Kathy
Spyware / Malware / Virus Removal
[Resolved] Slow and Buggy
59 min read
Kathy
Did I give you the wrong section of the log?
Kathy
Is it because I'm just a freshman so I can't have the ability to attach and upload, yet? 
Scotty
I have no idea. Did you get my pm?
Kathy
KASPERSKY ONLINE SCANNER REPORT
Friday, October 12, 2007 1:04:17 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 1 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 11/10/2007
Kaspersky Anti-Virus database records: 430926
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
C:\
D:\
E:\
Scan Statistics
Total number of scanned objects 80242
Number of viruses found 73
Number of infected objects 17894
Number of suspicious objects 0
Duration of the scan process 01:36:20
Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d953eda3e26304d35e06e3f99844845b_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows NT\MSFax\ActivityLog\InboxLOG.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows NT\MSFax\ActivityLog\OutboxLOG.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\QuickPageSwitchDialer.zip/ls.exe Infected: Backdoor.Win32.Delf.mb skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\QuickPageSwitchDialer.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC.zip/b128.exe/stream/data0002/data0002 Infected: Trojan-Downloader.Win32.PurityScan.eh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC.zip/b128.exe/stream/data0002 Infected: Trojan-Downloader.Win32.PurityScan.eh skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC.zip/b128.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Mostofate.u skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC.zip/b128.exe/stream Infected: not-a-virus:AdWare.Win32.Mostofate.u skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC.zip/b128.exe Infected: not-a-virus:AdWare.Win32.Mostofate.u skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC.zip ZIP: infected - 5 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC1.zip/popinstall.exe Infected: not-a-virus:AdWare.Win32.Rond.c skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC1.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SpywareSecure33.zip/Spyware-Secure_trial.exe Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SpywareSecure33.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SpywareSecure53.zip/uninst.exe/stream/data0002 Infected: not-a-virus:AdWare.Win32.NaviPromo.bw skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SpywareSecure53.zip/uninst.exe/stream Infected: not-a-virus:AdWare.Win32.NaviPromo.bw skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SpywareSecure53.zip/uninst.exe Infected: not-a-virus:AdWare.Win32.NaviPromo.bw skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SpywareSecure53.zip ZIP: infected - 3 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeWinpop.zip/winpop.exe Infected: not-a-virus:AdWare.Win32.Rond.c skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeWinpop.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VXa.zip/IEHelper.dll Infected: not-a-virus:AdWare.Win32.PowerSearch skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VXa.zip ZIP: infected - 1 skipped
C:\Documents and Settings\anthony_2\Application Data\Adobe\Acrobat\6.0\AcroForm\MRUFormsList Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Adobe\Acrobat\6.0\AdobeComFnt06.lst Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Adobe\Acrobat\6.0\Collab\OfflineDocs Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Adobe\Acrobat\6.0\Collab\Reviews Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Adobe\Acrobat\6.0\Messages\ENU\read0600win_ENUadbe0062w.pdf Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Adobe\Acrobat\6.0\Messages\ENU\read0600win_ENUyhoo0014w.pdf Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Adobe\Acrobat\6.0\Preferences\AutoFillDefaults.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Adobe\Acrobat\6.0\Preferences\defaultHeuristics.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Adobe\Acrobat\6.0\TMGrpPrm.sav Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Adobe\Acrobat\6.0\Updater\udstore.js Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Aim\Resources\CurrentSettings.xml Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectExpert\10\Custom WP Templates\bluterra.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectExpert\10\Custom WP Templates\greenbrk.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectExpert\10\Custom WP Templates\hatch.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectExpert\10\Custom WP Templates\lace1.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectExpert\10\Custom WP Templates\lace2.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectExpert\10\Custom WP Templates\marble1.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectExpert\10\Custom WP Templates\marble2.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectExpert\10\Custom WP Templates\oil1.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectExpert\10\Custom WP Templates\oil2.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectExpert\10\Custom WP Templates\paper1.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectExpert\10\Custom WP Templates\paper2.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectExpert\10\Custom WP Templates\pine.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectExpert\10\Custom WP Templates\poly.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectExpert\10\Custom WP Templates\poplar.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectExpert\10\Custom WP Templates\qw10en.wpt Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectExpert\10\Custom WP Templates\rock.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectExpert\10\Custom WP Templates\stucco1.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectExpert\10\Custom WP Templates\stucco2.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectExpert\10\Custom WP Templates\tile.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectExpert\10\Custom WP Templates\water.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectExpert\10\Custom WP Templates\wp10US.wpt Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectExpert\10\Custom WP Templates\wrinkle.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectExpert\10\Custom WP Templates\XML\XML.wpt Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectExpert\10\Custom WP Templates\_autotmp.wpx Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectScript\10\WordPerfect\ABBREV.WCM Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectScript\10\WordPerfect\adrs2mrg.wcm Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectScript\10\WordPerfect\ALLFONTS.WCM Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectScript\10\WordPerfect\checkbox.wcm Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectScript\10\WordPerfect\closeall.wcm Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectScript\10\WordPerfect\CTRLM.WCM Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectScript\10\WordPerfect\cvtdocs10.wcm Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectScript\10\WordPerfect\DCConvert.wcm Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectScript\10\WordPerfect\ender01.wpg Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectScript\10\WordPerfect\ender02.wpg Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectScript\10\WordPerfect\ender03.wpg Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectScript\10\WordPerfect\ender04.wpg Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectScript\10\WordPerfect\ender05.wpg Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectScript\10\WordPerfect\ender06.wpg Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectScript\10\WordPerfect\ender07.wpg Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectScript\10\WordPerfect\ender08.wpg Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectScript\10\WordPerfect\ender09.wpg Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectScript\10\WordPerfect\ender10.wpg Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectScript\10\WordPerfect\endfoot.wcm Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectScript\10\WordPerfect\EXPNDALL.WCM Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectScript\10\WordPerfect\FILESTMP.WCM Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectScript\10\WordPerfect\flipenv.wcm Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectScript\10\WordPerfect\FONTDN.WCM Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectScript\10\WordPerfect\FONTUP.WCM Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectScript\10\WordPerfect\footend.wcm Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectScript\10\WordPerfect\LONGNAME.WCM Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectScript\10\WordPerfect\nomacro.wcm Object is locked skipped
Scotty
Hi Kathy
Look, do another kaspersky scan, but this time just select the C:\WINDOWS folder to scan, then post the report.
Kathy
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectScript\10\WordPerfect\PARABRK.WCM Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectScript\10\WordPerfect\pleading.wcm Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectScript\10\WordPerfect\prompts.wcm Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectScript\10\WordPerfect\reverse.wcm Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectScript\10\WordPerfect\saveall.wcm Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectScript\10\WordPerfect\SAVETOA.WCM Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectScript\10\WordPerfect\tconvert.wcm Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectScript\10\WordPerfect\uawp10en.wcm Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectScript\10\WordPerfect\wp_org.wcm Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\PerfectScript\10\WordPerfect\wp_pr.wcm Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\WordPerfect\10\Labels\apli_eng.lab Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\WordPerfect\10\Labels\Avery Labels A4.lab Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\WordPerfect\10\Labels\Avery Labels EN.lab Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\WordPerfect\10\Labels\Herma_e.lab Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\WordPerfect\10\Labels\maco.lab Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\WordPerfect\10\Labels\Tower.lab Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Corel\WordPerfect\10\Labels\WilsonJ.lab Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\DESKTOP.INI Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\DriveCleaner Free\Logs\update.log Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Google\Local Search History\google%2Efroogle.w Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Google\Local Search History\google%2Eimages.w Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Google\Local Search History\google%2Emaps.w Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Google\Local Search History\google%2Esite.w Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Google\Local Search History\google%2Eweb.w Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\InstallShield\Professional\RunTime\11\50\Intel32\iGdi.dll Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\InstallShield\Professional\RunTime\11\50\Intel32\setup.dll Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\kdx\errorlog.ini Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\kdx\kontiki.fp Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\accelerated.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\arrow_down.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\arrow_up.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\arrow_white_up.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\background.jpg Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\background_nobar.jpg Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\btn_dlg.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\btn_med.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\btn_prefs.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\btn_sm.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\config.xml Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\dl.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\gofaster.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\jump.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\jump_popup.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\kdmx.css Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\kdmx_about.html Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\kdmx_auth.html Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\kdmx_blank.html Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\kdmx_changePassword.html Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\kdmx_complete.html Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\kdmx_delete.html Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\kdmx_error.html Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\kdmx_eventTemplate.html Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\kdmx_exitCancel.html Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\kdmx_goFaster.html Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\kdmx_helperApp.html Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\kdmx_htmlGroupAuth.html Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\kdmx_htmlGroupPreAuth.html Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\kdmx_inbox.html Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\kdmx_info.html Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\kdmx_kpgplayer.html Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\kdmx_kpgwatcher.html Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\kdmx_launched.html Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\kdmx_mainFrame.html Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\kdmx_menuContextComplete.html Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\kdmx_menuContextPending.html Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\kdmx_menuDeliveries.html Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\kdmx_menuHelp.html Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\kdmx_menuTools.html Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\kdmx_menuTray.html Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\kdmx_offline.html Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\kdmx_offlineTab.html Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\kdmx_openConfirm.html Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\kdmx_paneComplete.html Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\kdmx_panePending.html Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\kdmx_panePreview.html Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\kdmx_player.html Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\kdmx_preauth.html Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\kdmx_prefs.html Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\kdmx_progress.html Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\kdmx_splash.html Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\kdmx_streamOrDl.html Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\kdmx_template.html Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\kdx.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\kdx.js Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\kdx_collection.js Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\kdx_init.js Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\kdx_util.js Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\loading.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\loading_popup.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\lock.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\mainFill.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\Moviefone.ico Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\mvf_header.jpg Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\peers.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\progress-bluefill.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\progress.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\progressbar-long.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\scripts.js Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\secure.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\spacer.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\stream.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\subscription.jpg Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\success.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\success_popup.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\survey.jpg Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\tab_main_off.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\tab_main_on.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\tab_prefs_off.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\tab_prefs_on.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\tray.gif Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\tray0.ico Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\tray1.ico Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\tray2.ico Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Kontiki\moviefone_classic\cache\unMoviefone.ico Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\aolcdn.com\_media\aolvideo30\rootmovie351.swf\videoSO.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\assets.espn.go.com\motion\fsp\FSPRoot\espnmotion1_cv.swf\fspSettings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\atdmt.com\bandwidth.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\atv.disney.go.com\disneychannel\dc_games_skins.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\bannerfarm.ace.advertising.com\FlashBoxCookie.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\bin.clearspring.com\clearspring.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\blingjam.net\index.swf\user_espin.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\boston.redsox.mlb.com\flash\team_video\team_video_v2.swf\mlb_homepage_video.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\disney.go.com\disneychannel\kimpossiblePoll.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\disney.go.com\disneychannel\LiloAndStitchEmailTicker.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\eyespot.com\flash\flvplayer.swf\TestMovie_Config_Info.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\graphics.millsberry.com\buddy\buddy_edit_v17.swf\backup.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\graphics.millsberry.com\buddy\buddy_featured.swf\backup.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\graphics.millsberry.com\buddy\buddy_featured_v14.swf\backup.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\graphics.millsberry.com\buddy\buddy_nav_v15.swf\backup.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\graphics.millsberry.com\flashgames\g440_v18.swf\#millsberry\bumperboats\.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\graphics.millsberry.com\home\home_v79.swf\backup.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\hosted.ap.org\AP_roate_photo.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\localhost\core.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\login.yahoo.com\loginCache.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\media1.break.com\breakPlayerUserPreferences.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\midaddle.com\sharedObject.swf\Mcookie.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\millsberry.com\gamingsystem\flash_loader_v10_18.swf\#gmi\homerun_derby\userdata.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\millsberry.com\home\home_v76.swf\backup.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\miniclip.com\games\bubble-trouble\en\bubbletrouble.swf\MiniclipHighscores.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\miniclip.com\games\bubble-trouble\en\bubbletrouble.swf\MiniclipLoaderAd.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\mochibot.com\com.mochibot.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\myspace.com\willleftintl2562007.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\neave.com\games\simon\simon.swf\neaveSimon.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\oddcast.com\ctc.swf\oddcast_usage.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\oddcast.com\ctc_player.swf\oddcast_usage.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\pagead2.googlesyndication.com\pagead\googleadplayer.swf\mediaPlayerUserSettings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\quantserve.com\com.quantserve.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\static.espn.go.com\motion\fsp\FSPRoot\espnmotion1_cv.swf\fspSettings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\static.userplane.com\presence\m\presence.swf\presence.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\static.userplane.com\presence\presence.swf\presence_1.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\suitesmart.com\_f5e.swf\5thElement.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\us.i1.yimg.com\cosmos.bcst.yahoo.com\player\embed-2-0-2007-01-30-1601\swf\yup_embed_module.swf\TestMovie_Config_Info.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\us.i1.yimg.com\LCOMMENGINEMGR.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\video.google.com\googleplayer-syn.swf\mediaPlayerUserSettings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\video.google.com\googleplayer.swf\mediaPlayerUserSettings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\void.snocap.com\s\storefront.swf\SnocapDownloadManager.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\widgets.clearspring.com\clearspring.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\wwe.com\live\frontend.swf\wwe_bandwidth.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\wwe.com\wwe-chat.swf\123flashchat_user.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\www.finetune.com\finetune.user.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\www.ifilm.com\flash\container.swf\settings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\www.jibjab.com\originals\player\jibjabPlayer.swf\jibjabSettings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\www.lovemyflash.com\com.quantserve.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\www.sho.com\site\lword\season4\flash\carousel\lword_carousel.swf\dateID.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\www.superdeluxe.com\VideoUserData.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\www.wwe.com\content\media\touts\medium\29068\407668\wweSchedule.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\www.wwe.com\content\media\touts\medium\29068\thisweek.swf\wweSchedule.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\www.xatech.com\chat.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\www.youtube.com\soundData.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\xmodsrc.com\games\muscle-madness\main.swf\muscle_madness.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\#SharedObjects\4N5U5W7X\youtube.com\soundData.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#aolcdn.com\settings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#assets.espn.go.com\settings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#atdmt.com\settings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#atv.disney.go.com\settings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bannerfarm.ace.advertising.com\settings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin.clearspring.com\settings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#blingjam.net\settings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#boston.redsox.mlb.com\settings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#disney.go.com\settings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#eyespot.com\settings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#graphics.millsberry.com\settings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#hosted.ap.org\settings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#local\settings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#login.yahoo.com\settings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#macromedia.com\settings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#media1.break.com\settings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#midaddle.com\settings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#millsberry.com\settings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#miniclip.com\settings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#mochibot.com\settings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#myspace.com\settings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#neave.com\settings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#nigma3d.s3.amazonaws.com\settings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#oddcast.com\settings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#pagead2.googlesyndication.com\settings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#quantserve.com\settings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#static.espn.go.com\settings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#static.userplane.com\settings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#suitesmart.com\settings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#us.i1.yimg.com\settings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#video.google.com\settings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#void.snocap.com\settings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#widgets.clearspring.com\settings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#wwe.com\settings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.finetune.com\settings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.ifilm.com\settings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.jibjab.com\settings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.lovemyflash.com\settings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.sho.com\settings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.superdeluxe.com\settings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.wwe.com\settings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.xatech.com\settings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.youtube.com\settings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#xmodsrc.com\settings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#youtube.com\settings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Macromedia\Flash Player\miniclip.com\games\power-boat\en\powerboat.dcr\power_boat.sol Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Address Book\anthony_2.wab Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\CLR Security Config\v1.0.3705\security.config Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\CLR Security Config\v1.0.3705\security.config.cch Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\CLR Security Config\v1.0.3705\security.config.old Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Crypto\RSA\S-1-5-21-2964694076-940496205-2815504085-1011\1f0b60827a4c7c08356ee212eb67ae05_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Crypto\RSA\S-1-5-21-2964694076-940496205-2815504085-1011\a33d10b6c4f5b80ba19b6c5e2a7b2532_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Crypto\RSA\S-1-5-21-2964694076-940496205-2815504085-1011\bbfe273b5348b233a8c021f55b35b895_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\FrontPage\State\CmdUI.PRF Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\HTML Help\hh.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Internet Explorer\BRNDLOG.BAK Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Internet Explorer\BRNDLOG.TXT Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Internet Explorer\Desktop.htt Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Internet Explorer\Quick Launch\America Online 8.0.lnk Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Internet Explorer\Quick Launch\Dell Jukebox by musicmatch.lnk Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Internet Explorer\Quick Launch\DESKTOP.INI Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Internet Explorer\Quick Launch\MySpaceIM.lnk Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Media Catalog\artgal50.mmc Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Media Player\cyprusPresets.asx Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Media Player\OfflineUpdates.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\Backgrounds\map.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\Backgrounds\TFRD5.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\Backgrounds\TFRD6.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\Backgrounds\TFRD7.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\Backgrounds\TFRD8.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\Backgrounds\TFRD9.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\ListCache.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\MapFile\TFRD3.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\MapFile\TFRDA.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\MapFile\TFRF9.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\sqmdata00.sqm Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\sqmdata01.sqm Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\sqmdata02.sqm Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\sqmdata03.sqm Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\sqmdata04.sqm Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\sqmdata05.sqm Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\sqmdata06.sqm Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\sqmdata07.sqm Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\sqmdata08.sqm Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\sqmdata09.sqm Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\sqmdata10.sqm Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\sqmdata11.sqm Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\sqmdata12.sqm Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\sqmdata13.sqm Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\sqmdata14.sqm Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\sqmdata15.sqm Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\sqmdata16.sqm Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\sqmdata17.sqm Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\sqmdata18.sqm Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\sqmdata19.sqm Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\UserTile\map.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\UserTile\TFRC8.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\UserTile\TFRC9.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\UserTile\TFRCA.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\UserTile\TFRCB.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\UserTile\TFRCC.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\UserTile\TFRCD.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\UserTile\TFRCE.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\UserTile\TFRCF.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\UserTile\TFRD0.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\UserTile\TFRD1.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\UserTile\TFRD2.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\Winks3\map.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\Winks3\TFRDC.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\Winks3\TFRDE.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\Winks3\TFRE0.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\Winks3\TFRE2.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\Winks3\TFRE4.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\Winks3\TFRE6.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\Winks3\TFRE8.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\Winks3\TFREA.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\Winks3\TFREC.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\Winks3\TFREE.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\Winks3\TFRF0.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\Winks3\TFRF2.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\Winks3\TFRF4.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\Winks3\TFRF6.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1114899738\Winks3\TFRF8.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1467409189\Backgrounds\map.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1467409189\Backgrounds\TFREE.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1467409189\Backgrounds\TFREF.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1467409189\Backgrounds\TFRF0.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1467409189\Backgrounds\TFRF1.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1467409189\Backgrounds\TFRF2.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1467409189\ListCache.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1467409189\MapFile\TFR112.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1467409189\MapFile\TFREC.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1467409189\MapFile\TFRF3.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1467409189\sqmdata00.sqm Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1467409189\UserTile\map.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1467409189\UserTile\TFRE1.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1467409189\UserTile\TFRE2.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1467409189\UserTile\TFRE3.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1467409189\UserTile\TFRE4.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1467409189\UserTile\TFRE5.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1467409189\UserTile\TFRE6.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1467409189\UserTile\TFRE7.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1467409189\UserTile\TFRE8.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1467409189\UserTile\TFRE9.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1467409189\UserTile\TFREA.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1467409189\UserTile\TFREB.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1467409189\Winks3\map.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1467409189\Winks3\TFR101.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1467409189\Winks3\TFR103.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1467409189\Winks3\TFR105.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1467409189\Winks3\TFR107.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1467409189\Winks3\TFR109.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1467409189\Winks3\TFR10B.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1467409189\Winks3\TFR10D.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1467409189\Winks3\TFR10F.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1467409189\Winks3\TFR111.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1467409189\Winks3\TFRF5.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1467409189\Winks3\TFRF7.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1467409189\Winks3\TFRF9.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1467409189\Winks3\TFRFB.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1467409189\Winks3\TFRFD.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\MSN Messenger\1467409189\Winks3\TFRFF.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Office\Access.pip Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Office\Excel.pip Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Office\FP.pip Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Office\MSO1033.acl Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Office\MSOutlo.pip Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Office\PowerPoi.pip Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Office\Recent\432LWXSP.LNK Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Office\Recent\books.LNK Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Office\Recent\Crazy.LNK Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Office\Recent\Desktop.LNK Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Office\Recent\drum solo.LNK Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Office\Recent\EAST JR.LNK Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Office\Recent\future job plans.LNK Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Office\Recent\hereos.LNK Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Office\Recent\i like to meet.LNK Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Office\Recent\im cool.LNK Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Office\Recent\interests.LNK Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Office\Recent\Japan.LNK Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Office\Recent\jordan layout.LNK Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Office\Recent\korn layout.LNK Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Office\Recent\Ladies Wait In Line.LNK Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Office\Recent\movies.LNK Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Office\Recent\My Documents.LNK Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Office\Recent\My Pictures.LNK Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Office\Recent\My Webs.LNK Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Office\Recent\Normal.LNK Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Office\Recent\Patty O jump starting your carre work.LNK Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Office\Recent\Patty O res prop.LNK Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Office\Recent\Presentation2.LNK Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Office\Recent\quiz.LNK Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Office\Recent\Rag Doll.LNK Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Office\Recent\Sweet Child O.LNK Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Office\Recent\Templates.LNK Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Office\Recent\They practice in an unfinished basement in Brockton.LNK Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Office\Recent\tv.LNK Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Office\Recent\wordicon.LNK Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Office\Recent\yank.LNK Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Office\Recent\{00000409-78E1-11D2-B60F-006097C998E7}.LNK Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Office\Word.pip Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Outlook\extend.dat Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\PowerPoint\PPT.pcb Object is locked skipped
C:\Documents and Settings\anthony_2\Application Data\Microsoft\Proof\CUSTOM.DIC Object is locked skipped
Kathy
This is that portion of this scan; is that good?
C:\WINDOWS\arr.exe Infected: Backdoor.Win32.Delf.ll skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\UDC6_0001_D19M1908NetInstaller.exe Infected: not-a-virus:Downloader.Win32.WinFixer.bb skipped
C:\WINDOWS\Downloaded Program Files\CONFLICT.10\UDC6_0001_D19M1908NetInstaller.exe Infected: not-a-virus:Downloader.Win32.WinFixer.bb skipped
C:\WINDOWS\Downloaded Program Files\CONFLICT.11\UDC6_0001_D19M1908NetInstaller.exe Infected: not-a-virus:Downloader.Win32.WinFixer.bb skipped
C:\WINDOWS\Downloaded Program Files\CONFLICT.12\UDC6_0001_D19M1908NetInstaller.exe Infected: not-a-virus:Downloader.Win32.WinFixer.bb skipped
C:\WINDOWS\Downloaded Program Files\CONFLICT.13\UDC6_0001_D19M1908NetInstaller.exe Infected: not-a-virus:Downloader.Win32.WinFixer.bb skipped
C:\WINDOWS\Downloaded Program Files\CONFLICT.14\UDC6_0001_D19M1908NetInstaller.exe Infected: not-a-virus:Downloader.Win32.WinFixer.bb skipped
C:\WINDOWS\Downloaded Program Files\CONFLICT.15\UDC6_0001_D19M1908NetInstaller.exe Infected: not-a-virus:Downloader.Win32.WinFixer.bb skipped
C:\WINDOWS\Downloaded Program Files\CONFLICT.16\UDC6_0001_D19M1908NetInstaller.exe Infected: not-a-virus:Downloader.Win32.WinFixer.bb skipped
C:\WINDOWS\Downloaded Program Files\CONFLICT.17\UDC6_0001_D19M1908NetInstaller.exe Infected: not-a-virus:Downloader.Win32.WinFixer.bb skipped
C:\WINDOWS\Downloaded Program Files\CONFLICT.18\UDC6_0001_D19M1908NetInstaller.exe Infected: not-a-virus:Downloader.Win32.WinFixer.bb skipped
C:\WINDOWS\Downloaded Program Files\CONFLICT.19\UDC6_0001_D19M1908NetInstaller.exe Infected: not-a-virus:Downloader.Win32.WinFixer.bb skipped
C:\WINDOWS\Downloaded Program Files\CONFLICT.2\UDC6_0001_D19M1908NetInstaller.exe Infected: not-a-virus:Downloader.Win32.WinFixer.bb skipped
C:\WINDOWS\Downloaded Program Files\CONFLICT.20\UDC6_0001_D19M1908NetInstaller.exe Infected: not-a-virus:Downloader.Win32.WinFixer.bb skipped
C:\WINDOWS\Downloaded Program Files\CONFLICT.21\UDC6_0001_D19M1908NetInstaller.exe Infected: not-a-virus:Downloader.Win32.WinFixer.bb skipped
C:\WINDOWS\Downloaded Program Files\CONFLICT.22\UDC6_0001_D19M1908NetInstaller.exe Infected: not-a-virus:Downloader.Win32.WinFixer.bb skipped
C:\WINDOWS\Downloaded Program Files\CONFLICT.23\UDC6_0001_D19M1908NetInstaller.exe Infected: not-a-virus:Downloader.Win32.WinFixer.bb skipped
C:\WINDOWS\Downloaded Program Files\CONFLICT.3\UDC6_0001_D19M1908NetInstaller.exe Infected: not-a-virus:Downloader.Win32.WinFixer.bb skipped
C:\WINDOWS\Downloaded Program Files\CONFLICT.4\UDC6_0001_D19M1908NetInstaller.exe Infected: not-a-virus:Downloader.Win32.WinFixer.bb skipped
C:\WINDOWS\Downloaded Program Files\CONFLICT.5\UDC6_0001_D19M1908NetInstaller.exe Infected: not-a-virus:Downloader.Win32.WinFixer.bb skipped
C:\WINDOWS\Downloaded Program Files\CONFLICT.6\UDC6_0001_D19M1908NetInstaller.exe Infected: not-a-virus:Downloader.Win32.WinFixer.bb skipped
C:\WINDOWS\Downloaded Program Files\CONFLICT.7\UDC6_0001_D19M1908NetInstaller.exe Infected: not-a-virus:Downloader.Win32.WinFixer.bb skipped
C:\WINDOWS\Downloaded Program Files\CONFLICT.8\UDC6_0001_D19M1908NetInstaller.exe Infected: not-a-virus:Downloader.Win32.WinFixer.bb skipped
C:\WINDOWS\Downloaded Program Files\CONFLICT.9\UDC6_0001_D19M1908NetInstaller.exe Infected: not-a-virus:Downloader.Win32.WinFixer.bb skipped
C:\WINDOWS\Downloaded Program Files\vzbb.dll Infected: not-a-virus:AdWare.Win32.MegaSearch.b skipped
C:\WINDOWS\dxfopntsmyu.exe Infected: not-a-virus:AdWare.Win32.Bestofer.d skipped
C:\WINDOWS\enhtb.exe/enhtb.dll Infected: not-a-virus:AdWare.Win32.NoName.m skipped
C:\WINDOWS\enhtb.exe CAB: infected - 1 skipped
C:\WINDOWS\enhtb.exe MimarSinan: infected - 1 skipped
C:\WINDOWS\enhtb.exe UPX: infected - 1 skipped
C:\WINDOWS\enhuninstall.exe Infected: not-a-virus:AdWare.Win32.NoName.f skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\DataStore\DataStore.edb Object is locked skipped
C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log Object is locked skipped
C:\WINDOWS\SoftwareDistribution\DataStore\Logs\tmp.edb Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\svcproc.exe Infected: not-a-virus:AdWare.Win32.AdSquash.e skipped
C:\WINDOWS\systb.exe/systb.dll Infected: not-a-virus:AdWare.Win32.ImiBar.d skipped
C:\WINDOWS\systb.exe CAB: infected - 1 skipped
C:\WINDOWS\systb.exe MimarSinan: infected - 1 skipped
C:\WINDOWS\systb.exe UPX: infected - 1 skipped
C:\WINDOWS\SYSTEM32\arr.exe Infected: Backdoor.Win32.Delf.ll skipped
C:\WINDOWS\SYSTEM32\ayfxgi.exe Infected: Trojan.Win32.Agent.ay skipped
C:\WINDOWS\SYSTEM32\com.exe Infected: Trojan-Downloader.Win32.Delf.et skipped
C:\WINDOWS\SYSTEM32\CONFIG\AppEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SAM Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SecEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SysEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\dll.exe Infected: Trojan-Downloader.Win32.Delf.et skipped
C:\WINDOWS\SYSTEM32\DrPMon.dll_old Infected: Trojan.Win32.Agent.db skipped
C:\WINDOWS\SYSTEM32\DummyX.dll Infected: Trojan.Win32.Dialer.cp skipped
C:\WINDOWS\SYSTEM32\egaccess4_1058.dll Infected: not-a-virus:Porn-Dialer.Win32.EgroupDial.v skipped
C:\WINDOWS\SYSTEM32\egaccess4_1059.dll Infected: Trojan.Win32.Dialer.pc skipped
C:\WINDOWS\SYSTEM32\egaccess4_1060.dll Infected: not-a-virus:Porn-Dialer.Win32.InstantAccess.r skipped
C:\WINDOWS\SYSTEM32\egaccess4_1061.dll Infected: not-a-virus:Porn-Dialer.Win32.InstantAccess.r skipped
C:\WINDOWS\SYSTEM32\egaccess4_1064.dll Infected: not-a-virus:Porn-Dialer.Win32.EgroupDial.x skipped
C:\WINDOWS\SYSTEM32\EGDACCESS_ASPIV4_1063a.dll Infected: not-a-virus:Porn-Dialer.Win32.InstantAccess.f skipped
C:\WINDOWS\SYSTEM32\EGDACCESS_ASPIV4_1064.dll Infected: not-a-virus:Porn-Dialer.Win32.InstantAccess.f skipped
C:\WINDOWS\SYSTEM32\EGDACCESS_ASPIV4_1065.dll Infected: not-a-virus:Porn-Dialer.Win32.InstantAccess.f skipped
C:\WINDOWS\SYSTEM32\EGDACCESS_ASPIV4_1066.dll Infected: not-a-virus:Porn-Dialer.Win32.InstantAccess.f skipped
C:\WINDOWS\SYSTEM32\EGDACCESS_ASPIV4_1068.dll Infected: not-a-virus:Porn-Dialer.Win32.InstantAccess.f skipped
C:\WINDOWS\SYSTEM32\EGDACCESS_ASPIV4_1069.dll Infected: not-a-virus:Porn-Dialer.Win32.InstantAccess.f skipped
C:\WINDOWS\SYSTEM32\EGDACCESS_ASPIV4_1070.dll Infected: not-a-virus:Porn-Dialer.Win32.InstantAccess.f skipped
C:\WINDOWS\SYSTEM32\EGDACCESS_ASPIV4_1071.dll Infected: not-a-virus:Porn-Dialer.Win32.InstantAccess.f skipped
C:\WINDOWS\SYSTEM32\EGDACCESS_ASPIV4_1073.dll Infected: not-a-virus:Porn-Dialer.Win32.InstantAccess.n skipped
C:\WINDOWS\SYSTEM32\H323LOG.TXT Object is locked skipped
C:\WINDOWS\SYSTEM32\hit.exe Infected: Trojan.Win32.Dialer.dv skipped
C:\WINDOWS\SYSTEM32\IEHelper.dll_old Infected: not-a-virus:AdWare.Win32.PowerSearch skipped
C:\WINDOWS\SYSTEM32\int1.exe Infected: Trojan.Win32.Dialer.cp skipped
C:\WINDOWS\SYSTEM32\intl.exe Infected: Trojan.Win32.Dialer.cp skipped
C:\WINDOWS\SYSTEM32\jxcalm.exe Infected: Trojan.Win32.Agent.ay skipped
C:\WINDOWS\SYSTEM32\ldvrlhy.exe Infected: Trojan.Win32.Agent.ay skipped
C:\WINDOWS\SYSTEM32\mmgr32.exe Infected: Trojan.Win32.Dialer.cp skipped
C:\WINDOWS\SYSTEM32\mstar2.exe Infected: Trojan.Win32.Dialer.cp skipped
C:\WINDOWS\SYSTEM32\mstart.exe Infected: Trojan.Win32.Dialer.cp skipped
C:\WINDOWS\SYSTEM32\ntcpl.exe Infected: Trojan.Win32.Dialer.cp skipped
C:\WINDOWS\SYSTEM32\randreco.exe Infected: not-a-virus:AdWare.Win32.BetterInternet skipped
C:\WINDOWS\SYSTEM32\ru.exe Infected: Trojan.Win32.Dialer.cp skipped
C:\WINDOWS\SYSTEM32\runme2.exe Infected: Trojan.Win32.Dialer.cp skipped
C:\WINDOWS\SYSTEM32\run_21.exe Infected: Trojan.Win32.Dialer.cp skipped
C:\WINDOWS\SYSTEM32\sed.exe Infected: Trojan.Win32.Dialer.cp skipped
C:\WINDOWS\SYSTEM32\srv.exe Infected: Trojan.Win32.Dialer.cp skipped
C:\WINDOWS\SYSTEM32\SuiteInstall.exe/data0001 Infected: Trojan-Downloader.NSIS.Agent.a skipped
C:\WINDOWS\SYSTEM32\SuiteInstall.exe NSIS: infected - 1 skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\SYSTEM32\xxwavh.exe Infected: Trojan.Win32.Agent.ay skipped
C:\WINDOWS\SYSTEM32\ycasqp.exe Infected: Trojan.Win32.Agent.ay skipped
C:\WINDOWS\SYSTEM32\zloaym.exe Infected: not-a-virus:AdWare.Win32.NaviPromo.gen skipped
C:\WINDOWS\WIADEBUG.LOG Object is locked skipped
C:\WINDOWS\WIASERVC.LOG Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
Kathy
Hi, Scotty!
A lot of her programs start up when She starts up her PC. I tried to change the settings but many changed back. I was surprised that the AIM changed back.
Kathy
Scotty
Hi Kathy
Sent you a pm, regarding validation.
Scotty
Hello
Lets see what we can do here then.
Download ATF (Atribune Temp File) Cleaner� by Atribune to your desktop.
Double-click ATF Cleaner.exe to open it.
Under Main choose:
Windows Temp
Current User Temp
All Users Temp
Cookies
Temporary Internet Files
Prefetch
Java Cache
*The other boxes are optional*
Then click the Empty Selected button.
Firefox:
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.
Opera:
Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.
Click Exit on the Main menu to close the program.
*Note* If you do not have Firefox or Opera, those options will be greyed out.
Please download Navilog1 by IL-MAFIOSO:
http://perso.orange.fr/il.mafioso/Navifix/Navilog1.zip
Download win32delfkil.exe and save it on your desktop.
Lets see what we can do here then.
Download ATF (Atribune Temp File) Cleaner� by Atribune to your desktop.
Double-click ATF Cleaner.exe to open it.
Under Main choose:
Windows Temp
Current User Temp
All Users Temp
Cookies
Temporary Internet Files
Prefetch
Java Cache
*The other boxes are optional*
Then click the Empty Selected button.
Firefox:
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.
Opera:
Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.
Click Exit on the Main menu to close the program.
*Note* If you do not have Firefox or Opera, those options will be greyed out.
Please download Navilog1 by IL-MAFIOSO:
http://perso.orange.fr/il.mafioso/Navifix/Navilog1.zip
- Extract its contents to the desktop.
- Double click on navilog1.exe to install it on your computer.
- When the installation is complete, the tool will start automatically.
- If it doesn't start automatically, please double click on Navilog1 shortcut on your desktop to run it.
- Press E for English from the language Menu.
- Type 1 in the next Menu to select Search and press Enter.
- Wait for the Scan to finish (It may take a reasonable amount of time)
- Press any key as requested .
- A new document will be produced: fixnavi.txt.
- Please copy/paste the contents of this report in your next reply.
Download win32delfkil.exe and save it on your desktop.
- Close all windows.
- Double click on win32delfkil.exe to start the removal tool.
- The computer will reboot automatically.
- After reboot a logfile will open: C:\windelf.txt
- Create a folder on your desktop called Sysclean.
- Go to http://www.trendmicro.com/download/dcs.asp and download sysclean package to the folder you made.
- Go to http://www.trendmicro.com/download/pattern.asp and download the Virus Pattern File (Official Pattern Release) to your desktop.
This file will be called lptXXX.zip (XXX represents the version number) - Unzip lptXXX.zip and you'll get the file lpt$vpn.XXX. Read here how to unzip/extract properly.
- Move the lpt$vpn.XXX to the Sysclean-folder you created on your desktop.
- Open the sysclean-folder and doubleclick sysclean.com.
- Check: "Automatically clean or delete detected files".
- Click scan.
Kathy
Hi, Scotty! [external image: Posted Image]
[external image: Posted Image] Here's the fixnav log:
Search Navipromo version 3.3.0 began on Sat 10/20/2007 at 13:10:24.92
!!! Warning, this report may include legitimate files/programs !!!
!!! Post this report on the forum you are being helped !!!
!!! Don't continue with removal unless instructed by an authorized helper !!!
Fix running from C:\Program Files\navilog1
Updated on 17.10.2007 at 20h00 by IL-MAFIOSO
Microsoft Windows XP [Version 5.1.2600]
Version Internet Explorer : 6.0.2800.1106
Done in normal mode
*** Searching for installed Software ***
*** Search folders in C:\WINDOWS ***
*** Search folders in C:\Program Files ***
*** Search folders in C:\Documents and Settings\All Users\Application Data ***
*** Search folders in C:\Documents and Settings\Lisa Pacella\Application Data ***
*** Search folders in C:\DOCUME~1\ALLUSE~1\STARTM~1\PROGRAMS ***
*** Search with Catchme-rootkit/stealth malware detector by gmer ***
for more info : http://www.gmer.net
No file found in :
- C:\WINDOWS\system32
- C:\DOCUME~1\LISAPA~1\LOCALS~1\APPLIC~1
*** Search with GenericNaviSearch ***
!!! Possibility of legitimate files in the result !!!
!!! Must always be checked before manually deleting !!!
* Scan in C:\WINDOWS\system32 *
* Scan in C:\DOCUME~1\LISAPA~1\LOCALS~1\APPLIC~1 *
*** Search files ***
C:\WINDOWS\Downloaded Program Files\IaLdr32.inf found !
C:\WINDOWS\system32\egaccess4_1058.dll found !
C:\WINDOWS\system32\egaccess4_1059.dll found !
C:\WINDOWS\system32\egaccess4_1060.dll found !
C:\WINDOWS\system32\egaccess4_1061.dll found !
C:\WINDOWS\system32\egaccess4_1064.dll found !
C:\WINDOWS\system32\EGDACCESS_ASPIV4_1063a.dll found !
C:\WINDOWS\system32\EGDACCESS_ASPIV4_1064.dll found !
C:\WINDOWS\system32\EGDACCESS_ASPIV4_1065.dll found !
C:\WINDOWS\system32\EGDACCESS_ASPIV4_1066.dll found !
C:\WINDOWS\system32\EGDACCESS_ASPIV4_1068.dll found !
C:\WINDOWS\system32\EGDACCESS_ASPIV4_1069.dll found !
C:\WINDOWS\system32\EGDACCESS_ASPIV4_1070.dll found !
C:\WINDOWS\system32\EGDACCESS_ASPIV4_1071.dll found !
C:\WINDOWS\system32\EGDACCESS_ASPIV4_1073.dll found !
*** Search specific Registry keys ***
*** Complementary Search ***
(Search specific files)
1)Search known files:
2)Heuristic Search :
C:\WINDOWS\system32\zloaym.exe found !
3)Certificates Search :
Egroup certificate not found !
*** Search completed on Sat 10/20/2007 at 13:11:11.67 ***
[external image: Posted Image] Here's the windelf log:
WIN32DELFKIL LOGFILE - by Marckie
version 3.131
Sat 10/20/2007 13:16:02.23
running from: "C:\Documents and Settings\Lisa Pacella\Desktop\Kathy"
— File(s) found in Windows directory —
— File(s) found in system32 folder —
— Services —
— Export SharedTaskScheduler key —
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
— Notify key —
— rebooting the computer —
— File(s) found in Windows directory —
— File(s) found in system32 folder —
— Services —
— Export SharedTaskSchedulerkey —
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
— Notify key —
Finished!
[external image: Posted Image] Here's the sysclean log:
Damage Cleanup Engine (DCE) 5.3(Build 1103)
Windows XP(Build 2600: Service Pack 1)
Start time : Sat Oct 20 2007 13:41:50
Load Damage Cleanup Template (DCT) "C:\Documents and Settings\Lisa Pacella\Desktop\Kathy\Sysclean\TMRDCT.ptn" (version ) [fail]
Load Damage Cleanup Template (DCT) "C:\Documents and Settings\Lisa Pacella\Desktop\Kathy\Sysclean\tsc.ptn" (version 904) [success]
Complete time : Sat Oct 20 2007 13:42:15
Execute pattern count(2935), Virus found count(0), Virus clean count(0), Clean failed count(0)
[external image: Posted Image] and finally, a new HijackThis log:
Logfile of HijackThis v1.99.1
Scan saved at 2:45:56 PM, on 10/20/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\SiteAdvisor\6172\SAService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe
C:\WINDOWS\System32\NILaunch.exe
C:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE
C:\program files\mcafee.com\vso\mcvsshld.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
C:\Program Files\Common Files\Verizon Online\ConnMgr\cmisrv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\Program Files\America Online 8.0\aoltray.exe
C:\Program Files\Common Files\Verizon Online\AppMgr\vzOpenUIServer.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;http://localhost
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
O2 - BHO: Nick Aracde Toolbar - {4E7BD74F-2B8D-469E-9EB4-FE6FA694B13E} - C:\PROGRA~1\NICKAR~1\NICKAR~1.DLL (file missing)
O2 - BHO: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\WINDOWS\DOWNLO~1\vzbb.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\WINDOWS\DOWNLO~1\vzbb.dll (file missing)
O3 - Toolbar: Nick Aracde Toolbar - {4E7BD74F-2B8D-469E-9EB4-FE6FA694B13E} - C:\PROGRA~1\NICKAR~1\NICKAR~1.DLL (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [VerizonServicepoint.exe] C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe
O4 - HKLM\..\Run: [Net-It Launcher] C:\WINDOWS\System32\NILaunch.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [KAZAA] C:\Program Files\Kazaa\kazaa.exe /SYSTRAY
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [A Verizon App] C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE
O4 - HKLM\..\Run: [VirusScan Online] c:\program files\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\MWSBAR.DLL,S
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: America Online 8.0 Tray Icon.lnk = C:\Program Files\America Online 8.0\aoltray.exe
O4 - Global Startup: AOL Companion.lnk = C:\Program Files\AOL Companion\companion.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/…?p=ZKxdm011YYUS
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM
O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM95\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon…DSL/tgctlcm.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f…p1.0.0.15-3.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {A7ECD556-D6F6-4F41-8C6B-14AB246801A0} (Secure Delivery) - http://kdx.kontiki.com/kdx/Client403/kdx.cab
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6172\SAService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Talk to you soon!
Kathy
[external image: Posted Image] Here's the fixnav log:
Search Navipromo version 3.3.0 began on Sat 10/20/2007 at 13:10:24.92
!!! Warning, this report may include legitimate files/programs !!!
!!! Post this report on the forum you are being helped !!!
!!! Don't continue with removal unless instructed by an authorized helper !!!
Fix running from C:\Program Files\navilog1
Updated on 17.10.2007 at 20h00 by IL-MAFIOSO
Microsoft Windows XP [Version 5.1.2600]
Version Internet Explorer : 6.0.2800.1106
Done in normal mode
*** Searching for installed Software ***
*** Search folders in C:\WINDOWS ***
*** Search folders in C:\Program Files ***
*** Search folders in C:\Documents and Settings\All Users\Application Data ***
*** Search folders in C:\Documents and Settings\Lisa Pacella\Application Data ***
*** Search folders in C:\DOCUME~1\ALLUSE~1\STARTM~1\PROGRAMS ***
*** Search with Catchme-rootkit/stealth malware detector by gmer ***
for more info : http://www.gmer.net
No file found in :
- C:\WINDOWS\system32
- C:\DOCUME~1\LISAPA~1\LOCALS~1\APPLIC~1
*** Search with GenericNaviSearch ***
!!! Possibility of legitimate files in the result !!!
!!! Must always be checked before manually deleting !!!
* Scan in C:\WINDOWS\system32 *
* Scan in C:\DOCUME~1\LISAPA~1\LOCALS~1\APPLIC~1 *
*** Search files ***
C:\WINDOWS\Downloaded Program Files\IaLdr32.inf found !
C:\WINDOWS\system32\egaccess4_1058.dll found !
C:\WINDOWS\system32\egaccess4_1059.dll found !
C:\WINDOWS\system32\egaccess4_1060.dll found !
C:\WINDOWS\system32\egaccess4_1061.dll found !
C:\WINDOWS\system32\egaccess4_1064.dll found !
C:\WINDOWS\system32\EGDACCESS_ASPIV4_1063a.dll found !
C:\WINDOWS\system32\EGDACCESS_ASPIV4_1064.dll found !
C:\WINDOWS\system32\EGDACCESS_ASPIV4_1065.dll found !
C:\WINDOWS\system32\EGDACCESS_ASPIV4_1066.dll found !
C:\WINDOWS\system32\EGDACCESS_ASPIV4_1068.dll found !
C:\WINDOWS\system32\EGDACCESS_ASPIV4_1069.dll found !
C:\WINDOWS\system32\EGDACCESS_ASPIV4_1070.dll found !
C:\WINDOWS\system32\EGDACCESS_ASPIV4_1071.dll found !
C:\WINDOWS\system32\EGDACCESS_ASPIV4_1073.dll found !
*** Search specific Registry keys ***
*** Complementary Search ***
(Search specific files)
1)Search known files:
2)Heuristic Search :
C:\WINDOWS\system32\zloaym.exe found !
3)Certificates Search :
Egroup certificate not found !
*** Search completed on Sat 10/20/2007 at 13:11:11.67 ***
[external image: Posted Image] Here's the windelf log:
WIN32DELFKIL LOGFILE - by Marckie
version 3.131
Sat 10/20/2007 13:16:02.23
running from: "C:\Documents and Settings\Lisa Pacella\Desktop\Kathy"
— File(s) found in Windows directory —
— File(s) found in system32 folder —
— Services —
— Export SharedTaskScheduler key —
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
— Notify key —
— rebooting the computer —
— File(s) found in Windows directory —
— File(s) found in system32 folder —
— Services —
— Export SharedTaskSchedulerkey —
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
— Notify key —
Finished!
[external image: Posted Image] Here's the sysclean log:
Damage Cleanup Engine (DCE) 5.3(Build 1103)
Windows XP(Build 2600: Service Pack 1)
Start time : Sat Oct 20 2007 13:41:50
Load Damage Cleanup Template (DCT) "C:\Documents and Settings\Lisa Pacella\Desktop\Kathy\Sysclean\TMRDCT.ptn" (version ) [fail]
Load Damage Cleanup Template (DCT) "C:\Documents and Settings\Lisa Pacella\Desktop\Kathy\Sysclean\tsc.ptn" (version 904) [success]
Complete time : Sat Oct 20 2007 13:42:15
Execute pattern count(2935), Virus found count(0), Virus clean count(0), Clean failed count(0)
[external image: Posted Image] and finally, a new HijackThis log:
Logfile of HijackThis v1.99.1
Scan saved at 2:45:56 PM, on 10/20/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\SiteAdvisor\6172\SAService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe
C:\WINDOWS\System32\NILaunch.exe
C:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE
C:\program files\mcafee.com\vso\mcvsshld.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
C:\Program Files\Common Files\Verizon Online\ConnMgr\cmisrv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\Program Files\America Online 8.0\aoltray.exe
C:\Program Files\Common Files\Verizon Online\AppMgr\vzOpenUIServer.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;http://localhost
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
O2 - BHO: Nick Aracde Toolbar - {4E7BD74F-2B8D-469E-9EB4-FE6FA694B13E} - C:\PROGRA~1\NICKAR~1\NICKAR~1.DLL (file missing)
O2 - BHO: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\WINDOWS\DOWNLO~1\vzbb.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\WINDOWS\DOWNLO~1\vzbb.dll (file missing)
O3 - Toolbar: Nick Aracde Toolbar - {4E7BD74F-2B8D-469E-9EB4-FE6FA694B13E} - C:\PROGRA~1\NICKAR~1\NICKAR~1.DLL (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [VerizonServicepoint.exe] C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe
O4 - HKLM\..\Run: [Net-It Launcher] C:\WINDOWS\System32\NILaunch.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [KAZAA] C:\Program Files\Kazaa\kazaa.exe /SYSTRAY
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [A Verizon App] C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE
O4 - HKLM\..\Run: [VirusScan Online] c:\program files\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\MWSBAR.DLL,S
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: America Online 8.0 Tray Icon.lnk = C:\Program Files\America Online 8.0\aoltray.exe
O4 - Global Startup: AOL Companion.lnk = C:\Program Files\AOL Companion\companion.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/…?p=ZKxdm011YYUS
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM
O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM95\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon…DSL/tgctlcm.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f…p1.0.0.15-3.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {A7ECD556-D6F6-4F41-8C6B-14AB246801A0} (Secure Delivery) - http://kdx.kontiki.com/kdx/Client403/kdx.cab
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6172\SAService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Talk to you soon!
Scotty
Hello
* Double click on Navilog1 shortcut icon on your desktop to run it.
* Press E for English from the language Menu.
* Type 2 in the next Menu and press Enter.
* The tool will then advise you that it will restart your computer.
* Close all open windows and save personnal documents, if open, too.
* If your computer doesn't restart automatically, restart it manually.
* Choose your usual session.
* Wait for the *** Clean finished the … *** message (It may take a reasonable amount of time)
* A new document will be produced.
* Please copy/paste the contents of this report in your next reply.
* Your desktop will now appear.
Note : In the event you lose your desktop, press CTRL+ALT+Delete and run Explorer.exe as a new task.
The report is also saved in the root directory, %SystemDrive%\cleannavi.txt.. (usually C:\cleannavi.txt)
Also run Combofix again and post the latest log.
* Double click on Navilog1 shortcut icon on your desktop to run it.
* Press E for English from the language Menu.
* Type 2 in the next Menu and press Enter.
* The tool will then advise you that it will restart your computer.
* Close all open windows and save personnal documents, if open, too.
* If your computer doesn't restart automatically, restart it manually.
* Choose your usual session.
* Wait for the *** Clean finished the … *** message (It may take a reasonable amount of time)
* A new document will be produced.
* Please copy/paste the contents of this report in your next reply.
* Your desktop will now appear.
Note : In the event you lose your desktop, press CTRL+ALT+Delete and run Explorer.exe as a new task.
The report is also saved in the root directory, %SystemDrive%\cleannavi.txt.. (usually C:\cleannavi.txt)
Also run Combofix again and post the latest log.
Kathy
Hi, Scotty! 
[external image: Posted Image] Here is the Navilog1 report:
Navipromo Removal version 3.3.0 started on Sun 10/21/2007 at 15:55:38.14
Fix running from C:\Program Files\navilog1
Updated on 17.10.2007 at 20h00 by IL-MAFIOSO
Microsoft Windows XP [Version 5.1.2600]
Internet Explorer : 6.0.2800.1106
Automatic removal
*** fsbl1.txt not found ***
(Check that Catchme found nothing in Search Mode)
*** Deleting with Backups GenericNaviSearch results ***
* Deletion in C:\WINDOWS\System32 *
* Deletion in C:\DOCUME~1\LISAPA~1\LOCALS~1\APPLIC~1 *
*** Deleting folders in C:\WINDOWS ***
*** Deleting folders in C:\Program Files ***
*** Deleting folders in C:\Documents and Settings\All Users\Application Data ***
*** Deleting folders in C:\Documents and Settings\Lisa Pacella\Application Data ***
*** Deleting folders in C:\DOCUME~1\ALLUSE~1\STARTM~1\PROGRAMS ***
*** Deleting files ***
C:\WINDOWS\Downloaded Program Files\IaLdr32.inf deleted !
C:\WINDOWS\system32\egaccess4_1058.dll deleted !
C:\WINDOWS\system32\egaccess4_1059.dll deleted !
C:\WINDOWS\system32\egaccess4_1060.dll deleted !
C:\WINDOWS\system32\egaccess4_1061.dll deleted !
C:\WINDOWS\system32\egaccess4_1064.dll deleted !
C:\WINDOWS\system32\EGDACCESS_ASPIV4_1063a.dll deleted !
C:\WINDOWS\system32\EGDACCESS_ASPIV4_1064.dll deleted !
C:\WINDOWS\system32\EGDACCESS_ASPIV4_1065.dll deleted !
C:\WINDOWS\system32\EGDACCESS_ASPIV4_1066.dll deleted !
C:\WINDOWS\system32\EGDACCESS_ASPIV4_1068.dll deleted !
C:\WINDOWS\system32\EGDACCESS_ASPIV4_1069.dll deleted !
C:\WINDOWS\system32\EGDACCESS_ASPIV4_1070.dll deleted !
C:\WINDOWS\system32\EGDACCESS_ASPIV4_1071.dll deleted !
C:\WINDOWS\system32\EGDACCESS_ASPIV4_1073.dll deleted !
*** Deleting temporary files ***
Cleaning of C:\WINDOWS\Temp done !
Cleaning of C:\Documents and Settings\Lisa Pacella\Local Settings\Temp done !
*** Complementary Search ***
(Search specific files)
1)Search known files:
2)Heuristic search and deletion with backups :
C:\WINDOWS\system32\zloaym.exe found !
Copy C:\WINDOWS\system32\zloaym.exe done !
C:\WINDOWS\system32\zloaym.exe deleted !
*** Copy Registry to Backupnavi folder ***
Backing up Registry done !
*** Cleaning Registry ***
Registry cleaned
*** Certificates ***
Egroup Certificate not found !
*** fsbl1.txt not found ***
(Check that Catchme found nothing in Search Mode)
*** Deleting with Backups GenericNaviSearch results ***
* Deletion in C:\WINDOWS\System32 *
* Deletion in C:\DOCUME~1\LISAPA~1\LOCALS~1\APPLIC~1 *
*** Deleting folders in C:\WINDOWS ***
*** Deleting folders in C:\Program Files ***
*** Deleting folders in C:\Documents and Settings\All Users\Application Data ***
*** Deleting folders in C:\Documents and Settings\Lisa Pacella\Application Data ***
*** Deleting folders in C:\DOCUME~1\ALLUSE~1\STARTM~1\PROGRAMS ***
*** Deleting files ***
*** Deleting temporary files ***
Cleaning of C:\WINDOWS\Temp done !
Cleaning of C:\Documents and Settings\Lisa Pacella\Local Settings\Temp done !
*** Complementary Search ***
(Search specific files)
1)Search known files:
2)Heuristic search and deletion with backups :
*** Copy Registry to Backupnavi folder ***
Backing up Registry done !
*** Cleaning Registry ***
Error : File regnavi1.reg not found !
Registry was not cleaned !
*** Certificates ***
Egroup Certificate not found !
*** fsbl1.txt not found ***
(Check that Catchme found nothing in Search Mode)
*** Deleting with Backups GenericNaviSearch results ***
* Deletion in C:\WINDOWS\System32 *
* Deletion in C:\DOCUME~1\LISAPA~1\LOCALS~1\APPLIC~1 *
*** Deleting folders in C:\WINDOWS ***
*** Deleting folders in C:\Program Files ***
*** Deleting folders in C:\Documents and Settings\All Users\Application Data ***
*** Deleting folders in C:\Documents and Settings\Lisa Pacella\Application Data ***
*** Deleting folders in C:\DOCUME~1\ALLUSE~1\STARTM~1\PROGRAMS ***
*** Deleting files ***
*** Deleting temporary files ***
Cleaning of C:\WINDOWS\Temp done !
Cleaning of C:\Documents and Settings\Lisa Pacella\Local Settings\Temp done !
*** Complementary Search ***
(Search specific files)
1)Search known files:
2)Heuristic search and deletion with backups :
*** Copy Registry to Backupnavi folder ***
Backing up Registry done !
*** Cleaning Registry ***
Error : File regnavi1.reg not found !
Registry was not cleaned !
*** Certificates ***
Egroup Certificate not found !
[external image: Posted Image] Here's the ComboFix log:
ComboFix 07-10-11.3 - Lisa Pacella 2007-10-21 16:36:14.7 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.57 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\Kathy\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Lisa Pacella\Application Data\FunWebProducts
C:\Program Files\FunWebProducts
C:\Program Files\FunWebProducts\Shared\Cache\CursorManiaBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\MailStampBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\MyStationeryBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\SmileyCentralBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\WebfettiBtn.html
C:\Program Files\internet explorer\msimg32.dll
C:\Program Files\MyWebSearch\bar\1.bin\F3BKGERR.JPG
C:\Program Files\MyWebSearch\bar\1.bin\F3BROVLY.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3CJPEG.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3DTACTL.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3HISTSW.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3HTMLMU.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3HTTPCT.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3IMSTUB.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3POPSWT.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3PSSAVR.SCR
C:\Program Files\MyWebSearch\bar\1.bin\F3REPROX.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3SCHMON.EXE
C:\Program Files\MyWebSearch\bar\1.bin\F3SCRCTR.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3SHLLVW.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3SPACER.WMV
C:\Program Files\MyWebSearch\bar\1.bin\F3WALLPP.DAT
C:\Program Files\MyWebSearch\bar\1.bin\F3WPHOOK.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3FFXTBR.JAR
C:\Program Files\MyWebSearch\bar\1.bin\M3FFXTBR.MANIFEST
C:\Program Files\MyWebSearch\bar\1.bin\M3HTML.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3IDLE.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3IMPIPE.EXE
C:\Program Files\MyWebSearch\bar\1.bin\M3MSG.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3NTSTBR.JAR
C:\Program Files\MyWebSearch\bar\1.bin\M3NTSTBR.MANIFEST
C:\Program Files\MyWebSearch\bar\1.bin\M3OUTLCN.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3PLUGIN.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3SKIN.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3SKPLAY.EXE
C:\Program Files\MyWebSearch\bar\1.bin\M3SLSRCH.EXE
C:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE
C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
C:\Program Files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL
C:\Program Files\MyWebSearch\bar\1.bin\MWSOESTB.DLL
C:\Program Files\MyWebSearch\bar\1.bin\NPMYWEBS.DLL
C:\Program Files\MyWebSearch\bar\Avatar\COMMON.F3S
C:\Program Files\MyWebSearch\bar\Cache23A2F77
C:\Program Files\MyWebSearch\bar\Cache23A3505
C:\Program Files\MyWebSearch\bar\Cache23A3841.bin
C:\Program Files\MyWebSearch\bar\Cache23E93DB.bin
C:\Program Files\MyWebSearch\bar\Cache23E95B0.bin
C:\Program Files\MyWebSearch\bar\Cache23E9785.bin
C:\Program Files\MyWebSearch\bar\Cache23E9C28.bin
C:\Program Files\MyWebSearch\bar\Cache5F2A618.bin
C:\Program Files\MyWebSearch\bar\Cache5F2A86A.bin
C:\Program Files\MyWebSearch\bar\Cache5F2ACFE.bin
C:\Program Files\MyWebSearch\bar\Cache5F2AE94.bin
C:\Program Files\MyWebSearch\bar\Cache5F2AF9E.bin
C:\Program Files\MyWebSearch\bar\Cache5F2B21E.bin
C:\Program Files\MyWebSearch\bar\Cache5F2B3A5.bin
C:\Program Files\MyWebSearch\bar\Cache5F2B53B.bin
C:\Program Files\MyWebSearch\bar\Cache\files.ini
C:\Program Files\MyWebSearch\bar\Game\CHECKERS.F3S
C:\Program Files\MyWebSearch\bar\Game\CHESS.F3S
C:\Program Files\MyWebSearch\bar\Game\REVERSI.F3S
C:\Program Files\MyWebSearch\bar\History\search2
C:\Program Files\MyWebSearch\bar\icons\CM.ICO
C:\Program Files\MyWebSearch\bar\icons\MFC.ICO
C:\Program Files\MyWebSearch\bar\icons\PSS.ICO
C:\Program Files\MyWebSearch\bar\icons\SMILEY.ICO
C:\Program Files\MyWebSearch\bar\icons\WB.ICO
C:\Program Files\MyWebSearch\bar\icons\ZWINKY.ICO
C:\Program Files\MyWebSearch\bar\Message\COMMON.F3S
C:\Program Files\MyWebSearch\bar\Notifier\COMMON.F3S
C:\Program Files\MyWebSearch\bar\Notifier\DOG.F3S
C:\Program Files\MyWebSearch\bar\Notifier\FISH.F3S
C:\Program Files\MyWebSearch\bar\Notifier\KUNGFU.F3S
C:\Program Files\MyWebSearch\bar\Notifier\LIFEGARD.F3S
C:\Program Files\MyWebSearch\bar\Notifier\MAID.F3S
C:\Program Files\MyWebSearch\bar\Notifier\MAILBOX.F3S
C:\Program Files\MyWebSearch\bar\Notifier\OPERA.F3S
C:\Program Files\MyWebSearch\bar\Notifier\ROBOT.F3S
C:\Program Files\MyWebSearch\bar\Notifier\SEDUCT.F3S
C:\Program Files\MyWebSearch\bar\Notifier\SURFER.F3S
C:\Program Files\MyWebSearch\bar\Settings\prevcfg2.htm
C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat
C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
C:\WINDOWS\system32\f3PSSavr.scr
C:\Program Files\MyWebSearch
.
((((((((((((((((((((((((( Files Created from 2007-09-21 to 2007-10-21 )))))))))))))))))))))))))))))))
.
2007-10-21 16:08 3,953 –a—— C:\WINDOWS\SYSTEM32\gnc.exe
2007-10-20 13:16 d——– C:\_backupD
2007-10-20 13:15 d——– C:\WINDOWS\SYSTEM32\regdacl
2007-10-20 13:15 280,286 –a—— C:\win32delfkil.exe
2007-10-20 13:15 90,112 –a—— C:\WINDOWS\SYSTEM32\regdacl.exe
2007-10-20 13:15 53,248 –a—— C:\WINDOWS\SYSTEM32\process.exe
2007-10-20 13:15 16,384 –a—— C:\WINDOWS\SYSTEM32\restart.exe
2007-10-20 13:15 4,096 –a—— C:\WINDOWS\SYSTEM32\reboot.exe
2007-10-20 13:08 d——– C:\Program Files\Navilog1
2007-10-12 17:56 d——– C:\Documents and Settings\Lisa Pacella\Application Data\Grisoft
2007-10-12 17:56 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-10-12 17:56 10,872 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys
2007-10-12 09:29 d——– C:\WINDOWS\SYSTEM32\Kaspersky Lab
2007-10-12 09:29 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-10-11 17:35 d——– C:\Program Files\SiteAdvisor
2007-10-11 17:35 d——– C:\Documents and Settings\LocalService\Application Data\SiteAdvisor
2007-10-11 17:35 d——– C:\Documents and Settings\LocalService\Application Data\SiteAdvisor
2007-10-11 17:35 d——– C:\Documents and Settings\LocalService\Application Data\SiteAdvisor
2007-10-11 17:33 d——– C:\Documents and Settings\Lisa Pacella\Application Data\SiteAdvisor
2007-10-11 17:33 d——– C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2007-10-11 17:33 d——– C:\Documents and Settings\All Users\Application Data\McAfee
2007-10-11 13:29 d——– C:\Documents and Settings\Lisa Pacella\Application Data\ieSpell
2007-10-10 19:53 d——– C:\Program Files\ieSpell
2007-10-09 19:02 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-10-09 17:44 d——– C:\Documents and Settings\Lisa Pacella\Application Data\WinPatrol
2007-10-09 17:43 d——– C:\Program Files\BillP Studios
2007-10-09 13:20 d——– C:\Documents and Settings\Administrator\Application Data\Gtek
2007-10-06 17:42 21,760 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\usbstor.sys
2007-09-30 20:54 d——– C:\Program Files\The Weather Channel FW
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-21 20:24 ——— d—–w C:\Documents and Settings\Lisa Pacella\Application Data\MSN6
2007-10-20 18:11 ——— d—–w C:\Program Files\MSN Messenger
2007-10-12 19:57 ——— d—–w C:\Program Files\nickarcade
2007-10-11 11:03 ——— d—–w C:\Program Files\America Online 8.0
2007-09-26 21:35 ——— d—–w C:\Documents and Settings\Lisa Pacella\Application Data\MSNInstaller
2007-09-20 22:59 ——— d—–w C:\Program Files\Common Files\Ad-Aware SE Personal
2007-09-20 22:53 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2007-09-20 00:19 ——— d–h–r C:\Documents and Settings\Lisa Pacella\Application Data\yahoo!
2007-09-06 21:52 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-09-03 18:55 ——— d—–w C:\Program Files\EarthLink 5.0
2007-08-29 23:40 ——— d—–w C:\Documents and Settings\LocalService\Application Data\Yahoo!
2007-08-29 23:40 ——— d—–w C:\Documents and Settings\LocalService\Application Data\Yahoo!
2007-08-29 23:40 ——— d—–w C:\Documents and Settings\LocalService\Application Data\Yahoo!
2007-08-23 22:11 ——— d—–w C:\Program Files\QUICKENW
2006-11-05 15:48 0 —-a-w C:\Program Files\Common Files\err.log
2003-04-28 13:33 207,758 -c–a-w C:\Program Files\INSTALL.LOG
1998-04-02 20:51:12 77,312 -csha-r C:\WINDOWS\ic.exe
1998-04-02 20:55:56 80,384 -csha-r C:\WINDOWS\icfire.exe
1997-07-23 15:03:40 11,338 -csha-r C:\WINDOWS\ts.dll
.
((((((((((((((((((((((((((((( snapshot@2007-10-11_17.12.48.79 )))))))))))))))))))))))))))))))))))))))))
.
—-a-w 9,639,336 2006-10-04 17:03:46 C:\WINDOWS\SYSTEM32\MRT.exe
—-a-w 40,960 2007-10-20 17:15:54 C:\WINDOWS\SYSTEM32\swsc.exe
—-a-w 213,048 2005-05-24 16:27:16 C:\WINDOWS\SYSTEM32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
—-a-w 94,208 2007-08-29 19:47:20 C:\WINDOWS\SYSTEM32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
—-a-w 950,272 2007-08-29 19:49:54 C:\WINDOWS\SYSTEM32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
—-a-w 4,175 2007-10-20 17:15:54 C:\WINDOWS\SYSTEM32\regdacl\doc\SMWNCV.cmd
.
—-a-w 18,089,592 2007-09-28 05:19:39 C:\WINDOWS\SYSTEM32\MRT.exe
—-a-w 370,688 2006-11-29 21:21:29 C:\WINDOWS\SYSTEM32\swsc.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"@"="" []
"MCUpdateExe"="C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe" [2002-09-04 11:28]
"VerizonServicepoint.exe"="C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe" [2006-02-01 18:33]
"Net-It Launcher"="C:\WINDOWS\System32\NILaunch.exe" [1998-02-05 15:16]
"Motive SmartBridge"="C:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe" [2005-04-13 19:51]
"MCAgentExe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2002-09-06 19:15]
"Lexmark X1100 Series"="C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" [2003-03-28 10:18]
"KAZAA"="C:\Program Files\Kazaa\kazaa.exe" []
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2003-01-13 15:07]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2003-01-13 14:53]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 04:59 C:\WINDOWS\BCMSMMSG.exe]
"A Verizon App"="C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE" [2005-05-23 13:20]
"VirusScan Online"="c:\program files\mcafee.com\vso\mcvsshld.exe" [2002-10-04 16:09]
"WinPatrol"="C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe" [2007-09-23 13:30]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6172\SiteAdv.exe" [2007-08-13 14:05]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 05:25]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-08-13 20:04]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2005-06-14 10:05]
"MSMSGS"="C:\Program Files\Messenger\MSMSGS.exe" [2004-11-15 17:18]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
""=
"MySpaceIM"=C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
America Online 8.0 Tray Icon.lnk - C:\Program Files\America Online 8.0\aoltray.exe [2003-04-28 09:36:59]
AOL Companion.lnk - C:\Program Files\AOL Companion\companion.exe [2003-04-28 09:37:32]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 16:05:56]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
R2 mrtRate;mrtRate;C:\WINDOWS\System32\drivers\mrtRate.sys
R3 BCMModem;BCM V.92 56K Modem;C:\WINDOWS\System32\DRIVERS\BCMSM.sys
R3 NaiFiltr;NaiFiltr;C:\WINDOWS\System32\DRIVERS\NaiFiltr.sys
S3 JL2005;JL2005A Toy Camera;C:\WINDOWS\System32\Drivers\toywdm.sys
S3 MR97310_VGA_DUAL_CAMERA;VGA Dual-Mode Camera;C:\WINDOWS\System32\DRIVERS\mr97310v.sys
.
Contents of the 'Scheduled Tasks' folder
"2007-10-21 20:46:00 C:\WINDOWS\Tasks\McAfee.com Update Check (D3GH4R21-Owner).job"
- C:\PROGRA~1\McAfee.com\Agent\mcupdate.exe
"2007-10-21 20:37:00 C:\WINDOWS\Tasks\McAfee.com Update Check (LISA-$@nthony$).job"
- C:\PROGRA~1\McAfee.com\Agent\mcupdate.exe
"2007-10-21 20:43:02 C:\WINDOWS\Tasks\McAfee.com Update Check (LISA-Anthony).job"
"2007-10-21 20:37:00 C:\WINDOWS\Tasks\McAfee.com Update Check (LISA-anthony_2).job"
- C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
"2007-10-21 20:37:00 C:\WINDOWS\Tasks\McAfee.com Update Check (LISA-Christopher).job"
- C:\PROGRA~1\McAfee.com\Agent\mcupdate.exe
"2007-10-21 20:44:00 C:\WINDOWS\Tasks\McAfee.com Update Check (LISA-Guest).job"
- C:\PROGRA~1\McAfee.com\Agent\mcupdate.exe
"2007-10-21 20:43:19 C:\WINDOWS\Tasks\McAfee.com Update Check (LISA-Lisa Pacella).job"
- C:\PROGRA~1\McAfee.com\Agent\mcupdate.exe
"2007-10-21 20:46:01 C:\WINDOWS\Tasks\McAfee.com Update Check (LISA-Matthew).job"
- C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
"2007-10-21 20:41:00 C:\WINDOWS\Tasks\PCHealth Scheduler for Upload Library.job"
- C:\WINDOWS\PCHealth\UploadLB\Binaries\UploadM.exe
.
**************************************************************************
catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-21 16:43:14
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-10-21 16:46:55 - machine was rebooted
C:\ComboFix2.txt … 2007-10-12 09:02
C:\ComboFix3.txt … 2007-10-12 07:33
.
— E O F —
[external image: Posted Image] and here's a new HijackThis log:
Logfile of HijackThis v1.99.1
Scan saved at 4:57:57 PM, on 10/21/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\SiteAdvisor\6172\SAService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe
C:\WINDOWS\System32\NILaunch.exe
C:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE
C:\program files\mcafee.com\vso\mcvsshld.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
C:\Program Files\Common Files\Verizon Online\ConnMgr\cmisrv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\Program Files\Common Files\Verizon Online\AppMgr\vzOpenUIServer.exe
C:\Program Files\America Online 8.0\aoltray.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\MSN\MSNCoreFiles\msn.exe
C:\Program Files\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;http://localhost
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: &Yahoo;! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
O2 - BHO: Nick Aracde Toolbar - {4E7BD74F-2B8D-469E-9EB4-FE6FA694B13E} - C:\PROGRA~1\NICKAR~1\NICKAR~1.DLL (file missing)
O2 - BHO: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\WINDOWS\DOWNLO~1\vzbb.dll (file missing)
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\WINDOWS\DOWNLO~1\vzbb.dll (file missing)
O3 - Toolbar: Nick Aracde Toolbar - {4E7BD74F-2B8D-469E-9EB4-FE6FA694B13E} - C:\PROGRA~1\NICKAR~1\NICKAR~1.DLL (file missing)
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [VerizonServicepoint.exe] C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe
O4 - HKLM\..\Run: [Net-It Launcher] C:\WINDOWS\System32\NILaunch.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [KAZAA] C:\Program Files\Kazaa\kazaa.exe /SYSTRAY
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [A Verizon App] C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE
O4 - HKLM\..\Run: [VirusScan Online] c:\program files\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: America Online 8.0 Tray Icon.lnk = C:\Program Files\America Online 8.0\aoltray.exe
O4 - Global Startup: AOL Companion.lnk = C:\Program Files\AOL Companion\companion.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &ieSpell; Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: &Search; - http://edits.mywebsearch.com/toolbaredits/…?p=ZKxdm011YYUS
O8 - Extra context menu item: Check &Spelling; - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM
O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM95\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon…DSL/tgctlcm.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f…p1.0.0.15-3.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {A7ECD556-D6F6-4F41-8C6B-14AB246801A0} (Secure Delivery) - http://kdx.kontiki.com/kdx/Client403/kdx.cab
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6172\SAService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Kathy
[external image: Posted Image] Here is the Navilog1 report:
Navipromo Removal version 3.3.0 started on Sun 10/21/2007 at 15:55:38.14
Fix running from C:\Program Files\navilog1
Updated on 17.10.2007 at 20h00 by IL-MAFIOSO
Microsoft Windows XP [Version 5.1.2600]
Internet Explorer : 6.0.2800.1106
Automatic removal
*** fsbl1.txt not found ***
(Check that Catchme found nothing in Search Mode)
*** Deleting with Backups GenericNaviSearch results ***
* Deletion in C:\WINDOWS\System32 *
* Deletion in C:\DOCUME~1\LISAPA~1\LOCALS~1\APPLIC~1 *
*** Deleting folders in C:\WINDOWS ***
*** Deleting folders in C:\Program Files ***
*** Deleting folders in C:\Documents and Settings\All Users\Application Data ***
*** Deleting folders in C:\Documents and Settings\Lisa Pacella\Application Data ***
*** Deleting folders in C:\DOCUME~1\ALLUSE~1\STARTM~1\PROGRAMS ***
*** Deleting files ***
C:\WINDOWS\Downloaded Program Files\IaLdr32.inf deleted !
C:\WINDOWS\system32\egaccess4_1058.dll deleted !
C:\WINDOWS\system32\egaccess4_1059.dll deleted !
C:\WINDOWS\system32\egaccess4_1060.dll deleted !
C:\WINDOWS\system32\egaccess4_1061.dll deleted !
C:\WINDOWS\system32\egaccess4_1064.dll deleted !
C:\WINDOWS\system32\EGDACCESS_ASPIV4_1063a.dll deleted !
C:\WINDOWS\system32\EGDACCESS_ASPIV4_1064.dll deleted !
C:\WINDOWS\system32\EGDACCESS_ASPIV4_1065.dll deleted !
C:\WINDOWS\system32\EGDACCESS_ASPIV4_1066.dll deleted !
C:\WINDOWS\system32\EGDACCESS_ASPIV4_1068.dll deleted !
C:\WINDOWS\system32\EGDACCESS_ASPIV4_1069.dll deleted !
C:\WINDOWS\system32\EGDACCESS_ASPIV4_1070.dll deleted !
C:\WINDOWS\system32\EGDACCESS_ASPIV4_1071.dll deleted !
C:\WINDOWS\system32\EGDACCESS_ASPIV4_1073.dll deleted !
*** Deleting temporary files ***
Cleaning of C:\WINDOWS\Temp done !
Cleaning of C:\Documents and Settings\Lisa Pacella\Local Settings\Temp done !
*** Complementary Search ***
(Search specific files)
1)Search known files:
2)Heuristic search and deletion with backups :
C:\WINDOWS\system32\zloaym.exe found !
Copy C:\WINDOWS\system32\zloaym.exe done !
C:\WINDOWS\system32\zloaym.exe deleted !
*** Copy Registry to Backupnavi folder ***
Backing up Registry done !
*** Cleaning Registry ***
Registry cleaned
*** Certificates ***
Egroup Certificate not found !
*** fsbl1.txt not found ***
(Check that Catchme found nothing in Search Mode)
*** Deleting with Backups GenericNaviSearch results ***
* Deletion in C:\WINDOWS\System32 *
* Deletion in C:\DOCUME~1\LISAPA~1\LOCALS~1\APPLIC~1 *
*** Deleting folders in C:\WINDOWS ***
*** Deleting folders in C:\Program Files ***
*** Deleting folders in C:\Documents and Settings\All Users\Application Data ***
*** Deleting folders in C:\Documents and Settings\Lisa Pacella\Application Data ***
*** Deleting folders in C:\DOCUME~1\ALLUSE~1\STARTM~1\PROGRAMS ***
*** Deleting files ***
*** Deleting temporary files ***
Cleaning of C:\WINDOWS\Temp done !
Cleaning of C:\Documents and Settings\Lisa Pacella\Local Settings\Temp done !
*** Complementary Search ***
(Search specific files)
1)Search known files:
2)Heuristic search and deletion with backups :
*** Copy Registry to Backupnavi folder ***
Backing up Registry done !
*** Cleaning Registry ***
Error : File regnavi1.reg not found !
Registry was not cleaned !
*** Certificates ***
Egroup Certificate not found !
*** fsbl1.txt not found ***
(Check that Catchme found nothing in Search Mode)
*** Deleting with Backups GenericNaviSearch results ***
* Deletion in C:\WINDOWS\System32 *
* Deletion in C:\DOCUME~1\LISAPA~1\LOCALS~1\APPLIC~1 *
*** Deleting folders in C:\WINDOWS ***
*** Deleting folders in C:\Program Files ***
*** Deleting folders in C:\Documents and Settings\All Users\Application Data ***
*** Deleting folders in C:\Documents and Settings\Lisa Pacella\Application Data ***
*** Deleting folders in C:\DOCUME~1\ALLUSE~1\STARTM~1\PROGRAMS ***
*** Deleting files ***
*** Deleting temporary files ***
Cleaning of C:\WINDOWS\Temp done !
Cleaning of C:\Documents and Settings\Lisa Pacella\Local Settings\Temp done !
*** Complementary Search ***
(Search specific files)
1)Search known files:
2)Heuristic search and deletion with backups :
*** Copy Registry to Backupnavi folder ***
Backing up Registry done !
*** Cleaning Registry ***
Error : File regnavi1.reg not found !
Registry was not cleaned !
*** Certificates ***
Egroup Certificate not found !
[external image: Posted Image] Here's the ComboFix log:
ComboFix 07-10-11.3 - Lisa Pacella 2007-10-21 16:36:14.7 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.57 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\Kathy\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Lisa Pacella\Application Data\FunWebProducts
C:\Program Files\FunWebProducts
C:\Program Files\FunWebProducts\Shared\Cache\CursorManiaBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\MailStampBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\MyStationeryBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\SmileyCentralBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\WebfettiBtn.html
C:\Program Files\internet explorer\msimg32.dll
C:\Program Files\MyWebSearch\bar\1.bin\F3BKGERR.JPG
C:\Program Files\MyWebSearch\bar\1.bin\F3BROVLY.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3CJPEG.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3DTACTL.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3HISTSW.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3HTMLMU.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3HTTPCT.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3IMSTUB.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3POPSWT.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3PSSAVR.SCR
C:\Program Files\MyWebSearch\bar\1.bin\F3REPROX.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3SCHMON.EXE
C:\Program Files\MyWebSearch\bar\1.bin\F3SCRCTR.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3SHLLVW.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3SPACER.WMV
C:\Program Files\MyWebSearch\bar\1.bin\F3WALLPP.DAT
C:\Program Files\MyWebSearch\bar\1.bin\F3WPHOOK.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3FFXTBR.JAR
C:\Program Files\MyWebSearch\bar\1.bin\M3FFXTBR.MANIFEST
C:\Program Files\MyWebSearch\bar\1.bin\M3HTML.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3IDLE.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3IMPIPE.EXE
C:\Program Files\MyWebSearch\bar\1.bin\M3MSG.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3NTSTBR.JAR
C:\Program Files\MyWebSearch\bar\1.bin\M3NTSTBR.MANIFEST
C:\Program Files\MyWebSearch\bar\1.bin\M3OUTLCN.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3PLUGIN.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3SKIN.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3SKPLAY.EXE
C:\Program Files\MyWebSearch\bar\1.bin\M3SLSRCH.EXE
C:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE
C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
C:\Program Files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL
C:\Program Files\MyWebSearch\bar\1.bin\MWSOESTB.DLL
C:\Program Files\MyWebSearch\bar\1.bin\NPMYWEBS.DLL
C:\Program Files\MyWebSearch\bar\Avatar\COMMON.F3S
C:\Program Files\MyWebSearch\bar\Cache23A2F77
C:\Program Files\MyWebSearch\bar\Cache23A3505
C:\Program Files\MyWebSearch\bar\Cache23A3841.bin
C:\Program Files\MyWebSearch\bar\Cache23E93DB.bin
C:\Program Files\MyWebSearch\bar\Cache23E95B0.bin
C:\Program Files\MyWebSearch\bar\Cache23E9785.bin
C:\Program Files\MyWebSearch\bar\Cache23E9C28.bin
C:\Program Files\MyWebSearch\bar\Cache5F2A618.bin
C:\Program Files\MyWebSearch\bar\Cache5F2A86A.bin
C:\Program Files\MyWebSearch\bar\Cache5F2ACFE.bin
C:\Program Files\MyWebSearch\bar\Cache5F2AE94.bin
C:\Program Files\MyWebSearch\bar\Cache5F2AF9E.bin
C:\Program Files\MyWebSearch\bar\Cache5F2B21E.bin
C:\Program Files\MyWebSearch\bar\Cache5F2B3A5.bin
C:\Program Files\MyWebSearch\bar\Cache5F2B53B.bin
C:\Program Files\MyWebSearch\bar\Cache\files.ini
C:\Program Files\MyWebSearch\bar\Game\CHECKERS.F3S
C:\Program Files\MyWebSearch\bar\Game\CHESS.F3S
C:\Program Files\MyWebSearch\bar\Game\REVERSI.F3S
C:\Program Files\MyWebSearch\bar\History\search2
C:\Program Files\MyWebSearch\bar\icons\CM.ICO
C:\Program Files\MyWebSearch\bar\icons\MFC.ICO
C:\Program Files\MyWebSearch\bar\icons\PSS.ICO
C:\Program Files\MyWebSearch\bar\icons\SMILEY.ICO
C:\Program Files\MyWebSearch\bar\icons\WB.ICO
C:\Program Files\MyWebSearch\bar\icons\ZWINKY.ICO
C:\Program Files\MyWebSearch\bar\Message\COMMON.F3S
C:\Program Files\MyWebSearch\bar\Notifier\COMMON.F3S
C:\Program Files\MyWebSearch\bar\Notifier\DOG.F3S
C:\Program Files\MyWebSearch\bar\Notifier\FISH.F3S
C:\Program Files\MyWebSearch\bar\Notifier\KUNGFU.F3S
C:\Program Files\MyWebSearch\bar\Notifier\LIFEGARD.F3S
C:\Program Files\MyWebSearch\bar\Notifier\MAID.F3S
C:\Program Files\MyWebSearch\bar\Notifier\MAILBOX.F3S
C:\Program Files\MyWebSearch\bar\Notifier\OPERA.F3S
C:\Program Files\MyWebSearch\bar\Notifier\ROBOT.F3S
C:\Program Files\MyWebSearch\bar\Notifier\SEDUCT.F3S
C:\Program Files\MyWebSearch\bar\Notifier\SURFER.F3S
C:\Program Files\MyWebSearch\bar\Settings\prevcfg2.htm
C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat
C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
C:\WINDOWS\system32\f3PSSavr.scr
C:\Program Files\MyWebSearch
.
((((((((((((((((((((((((( Files Created from 2007-09-21 to 2007-10-21 )))))))))))))))))))))))))))))))
.
2007-10-21 16:08 3,953 –a—— C:\WINDOWS\SYSTEM32\gnc.exe
2007-10-20 13:16 d——– C:\_backupD
2007-10-20 13:15 d——– C:\WINDOWS\SYSTEM32\regdacl
2007-10-20 13:15 280,286 –a—— C:\win32delfkil.exe
2007-10-20 13:15 90,112 –a—— C:\WINDOWS\SYSTEM32\regdacl.exe
2007-10-20 13:15 53,248 –a—— C:\WINDOWS\SYSTEM32\process.exe
2007-10-20 13:15 16,384 –a—— C:\WINDOWS\SYSTEM32\restart.exe
2007-10-20 13:15 4,096 –a—— C:\WINDOWS\SYSTEM32\reboot.exe
2007-10-20 13:08 d——– C:\Program Files\Navilog1
2007-10-12 17:56 d——– C:\Documents and Settings\Lisa Pacella\Application Data\Grisoft
2007-10-12 17:56 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-10-12 17:56 10,872 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys
2007-10-12 09:29 d——– C:\WINDOWS\SYSTEM32\Kaspersky Lab
2007-10-12 09:29 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-10-11 17:35 d——– C:\Program Files\SiteAdvisor
2007-10-11 17:35 d——– C:\Documents and Settings\LocalService\Application Data\SiteAdvisor
2007-10-11 17:35 d——– C:\Documents and Settings\LocalService\Application Data\SiteAdvisor
2007-10-11 17:35 d——– C:\Documents and Settings\LocalService\Application Data\SiteAdvisor
2007-10-11 17:33 d——– C:\Documents and Settings\Lisa Pacella\Application Data\SiteAdvisor
2007-10-11 17:33 d——– C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2007-10-11 17:33 d——– C:\Documents and Settings\All Users\Application Data\McAfee
2007-10-11 13:29 d——– C:\Documents and Settings\Lisa Pacella\Application Data\ieSpell
2007-10-10 19:53 d——– C:\Program Files\ieSpell
2007-10-09 19:02 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-10-09 17:44 d——– C:\Documents and Settings\Lisa Pacella\Application Data\WinPatrol
2007-10-09 17:43 d——– C:\Program Files\BillP Studios
2007-10-09 13:20 d——– C:\Documents and Settings\Administrator\Application Data\Gtek
2007-10-06 17:42 21,760 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\usbstor.sys
2007-09-30 20:54 d——– C:\Program Files\The Weather Channel FW
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-21 20:24 ——— d—–w C:\Documents and Settings\Lisa Pacella\Application Data\MSN6
2007-10-20 18:11 ——— d—–w C:\Program Files\MSN Messenger
2007-10-12 19:57 ——— d—–w C:\Program Files\nickarcade
2007-10-11 11:03 ——— d—–w C:\Program Files\America Online 8.0
2007-09-26 21:35 ——— d—–w C:\Documents and Settings\Lisa Pacella\Application Data\MSNInstaller
2007-09-20 22:59 ——— d—–w C:\Program Files\Common Files\Ad-Aware SE Personal
2007-09-20 22:53 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2007-09-20 00:19 ——— d–h–r C:\Documents and Settings\Lisa Pacella\Application Data\yahoo!
2007-09-06 21:52 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-09-03 18:55 ——— d—–w C:\Program Files\EarthLink 5.0
2007-08-29 23:40 ——— d—–w C:\Documents and Settings\LocalService\Application Data\Yahoo!
2007-08-29 23:40 ——— d—–w C:\Documents and Settings\LocalService\Application Data\Yahoo!
2007-08-29 23:40 ——— d—–w C:\Documents and Settings\LocalService\Application Data\Yahoo!
2007-08-23 22:11 ——— d—–w C:\Program Files\QUICKENW
2006-11-05 15:48 0 —-a-w C:\Program Files\Common Files\err.log
2003-04-28 13:33 207,758 -c–a-w C:\Program Files\INSTALL.LOG
1998-04-02 20:51:12 77,312 -csha-r C:\WINDOWS\ic.exe
1998-04-02 20:55:56 80,384 -csha-r C:\WINDOWS\icfire.exe
1997-07-23 15:03:40 11,338 -csha-r C:\WINDOWS\ts.dll
.
((((((((((((((((((((((((((((( snapshot@2007-10-11_17.12.48.79 )))))))))))))))))))))))))))))))))))))))))
.
—-a-w 9,639,336 2006-10-04 17:03:46 C:\WINDOWS\SYSTEM32\MRT.exe
—-a-w 40,960 2007-10-20 17:15:54 C:\WINDOWS\SYSTEM32\swsc.exe
—-a-w 213,048 2005-05-24 16:27:16 C:\WINDOWS\SYSTEM32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
—-a-w 94,208 2007-08-29 19:47:20 C:\WINDOWS\SYSTEM32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
—-a-w 950,272 2007-08-29 19:49:54 C:\WINDOWS\SYSTEM32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
—-a-w 4,175 2007-10-20 17:15:54 C:\WINDOWS\SYSTEM32\regdacl\doc\SMWNCV.cmd
.
—-a-w 18,089,592 2007-09-28 05:19:39 C:\WINDOWS\SYSTEM32\MRT.exe
—-a-w 370,688 2006-11-29 21:21:29 C:\WINDOWS\SYSTEM32\swsc.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"@"="" []
"MCUpdateExe"="C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe" [2002-09-04 11:28]
"VerizonServicepoint.exe"="C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe" [2006-02-01 18:33]
"Net-It Launcher"="C:\WINDOWS\System32\NILaunch.exe" [1998-02-05 15:16]
"Motive SmartBridge"="C:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe" [2005-04-13 19:51]
"MCAgentExe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2002-09-06 19:15]
"Lexmark X1100 Series"="C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" [2003-03-28 10:18]
"KAZAA"="C:\Program Files\Kazaa\kazaa.exe" []
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2003-01-13 15:07]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2003-01-13 14:53]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 04:59 C:\WINDOWS\BCMSMMSG.exe]
"A Verizon App"="C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE" [2005-05-23 13:20]
"VirusScan Online"="c:\program files\mcafee.com\vso\mcvsshld.exe" [2002-10-04 16:09]
"WinPatrol"="C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe" [2007-09-23 13:30]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6172\SiteAdv.exe" [2007-08-13 14:05]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 05:25]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-08-13 20:04]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2005-06-14 10:05]
"MSMSGS"="C:\Program Files\Messenger\MSMSGS.exe" [2004-11-15 17:18]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
""=
"MySpaceIM"=C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
America Online 8.0 Tray Icon.lnk - C:\Program Files\America Online 8.0\aoltray.exe [2003-04-28 09:36:59]
AOL Companion.lnk - C:\Program Files\AOL Companion\companion.exe [2003-04-28 09:37:32]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 16:05:56]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
R2 mrtRate;mrtRate;C:\WINDOWS\System32\drivers\mrtRate.sys
R3 BCMModem;BCM V.92 56K Modem;C:\WINDOWS\System32\DRIVERS\BCMSM.sys
R3 NaiFiltr;NaiFiltr;C:\WINDOWS\System32\DRIVERS\NaiFiltr.sys
S3 JL2005;JL2005A Toy Camera;C:\WINDOWS\System32\Drivers\toywdm.sys
S3 MR97310_VGA_DUAL_CAMERA;VGA Dual-Mode Camera;C:\WINDOWS\System32\DRIVERS\mr97310v.sys
.
Contents of the 'Scheduled Tasks' folder
"2007-10-21 20:46:00 C:\WINDOWS\Tasks\McAfee.com Update Check (D3GH4R21-Owner).job"
- C:\PROGRA~1\McAfee.com\Agent\mcupdate.exe
"2007-10-21 20:37:00 C:\WINDOWS\Tasks\McAfee.com Update Check (LISA-$@nthony$).job"
- C:\PROGRA~1\McAfee.com\Agent\mcupdate.exe
"2007-10-21 20:43:02 C:\WINDOWS\Tasks\McAfee.com Update Check (LISA-Anthony).job"
"2007-10-21 20:37:00 C:\WINDOWS\Tasks\McAfee.com Update Check (LISA-anthony_2).job"
- C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
"2007-10-21 20:37:00 C:\WINDOWS\Tasks\McAfee.com Update Check (LISA-Christopher).job"
- C:\PROGRA~1\McAfee.com\Agent\mcupdate.exe
"2007-10-21 20:44:00 C:\WINDOWS\Tasks\McAfee.com Update Check (LISA-Guest).job"
- C:\PROGRA~1\McAfee.com\Agent\mcupdate.exe
"2007-10-21 20:43:19 C:\WINDOWS\Tasks\McAfee.com Update Check (LISA-Lisa Pacella).job"
- C:\PROGRA~1\McAfee.com\Agent\mcupdate.exe
"2007-10-21 20:46:01 C:\WINDOWS\Tasks\McAfee.com Update Check (LISA-Matthew).job"
- C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
"2007-10-21 20:41:00 C:\WINDOWS\Tasks\PCHealth Scheduler for Upload Library.job"
- C:\WINDOWS\PCHealth\UploadLB\Binaries\UploadM.exe
.
**************************************************************************
catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-21 16:43:14
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-10-21 16:46:55 - machine was rebooted
C:\ComboFix2.txt … 2007-10-12 09:02
C:\ComboFix3.txt … 2007-10-12 07:33
.
— E O F —
[external image: Posted Image] and here's a new HijackThis log:
Logfile of HijackThis v1.99.1
Scan saved at 4:57:57 PM, on 10/21/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\SiteAdvisor\6172\SAService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe
C:\WINDOWS\System32\NILaunch.exe
C:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE
C:\program files\mcafee.com\vso\mcvsshld.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
C:\Program Files\Common Files\Verizon Online\ConnMgr\cmisrv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\Program Files\Common Files\Verizon Online\AppMgr\vzOpenUIServer.exe
C:\Program Files\America Online 8.0\aoltray.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\MSN\MSNCoreFiles\msn.exe
C:\Program Files\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;http://localhost
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: &Yahoo;! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
O2 - BHO: Nick Aracde Toolbar - {4E7BD74F-2B8D-469E-9EB4-FE6FA694B13E} - C:\PROGRA~1\NICKAR~1\NICKAR~1.DLL (file missing)
O2 - BHO: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\WINDOWS\DOWNLO~1\vzbb.dll (file missing)
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\WINDOWS\DOWNLO~1\vzbb.dll (file missing)
O3 - Toolbar: Nick Aracde Toolbar - {4E7BD74F-2B8D-469E-9EB4-FE6FA694B13E} - C:\PROGRA~1\NICKAR~1\NICKAR~1.DLL (file missing)
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [VerizonServicepoint.exe] C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe
O4 - HKLM\..\Run: [Net-It Launcher] C:\WINDOWS\System32\NILaunch.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\HELPSU~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [KAZAA] C:\Program Files\Kazaa\kazaa.exe /SYSTRAY
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [A Verizon App] C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE
O4 - HKLM\..\Run: [VirusScan Online] c:\program files\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: America Online 8.0 Tray Icon.lnk = C:\Program Files\America Online 8.0\aoltray.exe
O4 - Global Startup: AOL Companion.lnk = C:\Program Files\AOL Companion\companion.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &ieSpell; Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: &Search; - http://edits.mywebsearch.com/toolbaredits/…?p=ZKxdm011YYUS
O8 - Extra context menu item: Check &Spelling; - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM
O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM95\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon…DSL/tgctlcm.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f…p1.0.0.15-3.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {A7ECD556-D6F6-4F41-8C6B-14AB246801A0} (Secure Delivery) - http://kdx.kontiki.com/kdx/Client403/kdx.cab
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6172\SAService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Scotty
Hello
Go to http://www.virustotal.com/en/indexf.html
Copy the following line into the white textbox:
C:\WINDOWS\SYSTEM32\reboot.exe
Click Send.
Please post the results of this scan to this thread.
Do the same for these files.
C:\WINDOWS\SYSTEM32\restart.exe
C:\WINDOWS\SYSTEM32\process.exe
C:\WINDOWS\SYSTEM32\regdacl.exe
Go to http://www.virustotal.com/en/indexf.html
Copy the following line into the white textbox:
C:\WINDOWS\SYSTEM32\reboot.exe
Click Send.
Please post the results of this scan to this thread.
Do the same for these files.
C:\WINDOWS\SYSTEM32\restart.exe
C:\WINDOWS\SYSTEM32\process.exe
C:\WINDOWS\SYSTEM32\regdacl.exe
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI