This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Infected - need help, Hijackthis log posted

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,
My computer is infected with something as I am continually being infected with Viruses which AVG does detect and clean but I keep getting hit with new ones. Also, the C drive icon has changed to a red X when I open up My Computer. Aside from AVG I have also run Adaware regularly and also recently ran Spybot S&D which found a number of threats and cleaned them up. I am still experiencing issues after all that. Below you will find the Hijackthis log file. Your assistance is greatly appreciated.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:45:16 PM, on 02/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\RABCO\X_RABCOse.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [cursor] "C:\Program Files\Screendragon VS3\Screendragon VS3 Taskbar.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Openwares LiveUpdate] C:\Program Files\LiveUpdate\LiveUpdate.exe
O4 - HKLM\..\Run: [LogonUIBootRandomizer] "C:\unzip\logonuibootrandomizer\RandomScreens.exe" /RandomizeLogon
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [BenQ] F:\BenQJoybeePlayer.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [EPSON Stylus CX4800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE /P26 "EPSON Stylus CX4800 Series" /O6 "USB001" /M "Stylus CX4800"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [BM3be630ec] Rundll32.exe "C:\WINDOWS\system32\ldeseqsd.dll",s
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [EPSON Stylus CX4800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE /P26 "EPSON Stylus CX4800 Series" /M "Stylus CX4800" /EF "HKCU"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe (User 'Default user')
O4 - Startup: RABCO - Auto Update.lnk = C:\Program Files\RABCO\RABCOse.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/cha…t/c381/chat.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} (Microsoft VM) - http://www.wildtangent.com/install/jvm/msjavx86_3805.exe
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {2253F320-AB68-4A07-917D-4F12D8884A06} (ChainCast VMR Client Proxy) - http://www.streamaudio.com/download/ccpm_0237.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {4788DE0A-3552-49EA-AC8C-233DA52523B9} (AxLoaderPassword Class) - http://www.blackberry.com/devicesoftware/AxLoader.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-CA/a-UNO1/GAME_UNO1.cab
O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} (WSDownloader Control) - http://www.webshots.com/samplers/WSDownloader.ocx
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…StatsClient.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://sympatico.zone.msn.com/binFramework…ro.cab33902.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab
O16 - DPF: {FA13A9FA-CA9B-11D2-9780-00104B242EA3} - http://www.wildtangent.com/install/wdriver…wave/wtinst.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Microsoft cache control (MSControlService) - Unknown owner - C:\WINDOWS\system32\windows (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe

–
End of file - 11015 bytes
Hi SS78,

Temporarily disable Spybot's TeaTimer. This is a two step process.
First:
  • Right click Spybot in the System Tray (looks like a calendar with a padlock symbol)
  • Choose Exit Spybot S&D Resident
Second:
  • Open Spybot S&D
  • Click Mode, check Advanced Mode
  • Go To Left Panel, Click Tools, then also in left panel, click Resident
  • If your firewall raises a question, say OK
  • Uncheck the box labeled Resident TeaTimer and OK any prompts.
  • Use File, Exit to terminate Spybot.
  • Reboot your machine for the changes to take effect.

Next, download ComboFix to your desktop
  • Double click combofix.exe and follow the prompts
  • Note: Do not click ComboFix's window while it's running - it may cause it to stall!
  • If after ComboFix finishes you do not have internet access, then reboot your computer to restore it
  • When finished, it shall produce a log for you, please post it in your next response

Now open HijackThis, select Open the Misc Tools section
Press the Open Uninstall Manager… button, then press Save list…
Save the Uninstall log to your Desktop and include a copy in your next response.
Now press Back and Scan and then Save log to create and save a new HijackThis log.

Once complete, please post the ComboFix report, the uninstall list and a new HijackThis log.
Hi, first off thank you for your help, it is very appreciated. Here are the 3 items you asked for:

ComboFix 08-03-05.1 - Sukhprit 2008-03-05 22:22:53.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.194 [GMT -8:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\Common Files\ymante~1
C:\Program Files\Common Files\ymante~1\?ymantec\
C:\Program Files\outerinfo
C:\Program Files\Outlook Express\toceh89104.dll
C:\Program Files\RABCO
C:\Program Files\RABCO\ExecutionDll.dll
C:\Program Files\RABCO\RABCO.dll
C:\Program Files\RABCO\RABCO.dll.intermediate.manifest
C:\Program Files\RABCO\RABCOse.exe
C:\Program Files\RABCO\RABCOse.info
C:\Program Files\RABCO\RABCOse.original
C:\Program Files\RABCO\Setup.log
C:\Program Files\RABCO\un_RABCOSetup_16230.exe
C:\Program Files\RABCO\un_RABCOSetup_16230.txt
C:\Program Files\RABCO\X_RABCOse.exe
C:\Program Files\RABCO\X_RABCOse.log
C:\Program Files\sks~1
C:\Program Files\sks~1\w?wexec.exe
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\Temp\isgTi19
C:\Temp\isgTi19\lPig.log
C:\WINDOWS\BM3be630ec.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\fhkmp.ini
C:\WINDOWS\system32\fhkmp.ini2
C:\WINDOWS\system32\grouppolicy\machine\scripts\scripts.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\nGpxx01
C:\WINDOWS\system32\p6
C:\WINDOWS\system32\p6\kipon89104.exe
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\pmkhf.dll
C:\WINDOWS\system32\qlink32.dll
C:\WINDOWS\system32\r2
C:\WINDOWS\system32\tltvbpwz.dll

.
((((((((((((((((((((((((( Files Created from 2008-02-06 to 2008-03-06 )))))))))))))))))))))))))))))))
.

2008-03-04 12:34 . 2008-03-04 12:34 d——– C:\Documents and Settings\Jas\Application Data\AVG7
2008-03-02 13:35 . 2008-03-02 13:35 d——– C:\Program Files\Trend Micro
2008-02-29 12:17 . 2008-03-01 11:19 d——– C:\Documents and Settings\Bhinder\Application Data\AVG7
2008-02-27 22:31 . 2008-02-27 22:31 d——– C:\Autoruns
2008-02-27 00:27 . 2008-02-27 00:29 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-27 00:25 . 2008-02-27 00:25 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-02-27 00:22 . 2008-02-27 23:45 d——– C:\Documents and Settings\Sukhprit\Application Data\AVG7
2008-02-27 00:21 . 2008-02-27 00:21 d——– C:\Documents and Settings\LocalService\Application Data\AVG7
2008-02-27 00:20 . 2008-02-27 00:20 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-27 00:12 . 2008-03-05 08:00 d——– C:\Documents and Settings\All Users\Application Data\Avg7
2008-02-25 22:14 . 2008-02-25 22:14 552 –a—— C:\WINDOWS\system32\d3d8caps.dat
2008-02-25 21:51 . 2008-02-25 21:52 d——– C:\theclenz
2008-02-25 04:07 . 2008-02-27 22:36 37,970 —hs—- C:\WINDOWS\system32\axxbxqbi.dllbox
2008-02-24 16:06 . 2008-02-29 00:23 15,086 –a—— C:\WINDOWS\system32\FreePokerBonus.ico
2008-02-24 15:56 . 2008-03-01 13:09 d——– C:\Documents and Settings\All Users\Application Data\Rabio
2008-02-24 15:55 . 2008-02-27 02:56 d——– C:\WINDOWS\system32\xo4
2008-02-24 15:55 . 2008-02-24 15:55 d——– C:\WINDOWS\system32\ap8

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-01 20:06 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-03-01 20:06 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-27 08:27 ——— d—–w C:\Program Files\Lavasoft
2008-02-27 08:17 ——— d—–w C:\Documents and Settings\Amarjot\Application Data\Lavasoft
2008-02-24 21:36 ——— d—–w C:\Program Files\Bodog Poker
2008-02-04 03:56 ——— d—–w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-01-19 02:30 ——— d—–w C:\Program Files\Winamp2
2008-01-12 03:35 ——— d—–w C:\Program Files\GPLGS
2008-01-12 03:34 ——— d—–w C:\Program Files\Acro Software
2006-10-06 06:14 4,096 —-a-w C:\Documents and Settings\Sukhprit\log.dat
2006-08-12 07:27 25,600 —-a-w C:\Documents and Settings\Sukhprit\usbsermptxp.sys
2006-08-12 07:27 22,768 —-a-w C:\Documents and Settings\Sukhprit\usbsermpt.sys
2005-11-20 03:20 33,056 —-a-w C:\Documents and Settings\Bhinder\Application Data\GDIPFONTCACHEV1.DAT
2005-03-21 21:38 33,056 —-a-w C:\Documents and Settings\Amarjot\Application Data\GDIPFONTCACHEV1.DAT
2003-10-04 03:29 811 —-a-w C:\Program Files\INSTALL.LOG
.
—-a-r			 5,205 2001-09-16 20:37:04  C:\unzip\winace\WinAce 2.04 + Crack\WinACE 2.03 - 2.04 keygen .exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{341494C1-0203-2B8F-0A10-2900BDBD8EBD}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{831FEB07-D9C1-4C0D-A4A6-12AE82578672}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8657CD5C-3651-4632-B006-6D25CD583AA8}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8DE11AE7-2B80-48F5-B059-8D0F15570C28}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D85530E8-D39D-49D0-9F36-300D594556D2}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MessengerPlus3"="C:\Program Files\MessengerPlus! 3\MsgPlus.exe" [2005-04-21 18:11 185480]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-17 06:28 68856]
"EPSON Stylus CX4800 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.exe" [2005-02-01 11:00 98304]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [ ]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:54 5674352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Jet Detection"="C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe" [2001-11-29 00:00 28672]
"IntelliType"="C:\Program Files\Microsoft Hardware\Keyboard\type32.exe" [2002-03-21 20:41 94208]
"POINTER"="point32.exe" []
"cursor"="C:\Program Files\Screendragon VS3\Screendragon VS3 Taskbar.exe" [ ]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 02:50 155648]
"NeroCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 02:50 155648]
"Openwares LiveUpdate"="C:\Program Files\LiveUpdate\LiveUpdate.exe" [ ]
"LogonUIBootRandomizer"="C:\unzip\logonuibootrandomizer\RandomScreens.exe" [2003-07-07 08:03 176128]
"MessengerPlus3"="C:\Program Files\MessengerPlus! 3\MsgPlus.exe" [2005-04-21 18:11 185480]
"SoundMan"="SOUNDMAN.EXE" [2004-12-01 14:54 77824 C:\WINDOWS\SOUNDMAN.EXE]
"BenQ"="F:\BenQJoybeePlayer.exe" [ ]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-16 22:11 49152]
"EPSON Stylus CX4800 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.exe" [2005-02-01 11:00 98304]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 08:41 282624]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-06-01 15:51 257088]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-02-27 00:20 579072]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 00:00 90112]
"BM3be630ec"="C:\WINDOWS\system32\ldeseqsd.dll" [ ]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\ctfmon.exe" [2004-08-03 23:56 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-02-27 00:21 219136]

C:\Documents and Settings\Sukhprit\Start Menu\Programs\Startup\
RABCO - Auto Update.lnk - C:\QooBox\Quarantine\C\Program Files\RABCO\RABCOse.exe.vir [2008-02-24 15:55:23 183216]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
RAMASST.lnk - C:\WINDOWS\system32\RAMASST.exe [2004-01-08 22:09:06 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\axxbxqbi]
axxbxqbi.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtusrst]
vtusrst.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\Program Files\\Macromedia\\Fireworks MX\\Fireworks.exe"=
"C:\\Program Files\\Macromedia\\Flash MX\\Flash.exe"=
"C:\\Program Files\\AIM95\\aim.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\WINDOWS\\system32\\rundll32.exe"=
"C:\\Program Files\\MSN Content Plus\\MSN Winks Plus\\MSNWinksPlus.exe"=
"C:\\Program Files\\MessengerPlus! 3\\MsgPlus.exe"=
"C:\\Program Files\\Winamp\\winamp.exe"=
"C:\\WINDOWS\\system32\\mshta.exe"=
"C:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
"C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"C:\\Program Files\\Real\\RealOne Player\\realplay.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Microsoft Office\\Office10\\FRONTPG.EXE"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Joost\\xulrunner\\tvprunner.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Mozilla Firefox\\plugins\\alhlp.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=

R2 MarxDev1;MarxDev1;C:\WINDOWS\system32\drivers\MarxDev1.sys [2001-05-28 15:30]
R2 MarxDev2;MarxDev2;C:\WINDOWS\system32\drivers\MarxDev2.sys [2001-05-28 15:30]
R2 MarxDev3;MarxDev3;C:\WINDOWS\system32\drivers\MarxDev3.sys [2001-05-28 15:30]
S3 dwusbdnt;dwusbdnt;C:\WINDOWS\system32\DRIVERS\dwusbdnt.sys [2002-05-24 11:52]
S3 MSControlService;Microsoft cache control;C:\WINDOWS\system32\windows []
S3 RushTopDevice;RushTopDevice;C:\Program Files\MSI\Core Center\RushTop.sys []

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{24d6b5ac-25a4-11dc-9c58-000c763c2cd7}]
\Shell\Auto\command - UFO.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL UFO.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-03-05 16:21:15 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-02-29 17:37:01 C:\WINDOWS\Tasks\HP DArC Task #Hewlett-Packard#hp psc 1300 series#1122654816.job"
- C:\Program Files\HP\hpcoretech\comp\hpdarc.exe0/#Hewlett-Packard#hp psc 1300 series#1122654816
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-05 22:35:07
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\MSControlService]
"ImagePath"="C:\WINDOWS\system32\windows"
.
———————— Other Running Processes ————————
.
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-03-05 22:41:10 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-06 06:41:06
.
2008-02-13 11:08:58 — E O F —

___________________________________________________________
uninstall_list.txt

99 Topless Babes by PatioLanterns without music.
Ad-Aware 2007
Adobe Acrobat 5.0
Adobe Atmosphere Player for Acrobat and Adobe Reader
Adobe Flash Player 9 ActiveX
Adobe Flash Player Plugin
Adobe Photoshop 6.0
Adobe Photoshop Album 2.0 Starter Edition
Adobe Reader 7.0.9
Ahead Nero Burning ROM
AOL Instant Messenger
Apple Software Update
ArcSoft PhotoImpression 5
Audacity 1.2.6
AVG 7.5
BearShare
BitTornado 0.3.15
BlackBerry Desktop Software 4.2
BlackBerry Desktop Software 4.2
BlueSoleil
Bodog Poker Version 2.13.4.21
BurnOn CD&DVD, Version 3.1.0 ( Build 2005-10-26, Win32, )
Canon Camera Support Core Library
Canon Camera Window DS for ZoomBrowser EX
Canon Camera Window DVC for ZoomBrowser EX
Canon Camera Window for ZoomBrowser EX
Canon MovieEdit Task for ZoomBrowser EX
Canon PhotoRecord
Canon RAW Image Task for ZoomBrowser EX
Canon RemoteCapture Task for ZoomBrowser EX
Canon Utilities PhotoStitch 3.1
Canon ZoomBrowser EX
CutePDF Writer 2.7
Doyles Room Poker
DVD Shrink 3.2
DVD-RAM Driver
DVDZip 3.1
Enhance/MP3 (remove only)
EPSON CX 4200 4800 Guide
EPSON Printer Software
EPSON Scan
FastStone Image Viewer 3.0
Girls Get Wicked 2
Google Toolbar for Internet Explorer
HijackThis 2.0.2
HP Software Update
HP USB Disk Storage Format Tool
iTunes
Java 2 Runtime Environment, SE v1.4.1_02
jetAudio
Joost ™ Beta 1.0.3
Low-latency waveOut plugin v1.11 (remove only)
Macromedia Extension Manager
Macromedia Fireworks MX
Macromedia Flash MX
Macromedia FreeHand 10
Macromedia Shockwave Player
Memories Disc Creator 2.0
Messenger Plus! 3
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0
Microsoft Data Access Components KB870669
Microsoft Office XP Professional with FrontPage
Microsoft Visual C++ 2005 Redistributable
Motorola Phone Tools
Mozilla Firefox (2.0.0.12)
MSN Winks
MSN Winks Plus
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
My DSC
neoDVDplus
NVIDIA Display Driver
palmOne
PartyPoker
Photo DVD Slideshow 2.0
PokerRoom.com (remove only)
PokerStars
PowerDVD
Print Server
QCDTrayControls
QuickTax 2004
QuickTime
QuickTime for Windows (32-bit)
RABCO
RealPlayer
Realtek AC'97 Audio
SAMSUNG CDMA Modem Driver Set
SAMSUNG Mobile USB Modem 1.0 Software
SAMSUNG Mobile USB Modem Software
Samsung PC Studio
Samsung PC Studio 3 USB Driver Installer
Screendragon VS3
Security Update for Microsoft .NET Framework 2.0 (KB928365)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901190)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931768)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937143)
Security Update for Windows XP (KB937894)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB939653)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB942615)
Security Update for Windows XP (KB943055)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944533)
Security Update for Windows XP (KB944653)
Security Update for Windows XP (KB946026)
Shockwave
SiS 900 PCI Fast Ethernet Adapter Driver
Sound Blaster Live!
Spybot - Search & Destroy
StyleXP (remove only)
The Off By One Web Browser
TMPGEnc DVD Author 1.5
TMPGEnc Plus 2.5
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update for Windows XP (KB942840)
Update for Windows XP (KB946627)
Virtual DJ - Atomix Productions
WinAce Archiver 2.0
Winamp
Windows Installer 3.1 (KB893803)
Windows Installer 3.1 (KB893803)
Windows Live Messenger
Windows Media Encoder 9 Series
Windows Media Encoder 9 Series
Windows Media Format Runtime
Windows Media Player 10
Windows Media Player Plugin for MPIO
Windows XP Hotfix - KB834707
Windows XP Hotfix - KB867282
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB885884
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
Windows XP Service Pack 2
WinRAR archiver
WMPlus 2 (remove only)

___________________________________________________________

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:44:43 PM, on 05/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\RAMASST.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\notepad.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [cursor] "C:\Program Files\Screendragon VS3\Screendragon VS3 Taskbar.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Openwares LiveUpdate] C:\Program Files\LiveUpdate\LiveUpdate.exe
O4 - HKLM\..\Run: [LogonUIBootRandomizer] "C:\unzip\logonuibootrandomizer\RandomScreens.exe" /RandomizeLogon
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [BenQ] F:\BenQJoybeePlayer.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [EPSON Stylus CX4800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE /P26 "EPSON Stylus CX4800 Series" /O6 "USB001" /M "Stylus CX4800"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [BM3be630ec] Rundll32.exe "C:\WINDOWS\system32\ldeseqsd.dll",s
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [EPSON Stylus CX4800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE /P26 "EPSON Stylus CX4800 Series" /M "Stylus CX4800" /EF "HKCU"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe (User 'Default user')
O4 - Startup: RABCO - Auto Update.lnk = C:\QooBox\Quarantine\C\Program Files\RABCO\RABCOse.exe.vir
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/cha…t/c381/chat.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} (Microsoft VM) - http://www.wildtangent.com/install/jvm/msjavx86_3805.exe
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {2253F320-AB68-4A07-917D-4F12D8884A06} (ChainCast VMR Client Proxy) - http://www.streamaudio.com/download/ccpm_0237.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {4788DE0A-3552-49EA-AC8C-233DA52523B9} (AxLoaderPassword Class) - http://www.blackberry.com/devicesoftware/AxLoader.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-CA/a-UNO1/GAME_UNO1.cab
O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} (WSDownloader Control) - http://www.webshots.com/samplers/WSDownloader.ocx
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…StatsClient.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://sympatico.zone.msn.com/binFramework…ro.cab33902.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab
O16 - DPF: {FA13A9FA-CA9B-11D2-9780-00104B242EA3} - http://www.wildtangent.com/install/wdriver…wave/wtinst.cab
O20 - Winlogon Notify: axxbxqbi - axxbxqbi.dll (file missing)
O20 - Winlogon Notify: vtusrst - vtusrst.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Microsoft cache control (MSControlService) - Unknown owner - C:\WINDOWS\system32\windows (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe

–
End of file - 12054 bytes
Hi SS78,

Spybot's Tea Timer still appears to be running, did you have any problems with the instructions? Please try doing this once more:

Temporarily disable Spybot's TeaTimer. This is a two step process.
First:
  • Right click Spybot in the System Tray (looks like a calendar with a padlock symbol)
  • Choose Exit Spybot S&D Resident
Second:
  • Open Spybot S&D
  • Click Mode, check Advanced Mode
  • Go To Left Panel, Click Tools, then also in left panel, click Resident
  • If your firewall raises a question, say OK
  • Uncheck the box labeled Resident TeaTimer and OK any prompts.
  • Use File, Exit to terminate Spybot.
  • Reboot your machine for the changes to take effect.

————————————————————————

Please open Start->Control Panel->Add/Remove Programs, look down the list for these items and remove them:

Java 2 Runtime Environment, SE v1.4.1_02
PartyPoker
PokerRoom.com (remove only)
PokerStars

The Java Runtime installation is out of date and now a security risk, you can get the latest update (version 6 update 5) when your machine is clean from here
The poker programs have been reported as being malware-related so I strongly recommend you remove them.

You have a program called Messenger Plus! 3 installed. When installing it offers a choice either to Install the sponsor program or I refuse to give my support, don't install the sponsor. The sponsor program is malware so if you installed it we need to remove it. Even if you didn't install the sponsor program I recommend you remove this program anyway as the developer is spreading malware for profit - read more information about this here.
To remove, uninstall these entries via Add/Remove Programs:

Messenger Plus! 3
WMPlus 2 (remove only)


I can't confirm the status of these two programs however they are downloadable from websites known to distribute malware so I strongly recommend you remove them:

99 Topless Babes by PatioLanterns without music.
Girls Get Wicked 2


You have BearShare and BitTornado, P2P file sharing programs installed on your computer. These programs do not come bundled with malware as some similar programs do, but peer-to-peer file sharing networks are one of the biggest sources of malware we see. Anything downloaded from them cannot be trusted to be clean, because even if the file appears to be what it claims to be, it can have malware embedded in it.
I recommend you remove them, but of course the choice is yours.
You can remove BearShare and BitTornado via Add/Remove Programs.

————————————————————————

Check that ComboFix.exe is on your Desktop
  • Then open Notepad: press Start->Run, type notepad and click OK
  • Copy/paste the contents of the below code box into Notepad:
    KillAll::
    File::
    C:\Documents and Settings\Sukhprit\Start Menu\Programs\Startup\Auto Update.lnk
    C:\WINDOWS\system32\windows
    C:\WINDOWS\system32\axxbxqbi.dllbox
    C:\WINDOWS\system32\FreePokerBonus.ico
    C:\unzip\winace\WinAce 2.04 + Crack\WinACE 2.03 - 2.04 keygen .exe
    Driver::
    MSControlService
    Registry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{E0E899AB-F487-11D5-8D29-0050BA6940E3}"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "BM3be630ec"=-
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\axxbxqbi]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtusrst]
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{341494C1-0203-2B8F-0A10-2900BDBD8EBD}]
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{831FEB07-D9C1-4C0D-A4A6-12AE82578672}]
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8657CD5C-3651-4632-B006-6D25CD583AA8}]
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8DE11AE7-2B80-48F5-B059-8D0F15570C28}]
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D85530E8-D39D-49D0-9F36-300D594556D2}]
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{24d6b5ac-25a4-11dc-9c58-000c763c2cd7}]
    DirLook::
    C:\theclenz
    C:\Autoruns
    C:\Documents and Settings\All Users\Application Data\Rabio
    C:\WINDOWS\system32\xo4
    C:\WINDOWS\system32\ap8
  • Save this to your Desktop as CFScript.

    [external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
Note: Do not click ComboFix's window while it's running - it may cause it to stall!

————————————————————————

Now open HijackThis, select Open the Misc Tools section
Press the Open Uninstall Manager… button
Look for and select the entry called RABCO
Then press the Delete this entry button and OK the prompt
Now press Back and Scan and then Save log to create and save a new HijackThis log.

————————————————————————

Once complete, please post the new ComboFix report and a new HijackThis log.
Hi silver,

Weird about the Teatimer as I did follow your instructions the first time as well. I double checked this time after the restart and it was still unchecked.

In regards to 99 Topless… and Girls Get… , I'm not sure what these are. They show as last accessed in 2003 and 2004 but i can't uninstall. I get the message "Could not open Install.log file" for both of them.

Here are the new log files:

ComboFix 08-03-05.1 - Sukhprit 2008-03-06 0:52:02.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.201 [GMT -8:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Sukhprit\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\Documents and Settings\Sukhprit\Start Menu\Programs\Startup\Auto Update.lnk
C:\unzip\winace\WinAce 2.04 + Crack\WinACE 2.03 - 2.04 keygen .exe
C:\WINDOWS\system32\axxbxqbi.dllbox
C:\WINDOWS\system32\FreePokerBonus.ico
C:\WINDOWS\system32\windows
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Bhinder\Start Menu\Programs\Startup\DW_Start.lnk
C:\Documents and Settings\Guest\Start Menu\Programs\Startup\DW_Start.lnk
C:\unzip\winace\WinAce 2.04 + Crack\WinACE 2.03 - 2.04 keygen .exe
C:\WINDOWS\NDNuninstall5_64.exe
C:\WINDOWS\system32\axxbxqbi.dllbox
C:\WINDOWS\system32\FreePokerBonus.ico

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_MSCONTROLSERVICE
——-\MSControlService


((((((((((((((((((((((((( Files Created from 2008-02-06 to 2008-03-06 )))))))))))))))))))))))))))))))
.

2008-03-04 12:34 . 2008-03-04 12:34 d——– C:\Documents and Settings\Jas\Application Data\AVG7
2008-03-02 13:35 . 2008-03-02 13:35 d——– C:\Program Files\Trend Micro
2008-02-29 12:17 . 2008-03-01 11:19 d——– C:\Documents and Settings\Bhinder\Application Data\AVG7
2008-02-27 22:31 . 2008-02-27 22:31 d——– C:\Autoruns
2008-02-27 00:27 . 2008-02-27 00:29 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-27 00:25 . 2008-02-27 00:25 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-02-27 00:22 . 2008-02-27 23:45 d——– C:\Documents and Settings\Sukhprit\Application Data\AVG7
2008-02-27 00:21 . 2008-02-27 00:21 d——– C:\Documents and Settings\LocalService\Application Data\AVG7
2008-02-27 00:20 . 2008-02-27 00:20 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-27 00:12 . 2008-03-05 08:00 d——– C:\Documents and Settings\All Users\Application Data\Avg7
2008-02-25 22:14 . 2008-02-25 22:14 552 –a—— C:\WINDOWS\system32\d3d8caps.dat
2008-02-25 21:51 . 2008-02-25 21:52 d——– C:\theclenz
2008-02-24 15:56 . 2008-03-01 13:09 d——– C:\Documents and Settings\All Users\Application Data\Rabio
2008-02-24 15:55 . 2008-02-27 02:56 d——– C:\WINDOWS\system32\xo4
2008-02-24 15:55 . 2008-02-24 15:55 d——– C:\WINDOWS\system32\ap8

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-06 08:51 ——— d—–w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-03-06 08:44 ——— d—–w C:\Program Files\BitTorrent
2008-03-06 08:41 ——— d—–w C:\Program Files\PokerStars
2008-03-06 08:41 ——— d—–w C:\Program Files\PokerRoom.com
2008-03-06 08:40 ——— d—–w C:\Program Files\PartyGaming
2008-03-06 08:39 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-03-01 20:06 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-03-01 20:06 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-27 08:27 ——— d—–w C:\Program Files\Lavasoft
2008-02-27 08:17 ——— d—–w C:\Documents and Settings\Amarjot\Application Data\Lavasoft
2008-02-24 21:36 ——— d—–w C:\Program Files\Bodog Poker
2008-02-04 03:56 ——— d—–w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-01-19 02:30 ——— d—–w C:\Program Files\Winamp2
2008-01-12 03:35 ——— d—–w C:\Program Files\GPLGS
2008-01-12 03:34 ——— d—–w C:\Program Files\Acro Software
2006-10-06 06:14 4,096 —-a-w C:\Documents and Settings\Sukhprit\log.dat
2006-08-12 07:27 25,600 —-a-w C:\Documents and Settings\Sukhprit\usbsermptxp.sys
2006-08-12 07:27 22,768 —-a-w C:\Documents and Settings\Sukhprit\usbsermpt.sys
2005-11-20 03:20 33,056 —-a-w C:\Documents and Settings\Bhinder\Application Data\GDIPFONTCACHEV1.DAT
2005-03-21 21:38 33,056 —-a-w C:\Documents and Settings\Amarjot\Application Data\GDIPFONTCACHEV1.DAT
2003-10-04 03:29 811 —-a-w C:\Program Files\INSTALL.LOG
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

—- Directory of C:\Autoruns —-

2008-02-25 11:44 603176 –a—— C:\Autoruns\autoruns.exe
2008-02-25 11:44 513064 –a—— C:\Autoruns\autorunsc.exe
2007-12-14 10:07 48130 –a—— C:\Autoruns\autoruns.chm
2006-07-28 08:32 7005 –a—— C:\Autoruns\Eula.txt

—- Directory of C:\Documents and Settings\All Users\Application Data\Rabio —-


—- Directory of C:\theclenz —-

2008-02-25 21:42 140288 –a—— C:\theclenz\vcleaner.exe

—- Directory of C:\WINDOWS\system32\ap8 —-

2008-01-30 13:19 183216 –a—— C:\WINDOWS\system32\ap8\yula4403.exe

—- Directory of C:\WINDOWS\system32\xo4 —-



((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-17 06:28 68856]
"EPSON Stylus CX4800 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.exe" [2005-02-01 11:00 98304]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Jet Detection"="C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe" [2001-11-29 00:00 28672]
"IntelliType"="C:\Program Files\Microsoft Hardware\Keyboard\type32.exe" [2002-03-21 20:41 94208]
"POINTER"="point32.exe" []
"cursor"="C:\Program Files\Screendragon VS3\Screendragon VS3 Taskbar.exe" [ ]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 02:50 155648]
"NeroCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 02:50 155648]
"Openwares LiveUpdate"="C:\Program Files\LiveUpdate\LiveUpdate.exe" [ ]
"LogonUIBootRandomizer"="C:\unzip\logonuibootrandomizer\RandomScreens.exe" [2003-07-07 08:03 176128]
"SoundMan"="SOUNDMAN.EXE" [2004-12-01 14:54 77824 C:\WINDOWS\SOUNDMAN.EXE]
"BenQ"="F:\BenQJoybeePlayer.exe" [ ]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-16 22:11 49152]
"EPSON Stylus CX4800 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.exe" [2005-02-01 11:00 98304]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 08:41 282624]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-06-01 15:51 257088]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-02-27 00:20 579072]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 00:00 90112]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\ctfmon.exe" [2004-08-03 23:56 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-02-27 00:21 219136]

C:\Documents and Settings\Sukhprit\Start Menu\Programs\Startup\
RABCO - Auto Update.lnk - C:\QooBox\Quarantine\C\Program Files\RABCO\RABCOse.exe.vir [2008-02-24 15:55:23 183216]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
RAMASST.lnk - C:\WINDOWS\system32\RAMASST.exe [2004-01-08 22:09:06 155648]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\Program Files\\Macromedia\\Fireworks MX\\Fireworks.exe"=
"C:\\Program Files\\Macromedia\\Flash MX\\Flash.exe"=
"C:\\Program Files\\AIM95\\aim.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\WINDOWS\\system32\\rundll32.exe"=
"C:\\Program Files\\MSN Content Plus\\MSN Winks Plus\\MSNWinksPlus.exe"=
"C:\\Program Files\\Winamp\\winamp.exe"=
"C:\\WINDOWS\\system32\\mshta.exe"=
"C:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"C:\\Program Files\\Real\\RealOne Player\\realplay.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Microsoft Office\\Office10\\FRONTPG.EXE"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Joost\\xulrunner\\tvprunner.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Mozilla Firefox\\plugins\\alhlp.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=

R2 MarxDev1;MarxDev1;C:\WINDOWS\system32\drivers\MarxDev1.sys [2001-05-28 15:30]
R2 MarxDev2;MarxDev2;C:\WINDOWS\system32\drivers\MarxDev2.sys [2001-05-28 15:30]
R2 MarxDev3;MarxDev3;C:\WINDOWS\system32\drivers\MarxDev3.sys [2001-05-28 15:30]
S3 dwusbdnt;dwusbdnt;C:\WINDOWS\system32\DRIVERS\dwusbdnt.sys [2002-05-24 11:52]
S3 RushTopDevice;RushTopDevice;C:\Program Files\MSI\Core Center\RushTop.sys []

.
Contents of the 'Scheduled Tasks' folder
"2008-03-05 16:21:15 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-02-29 17:37:01 C:\WINDOWS\Tasks\HP DArC Task #Hewlett-Packard#hp psc 1300 series#1122654816.job"
- C:\Program Files\HP\hpcoretech\comp\hpdarc.exe0/#Hewlett-Packard#hp psc 1300 series#1122654816
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-06 01:00:04
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-03-06 1:06:19 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-06 09:06:15
ComboFix2.txt 2008-03-06 06:41:11
.
2008-02-13 11:08:58 — E O F —


________________________________________


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:08:30 AM, on 06/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [cursor] "C:\Program Files\Screendragon VS3\Screendragon VS3 Taskbar.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Openwares LiveUpdate] C:\Program Files\LiveUpdate\LiveUpdate.exe
O4 - HKLM\..\Run: [LogonUIBootRandomizer] "C:\unzip\logonuibootrandomizer\RandomScreens.exe" /RandomizeLogon
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [BenQ] F:\BenQJoybeePlayer.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [EPSON Stylus CX4800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE /P26 "EPSON Stylus CX4800 Series" /O6 "USB001" /M "Stylus CX4800"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [EPSON Stylus CX4800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE /P26 "EPSON Stylus CX4800 Series" /M "Stylus CX4800" /EF "HKCU"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe (User 'Default user')
O4 - Startup: RABCO - Auto Update.lnk = C:\QooBox\Quarantine\C\Program Files\RABCO\RABCOse.exe.vir
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/cha…t/c381/chat.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} (Microsoft VM) - http://www.wildtangent.com/install/jvm/msjavx86_3805.exe
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {2253F320-AB68-4A07-917D-4F12D8884A06} (ChainCast VMR Client Proxy) - http://www.streamaudio.com/download/ccpm_0237.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {4788DE0A-3552-49EA-AC8C-233DA52523B9} (AxLoaderPassword Class) - http://www.blackberry.com/devicesoftware/AxLoader.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-CA/a-UNO1/GAME_UNO1.cab
O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} (WSDownloader Control) - http://www.webshots.com/samplers/WSDownloader.ocx
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.1_02) -
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…StatsClient.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://sympatico.zone.msn.com/binFramework…ro.cab33902.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_02) -
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab
O16 - DPF: {FA13A9FA-CA9B-11D2-9780-00104B242EA3} - http://www.wildtangent.com/install/wdriver…wave/wtinst.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe

–
End of file - 11196 bytes
Hi SS78,

Looking a lot better but we still have a few things to take care of.

Open HijackThis, select Open the Misc Tools section
Press the Open Uninstall Manager… button
Scroll down the list and find this entry:

99 Topless Babes by PatioLanterns without music

Click it to highlight it, then press Delete this entry
Repeat for these entries (if present):

Girls Get Wicked 2
RABCO

Then, press Back, then Scan and then place a checkmark next to the following lines:

O4 - Startup: RABCO - Auto Update.lnk = C:\QooBox\Quarantine\C\Program Files\RABCO\RABCOse.exe.vir
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O16 - DPF: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} (Microsoft VM) - http://www.wildtangent.com/install/jvm/msjavx86_3805.exe
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.1_02) -
O16 - DPF: {FA13A9FA-CA9B-11D2-9780-00104B242EA3} - http://www.wildtangent.com/install/wdriver…wave/wtinst.cab

Then close all open windows apart from HijackThis, press Fix checked, OK the prompt and close HijackThis.

Make hidden/system files and folders visible:
Click Start -> My Computer
Select the Tools menu, click Folder Options and select the View tab
Under the Hidden files and folders heading SELECT Show hidden files and folders
UNCHECK the Hide extensions for known file types option
UNCHECK the Hide protected operating system files (recommended) option
Click Yes to confirm and press OK

Use Windows Explorer (right-click Start, select Explore) to find and delete the following folders:

C:\Documents and Settings\All Users\Application Data\Rabio
C:\WINDOWS\system32\xo4
C:\WINDOWS\system32\ap8

If you have trouble finding or deleting any, please let me know in your next response.

Then, please do an online scan with Kaspersky:
Open Kaspersky Online Scanner in Internet Explorer using this link:
http://www.kaspersky.com/kos/eng/partner/d…kavwebscan.html
  • Click Accept and the web scanner will begin to load
  • If a yellow warning bar appears at the top of the browser, click it and choose Install ActiveX Control
  • You will be prompted to install an ActiveX component from Kaspersky, click Install
  • If you are prompted about another ActiveX control called Kaspersky Online Scanner GUI part then allow it to be installed also.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on Next and then Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • The program will start to scan your system.
  • Once the scan is complete, click on the Save Report As… button, change Save as type: to Text file and save the file to your desktop as Kaspersky.txt

Once complete, please post the Kaspersky report along with a new HijackThis log.
Also, tell me how your computer is behaving now.
Hi Silver,

I couldn't find the RABCO entry in the Hijackthis Uninstall Manager so couldn't delete it. I still have a red X as the c: icon, other than that, I don't really notice much wrong at this point but time will tell as i just finished running the scans. Thanks again for your help.

Here are the logs:

——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Thursday, March 06, 2008 10:56:32 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 7/03/2008
Kaspersky Anti-Virus database records: 607587
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
B:\
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\
K:\

Scan Statistics:
Total number of scanned objects: 130677
Number of viruses found: 48
Number of infected objects: 180
Number of suspicious objects: 1
Duration of the scan process: 02:10:54

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\DSS\MachineKeys\3f8a8ed8eb96ac8ca23c08ac3d13f1a9_5fc03d4e-2fa4-4f1b-a266-1becde9210d0 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\Amarjot\.jpi_cache\file\1.0\SecurityClassLoader.class-2c965182-4562ddc2.class Infected: Exploit.JS.ScriptSrc.a skipped
C:\Documents and Settings\Amarjot\Desktop\VVSNI_LOFS120501Inst.exe Infected: not-a-virus:AdTool.Win32.WhenU.a skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\001.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\003.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\004.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\005.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\008.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\009.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\010.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\011.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\012.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\013.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\014.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\111.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\13.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\138.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\139.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\140.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\141.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\15.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\16.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\18.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\185.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\186.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\187.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\188.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\189.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\19.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\190.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\191.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\20.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\23.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\28.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\34.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\35.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\36.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\37.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\3gs1.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\3gs2.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\3gs3.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\3gs4.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\3gs5.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\3gs6.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\3gs7.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\3gs8.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\3gs9.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\4.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\43.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\46.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\47.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\47[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\48.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\48[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\49.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\50.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\51.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\55[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\56[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\57[2].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\58[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\59[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\60[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\61.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\61[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\9.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Alex5.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Alex6.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Alex7.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Alex8.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\alley1[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\alley2[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\alley3[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\alley4[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\alley6[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\alley7[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\alley8[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\alley[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\ARIA1.JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\ARIA2.JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\ARIA3.JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\ARIA4.JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\ARIA5.JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\ARIA6.JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\ARIA7.JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\ARIA8.JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\ARIA9.JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\b0001[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\b0004[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\b0006[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\b0010[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\b0015[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\b0018[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\b0019[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\b0020[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\basic.htm Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\bcad7c29[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\bend1(2)[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\bend10(2)[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\bend2(2)[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\bend3(2)[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\bend4_1(2)[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\bend5_1(2)[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\bend6(2)[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\bend7_1(2)[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\bend8(2)[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\bend9_1(2)[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\bga_buffy_tyler_01[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\BM_PAME1[1].JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\BM_PAME2[1].JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\BM_PAME3[1].JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\BM_PAME4[1].JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\BM_PAME5[1].JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\BM_PAME6[1].JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\BM_PAME7[1].JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\BM_PAMEL[1].JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\BOTBBrookeRichards1[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\BOTBBrookeRichards2[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\BOTBBrookeRichards3[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\BOTBBrookeRichards4[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\BOTBBrookeRichards5[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\BOTBBrookeRichards6[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\BOTBBrookeRichards7[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\BOTBBrookeRichards8[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\BOTBBrookeRichards9[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\brooke_richards_002[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\brooke_richards_006[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\brooke_richards_007[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\brooke_richards_009[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\brooke_richards_010[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\brooke_richards_011[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\brooke_richards_012[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\buffy01[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\buffy06[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\buffy11[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\buffy13[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\buffy17[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\C1996h15[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\C1996h16[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\C1996h17[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\centerfolds007[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\d2ea577c[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\dent01[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\dent02[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\dent03[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\dent04[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\dent05[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\dent06[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\dent08[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\dent09[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\dent10[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\dent11[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\dent12[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\dent14[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\dent15[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\dent16[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\dent[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\abc1.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\abc10.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\abc10_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\abc11.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\abc11_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\abc12.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\abc12_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\abc13.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\abc13_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\abc14.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\abc14_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\abc15.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\abc15_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\abc16.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\abc16_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\abc17.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\abc17_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\abc1_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\abc2.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\abc2_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\abc3.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\abc3_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\abc4.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\abc4_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\abc5.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\abc5_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\abc6.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\abc6_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\abc7.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\abc7_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\abc8.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\abc8_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\abc9.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\abc9_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\angela1.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\angela12.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\angela12_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\angela1_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\angela2.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\angela2_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\angela3.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\angela3_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\angela4.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\angela4_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\angela5.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\angela5_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\angela6.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\angela6_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\angela7.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\angela7_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Angels.html Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Angels1.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Angels1_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Angels2.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Angels2_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Angels3.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Angels3_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Angels4.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Angels4_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Angels5.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Angels5_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Angels6.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Angels6_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Angels7.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Angels7_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Angels8.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Angels8_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\AP1.JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\AP10.JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Ap10_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\AP11.JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Ap11_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\AP12.JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Ap12_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Ap1_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\AP2.JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Ap2_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\AP3.JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Ap3_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\AP4.JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Ap4_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\AP5.JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Ap5_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\AP6.JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Ap6_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\AP7.JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Ap7_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\AP8.JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Ap8_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\AP9.JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Ap9_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\brown1.html Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\brown2.html Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\brown3.html Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\brown4.html Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\chick1.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\chick1_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\chick2.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\chick2_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\chick3.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\chick3_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\chick4.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\chick4_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\chick5.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\chick5_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\chick6.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\chick6_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\C_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\E_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\G_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Images\C.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Images\E.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Images\G.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Images\I.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Images\K.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Images\M.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Images\O.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Images\Q.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Images\S.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Images\snow01.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Images\snow05.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Images\snow06.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Images\snow10.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Images\snow16.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Images\snow17.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Images\snow18.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Images\snow22.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Images\Thumbs.db Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Images\U.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Images\W.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Images\Y.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\index.html Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\I_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\K_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\main.html Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\M_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\O_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Playboy.html Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Q_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\snow.html Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\snow01_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\snow05_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\snow06_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\snow10_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\snow16_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\snow17_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\snow18_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\snow22_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\surrey.html Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\surreyhoe5.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\surreyhoe5_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\surreyhoe6.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\surreyhoe6_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\surreyhoe7.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\surreyhoe7_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\surreyhoe8.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\surreyhoe8_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\surreyhoe9.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\surreyhoe9_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\S_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Thumbs.db Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\U_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\W_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Done\Y_small.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\erica7861[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\erica7862[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\erica7863[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\erica7864[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\erica7865[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\erica7867[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\erica7868[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\erica7870[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\erica7871[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\erica7872[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\eswa-p-bernaola_c_d-01_pmm0100[1].jpeg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\eswa-p-bernaola_c_d-02_pmm0100[1].jpeg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\eswa-p-bernaola_c_d-03_pmm0100[1].jpeg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\eswa-p-bernaola_c_d-04_pmm0100[1].jpeg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\eswa-p-bernaola_c_d-05_pmm0100[1].jpeg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\eswa-p-bernaola_c_d-06_pmm0100[1].jpeg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\etlez15[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\eve001[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\eve002[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\eve003[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\eve004[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\eve005[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\eve006[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\eve007[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\eve008[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\eve009[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\eve010[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\eve011[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\eve012[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\eve013[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\eve014[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\eve015[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\eve016[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\eve017[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\eve019[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\eve020[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\fine2[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\fine3[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\fine5[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\fine[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\foxxx001[2].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\foxxx002a[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\foxxx004[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\foxxx005[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\foxxx008[2].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\foxxx009[2].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\foxxx010[2].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\foxxx011[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\foxxx012[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\girl1[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\girl2[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\girl[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\gold11[1].JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\gold35[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\gold3[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\gold44[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\gold44_2[1].JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\gold55[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\gold87[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\gold88[1].JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\gold999[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\gold99[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\good1.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\good1[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\good2.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\good2[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\good3.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\good3[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\good4.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\good4[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\good5.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\good5[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\good6.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\good6[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\good7.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\good7[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\good8[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\grls70[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\grlz19[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\grlz25[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\grlz5[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\grlz7[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\grlza[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\grlze[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\h-h1.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\h-h2.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\h-h3.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\h-h4.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\h-h5.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\h-h6.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\h-h7.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\h-h8.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\h-h9.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\hawaii1.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\hawaii10.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\hawaii11.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\hawaii12.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\hawaii2.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\hawaii3.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\hawaii4.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\hawaii5.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\hawaii6.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\hawaii7.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\hawaii8.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\hawaii9.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\heather03[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\heather04[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Heshootshe(1)[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\hg10[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\hg11[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\hg12[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\hg13[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\hg14[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\hg7[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\hg8[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\hg9[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\hoody.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\hoody1.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\hoody2.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\hoody3..jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\hot1[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\hot2[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\hot3[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\hot4[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\hot5[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\hot6[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\HU_ON_192[1].JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\HU_ON_201[1].JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\HU_ON_202[1].JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\HU_ON_204[1].JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\HU_ON_205[1].JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\iLES01[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\iLES02[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\iLES03[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\indianmodels.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\irina02[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\irina10[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\irina30[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\irina33[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\irina34[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\irina35[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\irina39[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\irina41[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\irina50[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\irina51[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\JenniferLeone_5[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\JenniferLeone_6[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\jk1[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\jk2[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\jk3[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\jk4[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\jk5[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\jk6[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\jk7[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\jk8[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\KylaJen12[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\KylaJen13[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\KylaJen15[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\KylaJen16[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\KylaJen4[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\KylaJen6[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\KylaJen7[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\KylaJen9[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\l1.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\l10.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\l2.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\l3.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\l4.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\l5.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\l6.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\l7.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\l8.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\l9.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\le1.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\le10.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\le11.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\le12.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\le13.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\le2.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\le3.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\le4.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\le5.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\le6.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\le7.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\le8.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\le9.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\les011101[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\les011102[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\les011105[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\les011110[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\les011111[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\les011113[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\les011117[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\les011120[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Lingerie1[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Lingerie2[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Lingerie3[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\lisa05[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\lisa08[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\nicole_marie_lenz[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\nicole_marie_lenz_1[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\nicole_marie_lenz_2[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\nicole_marie_lenz_3[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\nicole_marie_lenz_4[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\nicole_marie_lenz_5[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\nicole_marie_lenz_6[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\nicole_marie_lenz_7[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\nicole_marie_lenz_8[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\paulina05[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\paulina19[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\pic01[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\pic02[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\pic04[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\pic05[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\pic08[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\pic09[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\pic11[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\pic12[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\pic13[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\pic14[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\pic15[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\pic16[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\pic17[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\pic18[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\pic19[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\pic20[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\pic21[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\pic22[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Playboy_Torrie_Wilson-001.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Playboy_Torrie_Wilson-002.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\playing[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\poker1[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\poker2[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\poker3[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\poker4[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\poker6[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\poker7[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\poker8[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\poker9[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\poker[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\pool[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\pornstarspicskydaddy011[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\pornstarspicskydaddy019[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\pp0020[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\pp0033[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\pp0053[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\pp0057[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\pp0094[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\priscilla04[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\priscilla05[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\priscilla23[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\priscilla40[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\priv7518[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\sec1.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\sec10.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\sec2.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\sec20.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\sec3.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\sec5.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\sec50.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\sec7.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\sec70.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\sec8.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\sec80.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\sexy3[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\sexy4[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\sexy5[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\sexy6[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\sexy7[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\sexy8[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\sexy9[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\sexy[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\shaemarks_14[1].jpg.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\shaemarks_5[1].jpg.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Shyla1.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Shyla10.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Shyla2.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Shyla3.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Shyla4.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Shyla6.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Shyla7.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Shyla8.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Shyla9.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\sky1[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\sky2[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\sky3[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\sky4[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\sky5[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\surrey1[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\surrey2[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\surrey3[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\surrey4[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\surrey5[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\surreysuck2[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\surreysuck3[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\surreysuck[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\suzanne07[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\suzanne08[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\suzanne10[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\teanna15[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\teanna1[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\teanna24[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\teanna28[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\teanna5[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Thumbs.db Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Torrie Wilson - Playboy 3.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Torrie Wilson - Playboy 4.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Torrie Wilson Early Playboy Photo.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Torrie Wilson Playboy Pic 1 -Madrox- (1).jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Torrie Wilson Playboy Pic 2 -Madrox-.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Torrie Wilson Playboy Pic 3 -Madrox-.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Torrie Wilson Playboy Pic 4 -Madrox-.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Torrie Wilson Playboy Pic 5.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Torrie Wilson Playboy Pic 6.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Torrie Wilson Playboy Pic 7.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\Torrie Wilson Playboy Pic 8.jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\tp08[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\tp10[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\tp11[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\tp12[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\txm1[1].JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\txm2[1].JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\txm3[1].JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\txm4[1].JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\txm5[1].JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\WET1.JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\WET10.JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\WET11.JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\WET12.JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\WET13.JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\WET14.JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\WET15.JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\WET16.JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\WET17.JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\WET18.JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\WET2.JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\WET3.JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\WET4.JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\WET5.JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\WET6.JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\WET7.JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\WET8.JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\WET9.JPG Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\whi01[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\whi06[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\whi07[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\whi08[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\whi12[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\whi15[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\Newsite\whi18[1].jpg Object is locked skipped
C:\Documents and Settings\Amarjot\My Documents\torrents\crack_13559248413176.zip/Zealot SWF2Video Studio v1.0/Install_1207.exe/data0001 Infected: Trojan-Downloader.Win32.IstBar.ja skipped
C:\Documents and Settings\Amarjot\My Documents\torrents\crack_13559248413176.zip/Zealot SWF2Video Studio v1.0/Install_1207.exe/data0003 Infected: Trojan-Downloader.Win32.IstBar.ny skipped
C:\Documents and Settings\Amarjot\My Documents\torrents\crack_13559248413176.zip/Zealot SWF2Video Studio v1.0/Install_1207.exe/data0005 Infected: Trojan-Downloader.Win32.IstBar.ja skipped
C:\Documents and Settings\Amarjot\My Documents\torrents\crack_13559248413176.zip/Zealot SWF2Video Studio v1.0/Install_1207.exe Infected: Trojan-Downloader.Win32.IstBar.ja skipped
C:\Documents and Settings\Amarjot\My Documents\torrents\crack_13559248413176.zip ZIP: infected - 4 skipped
C:\Documents and Settings\Amarjot\My Documents\torrents\crack_13567248413176.zip/Zealot SWF2Video Studio v1.0 by SND/Install_11492.exe/data0001 Infected: Trojan-Downloader.Win32.IstBar.ja skipped
C:\Documents and Settings\Amarjot\My Documents\torrents\crack_13567248413176.zip/Zealot SWF2Video Studio v1.0 by SND/Install_11492.exe/data0003 Infected: Trojan-Downloader.Win32.IstBar.ny skipped
C:\Documents and Settings\Amarjot\My Documents\torrents\crack_13567248413176.zip/Zealot SWF2Video Studio v1.0 by SND/Install_11492.exe/data0005 Infected: Trojan-Downloader.Win32.IstBar.ja skipped
C:\Documents and Settings\Amarjot\My Documents\torrents\crack_13567248413176.zip/Zealot SWF2Video Studio v1.0 by SND/Install_11492.exe Infected: Trojan-Downloader.Win32.IstBar.ja skipped
C:\Documents and Settings\Amarjot\My Documents\torrents\crack_13567248413176.zip ZIP: infected - 4 skipped
C:\Documents and Settings\Amarjot\My Documents\torrents\Zealot SWF2Video Studio v1.0\Install_1207.exe/data0001 Infected: Trojan-Downloader.Win32.IstBar.ja skipped
C:\Documents and Settings\Amarjot\My Documents\torrents\Zealot SWF2Video Studio v1.0\Install_1207.exe/data0003 Infected: Trojan-Downloader.Win32.IstBar.ny skipped
C:\Documents and Settings\Amarjot\My Documents\torrents\Zealot SWF2Video Studio v1.0\Install_1207.exe/data0005 Infected: Trojan-Downloader.Win32.IstBar.ja skipped
C:\Documents and Settings\Amarjot\My Documents\torrents\Zealot SWF2Video Studio v1.0\Install_1207.exe NSIS: infected - 3 skipped
C:\Documents and Settings\Amarjot\My Documents\xp mess\Boot\89333.exe/WISE0017.BIN Infected: not-a-virus:AdWare.Win32.Quick.a skipped
C:\Documents and Settings\Amarjot\My Documents\xp mess\Boot\89333.exe/WISE0018.BIN Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
C:\Documents and Settings\Amarjot\My Documents\xp mess\Boot\89333.exe/WISE0019.BIN Infected: not-a-virus:AdWare.Win32.EZula.z skipped
C:\Documents and Settings\Amarjot\My Documents\xp mess\Boot\89333.exe WiseSFX: infected - 3 skipped
C:\Documents and Settings\Amarjot\My Documents\xp mess\Vis STyle\31777.exe/WISE0015.BIN/Sync.exe Infected: not-a-virus:AdWare.Win32.SaveNow.v skipped
C:\Documents and Settings\Amarjot\My Documents\xp mess\Vis STyle\31777.exe/WISE0015.BIN/Uninst.exe Infected: not-a-virus:AdWare.Win32.SaveNow.v skipped
C:\Documents and Settings\Amarjot\My Documents\xp mess\Vis STyle\31777.exe/WISE0015.BIN Infected: not-a-virus:AdWare.Win32.SaveNow.v skipped
C:\Documents and Settings\Amarjot\My Documents\xp mess\Vis STyle\31777.exe/WISE0016.BIN Infected: not-a-virus:AdWare.Win32.Quick.a skipped
C:\Documents and Settings\Amarjot\My Documents\xp mess\Vis STyle\31777.exe/WISE0017.BIN Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
C:\Documents and Settings\Amarjot\My Documents\xp mess\Vis STyle\31777.exe WiseSFX: infected - 5 skipped
C:\Documents and Settings\Amarjot\NAV_EXCEL_tmp\kk20030521.exe/NHInstall.exe Infected: not-a-virus:AdWare.Win32.NavExcel.d skipped
C:\Documents and Settings\Amarjot\NAV_EXCEL_tmp\kk20030521.exe/v2.0.3.cab/NHelper.dll Infected: not-a-virus:AdWare.Win32.NavExcel.d skipped
C:\Documents and Settings\Amarjot\NAV_EXCEL_tmp\kk20030521.exe/v2.0.3.cab/NHUpdater.exe Infected: not-a-virus:AdWare.Win32.NavExcel.b skipped
C:\Documents and Settings\Amarjot\NAV_EXCEL_tmp\kk20030521.exe/v2.0.3.cab/NHUninstaller.exe Infected: not-a-virus:AdWare.Win32.NavExcel skipped
C:\Documents and Settings\Amarjot\NAV_EXCEL_tmp\kk20030521.exe/v2.0.3.cab Infected: not-a-virus:AdWare.Win32.NavExcel skipped
C:\Documents and Settings\Amarjot\NAV_EXCEL_tmp\kk20030521.exe CAB: infected - 5 skipped
C:\Documents and Settings\Bhinder\Application Data\Blackberry Desktop\Transaction Manager\ComponentData\TraceLogs\ODSTRACE.XML Object is locked skipped
C:\Documents and Settings\Bhinder\Application Data\Blackberry Desktop\Transaction Manager\ComponentData\TraceLogs\ODSTRACE_DS3BEFFFFF3BEFFFFF.XML Object is locked skipped
C:\Documents and Settings\Guest\.jpi_cache\jar\1.0\jvmsecman.jar-69ee0e0e-5c3da21f.zip/vlocal.class Infected: Trojan-Downloader.Java.Agent.f skipped
C:\Documents and Settings\Guest\.jpi_cache\jar\1.0\jvmsecman.jar-69ee0e0e-5c3da21f.zip ZIP: infected - 1 skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Sukhprit\Application Data\Mozilla\Firefox\Profiles\lvywmts5.default\cert8.db Object is locked skipped
C:\Documents and Settings\Sukhprit\Application Data\Mozilla\Firefox\Profiles\lvywmts5.default\history.dat Object is locked skipped
C:\Documents and Settings\Sukhprit\Application Data\Mozilla\Firefox\Profiles\lvywmts5.default\key3.db Object is locked skipped
C:\Documents and Settings\Sukhprit\Application Data\Mozilla\Firefox\Profiles\lvywmts5.default\parent.lock Object is locked skipped
C:\Documents and Settings\Sukhprit\Application Data\Mozilla\Firefox\Profiles\lvywmts5.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Sukhprit\Application Data\Mozilla\Firefox\Profiles\lvywmts5.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Sukhprit\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Sukhprit\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Sukhprit\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Sukhprit\Local Settings\Application Data\Mozilla\Firefox\Profiles\lvywmts5.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Sukhprit\Local Settings\Application Data\Mozilla\Firefox\Profiles\lvywmts5.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Sukhprit\Local Settings\Application Data\Mozilla\Firefox\Profiles\lvywmts5.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Sukhprit\Local Settings\Application Data\Mozilla\Firefox\Profiles\lvywmts5.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Sukhprit\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Sukhprit\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Sukhprit\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Sukhprit\NTUSER.dat.LOG Object is locked skipped
C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.614 skipped
C:\QooBox\Quarantine\C\Program Files\Outlook Express\toceh89104.dll.vir Infected: not-a-virus:AdWare.Win32.TTC.d skipped
C:\QooBox\Quarantine\C\Program Files\RABCO\RABCO.dll.vir Infected: not-a-virus:AdWare.Win32.Rabio.h skipped
C:\QooBox\Quarantine\C\Program Files\RABCO\RABCOse.exe.vir Infected: not-a-virus:AdWare.Win32.Rabio.g skipped
C:\QooBox\Quarantine\C\Program Files\RABCO\X_RABCOse.exe.vir Infected: not-a-virus:AdWare.Win32.Rabio.g skipped
C:\QooBox\Quarantine\C\Program Files\SKS~1\wоwexec.exe.vir Infected: not-a-virus:AdWare.Win32.PurityScan.gw skipped
C:\QooBox\Quarantine\C\WINDOWS\NDNuninstall5_64.exe.vir Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\p6\kipon89104.exe.vir/data0002 Infected: not-a-virus:AdWare.Win32.TTC.d skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\p6\kipon89104.exe.vir NSIS: infected - 1 skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\qlink32.dll.vir Infected: not-a-virus:AdWare.Win32.QLF.b skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\tltvbpwz.dll.vir Infected: not-a-virus:AdWare.Win32.PurityScan.gv skipped
C:\QooBox\Quarantine\catchme2008-03-05_223447.53.zip/pmkhf.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\QooBox\Quarantine\catchme2008-03-05_223447.53.zip ZIP: infected - 1 skipped
C:\RECYCLER\S-1-5-21-1715567821-1957994488-1801674531-1004\Dc3\yula4403.exe Infected: not-a-virus:AdWare.Win32.Rabio.g skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{1633BB83-D4F0-494A-A665-C612610C6C80}\RP1176\A0129245.exe Infected: not-a-virus:AdWare.Win32.Rabio.g skipped
C:\System Volume Information\_restore{1633BB83-D4F0-494A-A665-C612610C6C80}\RP1177\A0129266.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\System Volume Information\_restore{1633BB83-D4F0-494A-A665-C612610C6C80}\RP1177\A0129302.exe Infected: not-a-virus:AdWare.Win32.Rabio.g skipped
C:\System Volume Information\_restore{1633BB83-D4F0-494A-A665-C612610C6C80}\RP1178\A0130314.exe Infected: not-a-virus:AdWare.Win32.Rabio.g skipped
C:\System Volume Information\_restore{1633BB83-D4F0-494A-A665-C612610C6C80}\RP1181\A0130468.exe Infected: not-a-virus:AdWare.Win32.Rabio.g skipped
C:\System Volume Information\_restore{1633BB83-D4F0-494A-A665-C612610C6C80}\RP1183\A0130539.exe Infected: not-a-virus:AdWare.Win32.Rabio.g skipped
C:\System Volume Information\_restore{1633BB83-D4F0-494A-A665-C612610C6C80}\RP1184\A0130576.dll Infected: not-a-virus:AdWare.Win32.ZenoSearch.ad skipped
C:\System Volume Information\_restore{1633BB83-D4F0-494A-A665-C612610C6C80}\RP1184\A0130584.exe/WISE0026.BIN/clientax.dll Infected: not-a-virus:AdWare.Win32.180Solutions.ao skipped
C:\System Volume Information\_restore{1633BB83-D4F0-494A-A665-C612610C6C80}\RP1184\A0130584.exe/WISE0026.BIN Infected: not-a-virus:AdWare.Win32.180Solutions.ao skipped
C:\System Volume Information\_restore{1633BB83-D4F0-494A-A665-C612610C6C80}\RP1184\A0130584.exe WiseSFX: infected - 2 skipped
C:\System Volume Information\_restore{1633BB83-D4F0-494A-A665-C612610C6C80}\RP1184\A0130584.exe WiseSFXDropper: infected - 2 skipped
C:\System Volume Information\_restore{1633BB83-D4F0-494A-A665-C612610C6C80}\RP1184\A0130591.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{1633BB83-D4F0-494A-A665-C612610C6C80}\RP1184\A0130592.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{1633BB83-D4F0-494A-A665-C612610C6C80}\RP1184\A0130593.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{1633BB83-D4F0-494A-A665-C612610C6C80}\RP1184\A0130594.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{1633BB83-D4F0-494A-A665-C612610C6C80}\RP1184\A0130595.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.a skipped
C:\System Volume Information\_restore{1633BB83-D4F0-494A-A665-C612610C6C80}\RP1184\A0130596.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{1633BB83-D4F0-494A-A665-C612610C6C80}\RP1184\A0130597.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{1633BB83-D4F0-494A-A665-C612610C6C80}\RP1184\A0130598.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{1633BB83-D4F0-494A-A665-C612610C6C80}\RP1184\A0130599.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{1633BB83-D4F0-494A-A665-C612610C6C80}\RP1184\A0130601.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{1633BB83-D4F0-494A-A665-C612610C6C80}\RP1184\A0130603.exe/data0001 Infected: not-a-virus:AdWare.Win32.PurityScan.gp skipped
C:\System Volume Information\_restore{1633BB83-D4F0-494A-A665-C612610C6C80}\RP1184\A0130603.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{1633BB83-D4F0-494A-A665-C612610C6C80}\RP1184\A0130636.exe Infected: not-a-virus:AdWare.Win32.Rabio.g skipped
C:\System Volume Information\_restore{1633BB83-D4F0-494A-A665-C612610C6C80}\RP1184\A0130658.exe Infected: not-a-virus:AdWare.Win32.Rabio.g skipped
C:\System Volume Information\_restore{1633BB83-D4F0-494A-A665-C612610C6C80}\RP1185\A0130684.exe Infected: not-a-virus:AdWare.Win32.Rabio.g skipped
C:\System Volume Information\_restore{1633BB83-D4F0-494A-A665-C612610C6C80}\RP1185\A0130845.exe Infected: not-a-virus:AdWare.Win32.Rabio.g skipped
C:\System Volume Information\_restore{1633BB83-D4F0-494A-A665-C612610C6C80}\RP1188\A0130923.exe Infected: not-a-virus:AdWare.Win32.Rabio.g skipped
C:\System Volume Information\_restore{1633BB83-D4F0-494A-A665-C612610C6C80}\RP1189\A0130933.dll Infected: not-a-virus:AdWare.Win32.Rabio.h skipped
C:\System Volume Information\_restore{1633BB83-D4F0-494A-A665-C612610C6C80}\RP1189\A0130935.exe Infected: not-a-virus:AdWare.Win32.Rabio.g skipped
C:\System Volume Information\_restore{1633BB83-D4F0-494A-A665-C612610C6C80}\RP1189\A0130937.exe Infected: not-a-virus:AdWare.Win32.Rabio.g skipped
C:\System Volume Information\_restore{1633BB83-D4F0-494A-A665-C612610C6C80}\RP1189\A0130938.exe Infected: not-a-virus:AdWare.Win32.PurityScan.gw skipped
C:\System Volume Information\_restore{1633BB83-D4F0-494A-A665-C612610C6C80}\RP1189\A0130940.dll Infected: not-a-virus:AdWare.Win32.QLF.b skipped
C:\System Volume Information\_restore{1633BB83-D4F0-494A-A665-C612610C6C80}\RP1189\A0130942.dll Infected: not-a-virus:AdWare.Win32.PurityScan.gv skipped
C:\System Volume Information\_restore{1633BB83-D4F0-494A-A665-C612610C6C80}\RP1189\A0130943.dll Infected: not-a-virus:AdWare.Win32.TTC.d skipped
C:\System Volume Information\_restore{1633BB83-D4F0-494A-A665-C612610C6C80}\RP1189\A0130944.exe/data0002 Infected: not-a-virus:AdWare.Win32.TTC.d skipped
C:\System Volume Information\_restore{1633BB83-D4F0-494A-A665-C612610C6C80}\RP1189\A0130944.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{1633BB83-D4F0-494A-A665-C612610C6C80}\RP1191\A0131275.exe Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
C:\System Volume Information\_restore{1633BB83-D4F0-494A-A665-C612610C6C80}\RP1191\change.log Object is locked skipped
C:\unzip\2004babeyear.exe/WISE0014.BIN Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
C:\unzip\2004babeyear.exe WiseSFX: infected - 1 skipped
C:\unzip\BitTorrent.exe Suspicious: not-a-virus:Porn-Dialer.Win32.Star skipped
C:\unzip\BSINSTALL.exe/WISE0024.BIN/data0001.cab/Save.exe Infected: not-a-virus:AdWare.Win32.SaveNow.c skipped
C:\unzip\BSINSTALL.exe/WISE0024.BIN/data0001.cab/SaveUninst.exe Infected: not-a-virus:AdWare.Win32.SaveNow.af skipped
C:\unzip\BSINSTALL.exe/WISE0024.BIN/data0001.cab Infected: not-a-virus:AdWare.Win32.SaveNow.af skipped
C:\unzip\BSINSTALL.exe/WISE0024.BIN/data0002.cab/Weather.exe Infected: not-a-virus:AdWare.Win32.SaveNow.ay skipped
C:\unzip\BSINSTALL.exe/WISE0024.BIN/data0002.cab/Uninst.exe Infected: not-a-virus:AdWare.Win32.SaveNow.f skipped
C:\unzip\BSINSTALL.exe/WISE0024.BIN/data0002.cab Infected: not-a-virus:AdWare.Win32.SaveNow.f skipped
C:\unzip\BSINSTALL.exe/WISE0024.BIN Infected: not-a-virus:AdWare.Win32.SaveNow.f skipped
C:\unzip\BSINSTALL.exe WiseSFX: infected - 7 skipped
C:\unzip\BSINSTALL.exe WiseSFXDropper: infected - 7 skipped
C:\unzip\CliprexLite.exe/data0007 Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
C:\unzip\CliprexLite.exe/data0008 Infected: not-a-virus:AdWare.Win32.MyWay.j skipped
C:\unzip\CliprexLite.exe/data0009 Infected: not-a-virus:AdWare.Win32.EZula.d skipped
C:\unzip\CliprexLite.exe/data0010 Infected: not-a-virus:AdWare.Win32.180Solutions skipped
C:\unzip\CliprexLite.exe NSIS: infected - 4 skipped
C:\unzip\dvdrnb30.exe/data0003/NHInstall.exe Infected: not-a-virus:AdWare.Win32.NavExcel skipped
C:\unzip\dvdrnb30.exe/data0003/v2.0.2.cab/NHUninstaller.exe Infected: not-a-virus:AdWare.Win32.NavExcel skipped
C:\unzip\dvdrnb30.exe/data0003/v2.0.2.cab/NHUpdater.exe Infected: not-a-virus:AdWare.Win32.NavExcel skipped
C:\unzip\dvdrnb30.exe/data0003/v2.0.2.cab/NHelper.dll Infected: not-a-virus:AdWare.Win32.NavExcel skipped
C:\unzip\dvdrnb30.exe/data0003/v2.0.2.cab Infected: not-a-virus:AdWare.Win32.NavExcel skipped
C:\unzip\dvdrnb30.exe/data0003 Infected: not-a-virus:AdWare.Win32.NavExcel skipped
C:\unzip\dvdrnb30.exe Inno: infected - 6 skipped
C:\unzip\extremetease2.exe/WISE0017.BIN Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
C:\unzip\extremetease2.exe/WISE0018.BIN Infected: not-a-virus:AdWare.Win32.EZula.a skipped
C:\unzip\extremetease2.exe/WISE0019.BIN Infected: not-a-virus:AdWare.Win32.Gator.3103 skipped
C:\unzip\extremetease2.exe WiseSFX: infected - 3 skipped
C:\unzip\iMeshV4.exe/WISE0018.BIN Infected: not-a-virus:AdWare.Win32.NewDotNet.d skipped
C:\unzip\iMeshV4.exe/WISE0019.BIN Infected: not-a-virus:AdWare.Win32.Gator.4104 skipped
C:\unzip\iMeshV4.exe/WISE0020.BIN/data0008/lsp_.dll Infected: not-a-virus:AdWare.Win32.Sahat.av skipped
C:\unzip\iMeshV4.exe/WISE0020.BIN/data0008/SAHAgent_.exe Infected: not-a-virus:AdWare.Win32.Sahat.bb skipped
C:\unzip\iMeshV4.exe/WISE0020.BIN/data0008/SAHDownloader_.exe Infected: not-a-virus:AdWare.Win32.Sahat.e skipped
C:\unzip\iMeshV4.exe/WISE0020.BIN/data0008 Infected: not-a-virus:AdWare.Win32.Sahat.e skipped
C:\unzip\iMeshV4.exe/WISE0020.BIN Infected: not-a-virus:AdWare.Win32.Sahat.e skipped
C:\unzip\iMeshV4.exe/WISE0023.BIN Infected: not-a-virus:AdWare.Win32.MyWay.j skipped
C:\unzip\iMeshV4.exe/WISE0024.BIN Infected: not-a-virus:AdWare.Win32.Gator.4104 skipped
C:\unzip\iMeshV4.exe WiseSFX: infected - 9 skipped
C:\unzip\kazaa-download-accelerator-lite.exe/data0006/NHInstall.exe Infected: not-a-virus:AdWare.Win32.NavExcel.d skipped
C:\unzip\kazaa-download-accelerator-lite.exe/data0006/v2.0.2.cab/NHUninstaller.exe Infected: not-a-virus:AdWare.Win32.NavExcel.d skipped
C:\unzip\kazaa-download-accelerator-lite.exe/data0006/v2.0.2.cab/NHelper.dll Infected: not-a-virus:AdWare.Win32.NavExcel.d skipped
C:\unzip\kazaa-download-accelerator-lite.exe/data0006/v2.0.2.cab/NHUpdater.exe Infected: not-a-virus:AdWare.Win32.NavExcel.b skipped
C:\unzip\kazaa-download-accelerator-lite.exe/data0006/v2.0.2.cab Infected: not-a-virus:AdWare.Win32.NavExcel.b skipped
C:\unzip\kazaa-download-accelerator-lite.exe/data0006 Infected: not-a-virus:AdWare.Win32.NavExcel.b skipped
C:\unzip\kazaa-download-accelerator-lite.exe/data0007/data0002 Infected: not-a-virus:AdWare.Win32.BargainBuddy.a skipped
C:\unzip\kazaa-download-accelerator-lite.exe/data0007/data0003 Infected: not-a-virus:AdWare.Win32.BargainBuddy.a skipped
C:\unzip\kazaa-download-accelerator-lite.exe/data0007 Infected: not-a-virus:AdWare.Win32.BargainBuddy.a skipped
C:\unzip\kazaa-download-accelerator-lite.exe/data0008/WISE0011.BIN Infected: not-a-virus:AdWare.Win32.Exact.a skipped
C:\unzip\kazaa-download-accelerator-lite.exe/data0008/WISE0013.BIN Infected: not-a-virus:AdWare.Win32.Exact.a skipped
C:\unzip\kazaa-download-accelerator-lite.exe/data0008 Infected: not-a-virus:AdWare.Win32.Exact.a skipped
C:\unzip\kazaa-download-accelerator-lite.exe/data0009/data0001.cab/Save.exe Infected: not-a-virus:AdWare.Win32.SaveNow.t skipped
C:\unzip\kazaa-download-accelerator-lite.exe/data0009/data0001.cab/SaveUninst.exe Infected: not-a-virus:AdWare.Win32.SaveNow.af skipped
C:\unzip\kazaa-download-accelerator-lite.exe/data0009/data0001.cab Infected: not-a-virus:AdWare.Win32.SaveNow.af skipped
C:\unzip\kazaa-download-accelerator-lite.exe/data0009/data0002.cab/Weather.exe Infected: not-a-virus:AdWare.Win32.SaveNow.ak skipped
C:\unzip\kazaa-download-accelerator-lite.exe/data0009/data0002.cab/Uninst.exe Infected: not-a-virus:AdWare.Win32.SaveNow.f skipped
C:\unzip\kazaa-download-accelerator-lite.exe/data0009/data0002.cab Infected: not-a-virus:AdWare.Win32.SaveNow.f skipped
C:\unzip\kazaa-download-accelerator-lite.exe/data0009/data0003.cab/Sync.exe Infected: not-a-virus:AdWare.Win32.SaveNow.v skipped
C:\unzip\kazaa-download-accelerator-lite.exe/data0009/data0003.cab/Uninst.exe Infected: not-a-virus:AdWare.Win32.SaveNow.v skipped
C:\unzip\kazaa-download-accelerator-lite.exe/data0009/data0003.cab Infected: not-a-virus:AdWare.Win32.SaveNow.v skipped
C:\unzip\kazaa-download-accelerator-lite.exe/data0009 Infected: not-a-virus:AdWare.Win32.SaveNow.v skipped
C:\unzip\kazaa-download-accelerator-lite.exe Inno: infected - 22 skipped
C:\unzip\Matrix3DSetup.exe/WISE0011.BIN Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
C:\unzip\Matrix3DSetup.exe WiseSFX: infected - 1 skipped
C:\unzip\mirc612.exe/data0001.bin Infected: not-a-virus:Client-IRC.Win32.mIRC.612 skipped
C:\unzip\mirc612.exe mIRC: infected - 1 skipped
C:\unzip\mirc614.exe/data0001.bin Infected: not-a-virus:Client-IRC.Win32.mIRC.614 skipped
C:\unzip\mirc614.exe mIRC: infected - 1 skipped
C:\unzip\theidyllicaquarium.exe/WISE0019.BIN Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
C:\unzip\theidyllicaquarium.exe/WISE0020.BIN Infected: not-a-virus:AdWare.Win32.EZula.a skipped
C:\unzip\theidyllicaquarium.exe/WISE0021.BIN Infected: not-a-virus:AdWare.Win32.Gator.3103 skipped
C:\unzip\theidyllicaquarium.exe WiseSFX: infected - 3 skipped
C:\unzip\thesimpsonssetup.exe/WISE0014.BIN Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
C:\unzip\thesimpsonssetup.exe WiseSFX: infected - 1 skipped
C:\unzip\toplesspatio2.exe/WISE0013.BIN Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
C:\unzip\toplesspatio2.exe/WISE0021.BIN Infected: Trojan-Downloader.Win32.Wren.d skipped
C:\unzip\toplesspatio2.exe WiseSFX: infected - 2 skipped
C:\WINDOWS\$NtUninstallKB824141$\user32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB824141$\win32k.sys Object is locked skipped
C:\WINDOWS\$NtUninstallKB828028$\msasn1.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828035$\msgsvc.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828035$\wkssvc.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\catsrv.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\catsrvut.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\clbcatex.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\clbcatq.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\colbact.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\comadmin.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\comrepl.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\comsvcs.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\comuid.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\es.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\migregdb.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\msdtcprx.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\msdtctm.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\msdtcuiu.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\mtxclu.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\mtxoci.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\ole32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\rpcrt4.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\rpcss.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\txflog.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\callcont.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\cmdevtgprov.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\evtgprov.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\gdi32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\h323.tsp Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\h323msp.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\helpctr.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\ipnathlp.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\lsasrv.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\mf3216.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\msasn1.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\msgina.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\mst120.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\netapi32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\nmcom.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\rtcdll.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\schannel.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB837001$\dao360.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB837001$\expsrv.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB837001$\msexch40.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB837001$\msexcl40.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB837001$\msjet40.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB837001$\msjetoledb40.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB837001$\msjint40.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB837001$\msjter40.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB837001$\msjtes40.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB837001$\msltus40.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB837001$\mspbde40.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB837001$\msrd2x40.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB837001$\msrd3x40.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB837001$\msrepl40.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB837001$\mstext40.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB837001$\mswdat10.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB837001$\mswstr10.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB837001$\msxbde40.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB837001$\vbajet32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB839645$\fldrclnr.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB839645$\shell32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB839645$\shlwapi.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB839645$\sxs.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB839645$\xpsp2res.dll Object is locked skipped
C:\WINDOWS\$NtUninstallQ309521$\dxmasf.dll Object is locked skipped
C:\WINDOWS\$NtUninstallQ309521$\httpod51.dll Object is locked skipped
C:\WINDOWS\$NtUninstallQ309521$\lsasrv.dll Object is locked skipped
C:\WINDOWS\$NtUninstallQ309521$\msdxm.ocx Object is locked skipped
C:\WINDOWS\$NtUninstallQ309521$\sfcfiles.dll Object is locked skipped
C:\WINDOWS\$NtUninstallQ309521$\spuninst\spuninst.exe Object is locked skipped
C:\WINDOWS\$NtUninstallQ309521$\spuninst\spuninst.inf Object is locked skipped
C:\WINDOWS\$NtUninstallQ309521$\ssinc51.dll Object is locked skipped
C:\WINDOWS\$NtUninstallQ314862$\qmgr.dll Object is locked skipped
C:\WINDOWS\$NtUninstallQ314862$\spuninst\spuninst.exe Object is locked skipped
C:\WINDOWS\$NtUninstallQ314862$\spuninst\spuninst.inf Object is locked skipped
C:\WINDOWS\$NtUninstallQ315000$\netsetup.exe Object is locked skipped
C:\WINDOWS\$NtUninstallQ315000$\spuninst\spuninst.exe Object is locked skipped
C:\WINDOWS\$NtUninstallQ315000$\spuninst\spuninst.inf Object is locked skipped
C:\WINDOWS\$NtUninstallQ315000$\ssdpapi.dll Object is locked skipped
C:\WINDOWS\$NtUninstallQ315000$\ssdpsrv.dll Object is locked skipped
C:\WINDOWS\$NtUninstallQ315000$\upnp.dll Object is locked skipped
C:\WINDOWS\$NtUninstallQ323172$\reg00003 Object is locked skipped
C:\WINDOWS\$NtUninstallQ323172$\reg00005 Object is locked skipped
C:\WINDOWS\$NtUninstallQ323172$\reg00008 Object is locked skipped
C:\WINDOWS\$NtUninstallQ323172$\reg00009 Object is locked skipped
C:\WINDOWS\$NtUninstallQ323172$\reg00010 Object is locked skipped
C:\WINDOWS\$NtUninstallQ323172$\reg00011 Object is locked skipped
C:\WINDOWS\$NtUninstallQ329048$\reg00001 Object is locked skipped
C:\WINDOWS\$NtUninstallQ329390$\reg00001 Object is locked skipped
C:\WINDOWS\$NtUninstallQ828026$\msdxm.ocx Object is locked skipped
C:\WINDOWS\$NtUninstallQ828026$\wmpcore.dll Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\ajm2ipe0.ini Infected: not-a-virus:AdWare.Win32.Sahat.ao skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\My Downloads\BSINSTALL.exe/WISE0024.BIN/data0001.cab/VVSN.exe Infected: not-a-virus:AdWare.Win32.SaveNow.z skipped
D:\My Downloads\BSINSTALL.exe/WISE0024.BIN/data0001.cab Infected: not-a-virus:AdWare.Win32.SaveNow.z skipped
D:\My Downloads\BSINSTALL.exe/WISE0024.BIN Infected: not-a-virus:AdWare.Win32.SaveNow.z skipped
D:\My Downloads\BSINSTALL.exe WiseSFX: infected - 3 skipped
D:\My Downloads\BSINSTALL.exe WiseSFXDropper: infected - 3 skipped
D:\My Downloads\netpumper-1[1].20.1-setup.exe/data0081/Sync.exe Infected: not-a-virus:AdWare.Win32.SaveNow.v skipped
D:\My Downloads\netpumper-1[1].20.1-setup.exe/data0081/Uninst.exe Infected: not-a-virus:AdWare.Win32.SaveNow.v skipped
D:\My Downloads\netpumper-1[1].20.1-setup.exe/data0081 Infected: not-a-virus:AdWare.Win32.SaveNow.v skipped
D:\My Downloads\netpumper-1[1].20.1-setup.exe Inno: infected - 3 skipped
D:\Not Music\BSINSTALL.exe/WISE0024.BIN/data0001.cab/Save.exe Infected: not-a-virus:AdWare.Win32.SaveNow.c skipped
D:\Not Music\BSINSTALL.exe/WISE0024.BIN/data0001.cab/SaveUninst.exe Infected: not-a-virus:AdWare.Win32.SaveNow.af skipped
D:\Not Music\BSINSTALL.exe/WISE0024.BIN/data0001.cab Infected: not-a-virus:AdWare.Win32.SaveNow.af skipped
D:\Not Music\BSINSTALL.exe/WISE0024.BIN/data0002.cab/Weather.exe Infected: not-a-virus:AdWare.Win32.SaveNow.ay skipped
D:\Not Music\BSINSTALL.exe/WISE0024.BIN/data0002.cab/Uninst.exe Infected: not-a-virus:AdWare.Win32.SaveNow.f skipped
D:\Not Music\BSINSTALL.exe/WISE0024.BIN/data0002.cab Infected: not-a-virus:AdWare.Win32.SaveNow.f skipped
D:\Not Music\BSINSTALL.exe/WISE0024.BIN Infected: not-a-virus:AdWare.Win32.SaveNow.f skipped
D:\Not Music\BSINSTALL.exe WiseSFX: infected - 7 skipped
D:\Not Music\BSINSTALL.exe WiseSFXDropper: infected - 7 skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
D:\System Volume Information\_restore{1633BB83-D4F0-494A-A665-C612610C6C80}\RP1191\change.log Object is locked skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
E:\System Volume Information\_restore{1633BB83-D4F0-494A-A665-C612610C6C80}\RP1191\change.log Object is locked skipped
H:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
H:\System Volume Information\_restore{1633BB83-D4F0-494A-A665-C612610C6C80}\RP1191\change.log Object is locked skipped
I:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
I:\System Volume Information\_restore{1633BB83-D4F0-494A-A665-C612610C6C80}\RP1191\change.log Object is locked skipped
J:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
J:\System Volume Information\_restore{1633BB83-D4F0-494A-A665-C612610C6C80}\RP1191\change.log Object is locked skipped

Scan process completed.




________________________________________________________




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:58:55 PM, on 06/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [cursor] "C:\Program Files\Screendragon VS3\Screendragon VS3 Taskbar.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Openwares LiveUpdate] C:\Program Files\LiveUpdate\LiveUpdate.exe
O4 - HKLM\..\Run: [LogonUIBootRandomizer] "C:\unzip\logonuibootrandomizer\RandomScreens.exe" /RandomizeLogon
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [BenQ] F:\BenQJoybeePlayer.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [EPSON Stylus CX4800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE /P26 "EPSON Stylus CX4800 Series" /O6 "USB001" /M "Stylus CX4800"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [EPSON Stylus CX4800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE /P26 "EPSON Stylus CX4800 Series" /M "Stylus CX4800" /EF "HKCU"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/cha…t/c381/chat.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {2253F320-AB68-4A07-917D-4F12D8884A06} (ChainCast VMR Client Proxy) - http://www.streamaudio.com/download/ccpm_0237.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {4788DE0A-3552-49EA-AC8C-233DA52523B9} (AxLoaderPassword Class) - http://www.blackberry.com/devicesoftware/AxLoader.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-CA/a-UNO1/GAME_UNO1.cab
O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} (WSDownloader Control) - http://www.webshots.com/samplers/WSDownloader.ocx
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…StatsClient.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://sympatico.zone.msn.com/binFramework…ro.cab33902.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_02) -
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe

–
End of file - 10506 bytes
Hi SS78,


Please press Start->Run, copy/paste the following command (it's one long command) into the box and press OK:

regedit /a "%userprofile%\desktop\output.txt" hkey_local_machine\software\microsoft\windows\currentversion\explorer\driveicons

A file called output.txt should appear on your Desktop, please post the contents of this in your next response.

————————————————————————

Please download OTMoveIt2 by OldTimer to your Desktop (right-click the link, select Save Target As…, select your Desktop and press Save)
  • Double-click OTMoveIt2.exe to start the program.
  • Copy the lines in the OTMoveIt file list below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
    OTMoveIt Standard List:
    C:\Documents and Settings\Amarjot\.jpi_cache\file\1.0\SecurityClassLoader.class-2c965182-4562ddc2.class
    C:\Documents and Settings\Amarjot\Desktop\VVSNI_LOFS120501Inst.exe
    C:\Documents and Settings\Amarjot\My Documents\torrents\crack_13559248413176.zip
    C:\Documents and Settings\Amarjot\My Documents\torrents\crack_13567248413176.zip
    C:\Documents and Settings\Amarjot\My Documents\torrents\Zealot SWF2Video Studio v1.0\Install_1207.exe
    C:\Documents and Settings\Amarjot\My Documents\xp mess\Boot\89333.exe
    C:\Documents and Settings\Amarjot\My Documents\xp mess\Vis STyle\31777.exe
    C:\Documents and Settings\Amarjot\NAV_EXCEL_tmp\kk20030521.exe
    C:\Documents and Settings\Guest\.jpi_cache\jar\1.0\jvmsecman.jar-69ee0e0e-5c3da21f.zip
    C:\unzip\2004babeyear.exe
    C:\unzip\BitTorrent.exe
    C:\unzip\BSINSTALL.exe
    C:\unzip\CliprexLite.exe
    C:\unzip\dvdrnb30.exe
    C:\unzip\extremetease2.exe
    C:\unzip\iMeshV4.exe
    C:\unzip\kazaa-download-accelerator-lite.exe
    C:\unzip\Matrix3DSetup.exe
    C:\unzip\theidyllicaquarium.exe
    C:\unzip\thesimpsonssetup.exe
    C:\unzip\toplesspatio2.exe
    C:\WINDOWS\system32\ajm2ipe0.ini
    D:\My Downloads\BSINSTALL.exe
    D:\My Downloads\netpumper-1[1].20.1-setup.exe
    D:\Not Music\BSINSTALL.exe
  • Return to OTMoveIt2, right click in the "Paste Standard List of Files/Folders to Move" window (under the light blue bar) and choose Paste.
  • Then click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt2
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

————————————————————————

Then click Start->Run and type cleanmgr in the box and press OK
Ensure the boxes for Recycle Bin, Temporary Files and Temporary Internet Files are checked, you can choose to check other boxes if you wish but they are not required.
Press OK and Yes to confirm

————————————————————————

Clean with MalwareBytes' Anti-Malware
  • Please download the Installer to your Desktop from here:
    http://www.besttechie.net/tools/mbam-setup.exe
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to both of these options:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform Quick Scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure everything is checked, and click Remove Selected.
  • When finished, a log will open in Notepad. Please save it to your Desktop, and post the contents in your reply.
  • The log can also be found here if you need it:
    • Start->All Programs->Malwarebytes' Anti-Malware->Logs

————————————————————————

Once complete, please post the contents of output.txt, the OTMoveIt report, the MalwareBytes Anti-Malware report and a new HijackThis log.
Hi again,

Below are the requested logs. Thanks.

____________________________________________________

Output.txt

REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\driveicons]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\driveicons\c]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\driveicons\c\DefaultIcon]
@="%SystemRoot%\\system32\\shell32.dll,131"


______________________________________________________________________

OTMoveIt


C:\Documents and Settings\Amarjot\.jpi_cache\file\1.0\SecurityClassLoader.class-2c965182-4562ddc2.class moved successfully.
C:\Documents and Settings\Amarjot\Desktop\VVSNI_LOFS120501Inst.exe moved successfully.
C:\Documents and Settings\Amarjot\My Documents\torrents\crack_13559248413176.zip moved successfully.
C:\Documents and Settings\Amarjot\My Documents\torrents\crack_13567248413176.zip moved successfully.
C:\Documents and Settings\Amarjot\My Documents\torrents\Zealot SWF2Video Studio v1.0\Install_1207.exe moved successfully.
C:\Documents and Settings\Amarjot\My Documents\xp mess\Boot\89333.exe moved successfully.
C:\Documents and Settings\Amarjot\My Documents\xp mess\Vis STyle\31777.exe moved successfully.
C:\Documents and Settings\Amarjot\NAV_EXCEL_tmp\kk20030521.exe moved successfully.
C:\Documents and Settings\Guest\.jpi_cache\jar\1.0\jvmsecman.jar-69ee0e0e-5c3da21f.zip moved successfully.
C:\unzip\2004babeyear.exe moved successfully.
C:\unzip\BitTorrent.exe moved successfully.
C:\unzip\BSINSTALL.exe moved successfully.
C:\unzip\CliprexLite.exe moved successfully.
C:\unzip\dvdrnb30.exe moved successfully.
C:\unzip\extremetease2.exe moved successfully.
C:\unzip\iMeshV4.exe moved successfully.
C:\unzip\kazaa-download-accelerator-lite.exe moved successfully.
C:\unzip\Matrix3DSetup.exe moved successfully.
C:\unzip\theidyllicaquarium.exe moved successfully.
C:\unzip\thesimpsonssetup.exe moved successfully.
C:\unzip\toplesspatio2.exe moved successfully.
C:\WINDOWS\system32\ajm2ipe0.ini moved successfully.
D:\My Downloads\BSINSTALL.exe moved successfully.
D:\My Downloads\netpumper-1[1].20.1-setup.exe moved successfully.
D:\Not Music\BSINSTALL.exe moved successfully.

OTMoveIt2 v1.0.20 log created on 03072008_230903


______________________________________________________________


Malwarebytes' Anti-Malware 1.07
Database version: 468

Scan type: Quick Scan
Objects scanned: 32294
Time elapsed: 6 minute(s), 9 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 6
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{d714a94f-123a-45cc-8f03-040bcaf82ad6} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\xpre (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\RABCO (Adware.RABCO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\RABCO (Adware.RABCO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\RABCO (Adware.RABCO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\Guest\Desktop\Help and Support Center.lnk (Rogue.Link) -> Quarantined and deleted successfully.


____________________________________________________________


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:30:32 PM, on 07/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE
C:\WINDOWS\system32\RAMASST.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Sukhprit\Desktop\OTMoveIt2.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [cursor] "C:\Program Files\Screendragon VS3\Screendragon VS3 Taskbar.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Openwares LiveUpdate] C:\Program Files\LiveUpdate\LiveUpdate.exe
O4 - HKLM\..\Run: [LogonUIBootRandomizer] "C:\unzip\logonuibootrandomizer\RandomScreens.exe" /RandomizeLogon
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [BenQ] F:\BenQJoybeePlayer.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [EPSON Stylus CX4800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE /P26 "EPSON Stylus CX4800 Series" /O6 "USB001" /M "Stylus CX4800"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [EPSON Stylus CX4800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE /P26 "EPSON Stylus CX4800 Series" /M "Stylus CX4800" /EF "HKCU"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/cha…t/c381/chat.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {2253F320-AB68-4A07-917D-4F12D8884A06} (ChainCast VMR Client Proxy) - http://www.streamaudio.com/download/ccpm_0237.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {4788DE0A-3552-49EA-AC8C-233DA52523B9} (AxLoaderPassword Class) - http://www.blackberry.com/devicesoftware/AxLoader.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-CA/a-UNO1/GAME_UNO1.cab
O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} (WSDownloader Control) - http://www.webshots.com/samplers/WSDownloader.ocx
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…StatsClient.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://sympatico.zone.msn.com/binFramework…ro.cab33902.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_02) -
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe

–
End of file - 10548 bytes
Hi SS78,

Ok that looks good, now let's fix the C: drive icon:

Backup Your Registry with ERUNT:
  • Download erunt.zip to your Desktop from here:
    http://aumha.org/downloads/erunt.zip
  • Right-click erunt.zip, select Extract All… and follow the prompts to extract ERUNT to a new folder on your Desktop
  • Inside the new folder, double-click ERUNT.exe to start the program
  • OK all the prompts to back up your registry to the default location.
Note: to restore your registry, go to the backup folder and start ERDNT.exe

Then, open Notepad (press Start->Run, enter notepad and press OK)
Copy everything inside the code box below (Starting with REGEDIT4) and paste it into a new notepad file.

Note: Please copy and paste all the text at once, and check that there is NO blank line above REGEDIT4 and one blank line at the bottom.
REGEDIT4

[-HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\driveicons]
Change the Save As Type to All Files and save it as fix.reg to your Desktop.
Locate fix.reg on your Desktop, if you did it right it should look like this:[external image: Posted Image]
Double-click it, when it asks if you want to merge with the registry, click Yes.
You can then delete fix.reg

Now reboot your computer

Once complete, please tell me if the icon problem has been resolved and how your computer is running.
Hey Silver, I ran into a problem when double clicking the fix.reg icon (which did appear as expected). I get a pop up box that states C:\Documents and Settings\Sukhprit\desktop\fix.reg is not a valid Win32 application. Please advise, Thanks
Hi SS78,

OK we'll use a different method:

Please make sure you have backed up the registry with ERUNT before doing this

Press Start->Run, copy/paste the following command (it's one long command) into the box and press OK:

reg delete hklm\software\microsoft\windows\currentversion\explorer\driveicons /f


Then, reboot your computer

Once complete, please tell me if the icon problem has been resolved and how your computer is running.
Hey Silver, That worked! My system seems to be running well at this point. That last AVG virus scan from this morning came up clean and there are no more random icons showing up on the desktop or other weird things happening. Everything appears to be good. So are we done? If so, can I do away with some of the apps and logs that we generated to this point. Thank you again for your help with this. It is very appreciated. -SS78
Hi SS78,

Yes we're almost finished, here are some important final steps:

Clean up with ComboFix:
  • Make sure ComboFix.exe is on your Desktop
  • Next press Start->Run, copy/paste the following command into the box and press OK:

    "%userprofile%\desktop\combofix.exe" /u

  • You should be informed that "ComboFix is uninstalled", press OK to close the window

Please also delete OTMoveIt.exe from your Desktop, along with this folder:

C:\_OTMoveIt


You can remove MalwareBytes Anti-Malware via Add/Remove Programs if you wish, however I recommend you keep it and scan with it regularly as it's an excellent program (and free!).

These instructions are very important so if you have any difficulties with them please let me know.
————————————————————————

If all the above went well, I think your machine is clean of malware :) here are some tips to help you keep it that way:

Operating system vulnerabilities can easily be exploited by malware so please ensure your operating system is automatically kept up to date by using Windows Update:
Go to Start->Control Panel->Automatic Updates
Select Automatic and select a suitable schedule
Also, check that your antivirus and antispyware programs are set to automatically update daily.

You should consider installing a Personal Firewall program. Even if you are behind a NAT router, I recommend you use firewall software as it will improve the security of your computer by monitoring and controlling outbound connections to the internet as well as inbound. There are various free packages available, one I can recommend is Comodo:
http://www.personalfirewall.comodo.com/
A tutorial on firewalls to help you get started:
http://www.bleepingcomputer.com/tutorials/tutorial60.html

I recommend you install a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.
For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.
Also: subscribe to the mailing list to get update notifications.

Please take care when downloading programs. One of the easiest ways to be infected is to download freeware/shareware programs which come laden with malware - this includes allowing websites to install browser plug-ins or ActiveX controls. Before downloading, it is crucial to check whether the source is reputable.
One way to check is to use McAfee SiteAdvisor. Copy the domain name into the space provided and SiteAdvisor will give you a report on the website which can help you decide if it is safe. They also have a toolbar for IE and Firefox which adds this functionality to your browser.

Download and install the free version of WinPatrol. This program protects your computer in a variety of ways and will work well with your existing security software. Have a look at this tutorial to help you get started with the program.

Find out more about how to prevent infection in the future
http://forum.malwareremoval.com/viewtopic.php?p=33687

Please post back to let me know that you have read this, and if there are any further issues.
Hi Silver, I read the last response and have taken the measures you suggested. Everything appears to be running smoothly at this point. Thank you for all your help. Cheers, SS78

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI