Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Red & Black smartsecurity desktop can't change


  • Please log in to reply

#1
dunc11

dunc11

    New Member

  • Member
  • Pip
  • 3 posts
Running windows xp, Ran ad aware, spybot s&d, virus defs are up to date, I removed all spyware and a fix for the desktop, but once I shutdown and restart, the desktop changes again and I can not reset it. Please help. Here is Hijack Log:

Logfile of HijackThis v1.99.1
Scan saved at 9:26:06 AM, on 3/31/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\hkcmd.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\PROGRA~1\COMMON~1\AOL\110893~1\EE\AOLHOS~1.EXE
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\WINDOWS\system32\AOLOpt.exe
C:\WINDOWS\BCMSMMSG.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\PROGRA~1\COMMON~1\AOL\110893~1\EE\AOLServiceHost.exe
C:\WINDOWS\Til.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\AOL Computer Check-Up\ACCAgnt.exe
C:\hjt\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1108932405\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [AOL Messenger Optimized] AOLOpt.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [Media Access] C:\Program Files\Media Access\MediaAccK.exe
O4 - HKLM\..\Run: [Tte] C:\WINDOWS\Til.exe
O4 - HKLM\..\Run: [Ilu] C:\WINDOWS\system32\Lgq.exe
O4 - HKLM\..\Run: [Ajp] C:\WINDOWS\system32\Lnm.exe
O4 - HKLM\..\Run: [Sge] C:\WINDOWS\Eug.exe
O4 - HKLM\..\Run: [Meg] C:\WINDOWS\Mle.exe
O4 - HKLM\..\Run: [Fkk] C:\WINDOWS\system32\Fek.exe
O4 - HKLM\..\Run: [Igi] C:\WINDOWS\Mqr.exe
O4 - HKLM\..\Run: [Nts] C:\WINDOWS\Cpt.exe
O4 - HKLM\..\Run: [Nng] C:\WINDOWS\Qoe.exe
O4 - HKLM\..\Run: [Tml] C:\WINDOWS\Dbh.exe
O4 - HKLM\..\RunServices: [AOL Messenger Optimized] AOLOpt.exe
O4 - HKCU\..\Run: [AOLCC] "C:\Program Files\AOL Computer Check-Up\ACCAgnt.exe" /startup
O4 - HKCU\..\Run: [Nng] C:\WINDOWS\Qoe.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Tml] C:\WINDOWS\Dbh.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcaf...84/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcaf...,21/mcgdmgr.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
  • 0

Advertisements


#2
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
Quite the Bit of Nasties you have in there!!!

Lets use this Link to get Started!

Inside the Link is a Set of Instruction and a Link to Download Kasperskys Free Trial AV!

This is the Best way I know to begin to deal with the Infection you have!

Make sure that before you begin the Install,everything Mcafee is Disabled!

Locate the Tray Icons in the Taskbar,Right Click and select Disable!

Now Open the Task Manager(Right Click the Taskbar,near the Clock and select Task Manager)
Once Task Manager is Open,Select Processes,Click on Image Name,Now Locate every process labeled Mcafee, Right Click and Select End Process!
Some Processes may not end,Thats OK!

Once all Processes are Ended,continue to Install Kaspersky!

Follow the Instructions on How to Install,Configure and Update!

Restart in Safe Mode and end all Instances of Explorer just as Explained,it gets a bit weird,but I tried it myself and feel Comfortable telling you to do this!!!

Now this Process takes a long while to complete,so please take your time and be thorough!!

Once the Scan is Complete,I want you to Restart and Scan with Kaspersky once again,post those results with along with a fresh HijackThis log!
  • 0

#3
dunc11

dunc11

    New Member

  • Topic Starter
  • Member
  • Pip
  • 3 posts
I completed all steps, but when I booted in normal mode, I could not access anything on the desktop. It is frozen. Here is the Hijackthis log file
Logfile of HijackThis v1.99.1
Scan saved at 1:09:08 PM, on 4/1/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
C:\Documents and Settings\Administrator\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1108932405\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [AOL Messenger Optimized] AOLOpt.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [Media Access] C:\Program Files\Media Access\MediaAccK.exe
O4 - HKLM\..\Run: [McRegWiz] C:\PROGRA~1\mcafee.com\agent\mcregwiz.exe /autorun
O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize
O4 - HKLM\..\Run: [Bjf] C:\WINDOWS\system32\Rvg.exe
O4 - HKLM\..\RunServices: [AOL Messenger Optimized] AOLOpt.exe
O4 - HKCU\..\Run: [AOLCC] "C:\Program Files\AOL Computer Check-Up\ACCAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcaf...84/mcinsctl.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcaf...,21/mcgdmgr.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe
O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe

...And the log file of kaspersky
Statistics:
Task start time: 4/1/2005 1:02:20 PM
Task completion time: 4/1/2005 1:07:04 PM
Objects scanned: 42295
Viruses detected: 0
Viruses disinfected: 0
Objects deleted: 0
Objects quarantined: 0

Settings:
Objects to be scanned:
My Computer
If an infected object is found:
Perform recommended action
Scan level:
Recommended
Objects to be excluded from the scan scope:
Option not used

Report:
C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\News\valert.ui\CmnIds.vbs password protected, has not been processed 4/1/2005 1:03:22 PM
C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\News\valert.ui\images/arrow_right.gif password protected, has not been processed 4/1/2005 1:03:22 PM
C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\News\valert.ui\images/btn_signup_52x20.gif password protected, has not been processed 4/1/2005 1:03:22 PM
C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\News\valert.ui\images/more_info.gif password protected, has not been processed 4/1/2005 1:03:22 PM
C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\News\valert.ui\images/sidetable_bottom.gif password protected, has not been processed 4/1/2005 1:03:22 PM
C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\News\valert.ui\images/sidetable_bottom_red.gif password protected, has not been processed 4/1/2005 1:03:22 PM
C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\News\valert.ui\images/sidetable_top.gif password protected, has not been processed 4/1/2005 1:03:22 PM
C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\News\valert.ui\images/sidetable_top_red.gif password protected, has not been processed 4/1/2005 1:03:22 PM
C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\News\valert.ui\images/transpix.gif password protected, has not been processed 4/1/2005 1:03:22 PM
C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\News\valert.ui\images/watermark_mys_150x130.gif password protected, has not been processed 4/1/2005 1:03:22 PM
C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\News\valert.ui\oemcfg.vbs password protected, has not been processed 4/1/2005 1:03:22 PM
C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\News\valert.ui\OEMIds.vbs password protected, has not been processed 4/1/2005 1:03:22 PM
C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\News\valert.ui\valert.htm password protected, has not been processed 4/1/2005 1:03:22 PM
C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\News\valert.ui\valert_old.htm password protected, has not been processed 4/1/2005 1:03:22 PM
C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\News\valert.ui\hs~valert.htm password protected, has not been processed 4/1/2005 1:03:22 PM
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BrowserToolbar.zip\sbRecovery.reg password protected, has not been processed 4/1/2005 1:03:22 PM
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BrowserToolbar.zip\sbRecovery.ini password protected, has not been processed 4/1/2005 1:03:22 PM
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BrowserToolbar1.zip\Bvt.exe password protected, has not been processed 4/1/2005 1:03:22 PM
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\BrowserToolbar1.zip\sbRecovery.ini password protected, has not been processed 4/1/2005 1:03:22 PM
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit.zip\sbRecovery.reg password protected, has not been processed 4/1/2005 1:03:22 PM
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit.zip\sbRecovery.ini password protected, has not been processed 4/1/2005 1:03:22 PM
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit1.zip\sbRecovery.reg password protected, has not been processed 4/1/2005 1:03:23 PM
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit1.zip\sbRecovery.ini password protected, has not been processed 4/1/2005 1:03:23 PM
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit2.zip\sbRecovery.reg password protected, has not been processed 4/1/2005 1:03:23 PM
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit2.zip\sbRecovery.ini password protected, has not been processed 4/1/2005 1:03:23 PM
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit3.zip\sbRecovery.reg password protected, has not been processed 4/1/2005 1:03:23 PM
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit3.zip\sbRecovery.ini password protected, has not been processed 4/1/2005 1:03:23 PM
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit4.zip\sbRecovery.reg password protected, has not been processed 4/1/2005 1:03:23 PM
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit4.zip\sbRecovery.ini password protected, has not been processed 4/1/2005 1:03:23 PM
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit5.zip\sbRecovery.reg password protected, has not been processed 4/1/2005 1:03:23 PM
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit5.zip\sbRecovery.ini password protected, has not been processed 4/1/2005 1:03:23 PM
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit6.zip\sbRecovery.reg password protected, has not been processed 4/1/2005 1:03:23 PM
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit6.zip\sbRecovery.ini password protected, has not been processed 4/1/2005 1:03:23 PM
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit7.zip\sbRecovery.reg password protected, has not been processed 4/1/2005 1:03:23 PM
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit7.zip\sbRecovery.ini password protected, has not been processed 4/1/2005 1:03:23 PM
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit8.zip\sbRecovery.reg password protected, has not been processed 4/1/2005 1:03:23 PM
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit8.zip\sbRecovery.ini password protected, has not been processed 4/1/2005 1:03:23 PM
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit9.zip\sbRecovery.reg password protected, has not been processed 4/1/2005 1:03:23 PM
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit9.zip\sbRecovery.ini password protected, has not been processed 4/1/2005 1:03:23 PM
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HaxdoorH.zip\i.a3d password protected, has not been processed 4/1/2005 1:03:23 PM
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HaxdoorH.zip\sbRecovery.ini password protected, has not been processed 4/1/2005 1:03:23 PM
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HaxdoorH1.zip\sbRecovery.reg password protected, has not been processed 4/1/2005 1:03:23 PM
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HaxdoorH1.zip\sbRecovery.ini password protected, has not been processed 4/1/2005 1:03:23 PM
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HaxdoorH2.zip\sbRecovery.reg password protected, has not been processed 4/1/2005 1:03:23 PM
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HaxdoorH2.zip\sbRecovery.ini password protected, has not been processed 4/1/2005 1:03:23 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\agentins.ui\agentins.ini password protected, has not been processed 4/1/2005 1:03:38 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\agentins.ui\agntcons.vbs password protected, has not been processed 4/1/2005 1:03:38 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\agentins.ui\agntinst.htm password protected, has not been processed 4/1/2005 1:03:38 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\agentins.ui\agntinst.vbs password protected, has not been processed 4/1/2005 1:03:38 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\agentins.ui\agntlang.vbs password protected, has not been processed 4/1/2005 1:03:38 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\agentins.ui\default.htm password protected, has not been processed 4/1/2005 1:03:38 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\agentins.ui\header.vbs password protected, has not been processed 4/1/2005 1:03:38 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\agentins.ui\HtmlUtil.vbs password protected, has not been processed 4/1/2005 1:03:38 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\agentins.ui\images/bg_left_1x314.gif password protected, has not been processed 4/1/2005 1:03:38 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\agentins.ui\images/icon_info_16x16.gif password protected, has not been processed 4/1/2005 1:03:38 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\agentins.ui\images/icon_mcafee_61x61.gif password protected, has not been processed 4/1/2005 1:03:38 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\agentins.ui\images/icon_progress_checked_13x13.gif password protected, has not been processed 4/1/2005 1:03:38 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\agentins.ui\images/icon_progress_hot_13x13.gif password protected, has not been processed 4/1/2005 1:03:38 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\agentins.ui\images/icon_progress_unchecked_13x13.gif password protected, has not been processed 4/1/2005 1:03:38 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\agentins.ui\images/vssver.scc password protected, has not been processed 4/1/2005 1:03:38 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\agentins.ui\InstUtil.vbs password protected, has not been processed 4/1/2005 1:03:38 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\agentins.ui\instwiz.css password protected, has not been processed 4/1/2005 1:03:38 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\agentins.ui\instxp.css password protected, has not been processed 4/1/2005 1:03:38 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\agentins.ui\mcccom.lpk password protected, has not been processed 4/1/2005 1:03:38 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\agentins.ui\pbar.vbs password protected, has not been processed 4/1/2005 1:03:38 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\agentins.ui\setcss.vbs password protected, has not been processed 4/1/2005 1:03:38 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\agentins.ui\vssver.scc password protected, has not been processed 4/1/2005 1:03:38 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\mpfins.ui\appcons.vbs password protected, has not been processed 4/1/2005 1:03:38 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\mpfins.ui\appinst.htm password protected, has not been processed 4/1/2005 1:03:38 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\mpfins.ui\appinst.vbs password protected, has not been processed 4/1/2005 1:03:38 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\mpfins.ui\applang.vbs password protected, has not been processed 4/1/2005 1:03:38 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\mpfins.ui\default.htm password protected, has not been processed 4/1/2005 1:03:38 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\mpfins.ui\header.vbs password protected, has not been processed 4/1/2005 1:03:38 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\mpfins.ui\images/bg_left_1x314.gif password protected, has not been processed 4/1/2005 1:03:38 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\mpfins.ui\images/icon_info_16x16.gif password protected, has not been processed 4/1/2005 1:03:38 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\mpfins.ui\images/icon_mcafee_61x61.gif password protected, has not been processed 4/1/2005 1:03:38 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\mpfins.ui\images/icon_progress_checked_13x13.gif password protected, has not been processed 4/1/2005 1:03:38 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\mpfins.ui\images/icon_progress_hot_13x13.gif password protected, has not been processed 4/1/2005 1:03:38 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\mpfins.ui\images/icon_progress_unchecked_13x13.gif password protected, has not been processed 4/1/2005 1:03:38 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\mpfins.ui\instwiz.css password protected, has not been processed 4/1/2005 1:03:38 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\mpfins.ui\instxp.css password protected, has not been processed 4/1/2005 1:03:38 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\mpfins.ui\mcccom.lpk password protected, has not been processed 4/1/2005 1:03:38 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\mpfins.ui\mpfins.ini password protected, has not been processed 4/1/2005 1:03:38 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\mpfins.ui\pbar.vbs password protected, has not been processed 4/1/2005 1:03:38 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\mpfins.ui\setcss.vbs password protected, has not been processed 4/1/2005 1:03:38 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\shared\agentcfg.cab\screm.ui\agntcons.vbs password protected, has not been processed 4/1/2005 1:03:39 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\shared\agentcfg.cab\screm.ui\agntlang.vbs password protected, has not been processed 4/1/2005 1:03:39 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\shared\agentcfg.cab\screm.ui\comctl.lpk password protected, has not been processed 4/1/2005 1:03:39 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\shared\agentcfg.cab\screm.ui\config.ini password protected, has not been processed 4/1/2005 1:03:39 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\shared\agentcfg.cab\screm.ui\UnInsStr.vbs password protected, has not been processed 4/1/2005 1:03:39 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\shared\agentcfg.cab\screm.ui\uninstall.htm password protected, has not been processed 4/1/2005 1:03:39 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\shared\agentcfg.cab\screm.ui\vssver.scc password protected, has not been processed 4/1/2005 1:03:39 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\shared\agentcfg.cab\screm.ui\pbar.vbs password protected, has not been processed 4/1/2005 1:03:39 PM
C:\Documents and Settings\Owner\Local Settings\Temp\mpf90daysdell.tmp\shared\agentcfg.cab\screm.ui\uninst.vbs password protected, has not been processed 4/1/2005 1:03:39 PM
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\arrow1.bmp password protected, has not been processed 4/1/2005 1:05:30 PM
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\arrow2.bmp password protected, has not been processed 4/1/2005 1:05:30 PM
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bck1.bmp password protected, has not been processed 4/1/2005 1:05:30 PM
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bck2.bmp password protected, has not been processed 4/1/2005 1:05:30 PM
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt11.bmp password protected, has not been processed 4/1/2005 1:05:30 PM
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt12.bmp password protected, has not been processed 4/1/2005 1:05:30 PM
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt13.bmp password protected, has not been processed 4/1/2005 1:05:30 PM
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt21.bmp password protected, has not been processed 4/1/2005 1:05:30 PM
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt22.bmp password protected, has not been processed 4/1/2005 1:05:30 PM
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt23.bmp password protected, has not been processed 4/1/2005 1:05:30 PM
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt31.bmp password protected, has not been processed 4/1/2005 1:05:30 PM
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt32.bmp password protected, has not been processed 4/1/2005 1:05:30 PM
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt33.bmp password protected, has not been processed 4/1/2005 1:05:30 PM
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt41.bmp password protected, has not been processed 4/1/2005 1:05:30 PM
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt42.bmp password protected, has not been processed 4/1/2005 1:05:30 PM
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt43.bmp password protected, has not been processed 4/1/2005 1:05:30 PM
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt51.bmp password protected, has not been processed 4/1/2005 1:05:30 PM
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt52.bmp password protected, has not been processed 4/1/2005 1:05:30 PM
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt53.bmp password protected, has not been processed 4/1/2005 1:05:30 PM
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt61.bmp password protected, has not been processed 4/1/2005 1:05:30 PM
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt62.bmp password protected, has not been processed 4/1/2005 1:05:30 PM
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\checkbox1.bmp password protected, has not been processed 4/1/2005 1:05:30 PM
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\checkbox2.bmp password protected, has not been processed 4/1/2005 1:05:30 PM
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\checkbox3.bmp password protected, has not been processed 4/1/2005 1:05:30 PM
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\checkbox4.bmp password protected, has not been processed 4/1/2005 1:05:30 PM
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\default.skn password protected, has not been processed 4/1/2005 1:05:30 PM
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\defbtn1.bmp password protected, has not been processed 4/1/2005 1:05:30 PM
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\defbtn2.bmp password protected, has not been processed 4/1/2005 1:05:30 PM
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\defbtn3.bmp password protected, has not been processed 4/1/2005 1:05:30 PM
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\glyph1.bmp password protected, has not been processed 4/1/2005 1:05:30 PM
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\glyph2.bmp password protected, has not been processed 4/1/2005 1:05:30 PM
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\glyph3.bmp password protected, has not been processed 4/1/2005 1:05:30 PM
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\glyph4.bmp password protected, has not been processed 4/1/2005 1:05:30 PM
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\glyph5.bmp password protected, has not been processed 4/1/2005 1:05:30 PM
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\glyph6.bmp password protected, has not been processed 4/1/2005 1:05:30 PM
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\glyph7.bmp password protected, has not been processed 4/1/2005 1:05:30 PM
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\main.bmp password protected, has not been processed 4/1/2005 1:05:30 PM
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\preview.bmp password protected, has not been processed 4/1/2005 1:05:30 PM
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\sprite1.bmp password protected, has not been processed 4/1/2005 1:05:30 PM
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\tab1.bmp password protected, has not been processed 4/1/2005 1:05:30 PM
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\tab2.bmp password protected, has not been processed 4/1/2005 1:05:30 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0006.BIN\agentins.ini password protected, has not been processed 4/1/2005 1:05:31 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0006.BIN\agntcons.vbs password protected, has not been processed 4/1/2005 1:05:31 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0006.BIN\agntinst.htm password protected, has not been processed 4/1/2005 1:05:31 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0006.BIN\agntinst.vbs password protected, has not been processed 4/1/2005 1:05:31 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0006.BIN\agntlang.vbs password protected, has not been processed 4/1/2005 1:05:31 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0006.BIN\default.htm password protected, has not been processed 4/1/2005 1:05:31 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0006.BIN\header.vbs password protected, has not been processed 4/1/2005 1:05:31 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0006.BIN\HtmlUtil.vbs password protected, has not been processed 4/1/2005 1:05:31 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0006.BIN\images/bg_left_1x314.gif password protected, has not been processed 4/1/2005 1:05:31 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0006.BIN\images/icon_info_16x16.gif password protected, has not been processed 4/1/2005 1:05:31 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0006.BIN\images/icon_mcafee_61x61.gif password protected, has not been processed 4/1/2005 1:05:31 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0006.BIN\images/icon_progress_checked_13x13.gif password protected, has not been processed 4/1/2005 1:05:31 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0006.BIN\images/icon_progress_hot_13x13.gif password protected, has not been processed 4/1/2005 1:05:31 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0006.BIN\images/icon_progress_unchecked_13x13.gif password protected, has not been processed 4/1/2005 1:05:31 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0006.BIN\images/vssver.scc password protected, has not been processed 4/1/2005 1:05:31 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0006.BIN\InstUtil.vbs password protected, has not been processed 4/1/2005 1:05:31 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0006.BIN\instwiz.css password protected, has not been processed 4/1/2005 1:05:31 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0006.BIN\instxp.css password protected, has not been processed 4/1/2005 1:05:31 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0006.BIN\mcccom.lpk password protected, has not been processed 4/1/2005 1:05:31 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0006.BIN\pbar.vbs password protected, has not been processed 4/1/2005 1:05:31 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0006.BIN\setcss.vbs password protected, has not been processed 4/1/2005 1:05:31 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0006.BIN\vssver.scc password protected, has not been processed 4/1/2005 1:05:31 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0015.BIN\appcons.vbs password protected, has not been processed 4/1/2005 1:05:31 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0015.BIN\appinst.htm password protected, has not been processed 4/1/2005 1:05:31 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0015.BIN\appinst.vbs password protected, has not been processed 4/1/2005 1:05:31 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0015.BIN\applang.vbs password protected, has not been processed 4/1/2005 1:05:31 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0015.BIN\default.htm password protected, has not been processed 4/1/2005 1:05:31 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0015.BIN\header.vbs password protected, has not been processed 4/1/2005 1:05:31 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0015.BIN\images/bg_left_1x314.gif password protected, has not been processed 4/1/2005 1:05:31 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0015.BIN\images/icon_info_16x16.gif password protected, has not been processed 4/1/2005 1:05:31 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0015.BIN\images/icon_mcafee_61x61.gif password protected, has not been processed 4/1/2005 1:05:31 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0015.BIN\images/icon_progress_checked_13x13.gif password protected, has not been processed 4/1/2005 1:05:31 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0015.BIN\images/icon_progress_hot_13x13.gif password protected, has not been processed 4/1/2005 1:05:31 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0015.BIN\images/icon_progress_unchecked_13x13.gif password protected, has not been processed 4/1/2005 1:05:31 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0015.BIN\instwiz.css password protected, has not been processed 4/1/2005 1:05:31 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0015.BIN\instxp.css password protected, has not been processed 4/1/2005 1:05:31 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0015.BIN\mcccom.lpk password protected, has not been processed 4/1/2005 1:05:31 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0015.BIN\mpfins.ini password protected, has not been processed 4/1/2005 1:05:31 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0015.BIN\pbar.vbs password protected, has not been processed 4/1/2005 1:05:31 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0015.BIN\setcss.vbs password protected, has not been processed 4/1/2005 1:05:31 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0020.BIN\screm.ui\agntcons.vbs password protected, has not been processed 4/1/2005 1:05:37 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0020.BIN\screm.ui\agntlang.vbs password protected, has not been processed 4/1/2005 1:05:37 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0020.BIN\screm.ui\comctl.lpk password protected, has not been processed 4/1/2005 1:05:37 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0020.BIN\screm.ui\config.ini password protected, has not been processed 4/1/2005 1:05:37 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0020.BIN\screm.ui\UnInsStr.vbs password protected, has not been processed 4/1/2005 1:05:37 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0020.BIN\screm.ui\uninstall.htm password protected, has not been processed 4/1/2005 1:05:37 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0020.BIN\screm.ui\vssver.scc password protected, has not been processed 4/1/2005 1:05:37 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0020.BIN\screm.ui\pbar.vbs password protected, has not been processed 4/1/2005 1:05:37 PM
C:\Program Files\McAfee.com\Agent\mpfpinst.exe/WISE0020.BIN\screm.ui\uninst.vbs password protected, has not been processed 4/1/2005 1:05:37 PM
C:\Program Files\McAfee.com\Agent\mpsinst.exe/WISE0016.BIN\appcons.vbs password protected, has not been processed 4/1/2005 1:05:39 PM
C:\Program Files\McAfee.com\Agent\mpsinst.exe/WISE0016.BIN\appinst.htm password protected, has not been processed 4/1/2005 1:05:39 PM
C:\Program Files\McAfee.com\Agent\mpsinst.exe/WISE0016.BIN\appinst.vbs password protected, has not been processed 4/1/2005 1:05:39 PM
C:\Program Files\McAfee.com\Agent\mpsinst.exe/WISE0016.BIN\applang.vbs password protected, has not been processed 4/1/2005 1:05:39 PM
C:\Program Files\McAfee.com\Agent\mpsinst.exe/WISE0016.BIN\default.htm password protected, has not been processed 4/1/2005 1:05:39 PM
C:\Program Files\McAfee.com\Agent\mpsinst.exe/WISE0016.BIN\header.vbs password protected, has not been processed 4/1/2005 1:05:39 PM
C:\Program Files\McAfee.com\Agent\mpsinst.exe/WISE0016.BIN\images/bg_left_1x314.gif password protected, has not been processed 4/1/2005 1:05:39 PM
C:\Program Files\McAfee.com\Agent\mpsinst.exe/WISE0016.BIN\images/icon_info_16x16.gif password protected, has not been processed 4/1/2005 1:05:39 PM
C:\Program Files\McAfee.com\Agent\mpsinst.exe/WISE0016.BIN\images/icon_mcafee_61x61.gif password protected, has not been processed 4/1/2005 1:05:39 PM
C:\Program Files\McAfee.com\Agent\mpsinst.exe/WISE0016.BIN\images/icon_progress_checked_13x13.gif password protected, has not been processed 4/1/2005 1:05:39 PM
C:\Program Files\McAfee.com\Agent\mpsinst.exe/WISE0016.BIN\images/icon_progress_hot_13x13.gif password protected, has not been processed 4/1/2005 1:05:39 PM
C:\Program Files\McAfee.com\Agent\mpsinst.exe/WISE0016.BIN\images/icon_progress_unchecked_13x13.gif password protected, has not been processed 4/1/2005 1:05:39 PM
C:\Program Files\McAfee.com\Agent\mpsinst.exe/WISE0016.BIN\instwiz.css password protected, has not been processed 4/1/2005 1:05:39 PM
C:\Program Files\McAfee.com\Agent\mpsinst.exe/WISE0016.BIN\instxp.css password protected, has not been processed 4/1/2005 1:05:39 PM
C:\Program Files\McAfee.com\Agent\mpsinst.exe/WISE0016.BIN\mcccom.lpk password protected, has not been processed 4/1/2005 1:05:39 PM
C:\Program Files\McAfee.com\Agent\mpsinst.exe/WISE0016.BIN\mpsins.ini password protected, has not been processed 4/1/2005 1:05:39 PM
C:\Program Files\McAfee.com\Agent\mpsinst.exe/WISE0016.BIN\pbar.vbs password protected, has not been processed 4/1/2005 1:05:39 PM
C:\Program Files\McAfee.com\Agent\mpsinst.exe/WISE0016.BIN\setcss.vbs password protected, has not been processed 4/1/2005 1:05:39 PM
C:\Program Files\McAfee.com\Agent\mpsinst.exe/WISE0019.BIN\mpsrem.ui\comctl.lpk password protected, has not been processed 4/1/2005 1:05:40 PM
C:\Program Files\McAfee.com\Agent\mpsinst.exe/WISE0019.BIN\mpsrem.ui\config.ini password protected, has not been processed 4/1/2005 1:05:40 PM
C:\Program Files\McAfee.com\Agent\mpsinst.exe/WISE0019.BIN\mpsrem.ui\pbar.vbs password protected, has not been processed 4/1/2005 1:05:40 PM
C:\Program Files\McAfee.com\Agent\mpsinst.exe/WISE0019.BIN\mpsrem.ui\uninstall.htm password protected, has not been processed 4/1/2005 1:05:40 PM
C:\Program Files\McAfee.com\Agent\mpsinst.exe/WISE0020.BIN\RemoveMPS.exe/WISE0005.BIN\comctl.lpk password protected, has not been processed 4/1/2005 1:05:42 PM
C:\Program Files\McAfee.com\Agent\mpsinst.exe/WISE0020.BIN\RemoveMPS.exe/WISE0005.BIN\config.ini password protected, has not been processed 4/1/2005 1:05:42 PM
C:\Program Files\McAfee.com\Agent\mpsinst.exe/WISE0020.BIN\RemoveMPS.exe/WISE0005.BIN\uninstall.htm password protected, has not been processed 4/1/2005 1:05:42 PM
C:\Program Files\McAfee.com\Agent\vsoinst.exe/WISE0020.BIN\default.htm password protected, has not been processed 4/1/2005 1:05:46 PM
C:\Program Files\McAfee.com\Agent\vsoinst.exe/WISE0020.BIN\header.vbs password protected, has not been processed 4/1/2005 1:05:46 PM
C:\Program Files\McAfee.com\Agent\vsoinst.exe/WISE0020.BIN\HtmlUtil.vbs password protected, has not been processed 4/1/2005 1:05:46 PM
C:\Program Files\McAfee.com\Agent\vsoinst.exe/WISE0020.BIN\images/bg_left_1x314.gif password protected, has not been processed 4/1/2005 1:05:46 PM
C:\Program Files\McAfee.com\Agent\vsoinst.exe/WISE0020.BIN\images/icon_info_16x16.gif password protected, has not been processed 4/1/2005 1:05:46 PM
C:\Program Files\McAfee.com\Agent\vsoinst.exe/WISE0020.BIN\images/icon_mcafee_61x61.gif password protected, has not been processed 4/1/2005 1:05:46 PM
C:\Program Files\McAfee.com\Agent\vsoinst.exe/WISE0020.BIN\images/icon_progress_checked_13x13.gif password protected, has not been processed 4/1/2005 1:05:46 PM
C:\Program Files\McAfee.com\Agent\vsoinst.exe/WISE0020.BIN\images/icon_progress_hot_13x13.gif password protected, has not been processed 4/1/2005 1:05:46 PM
C:\Program Files\McAfee.com\Agent\vsoinst.exe/WISE0020.BIN\images/icon_progress_unchecked_13x13.gif password protected, has not been processed 4/1/2005 1:05:46 PM
C:\Program Files\McAfee.com\Agent\vsoinst.exe/WISE0020.BIN\install.htm password protected, has not been processed 4/1/2005 1:05:46 PM
C:\Program Files\McAfee.com\Agent\vsoinst.exe/WISE0020.BIN\InstUtil.vbs password protected, has not been processed 4/1/2005 1:05:46 PM
C:\Program Files\McAfee.com\Agent\vsoinst.exe/WISE0020.BIN\instwiz.css password protected, has not been processed 4/1/2005 1:05:46 PM
C:\Program Files\McAfee.com\Agent\vsoinst.exe/WISE0020.BIN\instxp.css password protected, has not been processed 4/1/2005 1:05:46 PM
C:\Program Files\McAfee.com\Agent\vsoinst.exe/WISE0020.BIN\mcccom.lpk password protected, has not been processed 4/1/2005 1:05:46 PM
C:\Program Files\McAfee.com\Agent\vsoinst.exe/WISE0020.BIN\pbar.vbs password protected, has not been processed 4/1/2005 1:05:46 PM
C:\Program Files\McAfee.com\Agent\vsoinst.exe/WISE0020.BIN\setcss.vbs password protected, has not been processed 4/1/2005 1:05:46 PM
C:\Program Files\McAfee.com\Agent\vsoinst.exe/WISE0020.BIN\VsoConst.vbs password protected, has not been processed 4/1/2005 1:05:46 PM
C:\Program Files\McAfee.com\Agent\vsoinst.exe/WISE0020.BIN\vsoins.ini password protected, has not been processed 4/1/2005 1:05:46 PM
C:\Program Files\McAfee.com\Agent\vsoinst.exe/WISE0020.BIN\vsolang.vbs password protected, has not been processed 4/1/2005 1:05:46 PM
C:\Program Files\McAfee.com\Agent\vsoinst.exe/WISE0020.BIN\VSOPropConst.vbs password protected, has not been processed 4/1/2005 1:05:46 PM
C:\Program Files\McAfee.com\Agent\Uninst\screm.ui\agntcons.vbs password protected, has not been processed 4/1/2005 1:05:57 PM
C:\Program Files\McAfee.com\Agent\Uninst\screm.ui\agntlang.vbs password protected, has not been processed 4/1/2005 1:05:57 PM
C:\Program Files\McAfee.com\Agent\Uninst\screm.ui\comctl.lpk password protected, has not been processed 4/1/2005 1:05:57 PM
C:\Program Files\McAfee.com\Agent\Uninst\screm.ui\config.ini password protected, has not been processed 4/1/2005 1:05:57 PM
C:\Program Files\McAfee.com\Agent\Uninst\screm.ui\pbar.vbs password protected, has not been processed 4/1/2005 1:05:57 PM
C:\Program Files\McAfee.com\Agent\Uninst\screm.ui\UnInsStr.vbs password protected, has not been processed 4/1/2005 1:05:57 PM
C:\Program Files\McAfee.com\Agent\Uninst\screm.ui\uninst.vbs password protected, has not been processed 4/1/2005 1:05:57 PM
C:\Program Files\McAfee.com\Agent\Uninst\screm.ui\uninstall.htm password protected, has not been processed 4/1/2005 1:05:57 PM

Thanks again for all of your help

Attached Files


  • 0

#4
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
Sorry about that,I am hoping this just a Conflict of the 2 Antivirus Programs running at the same time!

Go to Add\Remove Programs and remove:

Kaspersky Anti-Virus Personal
Media Access


Open HijackThis and put a check by these but DO NOT hit the Fix Checked button yet!

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

R3 - Default URLSearchHook is missing

O4 - HKLM\..\Run: [AOL Messenger Optimized] AOLOpt.exe

O4 - HKLM\..\Run: [Media Access] C:\Program Files\Media Access\MediaAccK.exe

O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize

O4 - HKLM\..\Run: [Bjf] C:\WINDOWS\system32\Rvg.exe

O4 - HKLM\..\RunServices: [AOL Messenger Optimized] AOLOpt.exe

Now Make sure ALL WINDOWS and BROWSERS are CLOSED and hit the Fix Checked Button!!

Locate and Delete these 2 files:

C:\WINDOWS\system32\Rvg.exe

AOLOpt.exe<<< Unsure of exact location!

Restart Normal and See if you can Access the Desktop OK!

If so post back with a fresh HijackThis log!
  • 0

#5
dunc11

dunc11

    New Member

  • Topic Starter
  • Member
  • Pip
  • 3 posts
Yes, that corrected the problem. Thanks for all of your help. Have a gread day!!
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP