This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] getting rid of virtumonde

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hi, im new to using whatthetech forums. my spy doctor notified that it blocked virtumonde trying to access my folders. i tried using vundofix, it found something, but it could not remove it, and i got tired of rebooting.
thanks
this is vundofix


VundoFix V6.7.8

Checking Java version…

Scan started at 9:32:45 PM 2/20/2008

Listing files found while scanning….


VundoFix V6.7.8

Checking Java version…

Scan started at 11:29:44 PM 2/20/2008

Listing files found while scanning….

C:\WINDOWS\system32\ddcbaay.dll

Beginning removal…

Attempting to delete C:\WINDOWS\system32\ddcbaay.dll
C:\WINDOWS\system32\ddcbaay.dll Could not be deleted.

Performing Repairs to the registry.
Done!

Beginning removal…

Attempting to delete C:\WINDOWS\system32\ddcbaay.dll
C:\WINDOWS\system32\ddcbaay.dll Could not be deleted.

Performing Repairs to the registry.
Done!

VundoFix V6.7.8

Checking Java version…

Scan started at 12:51:41 AM 2/21/2008

Listing files found while scanning….


VundoFix V6.7.8

Checking Java version…

Scan started at 12:02:29 PM 2/21/2008

Listing files found while scanning….

C:\WINDOWS\system32\ddcbaay.dll

Beginning removal…

Attempting to delete C:\WINDOWS\system32\ddcbaay.dll
C:\WINDOWS\system32\ddcbaay.dll Could not be deleted.

Performing Repairs to the registry.
Done!

Beginning removal…

Attempting to delete C:\WINDOWS\system32\ddcbaay.dll
C:\WINDOWS\system32\ddcbaay.dll Could not be deleted.

Performing Repairs to the registry.
Done!




and hijackthis log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:47:09 PM, on 2/21/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Symantec AntiVirus\DoScan.exe
C:\Program Files\HPQ\shared\hpqwmi.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\SYSTEM32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://gunz.ijji.com/?from=desktop
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {182C7ED7-E56D-4509-9D9B-AC49318D9895} - C:\WINDOWS\system32\ddcbaay.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /SYNC
O4 - HKLM\..\Run: [PHIME2002A] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /IMEName
O4 - HKLM\..\Run: [SynTPLpr] "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [eabconfg.cpl] "C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" /Start
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [hpWirelessAssistant] "%ProgramFiles%\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=laptop
O21 - SSODL: PrxKernel - {4b1e0f79-8dd7-4971-be06-4345a35d3f01} - C:\WINDOWS\Installer\{4b1e0f79-8dd7-4971-be06-4345a35d3f01}\PrxKernel.dll
O21 - SSODL: zip - {f089578e-3e48-4d0a-8745-a4a94ce478eb} - C:\WINDOWS\Installer\{f089578e-3e48-4d0a-8745-a4a94ce478eb}\zip.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\shared\hpqwmi.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 8649 bytes
_________________________________
Welcome to the Forums.

The fixes we will use are specific to your problems and should only be used for this issue on this machine.

Please only use this topic to reply to. Do not start another thread.
If any other issues arise let me know.
The process is not instant. Please continue to review my answers until I tell you your machine is clear. Absence of symptoms does not mean that everything is clear. So lets do this to the end!

  • All hijackthis logs I ask for should be done in normal mode ( not safe mode)
  • These logs should be done last after you have followed my instructions in the previous post.


Please if you decide to seek help at another forum let us know. There is a shortage of helpers and tying 2 of us up is a waste of time.
If you have any questions about any advice given here please STOP and ask!



______________________________
RUN HJT

HJT
Run hijackthis and choose scan only and place a check by the following lines if present.
Close all other windows and browsers except HJT before clicking on Fix Checked

O21 - SSODL: zip - {f089578e-3e48-4d0a-8745-a4a94ce478eb} - C:\WINDOWS\Installer\{f089578e-3e48-4d0a-8745-a4a94ce478eb}\zip.dll


Close that.


___________________________________
Reconfigure Windows XP to show hidden files::

Click Start. My Computer.
Select the Tools menu Folder Options. Select the View Tab.
Under the Hidden files and folders heading select "Show hidden files and folders".
Uncheck the "Hide protected operating system files (recommended)" option.
Uncheck the "Hide file extensions for known file types" option.
Click Yes to confirm. Click OK.
___________________________________
Search for and remove
Now I want you to search for and delete the following folder and all it's contents if present. If you need help finding it.
Click start /search/ all files and folders/ look for More advanced options. once in there select the first 3 boxes.
Please just remove the files/folders I listed in BOLD

C:\WINDOWS\Installer\{f089578e-3e48-4d0a-8745-a4a94ce478eb}





______________________________________________
1. Download Combo fix from one of these locations.
* IMPORTANT !!! Place combofix.exe on your Desktop

http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

2. Click start/run and copy and Paste this in exactly using the picture below for reference:

"%userprofile%\desktop\combofix.exe" /killall


[external image: Posted Image]

3. Combo will begin to run DO NOTHING while this is happeneing.
  • It will kill a few processes and disconnect you from the internet.
  • If by chance it stops prematurly you can re-establish your internet connection by restarting your computer.
  • This needs to be done so the program can work most efficiently for you.
Do not attempt to use the internet or anything else while it's doing its job for you.

If when it's completed you can not get on the internet just reboot the computer

Post the log from comboFix for me located in
c:\comboFix.txt




_____________________________
Submit a file to Jotti
Please go here : http://virusscan.jotti.org/
On top of the page there is a field to add the filepath, copy and paste these filepaths: 1 at a time.


C:\WINDOWS\Installer\{4b1e0f79-8dd7-4971-be06-4345a35d3f01}\PrxKernel.dll


Then hit Submit
The scan will take a while before the result comes up so please be patient.
Then copy the result and post it here in this thread.

If Jotti's service load is too high, you can use the following scanner instead:
http://www.virustotal.com/xhtml/index_en.html


_________________________
In your next reply I would like to see:
  • A new HJT log
  • The report from ComboFix
  • The report from Jottis/Virus Total
i ran hjt, reconfigured, but i could not remove C:\WINDOWS\Installer\{f089578e-3e48-4d0a-8745-a4a94ce478eb}
it said access denied

i added another log in case it helps

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:10:25 PM, on 2/21/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HPQ\shared\hpqwmi.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://gunz.ijji.com/?from=desktop
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {182C7ED7-E56D-4509-9D9B-AC49318D9895} - C:\WINDOWS\system32\ddcbaay.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /SYNC
O4 - HKLM\..\Run: [PHIME2002A] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /IMEName
O4 - HKLM\..\Run: [SynTPLpr] "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [eabconfg.cpl] "C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" /Start
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [hpWirelessAssistant] "%ProgramFiles%\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=laptop
O21 - SSODL: PrxKernel - {4b1e0f79-8dd7-4971-be06-4345a35d3f01} - C:\WINDOWS\Installer\{4b1e0f79-8dd7-4971-be06-4345a35d3f01}\PrxKernel.dll
O21 - SSODL: zip - {f089578e-3e48-4d0a-8745-a4a94ce478eb} - C:\WINDOWS\Installer\{f089578e-3e48-4d0a-8745-a4a94ce478eb}\zip.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\shared\hpqwmi.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 8478 bytes
jotti result

Scan taken on 22 Feb 2008 02:03:47 (GMT)
A-Squared
Found nothing
AntiVir
Found TR/Agent.feh.22
ArcaVir
Found Trojan.Agent.Feh
Avast
Found nothing
AVG Antivirus
Found Agent.ORQ
BitDefender
Found Generic.Malware.Sdld.E84A05C4 (probable variant)
ClamAV
Found nothing
CPsecure
Found nothing
Dr.Web
Found Trojan.Click.origin
F-Prot Antivirus
Found nothing
F-Secure Anti-Virus
Found Trojan.Win32.Agent.feh
Fortinet
Found nothing
Ikarus
Found Trojan-Clicker.Win32.Small.BG
Kaspersky Anti-Virus
Found Trojan.Win32.Agent.feh
NOD32
Found a variant of Win32/TrojanClicker.Agent.NCU
Norman Virus Control
Found W32/Agent.dam
Panda Antivirus
Found nothing
Rising Antivirus
Found nothing
Sophos Antivirus
Found Mal/Heuri-E
VirusBuster
Found nothing
VBA32
Found Trojan.Win32.Agent.feh



Combofix log

ComboFix 08-02-22 - SL 2008-02-21 17:40:00.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.253 [GMT -8:00]
Running from: C:\Documents and Settings\[removed]\desktop\combofix.exe
Command switches used :: /killall

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-01-22 to 2008-02-22 )))))))))))))))))))))))))))))))
.

2008-02-21 12:39 . 2008-02-21 12:39 24,576 –a—— C:\WINDOWS\system32\VundoFixSVC.exe
2008-02-21 00:47 . 2008-02-21 00:47 d——– C:\Program Files\Trend Micro
2008-02-20 23:25 . 2008-02-20 23:25 15,872 –a—— C:\Program Files\tmp265625.exe
2008-02-20 21:32 . 2008-02-21 15:34 d——– C:\VundoFix Backups
2008-02-20 10:04 . 2008-02-20 10:04 d——– C:\Program Files\Spiderweb Software
2008-02-19 22:55 . 2008-02-20 10:04 d——– C:\Documents and Settings\SL\Application Data\Downloaded Installations
2008-02-16 12:53 . 2008-02-16 12:53 d——– C:\Program Files\Viewpoint
2008-02-16 12:53 . 2008-02-16 12:53 d——– C:\Documents and Settings\SL\Application Data\acccore
2008-02-16 12:53 . 2008-02-16 12:53 d——– C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-02-16 12:52 . 2008-02-16 12:54 d——– C:\Documents and Settings\All Users\Application Data\AOL OCP
2008-02-16 12:52 . 2008-02-16 12:52 d——– C:\Documents and Settings\All Users\Application Data\AOL
2008-02-16 12:51 . 2008-02-16 12:51 d——– C:\Program Files\Common Files\AOL
2008-02-16 12:51 . 2008-02-16 12:53 d——– C:\Program Files\AIM6
2008-02-16 12:51 . 2008-02-16 12:53 445 –ah—– C:\IPH.PH
2008-02-15 19:54 . 2008-02-15 19:54 62,208 –a—— C:\WINDOWS\iun1401.exe
2008-02-09 19:47 . 2008-02-09 19:47 d——– C:\Program Files\Common Files\Adobe
2008-02-06 20:04 . 2008-02-06 20:24 d——– C:\Documents and Settings\SL\Application Data\Wyzo
2008-01-31 22:04 . 2008-01-31 22:04 d——– C:\Documents and Settings\SL\Application Data\vlc
2008-01-31 21:53 . 2008-01-31 21:53 d——– C:\Program Files\VideoLAN
2008-01-31 20:25 . 2008-01-31 22:51 d——– C:\Program Files\DC++
2008-01-25 17:25 . 2008-01-25 17:25 0 –a—— C:\WINDOWS\iPlayer.INI
2008-01-25 17:22 . 2008-01-25 17:22 d——– C:\Program Files\InterActual
2008-01-23 18:42 . 2008-02-19 18:12 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-01-23 18:42 . 2008-01-23 18:42 1,409 –a—— C:\WINDOWS\QTFont.for

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-22 01:45 ——— d—–w C:\Program Files\Symantec AntiVirus
2008-02-22 01:44 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-21 08:21 ——— d—–w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-02-21 07:55 ——— d—–w C:\Program Files\Spyware Doctor
2008-02-19 19:26 ——— d—–w C:\Program Files\DivX
2008-02-16 03:54 1,409 —-a-w C:\WINDOWS\Fonts\MAIDWORD.fot
2008-02-10 22:10 ——— d—–w C:\Documents and Settings\SL\Application Data\U3
2008-01-26 03:56 ——— d—–w C:\Program Files\Google
2008-01-22 02:07 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-01-22 02:07 ——— d—–w C:\Program Files\LizardTech
2008-01-16 19:56 ——— d—–w C:\Documents and Settings\SL\Application Data\InterVideo
2008-01-15 02:38 ——— d—–w C:\Program Files\Picasa2
2008-01-14 01:45 ——— d—–w C:\Documents and Settings\SL\Application Data\LimeWire
2008-01-10 22:47 ——— d—–w C:\Program Files\Java
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 04:00 15360]
"Aim6"="" []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-04 04:00 208952]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 04:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 04:00 455168]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-04 10:40 98394]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-04 10:38 688218]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-01-22 10:36 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-01-22 10:31 126976]
"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [2004-11-05 13:52 233534]
"eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [2004-12-03 13:24 290816]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"hpWirelessAssistant"="C:\Program Files\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-01-21 13:40 790528]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-16 23:11 49152]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-11-21 17:38 52840]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2007-03-14 19:49 125632]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-10-02 16:27 1065288]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-11-08 17:01 185632]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-11-04 11:53:18 126136]
HP Digital Imaging Monitor.lnk - C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe [2006-02-19 04:21:22 288472]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 13:05:56 65588]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"PrxKernel"= {4b1e0f79-8dd7-4971-be06-4345a35d3f01} - C:\WINDOWS\Installer\{4b1e0f79-8dd7-4971-be06-4345a35d3f01}\PrxKernel.dll [2008-02-18 18:56 14374]
"zip"= {f089578e-3e48-4d0a-8745-a4a94ce478eb} - C:\WINDOWS\Installer\{f089578e-3e48-4d0a-8745-a4a94ce478eb}\zip.dll [2008-02-18 18:56 38438]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2007-11-02 18:36 267048 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
——— 2004-10-13 08:24 1694208 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2007-10-19 20:16 286720 C:\Program Files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
–a—— 2007-11-29 15:52 1266936 C:\Program Files\Valve\Steam\Steam.exe

R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 13:38]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ae8d0eaa-959d-11dc-a08a-00c09fab9352}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

.
Contents of the 'Scheduled Tasks' folder
"2008-01-25 15:40:05 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-21 17:45:15
Windows 5.1.2600 Service Pack 2 NTFS

detected NTDLL code modification:
ZwClose

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = C:\Program Files\HPQ\Default Settings\cpqset.exe????????4?0?8?9??????? ?,?B?????????????hLC? ??????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HPQ\shared\hpqwmi.exe
C:\Program Files\Symantec AntiVirus\DoScan.exe
.
**************************************************************************
.
Completion time: 2008-02-21 17:55:16 - machine was rebooted [SL]
ComboFix-quarantined-files.txt 2008-02-22 01:55:06
ComboFix2.txt 2008-02-22 01:37:09
.
2008-02-13 17:29:50 — E O F —
___________________________________
DISABLE Spyware Doctor
It is a good program, but … it may hinder the removal of some HijackThis entries. You can re-enable it after you're clean.
From within Spyware Doctor, click the "OnGuard" button on the left side.
Uncheck "Activate OnGuard".




______________________________
RUN HJT

HJT
Run hijackthis and choose scan only and place a check by the following lines if present.
Close all other windows and browsers except HJT before clicking on Fix Checked

O2 - BHO: (no name) - {182C7ED7-E56D-4509-9D9B-AC49318D9895} - C:\WINDOWS\system32\ddcbaay.dll
O21 - SSODL: PrxKernel - {4b1e0f79-8dd7-4971-be06-4345a35d3f01} - C:\WINDOWS\Installer\{4b1e0f79-8dd7-4971-be06-4345a35d3f01}\PrxKernel.dll
O21 - SSODL: zip - {f089578e-3e48-4d0a-8745-a4a94ce478eb} - C:\WINDOWS\Installer\{f089578e-3e48-4d0a-8745-a4a94ce478eb}\zip.dll

Close that.




________________________________________
Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\system32\ddcbaay.dll
C:\Program Files\tmp265625.exe
C:\WINDOWS\Installer\{f089578e-3e48-4d0a-8745-a4a94ce478eb}



Folder::
C:\WINDOWS\Installer\{4b1e0f79-8dd7-4971-be06-4345a35d3f01}
C:\WINDOWS\Installer\{f089578e-3e48-4d0a-8745-a4a94ce478eb}



NOTE: This script was done for this user specifically.
DO NOT ATTEMPT TO USE IT IF YOU ARE NOT THIS USER
YOU WILL HURT THE WORKINGS OF YOUR COMPUTER !!
.

Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:ComboFix.txt which I will need in your next reply.





_____________________________
Submit a file to Jotti
Please go here : http://virusscan.jotti.org/
On top of the page there is a field to add the filepath, copy and paste these filepaths: 1 at a time.


C:\WINDOWS\Fonts\MAIDWORD.fot


Then hit Submit
The scan will take a while before the result comes up so please be patient.
Then copy the result and post it here in this thread.

If Jotti's service load is too high, you can use the following scanner instead:
http://www.virustotal.com/xhtml/index_en.html





_________________________
In your next reply I would like to see:
  • A new HJT log
  • The report from ComboFix
  • The report from Jottis/virus total
jotti results

Scan taken on 22 Feb 2008 03:31:20 (GMT)
A-Squared
Found nothing
AntiVir
Found nothing
ArcaVir
Found nothing
Avast
Found nothing
AVG Antivirus
Found nothing
BitDefender
Found nothing
ClamAV
Found nothing
CPsecure
Found nothing
Dr.Web
Found nothing
F-Prot Antivirus
Found nothing
F-Secure Anti-Virus
Found nothing
Fortinet
Found nothing
Ikarus
Found nothing
Kaspersky Anti-Virus
Found nothing
NOD32
Found nothing
Norman Virus Control
Found nothing
Panda Antivirus
Found nothing
Rising Antivirus
Found nothing
Sophos Antivirus
Found nothing
VirusBuster
Found nothing
VBA32
Found nothing




combofix log

ComboFix 08-02-22 - SL 2008-02-21 19:25:46.3 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\SL\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\Program Files\tmp265625.exe
C:\WINDOWS\Installer\{f089578e-3e48-4d0a-8745-a4a94ce478eb}
C:\WINDOWS\system32\ddcbaay.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\tmp265625.exe
C:\WINDOWS\Installer\{4b1e0f79-8dd7-4971-be06-4345a35d3f01}
C:\WINDOWS\Installer\{4b1e0f79-8dd7-4971-be06-4345a35d3f01}\PrxKernel.dll
C:\WINDOWS\Installer\{f089578e-3e48-4d0a-8745-a4a94ce478eb}
C:\WINDOWS\Installer\{f089578e-3e48-4d0a-8745-a4a94ce478eb}\zip.dll

.
((((((((((((((((((((((((( Files Created from 2008-01-22 to 2008-02-22 )))))))))))))))))))))))))))))))
.

2008-02-21 12:39 . 2008-02-21 12:39 24,576 –a—— C:\WINDOWS\system32\VundoFixSVC.exe
2008-02-21 00:47 . 2008-02-21 00:47 d——– C:\Program Files\Trend Micro
2008-02-20 21:32 . 2008-02-21 15:34 d——– C:\VundoFix Backups
2008-02-20 10:04 . 2008-02-20 10:04 d——– C:\Program Files\Spiderweb Software
2008-02-19 22:55 . 2008-02-20 10:04 d——– C:\Documents and Settings\SL\Application Data\Downloaded Installations
2008-02-16 12:53 . 2008-02-16 12:53 d——– C:\Program Files\Viewpoint
2008-02-16 12:53 . 2008-02-16 12:53 d——– C:\Documents and Settings\SL\Application Data\acccore
2008-02-16 12:53 . 2008-02-16 12:53 d——– C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-02-16 12:52 . 2008-02-16 12:54 d——– C:\Documents and Settings\All Users\Application Data\AOL OCP
2008-02-16 12:52 . 2008-02-16 12:52 d——– C:\Documents and Settings\All Users\Application Data\AOL
2008-02-16 12:51 . 2008-02-16 12:51 d——– C:\Program Files\Common Files\AOL
2008-02-16 12:51 . 2008-02-16 12:53 d——– C:\Program Files\AIM6
2008-02-16 12:51 . 2008-02-16 12:53 445 –ah—– C:\IPH.PH
2008-02-15 19:54 . 2008-02-15 19:54 62,208 –a—— C:\WINDOWS\iun1401.exe
2008-02-09 19:47 . 2008-02-09 19:47 d——– C:\Program Files\Common Files\Adobe
2008-02-06 20:04 . 2008-02-06 20:24 d——– C:\Documents and Settings\SL\Application Data\Wyzo
2008-01-31 22:04 . 2008-01-31 22:04 d——– C:\Documents and Settings\SL\Application Data\vlc
2008-01-31 21:53 . 2008-01-31 21:53 d——– C:\Program Files\VideoLAN
2008-01-31 20:25 . 2008-01-31 22:51 d——– C:\Program Files\DC++
2008-01-25 17:25 . 2008-01-25 17:25 0 –a—— C:\WINDOWS\iPlayer.INI
2008-01-25 17:22 . 2008-01-25 17:22 d——– C:\Program Files\InterActual
2008-01-23 18:42 . 2008-02-19 18:12 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-01-23 18:42 . 2008-01-23 18:42 1,409 –a—— C:\WINDOWS\QTFont.for

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-22 03:18 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-22 01:45 ——— d—–w C:\Program Files\Symantec AntiVirus
2008-02-21 08:21 ——— d—–w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-02-21 07:55 ——— d—–w C:\Program Files\Spyware Doctor
2008-02-19 19:26 ——— d—–w C:\Program Files\DivX
2008-02-16 03:54 1,409 —-a-w C:\WINDOWS\Fonts\MAIDWORD.fot
2008-02-10 22:10 ——— d—–w C:\Documents and Settings\SL\Application Data\U3
2008-01-26 03:56 ——— d—–w C:\Program Files\Google
2008-01-22 02:07 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-01-22 02:07 ——— d—–w C:\Program Files\LizardTech
2008-01-16 19:56 ——— d—–w C:\Documents and Settings\SL\Application Data\InterVideo
2008-01-15 02:38 ——— d—–w C:\Program Files\Picasa2
2008-01-14 01:45 ——— d—–w C:\Documents and Settings\SL\Application Data\LimeWire
2008-01-10 22:47 ——— d—–w C:\Program Files\Java
2008-01-04 21:56 156,992 —-a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-12-07 01:07 659,456 —-a-w C:\WINDOWS\system32\wininet.dll
2007-12-04 18:38 550,912 —-a-w C:\WINDOWS\system32\oleaut32.dll
2007-11-29 22:30 200,704 —-a-w C:\WINDOWS\system32\ssldivx.dll
2007-11-29 22:30 1,044,480 —-a-w C:\WINDOWS\system32\libdivx.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 04:00 15360]
"Aim6"="" []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-04 04:00 208952]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 04:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 04:00 455168]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-04 10:40 98394]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-04 10:38 688218]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-01-22 10:36 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-01-22 10:31 126976]
"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [2004-11-05 13:52 233534]
"eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [2004-12-03 13:24 290816]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"hpWirelessAssistant"="C:\Program Files\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-01-21 13:40 790528]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-16 23:11 49152]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-11-21 17:38 52840]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2007-03-14 19:49 125632]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-10-02 16:27 1065288]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-11-08 17:01 185632]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-11-04 11:53:18 126136]
HP Digital Imaging Monitor.lnk - C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe [2006-02-19 04:21:22 288472]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 13:05:56 65588]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"zip"= {f089578e-3e48-4d0a-8745-a4a94ce478eb} - C:\WINDOWS\Installer\{f089578e-3e48-4d0a-8745-a4a94ce478eb}\zip.dll [ ]
"PrxKernel"= {4b1e0f79-8dd7-4971-be06-4345a35d3f01} - C:\WINDOWS\Installer\{4b1e0f79-8dd7-4971-be06-4345a35d3f01}\PrxKernel.dll [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2007-11-02 18:36 267048 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
——— 2004-10-13 08:24 1694208 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2007-10-19 20:16 286720 C:\Program Files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
–a—— 2007-11-29 15:52 1266936 C:\Program Files\Valve\Steam\Steam.exe

R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 13:38]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ae8d0eaa-959d-11dc-a08a-00c09fab9352}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

.
Contents of the 'Scheduled Tasks' folder
"2008-01-25 15:40:05 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-21 19:29:26
Windows 5.1.2600 Service Pack 2 NTFS

detected NTDLL code modification:
ZwClose

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = C:\Program Files\HPQ\Default Settings\cpqset.exe????????4?0?8?9??????? ?,?B?????????????hLC? ??????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-21 19:30:31
ComboFix-quarantined-files.txt 2008-02-22 03:30:21
ComboFix2.txt 2008-02-22 01:55:18
ComboFix3.txt 2008-02-22 01:37:09
.
2008-02-13 17:29:50 — E O F —




hjt log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:32, on 2/21/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HPQ\shared\hpqwmi.exe
C:\Program Files\Hp\HP Software Update\HPWUCli.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://gunz.ijji.com/?from=desktop
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /SYNC
O4 - HKLM\..\Run: [PHIME2002A] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /IMEName
O4 - HKLM\..\Run: [SynTPLpr] "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [eabconfg.cpl] "C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" /Start
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [hpWirelessAssistant] "%ProgramFiles%\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=laptop
O21 - SSODL: zip - {f089578e-3e48-4d0a-8745-a4a94ce478eb} - C:\WINDOWS\Installer\{f089578e-3e48-4d0a-8745-a4a94ce478eb}\zip.dll (file missing)
O21 - SSODL: PrxKernel - {4b1e0f79-8dd7-4971-be06-4345a35d3f01} - C:\WINDOWS\Installer\{4b1e0f79-8dd7-4971-be06-4345a35d3f01}\PrxKernel.dll (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\shared\hpqwmi.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 8186 bytes
You need to update SunJava for security reasons.
Updating Java:
Download the latest version of
Java Runtime Environment (JRE) 6 Update 4

  • Scroll down to where it says "Java Runtime Environment (JRE) 6 Update 4
    … allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name. It should have the [external image: Posted Image] icon next to it.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u4-windows-i586-p.exe
    to install the newest version.


_______________________________________
I see that Viewpoint is installed.

Viewpoint, Viewpoint Manager, Viewpoint Media Player are Viewpoint components which are installed as a side effect of installing other software, most notably AOL and AOL Instant Messenger (AIM). Viewpoint Manager is responsible for managing and updating Viewpoint Media Player’s components. Viewpoint Manager is considered as foistware instead of malware since it is installed without user's approval but doesn't spy or do anything "bad". In 2006, this may change, read Viewpoint to Plunge Into Adware.

I suggest you remove the program now. Go to Start > Settings > Control Panel > Add/Remove Programs and remove the following programs if present:
  • Viewpoint
  • Viewpoint Manager
  • Viewpoint Media Player
If AOL is present, to prevent it from being recreated every time you run the AOL software:
  • Open AOL
  • Go to Help on the toolbar
  • Select About AOL
  • Hit Ctrl D and a secret panel can be accessed which will allow you to disable all desktop and IM features associated with Viewpoint.
Another way to prevent Viewpoint from being recreated every time you run the AOL software is:
  • Click C:\Program Files\AOL 9.0\Jiti (a hidden folder).
  • Rename viewpoint.exe to viewpoint.old.
This is the item to fix in HijackThis.

O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe



______________________________

Download and install CCleaner from here


If you use either the Firefox or Mozilla browsers, the box to uncheck for Cookies is on the Applications tab, under Firefox/Mozilla.

  • Set Cookie Retention.
    Click on the Options block on the left, then choose Cookies.
    Under the Cookies to delete pane, highlight any cookies you would like to retain permanently (those companies or sites with which you regularly visit or do business), and click the right arrow > to move them to the Cookies to keep pane.
  • Reset Temp File Removal for Regular Use.
    Click on the Options block on the left. Select the Advanced button.
    Check "Only delete files in Windows Temp folders older than 48 hours".


    Now run the program and click on Run Cleaner
    ( Do not use the Registry function to clean anything with this program. Having anything auto clean your regisrty is risky).


_________________________________


Using Internet explorer (firefox will not work)
Please do an online scan with Kaspersky Online Scanner
Click accept on the first page.

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
The program will launch and then start to download the latest definition files.
Once the scanner is installed and the definitions downloaded, click Next.
Now click on Scan Settings
In the scan settings make sure that the following are selected:
Scan using the following Anti-Virus database:

Extended (If available otherwise Standard)
Scan Options:
Scan Archives
Scan Mail Bases
Click OK

Now under select a target to scan select My Computer



The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.

Now click on the Save as Text button:
Save the file to your desktop.
Copy and paste that information in your next post.


_________________________
In your next reply I would like to see:
  • A new HJT log
  • The report from Kasperskys
  • The report from
  • Let me know how things are running.
i deleted and installed java, which seems to working. i deleted viewpoint, i dont have aol and the item on hijackthis. i downloaded ccleaner. i am not sure how to reset the temp file. i have firefox version 2.0.0.12. i went under tools>options>privacy where i set the cookies, but i cant find the place to set temp file.
I think there was a slight bit of confusion there.
In ccleaner choose options/ advanced
place a check mark by "Only delete windows temp files older than 48 hrs"

At least I think this is what your referring to.
everything seems to be running ok

kaspersky report

——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Friday, February 22, 2008 4:22:54 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 22/02/2008
Kaspersky Anti-Virus database records: 575891
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\

Scan Statistics:
Total number of scanned objects: 39066
Number of viruses found: 8
Number of infected objects: 17
Number of suspicious objects: 0
Duration of the scan process: 01:06:02

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\Log.LiveUpdate Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09540000\4FFE47B5.VBN Infected: Trojan-Downloader.Win32.Zlob.hts skipped
C:\Documents and Settings\DJ\Application Data\Adobe\Acrobat\8.0\AdobeCMapFnt08.lst Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Adobe\Acrobat\8.0\AdobeSysFnt08.lst Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Adobe\Acrobat\8.0\UserCache.bin Object is locked skipped
C:\Documents and Settings\DJ\Application Data\desktop.ini Object is locked skipped
C:\Documents and Settings\DJ\Application Data\HP\CRMLogs\BrandAuthentication.htm Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Microsoft\CLR Security Config\v1.1.4322\security.config Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Microsoft\CLR Security Config\v1.1.4322\security.config.cch Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Microsoft\CryptnetUrlCache\Content\486CC6AFD08942336C61FCD401C4A1D1 Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Microsoft\CryptnetUrlCache\Content\60E31627FDA0A46932B0E5948949F2A5 Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Microsoft\CryptnetUrlCache\Content\74BFD122C0875EC75DBE5C6DB4C59019 Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Microsoft\CryptnetUrlCache\Content\A8FABA189DB7D25FBA7CAC806625FD30 Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Microsoft\CryptnetUrlCache\MetaData\486CC6AFD08942336C61FCD401C4A1D1 Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Microsoft\CryptnetUrlCache\MetaData\60E31627FDA0A46932B0E5948949F2A5 Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Microsoft\CryptnetUrlCache\MetaData\74BFD122C0875EC75DBE5C6DB4C59019 Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Microsoft\CryptnetUrlCache\MetaData\A8FABA189DB7D25FBA7CAC806625FD30 Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Microsoft\FrontPage\State\CmdUI.PRF Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Microsoft\IMJP8_1\imjp81u.dic Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Microsoft\Internet Explorer\brndlog.bak Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Microsoft\Internet Explorer\brndlog.txt Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Microsoft\Internet Explorer\Desktop.htt Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Microsoft\Office\Access.pip Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Microsoft\Office\Excel.pip Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Microsoft\Office\FP.pip Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Microsoft\Office\MSO1033.acl Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Microsoft\Office\MSOutlo.pip Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Microsoft\Office\PowerPoi.pip Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Microsoft\Office\Recent\1 SECURITY SETTING.LNK Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Microsoft\Office\Recent\1 SYSTEM NOTES.LNK Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Microsoft\Office\Recent\a SYS.LNK Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Microsoft\Office\Recent\My Webs.LNK Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Microsoft\Office\Recent\Removable Disk (E).LNK Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Microsoft\Office\Recent\Templates.LNK Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Microsoft\Office\Word.pip Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Microsoft\Outlook\extend.dat Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Microsoft\Outlook\Microsoft Outlook Internet Settings.FAV Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Microsoft\PowerPoint\PPT.pcb Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Microsoft\Proof\custom.dic Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Microsoft\Protect\CREDHIST Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Microsoft\Protect\S-1-5-21-1004336348-1960408961-682003330-1005\3b16f59c-6356-4c92-8ee7-3d367fe9f716 Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Microsoft\Protect\S-1-5-21-1004336348-1960408961-682003330-1005\Preferred Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Microsoft\Templates\Normal.dot Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Microsoft\Windows\Themes\Custom.theme Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\pluginreg.dat Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\bookmarkbackups\bookmarks-2007-11-04.html Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\bookmarks.bak Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\bookmarks.html Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\cert8.db Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\chrome\userChrome-example.css Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\chrome\userContent-example.css Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\compatibility.ini Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\compreg.dat Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\cookies.txt Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\downloads.rdf Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}\chrome\forecastfox.jar Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}\chrome.manifest Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}\components\nsForecastfox.js Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}\components\nsForecastfox.xpt Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}\defaults\.autoreg Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}\defaults\converters.js Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}\defaults\default.jar Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}\defaults\parser.js Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}\defaults\preferences\forecastfox.js Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}\defaults\upgrade.js Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}\install.js Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}\install.locales Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}\install.rdf Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}\license.txt Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\content\aboutdownbar.js Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\content\aboutdownbar.xul Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\content\addonDonate.js Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\content\addonDonate.xul Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\content\colorPicker\brightness.png Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\content\colorPicker\colourPickerArrow.gif Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\content\colorPicker\colourPickerCrosshair.gif Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\content\colorPicker\EdColorPicker.css Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\content\colorPicker\EdColorPicker.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\content\colorPicker\EdColorPicker.js Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\content\colorPicker\EdColorPicker.xul Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\content\colorPicker\hsPanel.png Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\content\downbarAboutTitle.png Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\content\downbarDLoverlay.xul Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\content\downbaroverlay.js Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\content\downbaroverlay.xul Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\content\downbarprefs.js Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\content\downbarprefs.xul Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\content\downbar_finished.wav Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\content\privacyPrefsOverlay.js Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\content\privacyPrefsOverlay.xul Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\locale\en-US\downbar.properties Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\locale\en-US\downbarAboutText.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\locale\en-US\downbartext.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\skin\classic\about_bkgd.png Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\skin\classic\about_header.png Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\skin\classic\about_title.png Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\skin\classic\buttonBackground.png Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\skin\classic\buttonBackgroundHover.png Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\skin\classic\buttonGradient.png Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\skin\classic\closeX.png Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\skin\classic\delete1.png Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\skin\classic\delete2.png Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\skin\classic\downbarIcon.png Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\skin\classic\downbaroverlay.css Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\skin\classic\download_manager.png Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\skin\classic\download_manager_arrow.png Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\skin\classic\download_manager_wide.png Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\skin\classic\exclamationPoint.png Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\skin\classic\folder.png Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\skin\classic\greenArrow16.png Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\skin\classic\leftTooltip.png Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\skin\classic\leftTooltip_white.png Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\skin\classic\leftTooltip_white_square.png Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\skin\classic\middleTooltip.png Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\skin\classic\middleTooltip_white.png Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\skin\classic\middleTooltip_white_160.png Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\skin\classic\rightTooltip.png Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\skin\classic\rightTooltip_white.png Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\skin\classic\rightTooltip_white_square.png Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome\skin\classic\whiteToTransGrad.png Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\chrome.manifest Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\components\downbar.js Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\defaults\preferences\downbarconfig.js Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\install.rdf Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\ar\downbar.properties Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\ar\downbarAboutText.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\ar\downbartext.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\ca-AD\downbar.properties Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\ca-AD\downbarAboutText.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\ca-AD\downbartext.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\cs-CZ\downbar.properties Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\cs-CZ\downbarAboutText.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\cs-CZ\downbartext.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\de-DE\downbar.properties Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\de-DE\downbarAboutText.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\de-DE\downbartext.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\el-GR\downbar.properties Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\el-GR\downbarAboutText.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\el-GR\downbartext.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\en-GB\downbar.properties Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\en-GB\downbarAboutText.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\en-GB\downbartext.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\es-AR\downbar.properties Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\es-AR\downbarAboutText.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\es-AR\downbartext.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\fi-FI\downbar.properties Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\fi-FI\downbarAboutText.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\fi-FI\downbartext.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\fr-FR\downbar.properties Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\fr-FR\downbarAboutText.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\fr-FR\downbartext.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\it-IT\downbar.properties Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\it-IT\downbarAboutText.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\it-IT\downbartext.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\ja-JP\downbar.properties Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\ja-JP\downbarAboutText.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\ja-JP\downbartext.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\ko-KR\downbar.properties Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\ko-KR\downbarAboutText.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\ko-KR\downbartext.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\mn-MN\downbar.properties Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\mn-MN\downbarAboutText.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\mn-MN\downbartext.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\nl-NL\downbar.properties Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\nl-NL\downbarAboutText.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\nl-NL\downbartext.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\pl-PL\downbar.properties Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\pl-PL\downbarAboutText.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\pl-PL\downbartext.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\pt-BR\downbar.properties Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\pt-BR\downbarAboutText.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\pt-BR\downbartext.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\pt-PT\downbar.properties Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\pt-PT\downbarAboutText.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\pt-PT\downbartext.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\ro-RO\downbar.properties Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\ro-RO\downbarAboutText.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\ro-RO\downbartext.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\ru-RU\downbar.properties Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\ru-RU\downbarAboutText.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\ru-RU\downbartext.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\sk-SK\downbar.properties Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\sk-SK\downbarAboutText.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\sk-SK\downbartext.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\uk-UA\downbar.properties Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\uk-UA\downbarAboutText.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\uk-UA\downbartext.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\zh-CN\downbar.properties Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\zh-CN\downbarAboutText.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\zh-CN\downbartext.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\zh-TW\downbar.properties Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\zh-TW\downbarAboutText.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}\translations\0.9.5\zh-TW\downbartext.dtd Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions.cache Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions.ini Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\extensions.rdf Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\forecastfox\cache\feed-default.js Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\forecastfox\errors\errors.log Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\forecastfox\icons\default.jar Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\forecastfox\icons.xml Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\forecastfox\profiles.bak Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\forecastfox\profiles.xml Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\formhistory.dat Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\history.dat Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\hostperm.1 Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\key3.db Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\localstore.rdf Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\mimeTypes.rdf Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\prefs.js Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\search.rdf Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\search.sqlite Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\secmod.db Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\sessionstore.js Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\webappsstore.sqlite Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\xpti.dat Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Mozilla\Firefox\profiles.ini Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Sun\Java\Deployment\deployment.properties Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Sun\Java\Deployment\log\plugin150.trace Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Talkback\MozillaOrg\Firefox2\Win32\2007102514\manifest.ini Object is locked skipped
C:\Documents and Settings\DJ\Application Data\Talkback\MozillaOrg\Firefox2\Win32\2007102514\permdata.box Object is locked skipped
C:\Documents and Settings\DJ\Cookies\dj@1067766890[1].txt Object is locked skipped
C:\Documents and Settings\DJ\Cookies\dj@2o7[2].txt Object is locked skipped
C:\Documents and Settings\DJ\Cookies\dj@advertising[1].txt Object is locked skipped
C:\Documents and Settings\DJ\Cookies\dj@aol[1].txt Object is locked skipped
C:\Documents and Settings\DJ\Cookies\dj@atdmt[1].txt Object is locked skipped
C:\Documents and Settings\DJ\Cookies\dj@atwola[2].txt Object is locked skipped
C:\Documents and Settings\DJ\Cookies\[removed][1].txt Object is locked skipped
C:\Documents and Settings\DJ\Cookies\[removed][2].txt Object is locked skipped
C:\Documents and Settings\DJ\Cookies\dj@google[1].txt Object is locked skipped
C:\Documents and Settings\DJ\Cookies\[removed][1].txt Object is locked skipped
C:\Documents and Settings\DJ\Cookies\dj@microsoft[2].txt Object is locked skipped
C:\Documents and Settings\DJ\Cookies\dj@mozilla[2].txt Object is locked skipped
C:\Documents and Settings\DJ\Cookies\[removed][1].txt Object is locked skipped
C:\Documents and Settings\DJ\Cookies\[removed][2].txt Object is locked skipped
C:\Documents and Settings\DJ\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\DJ\Favorites\Accessories.URL Object is locked skipped
C:\Documents and Settings\DJ\Favorites\Create & Print.URL Object is locked skipped
C:\Documents and Settings\DJ\Favorites\Desktop.ini Object is locked skipped
C:\Documents and Settings\DJ\Favorites\Home.URL Object is locked skipped
C:\Documents and Settings\DJ\Favorites\HP Music.URL Object is locked skipped
C:\Documents and Settings\DJ\Favorites\Links\Customize Links.url Object is locked skipped
C:\Documents and Settings\DJ\Favorites\Links\Free Hotmail.url Object is locked skipped
C:\Documents and Settings\DJ\Favorites\Links\Windows Marketplace.url Object is locked skipped
C:\Documents and Settings\DJ\Favorites\Links\Windows Media.url Object is locked skipped
C:\Documents and Settings\DJ\Favorites\Links\Windows.url Object is locked skipped
C:\Documents and Settings\DJ\Favorites\MSN.com.url Object is locked skipped
C:\Documents and Settings\DJ\Favorites\Radio Station Guide.url Object is locked skipped
C:\Documents and Settings\DJ\Favorites\Search.URL Object is locked skipped
C:\Documents and Settings\DJ\Favorites\Shop.URL Object is locked skipped
C:\Documents and Settings\DJ\Favorites\Spyware Protection.URL Object is locked skipped
C:\Documents and Settings\DJ\Favorites\Symantec Security.URL Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Application Data\Adobe\Acrobat\8.0\Cache\AcroFnt08.lst Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Application Data\Adobe\Acrobat\8.0\Updater\updater.log Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Application Data\Adobe\Color\ACECache6.lst Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Application Data\Adobe\Updater5\acrobatPI.log Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Application Data\Adobe\Updater5\AdobeUpdaterPrefs.dat Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Application Data\Adobe\Updater5\aum.log Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Application Data\Adobe\Updater5\aumLib.log Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Application Data\Adobe\Updater5\Data\reader8rdr-en_US.aup.xml Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Application Data\ApplicationHistory\ngen.exe.2c05686e.ini Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Application Data\ApplicationHistory\SL264.tmp.daa59632.ini Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Application Data\ApplicationHistory\SL5DE.tmp.595e0a38.ini Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Application Data\GDIPFONTCACHEV1.DAT Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Application Data\IconCache.db Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Application Data\Microsoft\FORMS\FRMCACHE.DAT Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Application Data\Microsoft\HelpCtr\HelpSessionHistory.dat Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Application Data\Microsoft\Internet Explorer\MSIMGSIZ.DAT Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Application Data\Microsoft\Media Player\CurrentDatabase_59R.wmdb Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Application Data\Microsoft\Outlook\outlook.pst Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Application Data\Microsoft\Wallpaper1.bmp Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNS.DTD Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNS.XML Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Application Data\Microsoft\Windows Media\9.0\WMSDKNS.DTD Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Application Data\Microsoft\Windows Media\9.0\WMSDKNS.XML Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\XPC.mfl Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Application Data\Mozilla\Firefox\Profiles\minp9eb0.default\XUL.mfl Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Logs\11042007.Log Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Logs\11232007.Log Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Application Data\{3248F0A6-6813-11D6-A77B-00B0D0150000}\1033.MST Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Application Data\{3248F0A6-6813-11D6-A77B-00B0D0150000}\J2SE Runtime Environment 5.0.msi Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\desktop.ini Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\History\desktop.ini Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\History\History.IE5\desktop.ini Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\History\History.IE5\MSHist012007102920071105\index.dat Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\History\History.IE5\MSHist012007112320071124\index.dat Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temp\12a61c.mst Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temp\ASPNETSetup.log Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temp\dotNetFx.log Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temp\hpodvd09.log Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temp\IEC4AF.tmp Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temp\IECBB.tmp Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temp\is-8V3P5.tmp\SecurityUtil.dll Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temp\isp344.tmp\_Setup.dll Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temp\isp39B.tmp\_Setup.dll Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temp\java_install.log Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temp\java_install_reg.log Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temp\jusched.log Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temp\MSI648.tmp Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temp\netfxsl.log Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temp\netfxupdate.log Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temp\offcln9.log Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temp\Office 2000 Premium Setup(0002).txt Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temp\Office 2000 Premium Setup(0002)_MsiExec.txt Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temp\Outlook Startup.Log Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temp\pftD1.tmp\SpySweeper5.3.2.exe Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temp\plfCF.tmp Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temp\QTInstallerHelper.dll Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temp\SAV_INST.LOG Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temp\set340.tmp Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temp\set397.tmp Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temp\Setup Log 2007-11-04 #001.txt Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temp\STS3.tmp Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temp\SYMEVENT.LOG Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temp\UIUCU2.EXE Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temp\{AC76BA86-7AD7-1033-7B44-A81000000003}.ini Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temp\~8F.tmp Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\3s30[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\47293b17-001b6-064b6-c7bcbccd[1].jpg Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\au_bg_leftbottom[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\au_bg_leftmiddle[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\au_shieldyellow[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\banner-bg[1].jpg Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\bg-header-small[1].jpg Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\blue_table_header[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\blue_table_header_rt[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\broker[1].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\button_lrg[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\CATQ3F2N.htm Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\commontop[1].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\Common[1].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\content[1].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\content[2].css Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\content[2].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\content[3].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\desktop.ini Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\domainHomeSearch[1].htm Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\download[1].htm Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\e_google1[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\failed-sm[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\fctrl[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\fsh-oil-pills-200lvg110107[1].jpg Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\games_com[1].jpg Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\hcp[2].css Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\header-background[1].png Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\header_frontpage[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\Homepage__DESKTOP[1].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\Homepage__SHARED[1].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\hp6_19[2].css Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\hps_1107_club180x150[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\hp_logo2[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\HSCMoreHeadlinesUS[1].xml Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\icon.plus[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\icon_book[1].jpg Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\icon_view[1].jpg Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\jquery-1.1.2[1].htm Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\LT;MN=93235420;wm=o;rm=1;!c=HPC;!c=d-gif;!c=d-jpg;!c=d-imrd;!c=d-fls;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=291x15;tile=1;dcove=d;ord=165392652[1] Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\LTD;MN=93235419;wm=o;rm=1;!c=HPC;!c=d-gif;!c=d-jpg;!c=d-imrd;!c=d-fls;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=291x30;tile=8;dcove=d;ord=165392652[1] Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\moviefan_com[1].jpg Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\mu_getstarted-part1top_ltr[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\mu_getstarted-part2top_ltr[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\NavBar[1].xml Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\nav_sprite[1].png Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\news[1].htm Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\news[1].jpg Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\news_bg_bottommiddle[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\news_info[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\personaldomain[1].htm Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\redirect[1].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\registration[2].css Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\scottrade_88x31[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\shared[1].css Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\Shop;MN=93238368;wm=o;rm=1;!c=d-gif;!c=d-jpg;!c=d-imrd;!c=d-fls;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=291x15;tile=5;dcove=d;ord=165392652[1] Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\side-box[1].css Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\stab_hp[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\step4[1].png Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\tgar[1].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\tgar[2].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\tgar[3].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\trans_pixel[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\vista_header[1].jpg Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\webcomtop[1].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\webcomtop[2].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\welcome-bg[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\wild4music_com[1].jpg Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\wsus3setup[1].cab Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\89IVCHI3\__utm[1].htm Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\1107_300x250_ev_BSOTA_v3_fl[1].jpg Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\45fb58fc-0006d-04433-0a00ec5a[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\467abd8c-000b9-05971-0a00ead6[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\au_bg_lefttop[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\au_button_left[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\au_button_middle[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\au_shieldgreen[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\banner_chalkboard[1].jpg Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\bctrl[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\bmw-m3-coupe-200mk103107[1].jpg Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\broker[1].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\CA9TMZWD.gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\CAMJLIBL.htm Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\camoflauge_10.30[1].jpg Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\checkbox[1].jpg Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\commontop[1].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\Common[1].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\computer-scams-120-1102[1].jpg Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\content[1].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\content[2].css Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\content[2].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\desktop.ini Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\dir_sprite[1].png Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\download-box[1].png Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\download-firefox-title[1].png Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\download.old[1].htm Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\feature[1].css Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\firstpage[1].htm Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\frontpage[2].css Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\google[1].htm Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\HomePage[1].htm Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\icon_monitor[1].jpg Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\int_1107_nav_hpdt[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\jquery-plugins[1].htm Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\logo[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\LT-FP2;MN=93236699;wm=o;rm=1;!c=HPC;!c=d-fls;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=121x60;tile=3;dcove=d;ord=165392652[1] Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\luckymail_com[1].jpg Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\main[2].css Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\main[2].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\menu-box[1].css Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\music-chesney-z-200ab110107[1].jpg Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\mu_getstarted-center[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\mu_getstarted-part1middle_ltr[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\newsver[1].xml Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\news_bg_leftbottom[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\news_bg_leftmiddle[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\new[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\personaldomain[1].htm Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\personaldomain_js[1].htm Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\pixel[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\redirect[1].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\resultslist[1].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\resultslist[2].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\search[1].htm Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\shared[1].css Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\shared[2].css Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\snsStyles[2].css Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\spupdateids[1].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\step1[1].png Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\success-lg[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\success-sm[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\template[2].css Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\tgar[1].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\tgar[2].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\trans_pixel[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\windows_masthead_ltr[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\wsus3setup[1].cab Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\wuredir[1].cab Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\CPE7K1IR\__utm[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\472D7A290000867A00000000[1].jpg Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\817-grey[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\aolemail-200x150-c[1].jpg Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\arrowsquare[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\au_bg_bottommiddle[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\au_bg_rightmiddle[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\au_shieldred[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\awards[1].png Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\base[2].css Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\base[3].css Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\Behaviors[1].css Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\blank[1].htm Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\breadcrumbs-background[1].png Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\button_sm[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\CADK4R1T.swf Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\Common[1].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\content[1].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\content[2].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\Context[1].htm Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\core[1].css Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\corner-box[2].css Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\corner[1].jpg Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\desktop.ini Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\diagram[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\dir_sprite1[1].png Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\download[2].css Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\footer[1].png Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\hp-laptop.aol[1].htm Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\InstallStatus[1].htm Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\jquery-1.1.2[1].htm Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\jquery-plugins[1].htm Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\load[1].htm Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\login[1].htm Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\logo[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\luvgolfing_com[1].jpg Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\moz-com-logo[1].png Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\mu_getstarted-part1bottom_ltr[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\mu_getstarted-part2bottom_ltr[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\NavBar[1].htm Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\nav_logo3[1].png Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\news_bg_righttop[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\news_bg_topmiddle[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\p2_200_beige2[1].jpg Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\pointer[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\RadioLaunch[1].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\redirect[1].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\remaining-sm[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\search[1].htm Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\shared[1].css Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\Shop;MN=93238369;wm=o;rm=1;!c=d-gif;!c=d-jpg;!c=d-imrd;!c=d-fls;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=291x15;tile=6;dcove=d;ord=165392652[1] Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\SiteRecruit_PageConfiguration_2944mt-WU[1].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\snagbutton_default[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\spupdateids[1].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\spupdateids[2].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\tab[1].adp Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\tcode[1].htm Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\tgar[1].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\tgar[2].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\tgar[3].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\tgar[4].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\tgar[5].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\toc[1].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\toc[2].css Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\track[1].htm Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\webcomtop[1].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\window[2].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\V0KMPGQF\wrtflash_v2[2].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\18035_300x100_FCR_01[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\4602fec6-002ab-06ee1-0a00ec5a[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\adsWrapper[1].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\arrow[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\au_bg_rightbottom[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\au_bg_righttop[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\au_button_right[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\background[1].jpg Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\banner-right[1].jpg Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\beacon[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\better[1].htm Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\commontop[1].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\content[1].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\desktop.ini Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\download[1].htm Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\failed-lg[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\footer[1].htm Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\hdr_finish_left[1].jpg Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\hdr_welcome[1].jpg Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\header[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\hp_st_drop[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\HSCHeadlinesUS[1].xml Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\icon_ham_wrench[1].jpg Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\install-steps[1].png Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\jsonrpc[1].htm Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\landing[2].css Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\LT;MN=93236008;wm=o;rm=1;!c=HPC;!c=d-fls;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=121x60;tile=2;dcove=d;ord=165392652[1] Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\LTA;MN=93235416;wm=o;rm=1;!c=HPC;!c=d-gif;!c=d-jpg;!c=d-imrd;!c=d-fls;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=291x30;tile=4;dcove=d;ord=165392652[1] Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\LTB;MN=93235417;wm=o;rm=1;!c=HPC;!c=d-gif;!c=d-jpg;!c=d-imrd;!c=d-fls;!c=d-jav;!c=d-dxp;!c=d-pxp;sz=291x30;tile=7;dcove=d;ord=165392652[1] Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\main-feature[1].jpg Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\mstoolbar[1].htm Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\mu_getstarted-part2middle_ltr[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\m_sprite[1].png Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\news_bg_lefttop[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\news_bg_rightbottom[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\news_bg_rightmiddle[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\omniunih[1].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\omniunih[3].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\openreg[1].htm Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\pctrl[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\personaldomain_js[1].htm Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\redirect[1].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\registration[2].css Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\remaining-lg[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\resultslist[1].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\SiteRecruit_PageConfiguration_2944mt-WU[1].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\stb_arr_dn[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\stb_arr_up[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\step2[1].png Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\step3[1].png Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\table[2].css Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\tab[1].adp Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\tab[2].adp Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\template[1].css Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\tgar[1].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\tgar[2].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\tgar[3].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\tgar[4].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\tgar[5].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\TiVo_Flat_Pic_60x60_Logo[1].bmp Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\toc[1].htm Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\toc[1].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\update_webtrends[1].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\util[1].htm Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\util[2].js Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\welcome-right[1].jpg Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\windowsupdate.microsoft[1].htm Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\wuident[1].cab Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\Content.IE5\WXQJ0LEZ\__utm[1].gif Object is locked skipped
C:\Documents and Settings\DJ\Local Settings\Temporary Internet Files\desktop.ini Object is locked skipped
C:\Documents and Settings\DJ\My Documents\desktop.ini Object is locked skipped
C:\Documents and Settings\DJ\My Documents\My Music\Desktop.ini Object is locked skipped
C:\Documents and Settings\DJ\My Documents\My Music\Sample Music.lnk Object is locked skipped
C:\Documents and Settings\DJ\My Documents\My Music\Samples.lnk Object is locked skipped
C:\Documents and Settings\DJ\My Documents\My Pictures\Desktop.ini Object is locked skipped
C:\Documents and Settings\DJ\My Documents\My Pictures\Sample Pictures.lnk Object is locked skipped
C:\Documents and Settings\DJ\My Documents\My Pictures\Samples.lnk Object is locked skipped
C:\Documents and Settings\DJ\My Documents\My Videos\Desktop.ini Object is locked skipped
C:\Documents and Settings\DJ\My Documents\My Videos\Samples.lnk Object is locked skipped
C:\Documents and Settings\DJ\My Documents\My Webs\_vti_pvt\botinfs.cnf Object is locked skipped
C:\Documents and Settings\DJ\My Documents\My Webs\_vti_pvt\bots.cnf Object is locked skipped
C:\Documents and Settings\DJ\My Documents\My Webs\_vti_pvt\service.cnf Object is locked skipped
C:\Documents and Settings\DJ\My Documents\My Webs\_vti_pvt\service.lck Object is locked skipped
C:\Documents and Settings\DJ\My Documents\My Webs\_vti_pvt\services.cnf Object is locked skipped
C:\Documents and Settings\DJ\My Documents\sys\adobereader81.exe Object is locked skipped
C:\Documents and Settings\DJ\My Documents\sys\cleartype setup.exe Object is locked skipped
C:\Documents and Settings\DJ\My Documents\sys\Firefox Setup 2.0.0.9.exe Object is locked skipped
C:\Documents and Settings\DJ\My Documents\sys\flashplayer9.exe Object is locked skipped
C:\Documents and Settings\DJ\My Documents\sys\Google Updater.exe Object is locked skipped
C:\Documents and Settings\DJ\My Documents\sys\sav1016.exe Object is locked skipped
C:\Documents and Settings\DJ\My Documents\sys\spy_sweeper_installer532.exe Object is locked skipped
C:\Documents and Settings\DJ\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\DJ\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\DJ\ntuser.ini Object is locked skipped
C:\Documents and Settings\DJ\Recent\1 SECURITY SETTING.lnk Object is locked skipped
C:\Documents and Settings\DJ\Recent\1 SYSTEM NOTES.lnk Object is locked skipped
C:\Documents and Settings\DJ\Recent\a SYS.lnk Object is locked skipped
C:\Documents and Settings\DJ\Recent\Desktop.ini Object is locked skipped
C:\Documents and Settings\DJ\Recent\Removable Disk (E).lnk Object is locked skipped
C:\Documents and Settings\DJ\SendTo\Compressed (zipped) Folder.ZFSendToTarget Object is locked skipped
C:\Documents and Settings\DJ\SendTo\Desktop (create shortcut).DeskLink Object is locked skipped
C:\Documents and Settings\DJ\SendTo\desktop.ini Object is locked skipped
C:\Documents and Settings\DJ\SendTo\Mail Recipient.MAPIMail Object is locked skipped
C:\Documents and Settings\DJ\SendTo\My Documents.mydocs Object is locked skipped
C:\Documents and Settings\DJ\Start Menu\desktop.ini Object is locked skipped
C:\Documents and Settings\DJ\Start Menu\Programs\Accessories\Accessibility\desktop.ini Object is locked skipped
C:\Documents and Settings\DJ\Start Menu\Programs\Accessories\Accessibility\Magnifier.lnk Object is locked skipped
C:\Documents and Settings\DJ\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk Object is locked skipped
C:\Documents and Settings\DJ\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk Object is locked skipped
C:\Documents and Settings\DJ\Start Menu\Programs\Accessories\Accessibility\Utility Manager.lnk Object is locked skipped
C:\Documents and Settings\DJ\Start Menu\Programs\Accessories\Address Book.lnk Object is locked skipped
C:\Documents and Settings\DJ\Start Menu\Programs\Accessories\Command Prompt.lnk Object is locked skipped
C:\Documents and Settings\DJ\Start Menu\Programs\Accessories\desktop.ini Object is locked skipped
C:\Documents and Settings\DJ\Start Menu\Programs\Accessories\Entertainment\desktop.ini Object is locked skipped
C:\Documents and Settings\DJ\Start Menu\Programs\Accessories\Entertainment\Windows Media Player.lnk Object is locked skipped
C:\Documents and Settings\DJ\Start Menu\Programs\Accessories\Notepad.lnk Object is locked skipped
C:\Documents and Settings\DJ\Start Menu\Programs\Accessories\Program Compatibility Wizard.lnk Object is locked skipped
C:\Documents and Settings\DJ\Start Menu\Programs\Accessories\Synchronize.lnk Object is locked skipped
C:\Documents and Settings\DJ\Start Menu\Programs\Accessories\Tour Windows XP.lnk Object is locked skipped
C:\Documents and Settings\DJ\Start Menu\Programs\Accessories\Windows Explorer.lnk Object is locked skipped
C:\Documents and Settings\DJ\Start Menu\Programs\desktop.ini Object is locked skipped
C:\Documents and Settings\DJ\Start Menu\Programs\Internet Explorer.lnk Object is locked skipped
C:\Documents and Settings\DJ\Start Menu\Programs\Outlook Express.lnk Object is locked skipped
C:\Documents and Settings\DJ\Start Menu\Programs\Remote Assistance.lnk Object is locked skipped
C:\Documents and Settings\DJ\Start Menu\Programs\Startup\desktop.ini Object is locked skipped
C:\Documents and Settings\DJ\Start Menu\Programs\Windows Media Player.lnk Object is locked skipped
C:\Documents and Settings\DJ\Templates\amipro.sam Object is locked skipped
C:\Documents and Settings\DJ\Templates\excel.xls Object is locked skipped
C:\Documents and Settings\DJ\Templates\excel4.xls Object is locked skipped
C:\Documents and Settings\DJ\Templates\lotus.wk4 Object is locked skipped
C:\Documents and Settings\DJ\Templates\powerpnt.ppt Object is locked skipped
C:\Documents and Settings\DJ\Templates\presenta.shw Object is locked skipped
C:\Documents and Settings\DJ\Templates\quattro.wb2 Object is locked skipped
C:\Documents and Settings\DJ\Templates\sndrec.wav Object is locked skipped
C:\Documents and Settings\DJ\Templates\winword.doc Object is locked skipped
C:\Documents and Settings\DJ\Templates\winword2.doc Object is locked skipped
C:\Documents and Settings\DJ\Templates\wordpfct.wpd Object is locked skipped
C:\Documents and Settings\DJ\Templates\wordpfct.wpg Object is locked skipped
C:\Documents and Settings\DJ\UserData\G9LPWEEF\oWindowsUpdate[1].xml Object is locked skipped
C:\Documents and Settings\DJ\UserData\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\SL\Application Data\Microsoft\Templates\Normal.dot Object is locked skipped
C:\Documents and Settings\SL\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\SL\Desktop\Doc1.doc Object is locked skipped
C:\Documents and Settings\SL\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\SL\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\SL\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\SL\Local Settings\History\History.IE5\MSHist012008022220080223\index.dat Object is locked skipped
C:\Documents and Settings\SL\Local Settings\Temp\hpodvd09.log Object is locked skipped
C:\Documents and Settings\SL\Local Settings\Temp\~DF59F8.tmp Object is locked skipped
C:\Documents and Settings\SL\Local Settings\Temp\~DF5D40.tmp Object is locked skipped
C:\Documents and Settings\SL\Local Settings\Temp\~DFCBB7.tmp Object is locked skipped
C:\Documents and Settings\SL\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\SL\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\SL\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBConfig.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDebug.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDetect.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBNotify.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBRefr.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg2.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetDev.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetLoc.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetUsr.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMNot.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMReg.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMRSt.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStHash.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStMSI.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBValid.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPPolicy.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStart.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStop.log Object is locked skipped
C:\Program Files\Mozilla Firefox\crack.exe Infected: Trojan-Downloader.Win32.Small.iel skipped
C:\Program Files\Mozilla Firefox\install.exe Infected: Trojan-Downloader.Win32.Small.ijp skipped
C:\Program Files\Mozilla Firefox\keygen.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.isr skipped
C:\Program Files\Symantec AntiVirus\SAVRT\0492NAV~.TMP Object is locked skipped
C:\QooBox\Quarantine\C\WINDOWS\Installer\{4b1e0f79-8dd7-4971-be06-4345a35d3f01}\PrxKernel.dll.vir Infected: Trojan.Win32.Agent.feh skipped
C:\QooBox\Quarantine\C\WINDOWS\Installer\{f089578e-3e48-4d0a-8745-a4a94ce478eb}\zip.dll.vir Infected: Trojan-Downloader.Win32.BHO.ct skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\ddcbaay.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{C32CB2A1-0DC1-4635-9A62-E80B63218894}\RP169\A0084598.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{C32CB2A1-0DC1-4635-9A62-E80B63218894}\RP169\A0084617.exe/data.rar/keygen.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.isr skipped
C:\System Volume Information\_restore{C32CB2A1-0DC1-4635-9A62-E80B63218894}\RP169\A0084617.exe/data.rar/patch.exe Infected: Trojan.Win32.Dialer.yz skipped
C:\System Volume Information\_restore{C32CB2A1-0DC1-4635-9A62-E80B63218894}\RP169\A0084617.exe/data.rar/crack.exe Infected: Trojan-Downloader.Win32.Small.iel skipped
C:\System Volume Information\_restore{C32CB2A1-0DC1-4635-9A62-E80B63218894}\RP169\A0084617.exe/data.rar/install.exe Infected: Trojan-Downloader.Win32.Small.ijp skipped
C:\System Volume Information\_restore{C32CB2A1-0DC1-4635-9A62-E80B63218894}\RP169\A0084617.exe/data.rar Infected: Trojan-Downloader.Win32.Small.ijp skipped
C:\System Volume Information\_restore{C32CB2A1-0DC1-4635-9A62-E80B63218894}\RP169\A0084617.exe RarSFX: infected - 5 skipped
C:\System Volume Information\_restore{C32CB2A1-0DC1-4635-9A62-E80B63218894}\RP170\A0084765.dll Infected: Trojan.Win32.Agent.feh skipped
C:\System Volume Information\_restore{C32CB2A1-0DC1-4635-9A62-E80B63218894}\RP170\A0084766.dll Infected: Trojan-Downloader.Win32.BHO.ct skipped
C:\System Volume Information\_restore{C32CB2A1-0DC1-4635-9A62-E80B63218894}\RP175\change.log Object is locked skipped
C:\VundoFix Backups\ddcbaay.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.





hjt log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:23:31 PM, on 2/22/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\HPQ\shared\hpqwmi.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://gunz.ijji.com/?from=desktop
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /SYNC
O4 - HKLM\..\Run: [PHIME2002A] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /IMEName
O4 - HKLM\..\Run: [SynTPLpr] "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [eabconfg.cpl] "C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" /Start
O4 - HKLM\..\Run: [hpWirelessAssistant] "%ProgramFiles%\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=laptop
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O21 - SSODL: zip - {f089578e-3e48-4d0a-8745-a4a94ce478eb} - C:\WINDOWS\Installer\{f089578e-3e48-4d0a-8745-a4a94ce478eb}\zip.dll (file missing)
O21 - SSODL: PrxKernel - {4b1e0f79-8dd7-4971-be06-4345a35d3f01} - C:\WINDOWS\Installer\{4b1e0f79-8dd7-4971-be06-4345a35d3f01}\PrxKernel.dll (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\shared\hpqwmi.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

–
End of file - 8175 bytes
Ok were just about there. Delete 2 files and remove 2 stubborn registry entries.





Navigate to and delete these two files I have listed in bold type/
Delete only what is in bold type:


C:\Program Files\Mozilla Firefox\crack.exe
C:\Program Files\Mozilla Firefox\install.exe



_____________________________________
Next
__________________________________

Open note pad and copy the text in the box exactly to notepad.


Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"PrxKernel"=-
"zip"= -

Make sure there are NO blank lines before REGEDIT4
Make sure there IS one blank line at the end of the file.



Then click on the FILE menu and select save as
Save the file as regfix.reg. Save the file to the desktop.
IMPORTANT: make sure to save the file as "all types" and NOT as a text file.
It should look like this now
[external image: Posted Image]

Now double click the file on the desktop
When asked if you want this to merge with the registry.
Click YES!

You may delete that file now.

______________________________

Post 1 last HJT log please so I can see that 2 stubborn entries are gone.
hjt log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:21:31 PM, on 2/22/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\HPQ\shared\hpqwmi.exe
C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://gunz.ijji.com/?from=desktop
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /SYNC
O4 - HKLM\..\Run: [PHIME2002A] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /IMEName
O4 - HKLM\..\Run: [SynTPLpr] "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [eabconfg.cpl] "C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" /Start
O4 - HKLM\..\Run: [hpWirelessAssistant] "%ProgramFiles%\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=laptop
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\shared\hpqwmi.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

–
End of file - 7869 bytes

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI