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\16715 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\16698 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\16693 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\16684 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\16666 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\16661 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\16660 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\16542 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\16425 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\16411 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\16410 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\16376 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\16325 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\16316 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\16313 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\16289 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\16265 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\16248 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\16237 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\16235 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\16105 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\16104 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\16040 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15961 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15957 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15936 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15935 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15891 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15878 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15863 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15836 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15823 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15821 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15771 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15741 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15676 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15674 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15662 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15660 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15658 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15656 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15655 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15651 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15649 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15637 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15630 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15531 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15530 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15528 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15496 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15488 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15476 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15449 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15443 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15440 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15418 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15332 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15318 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15317 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15316 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15309 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15299 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15298 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15295 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15290 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15283 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15277 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15214 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15210 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15207 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15205 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15176 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15123 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\15104 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\14982 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\14981 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\14980 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\14791 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\14729 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\14694 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\14683 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\14682 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\14673 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\14672 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\14622 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\14621 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\14617 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\14616 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\14614 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\14613 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\14612 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\14611 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\14610 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\14600 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\14581 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\14579 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\14568 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\14565 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\14372 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\14370 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\14368 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\14312 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\14310 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\14309 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\14014 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\13791 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\13790 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\13789 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\13613 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\13604 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\13603 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\13600 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\13599 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\13597 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\13596 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\13574 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\13572 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\13538 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\13537 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\13536 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\13523 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\13433 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\13342 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\13340 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\13337 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\13273 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\13165 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12972 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12968 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12959 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12958 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12933 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12930 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12928 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12906 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12891 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12888 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12833 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12776 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12766 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12761 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12742 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12741 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12740 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12736 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12735 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12734 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12730 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12724 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12722 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12676 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12580 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12579 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12577 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12549 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12536 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12532 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12528 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12527 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12526 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12519 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12516 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12509 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12503 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12460 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12458 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12439 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12298 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12297 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12259 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12253 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12076 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12071 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12067 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12066 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12064 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\12062 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\11981 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\11887 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\11795 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\11649 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\11637 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\11588 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\11578 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\11571 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\11569 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\11517 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\11510 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\11498 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\11495 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\11493 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\11490 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\11489 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\11487 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\11485 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\11483 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\11480 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\11473 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\11470 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\11469 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\11468 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\11467 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\11466 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\11461 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\11453 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\11364 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\11351 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\11323 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\11300 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\11299 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\11287 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\11283 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\11278 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\11277 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\11255 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\10689 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\10436 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb\10428 moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\gb moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm\ga moved successfully. C:\Program Files\Common Files\GMT\q25vg895cm moved successfully. C:\Program Files\Common Files\GMT\DownloadTemp\accum\GMT moved successfully. C:\Program Files\Common Files\GMT\DownloadTemp\accum moved successfully. C:\Program Files\Common Files\GMT\DownloadTemp moved successfully. C:\Program Files\Common Files\GMT\Data moved successfully. C:\Program Files\Common Files\GMT moved successfully. C:\Program Files\mt.html moved successfully. D:\software\DivXPro511Adware.exe moved successfully. File/Folder not found. Created on 08/23/2007 14:15:16
Hi Dave,

Following is the Hijackthis log file :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:35:20 PM, on 8/23/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
D:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
D:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
D:\Program Files\Network Associates\VirusScan\avsynmgr.exe
D:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
D:\WINDOWS\system32\cisvc.exe
D:\Program Files\QuickTime\qttask.exe
D:\WINDOWS\System32\CTSvcCDA.exe
D:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
D:\WINDOWS\system32\inetsrv\inetinfo.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
D:\Program Files\Network Associates\VirusScan\VsStat.exe
D:\Program Files\Network Associates\VirusScan\Vshwin32.exe
D:\Program Files\Network Associates\VirusScan\Avconsol.exe
D:\Program Files\Network Associates\VirusScan\Webscanx.exe
D:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
D:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
D:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
D:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
D:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
D:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\WINDOWS\System32\mdm.exe
D:\WINDOWS\system32\cidaemon.exe
D:\WINDOWS\system32\cidaemon.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - D:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - D:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - D:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar3.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - D:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [MSConfig] D:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [EPSON Stylus Photo 825] D:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /A "D:\WINDOWS\system32\E_S494.tmp"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "D:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] D:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] D:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] D:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] D:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Service Manager.lnk = D:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: WebSecureAlert.lnk = D:\Program Files\WebSecureAlert\WebSecureAlert.exe
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Yahoo! Search - file:///D:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///D:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///D:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///D:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - D:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - D:\PROGRA~1\Yahoo!\MESSEN~1\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - D:\PROGRA~1\Yahoo!\MESSEN~1\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: D:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: YExplorer1_8US.CAB - http://photos.groups.yahoo.com/ocx/us/yexplorer1_8us.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.35mb.com/applet/applet_l.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - D:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://inotes.cwinsider.com/mailrm02/iNotes6W.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.snapfish.com/SnapfishActivia.cab
O16 - DPF: {5F8A33E7-6A32-4EE0-887A-134C627CB052} (Easy Upload Tool Combo Control) - http://sridharpatturu.myphotoalbum.com/EasyUploadTool.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1120406532343
O16 - DPF: {7114683A-020D-4D16-80FD-6ACE384B66DF} (FarPoint Spread 7.0 (OLEDB)) - https://qaive.cwinsider.com/,DanaInfo=.aahq…ava+fpspr70.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {90051A81-3018-4826-8B38-DD60B6B53F9C} (Snapfish File Upload ActiveX Control) - http://www.costcophotocenter.com/CostcoUpload.cab
O16 - DPF: {95EEE69E-27B4-4D13-BD32-766617A16909} (NDTVVideo.MPlayer) - http://www.ndtv.com/video/NDTVseekvideo.CAB
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O16 - DPF: {C915801D-6F00-49CD-8A9A-8DE5C11ADDC1} (Pixami Drag/Drop Upload UI Control) - http://www.photoworks.com/pixami/DragDropUploader.cab
O16 - DPF: {E2454650-4D87-11D2-B8B2-0000C00A958C} (FarPoint Spread 3.0) - https://www.cwinsider.com/cwi/spr32x30.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVSync Manager (AvSynMgr) - Unknown owner - D:\Program Files\Network Associates\VirusScan\avsynmgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - D:\WINDOWS\System32\CTSvcCDA.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - D:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Google Updater Service (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McShield - Unknown owner - D:\Program Files\Common Files\Network Associates\McShield\mcshield.exe
O23 - Service: NBService - Nero AG - D:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - D:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

–
End of file - 9254 bytes

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI