I really appreciate you taking the time to help mefix this computer. Here are the 3 logs you wanted. ComboFix, DSS extra.txt and Kaspersky (it is way too long so I have to break it down and put it many reply windows)
___________________________________________________________________
ComboFix 08-03-30.2 - user 2008-03-31 11:48:24.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.197 [GMT -4:00]
Running from: C:\Documents and Settings\user\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\user\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!FILE ::
C:\WINDOWS\mindep.dll
C:\WINDOWS\SETUPZMP.DLL
C:\WINDOWS\system32\yaywvstQ.dll
c:\windows\vcpdll.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\user\Application Data\BitTorrent
C:\Documents and Settings\user\Application Data\BitTorrent\dht.dat
C:\Documents and Settings\user\Application Data\BitTorrent\dht.dat.old
C:\Documents and Settings\user\Application Data\BitTorrent\Gorillaz - Demon Days (Special Edition).torrent
C:\Documents and Settings\user\Application Data\BitTorrent\Gorillaz - Gorillaz.torrent
C:\Documents and Settings\user\Application Data\BitTorrent\Jet - Get Born.torrent
C:\Documents and Settings\user\Application Data\BitTorrent\Korn - Greatest Hits Vol.1.rar.torrent
C:\Documents and Settings\user\Application Data\BitTorrent\Modest Mouse - Good News For People Who Love Bad News.torrent
C:\Documents and Settings\user\Application Data\BitTorrent\resume.dat
C:\Documents and Settings\user\Application Data\BitTorrent\resume.dat.old
C:\Documents and Settings\user\Application Data\BitTorrent\settings.dat
C:\Documents and Settings\user\Application Data\BitTorrent\settings.dat.old
C:\Documents and Settings\user\Application Data\BitTorrent\Sublime - 40oz. To Freedom.torrent
C:\Documents and Settings\user\Application Data\BitTorrent\Sublime - Sublime.torrent
C:\Documents and Settings\user\Application Data\BitTorrent\The Fray - How To Save A Life.torrent
C:\Documents and Settings\user\Application Data\BitTorrent\The Killers - Hot Fuss.torrent
C:\Documents and Settings\user\aria.txt
C:\WINDOWS\NDNuninstall6_38.exe
C:\WINDOWS\SETUPZMP.DLL
C:\WINDOWS\SYSTEM32\LTENonmp.ini
C:\WINDOWS\SYSTEM32\LTENonmp.ini2
C:\WINDOWS\system32\pmnoNETL.dll
C:\WINDOWS\system32\pywrmsf
C:\WINDOWS\system32\yaywvstQ.dll
.
((((((((((((((((((((((((( Files Created from 2008-02-28 to 2008-03-31 )))))))))))))))))))))))))))))))
.
2008-03-31 01:13 . 2008-03-31 01:13 <DIR> d-------- C:\Deckard
2008-03-30 23:36 . 2008-03-30 23:36 <DIR> d-------- C:\WINDOWS\ERUNT
2008-03-30 23:29 . 2008-03-31 00:11 <DIR> d-------- C:\SDFix
2008-03-30 14:08 . 2008-03-30 14:08 <DIR> d-------- C:\Program Files\Trymedia
2008-03-30 14:08 . 2008-03-30 14:08 <DIR> d-------- C:\Program Files\HangStan Trivia
2008-03-27 22:45 . 2008-03-27 22:45 <DIR> d-------- C:\Program Files\Trend Micro
2008-03-27 14:40 . 2008-03-30 23:47 1,324 --a------ C:\WINDOWS\SYSTEM32\d3d9caps.dat
2008-03-20 18:11 . 2008-03-20 18:11 0 --ah----- C:\WINDOWS\SYSTEM32\DRIVERS\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-03-20 18:11 . 2008-03-20 18:11 0 --ah----- C:\WINDOWS\SYSTEM32\DRIVERS\Msft_Kernel_zumbus_01005.Wdf
2008-03-20 18:10 . 2008-01-11 17:39 145,408 --a------ C:\WINDOWS\SYSTEM32\ZuneMTPZ.dll
2008-03-20 18:10 . 2008-01-11 17:39 70,656 --a------ C:\WINDOWS\SYSTEM32\ZuneIpTransport.dll
2008-03-20 18:10 . 2008-01-11 17:39 62,464 --a------ C:\WINDOWS\SYSTEM32\ZuneUsbTransport.dll
2008-03-20 18:10 . 2008-01-11 17:39 35,840 --a------ C:\WINDOWS\SYSTEM32\ZuneUsbCOnnection.dll
2008-03-20 18:09 . 2008-03-20 18:12 <DIR> d-------- C:\Program Files\Zune
2008-03-17 17:49 . 2008-03-22 10:05 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-03-17 17:49 . 2008-03-17 17:49 1,409 --a------ C:\WINDOWS\QTFont.for
2008-03-08 12:12 . 2008-03-08 12:12 <DIR> d-------- C:\Program Files\DNA
2008-03-08 12:12 . 2008-03-30 23:16 <DIR> d-------- C:\Documents and Settings\user\Application Data\DNA
2008-02-19 12:51 . 2003-07-19 11:17 5,174 --a------ C:\WINDOWS\SYSTEM32\nppt9x.vxd
2008-02-19 12:51 . 2005-01-03 02:43 4,682 --a------ C:\WINDOWS\SYSTEM32\npptNT2.sys
2008-02-19 12:50 . 2008-02-19 12:50 <DIR> d-------- C:\Program Files\Common Files\INCA Shared
2008-02-18 19:10 . 2008-02-18 19:10 <DIR> d-------- C:\Ntreev
2008-02-18 17:53 . 2008-02-18 17:53 <DIR> d-------- C:\Program Files\Veoh Networks
2008-02-15 17:40 . 2008-02-15 17:40 <DIR> d-------- C:\Program Files\Norton Security Scan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-31 04:12 --------- d-----w C:\Documents and Settings\user\Application Data\AVG7
2008-03-31 03:29 --------- d-----w C:\Program Files\Lx_cats
2008-03-30 02:25 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Google Updater
2008-02-22 22:31 --------- d-----w C:\Program Files\Common Files\Adobe
2008-02-19 14:10 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-02-18 21:56 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-11 03:42 --------- d-----w C:\Program Files\Microsoft Picture It! PhotoPub
2007-05-21 20:38 374 ----a-w C:\Documents and Settings\user\Application Data\internaldb6334.dat
2007-04-01 22:49 538 ----a-w C:\Documents and Settings\user\Application Data\internaldb8467.dat
2007-04-01 22:49 18,432 ----a-w C:\Documents and Settings\user\Application Data\internaldb41.dat
2005-06-29 05:06 330,771,738 ----a-w C:\Program Files\PEN DRIVE FINAL- DO NOT DELETE.zip
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 13:54 5674352]
"MoneyAgent"="C:\Program Files\Microsoft Money\System\mnyexpr.exe" [ ]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-03-27 15:22 4670968]
"ofor"="C:\Program Files\Common Files\ofor\oform.exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56 15360]
"OM2_Monitor"="C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" [2006-12-01 21:28 95800]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-12-18 21:47 8720384]
"Veoh"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" [2008-02-07 13:53 3497984]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-10-19 08:59 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-10-19 08:59 126976]
"IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\point32.exe" [2005-03-23 19:26 217088]
"LXBSCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBStime.dll" [2004-03-17 12:26 65536]
"MemoryCardManager"="C:\Program Files\Lexmark\Lexmark Precision Photo\MemCard.exe" [2004-02-02 14:58 139264]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 19:58 282624]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 10:36 256576]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-12-20 18:09 579072]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-02-08 21:08 29744]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 14:42 1404928]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" [ ]
"Zune Launcher"="c:\Program Files\Zune\ZuneLauncher.exe" [2008-01-11 17:54 166304]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-10-25 16:37 219136]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-12-18 21:47 8720384]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2006-10-04 04:48 53760 C:\WINDOWS\SYSTEM32\narrator.exe]
C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-07-19 20:51:07 124912]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Microsoft Office Fast Start.lnk]
path=C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\Microsoft Office Fast Start.lnk
backup=C:\WINDOWS\pss\Microsoft Office Fast Start.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Microsoft Office Find Fast Indexer.lnk]
path=C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\Microsoft Office Find Fast Indexer.lnk
backup=C:\WINDOWS\pss\Microsoft Office Find Fast Indexer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^MyWebSearch Email Plugin.lnk]
path=C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\MyWebSearch Email Plugin.lnk
backup=C:\WINDOWS\pss\MyWebSearch Email Plugin.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner.HOME^Start Menu^Programs^Startup^MyWebSearch Email Plugin.lnk]
path=C:\Documents and Settings\Owner.HOME\Start Menu\Programs\Startup\MyWebSearch Email Plugin.lnk
backup=C:\WINDOWS\pss\MyWebSearch Email Plugin.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]
C:\PROGRA~1\AVG\avgcc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
--a------ 2005-10-19 08:59 126976 C:\WINDOWS\System32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
--a------ 2005-10-19 08:59 155648 C:\WINDOWS\System32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 13:54 5674352 C:\Program Files\MSN Messenger\MsnMsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MyWebSearch Email Plugin]
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a--c--- 2004-12-06 22:31 36975 C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Win32 SSL Driver]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Compliant]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Documents and Settings\\user\\My Documents\\firefox\\firefox.exe"=
"C:\\WINDOWS\\SYSTEM32\\dplaysvr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
R2 zumbus;Zune Bus Enumerator Driver;C:\WINDOWS\system32\DRIVERS\zumbus.sys [2008-01-11 17:39]
R2 ZuneBusEnum;Zune Bus Enumerator;c:\WINDOWS\system32\ZuneBusEnum.exe [2008-01-11 17:54]
S3 GoogleDesktopManager-093007-112848;Google Desktop Manager 5.5.709.30344;"C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-02-08 21:08]
S3 ZuneWlanCfgSvc;Zune Wireless Configuration Service;c:\WINDOWS\system32\ZuneWlanCfgSvc.exe [2008-01-11 17:54]
S4 scagent;Security Agent;"C:\WINDOWS\system32\scagent.exe" start []
.
Contents of the 'Scheduled Tasks' folder
"2008-03-21 19:00:00 C:\WINDOWS\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-03-31 12:04:50
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 2008-03-31 12:15:21 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-31 16:15:05
ComboFix2.txt 2008-03-31 04:59:56
Pre-Run: 4,999,925,760 bytes free
Post-Run: 5,014,892,544 bytes free
.
2008-03-13 03:15:17 --- E O F ---
Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------
-- System Information ----------------------------------------------------------
Microsoft Windows XP Home Edition (build 2600) SP 2.0
Architecture: X86; Language: English
CPU 0: Intel® Celeron® CPU 2.40GHz
Percentage of Memory in Use: 78%
Physical Memory (total/avail): 510 MiB / 110.4 MiB
Pagefile Memory (total/avail): 672.75 MiB / 331.59 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1932.7 MiB
A: is Removable (No Media)
C: is Fixed (NTFS) - 37.21 GiB total, 9.17 GiB free.
D: is CDROM (No Media)
\\.\PHYSICALDRIVE0 - WDC WD400BB-75FJA1 - 37.25 GiB - 2 partitions
\PARTITION0 - Unknown - 39.19 MiB
\PARTITION1 (bootable) - Installable File System - 37.21 GiB - C:
-- Security Center -------------------------------------------------------------
AUOptions is set to notify before install.
Windows Internal Firewall is enabled.
AV: AVG 7.5.519 v7.5.519 (Grisoft)
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Documents and Settings\\user\\My Documents\\firefox\\firefox.exe"="C:\\Documents and Settings\\user\\My Documents\\firefox\\firefox.exe:*:Disabled:Firefox"
"C:\\WINDOWS\\SYSTEM32\\dplaysvr.exe"="C:\\WINDOWS\\SYSTEM32\\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
"C:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"="C:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe:*:Enabled:Veoh Client"
-- Environment Variables -------------------------------------------------------
ALLUSERSPROFILE=C:\Documents and Settings\All Users.WINDOWS
APPDATA=C:\Documents and Settings\user\Application Data
CLASSPATH=.;C:\Program Files\Java\jre1.5.0_01\lib\ext\QTJava.zip
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=HOME
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\user
LOGONSERVER=\\HOME
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\system32\wbem;C:\Downloads\Gimp\bin;C:\Program Files\QuickTime\QTSystem
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 2 Stepping 9, GenuineIntel
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=0209
ProgramFiles=C:\Program Files
PROMPT=$P$G
QTJAVA=C:\Program Files\Java\jre1.5.0_01\lib\ext\QTJava.zip
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\user\LOCALS~1\Temp
TMP=C:\DOCUME~1\user\LOCALS~1\Temp
USERDOMAIN=HOME
USERNAME=user
USERPROFILE=C:\Documents and Settings\user
windir=C:\WINDOWS
-- User Profiles ---------------------------------------------------------------
Owner.HOME
(admin)user
(admin)Administrator
(new local, admin)-- Add/Remove Programs ---------------------------------------------------------
--> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Ad-Aware 2007 --> MsiExec.exe /X{0E6AB9FC-76C2-431B-9C06-6C1CFFFEA8EB}
Adobe Flash Player 9 ActiveX --> C:\WINDOWS\system32\Macromed\Flash\UninstFl.exe -q
Adobe Flash Player Plugin --> C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Photoshop Album 2.0 Starter Edition --> MsiExec.exe /I{11B569C2-4BF6-4ED0-9D17-A4273943CB24}
Adobe Reader 8.1.2 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81200000003}
Adobe Shockwave Player --> C:\WINDOWS\SYSTEM32\Macromed\SHOCKW~2\UNWISE.EXE C:\WINDOWS\SYSTEM32\Macromed\SHOCKW~2\Install.log
Audacity 1.2.3 --> "C:\Program Files\Audacity\unins000.exe"
Audition --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6CB9AF08-79AE-4020-84A8-29CF15C67BD5}\Setup.exe" -l0x9
AVG 7.5 --> C:\Program Files\Grisoft\AVG7\setup.exe /UNINSTALL
BitTorrent --> C:\Program Files\BitTorrent\uninst.exe
Broadcom 440x 10/100 Integrated Controller --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{52504CE6-E909-4113-B232-4AFEC6543A61} /l1033
Broadcom Advanced Control Suite --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{468190DA-FB4C-45BA-8E40-4B165FF1A939} /l1033
Broadcom Management Programs --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{89EE857B-8970-4F9F-AB58-A1C873AC72B3} /l1033
Campaign Suite --> C:\Documents and Settings\Owner.HOME\Desktop\DND\campaign thing\uninstall.exe
Daimonin Client BETA3-0.966 --> C:\Downloads\client\unins000.exe
Dell ResourceCD --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D78653C3-A8FF-415F-92E6-D774E634FF2D}\setup.exe"
DivX --> C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
DivX Player --> C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
DNA --> "C:\Program Files\DNA\btdna.exe" /UNINSTALL
Efficient Networks SpeedStream DSL --> C:\Program Files\Efficient Networks\SpeedStream DSL\setup.exe -uninstall
Files for Remmy.exe Animation Patcher --> C:\WINDOWS\st6unst.exe -n "c:\Program Files\Sony\EverQuest\uifiles\ST6UNST.LOG"
FinePixViewer Ver.4.2 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{24ED4D80-8294-11D5-96CD-0040266301AD}\SETUP.EXE"
Google Desktop --> C:\Program Files\Google\Google Desktop Search\GoogleDesktopSetup.exe -uninstall
Google Earth --> MsiExec.exe /I{1E04F83B-2AB9-4301-9EF7-E86307F79C72}
Google Photos Screensaver --> MsiExec.exe /X{A52415E5-CA1E-44DE-9EDC-D412F31D271C}
Google Toolbar for Internet Explorer --> MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29}
Google Toolbar for Internet Explorer --> regsvr32 /u /s "c:\program files\google\googletoolbar1.dll"
Google Updater --> "C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
Grand Chase --> C:\Ntreev\Grand Chase\uninst.exe
HangStan Trivia (remove only) --> "C:\Program Files\HangStan Trivia\Uninstall.exe"
Hellfire --> C:\WINDOWS\IsUninst.exe -f"c:\documents and settings\all users.windows\documents\games\diablo\sierra\SIERRA\HELLFIRE\Uninst.isu"
HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Intel® 537EP V9x DF PCI Modem --> rundll32 IntelCci.dll,iSMUninstallation "Intel® 537EP V9x DF PCI Modem"
Intel® Extreme Graphics Driver --> RUNDLL32.EXE C:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx PCI\VEN_8086&DEV_2562
IpWins --> C:\Program Files\Ipwindows\Uninst.exe
iTunes --> MsiExec.exe /I{446DBFFA-4088-48E3-8932-74316BA4CAE4}
J2SE Runtime Environment 5.0 Update 1 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150010}
Lexmark 810 Series --> C:\WINDOWS\system32\spool\drivers\w32x86\3\LXBSUNST.EXE -NOLICENSE
Lexmark Precision Photo --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\8\INTEL3~1\IDriver.exe /M{56F81937-C3B5-4C98-A260-E47B631709D7} /l1033 /z/U
LimeWire PRO 4.12.3 --> "C:\Program Files\LimeWire\uninstall.exe"
Masque Slots --> C:\Masque\Slots\UNWISE.EXE C:\Masque\Slots\INSTALL.LOG
Microsoft Base Smart Card Cryptographic Service Provider Package --> "C:\WINDOWS\$NtUninstallbasecsp$\spuninst\spuninst.exe"
Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Encarta Encyclopedia Standard 2004 --> MsiExec.exe /I{04410044-9149-45C6-A806-F2BF9CFCE762}
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 --> "C:\WINDOWS\$NtUninstallWdf01005$\spuninst\spuninst.exe"
Microsoft Office Professional --> C:\program files\microsft office 95\Office\Setup\Acme.exe /w OFF95PRO.STF
Microsoft Picture It! Publishing Platinum 2001 --> MsiExec.exe /I{501FC6C0-7F99-4937-99F6-9A65A964B710}
Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
Microsoft Windows Journal Viewer --> MsiExec.exe /X{43DCF766-6838-4F9A-8C91-D92DA586DFA8}
Microsoft Works 2003 Setup Launcher --> C:\Program Files\Microsoft Works Suite 2003\Setup\Launcher.exe D:\
Microsoft Works 7.0 --> MsiExec.exe /I{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}
Mozilla Firefox (2.0.0.13) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSXML 6.0 Parser (KB933579) --> MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
MySpaceIM --> C:\Program Files\MySpace\IM\Uninstall.exe
Norton Security Scan --> MsiExec.exe /I{3A4FFB84-D070-4DA5-AB7B-D41D87FD8D19}
NoteWorthy Composer --> C:\DOCUME~1\ALLUSE~1.WIN\DOCUME~1\MYMUSI~1\NOTEWO~1\UNINSTAL.EXE C:\DOCUME~1\ALLUSE~1.WIN\DOCUME~1\MYMUSI~1\NOTEWO~1\INSTALL.LOG
OIN Search --> C:\Program Files\OIN Search\Uninstall.exe
OLYMPUS Master 2 --> MsiExec.exe /X{F0FC1E09-AF67-47BC-9E61-90ECFEB4CE82}
OLYMPUS muvee theaterPack --> MsiExec.exe /X{691B06EC-F84C-4103-B4D4-3FC5BC4941E9}
Pixia --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A0BCF90F-B4E4-435C-A48D-8FAAE10554F9}\Setup.exe" -l0x9 UNINSTALL
Power Scan --> C:\Program Files\Power Scan\uninstall.exe
project dogwaffle --> C:\WINDOWS\ST5UNST.EXE -n "c:\ST5UNST.LOG"
Pygame-Docs 1.6 --> "C:\Program Files\Pygame-Docs\unins000.exe"
QuickTime --> MsiExec.exe /I{50D8FFDD-90CD-4859-841F-AA1961C7767A}
RAW FILE CONVERTER LE --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D680C913-5955-469D-9D88-C1940F7506D6}\SETUP.EXE" -l0x9
RealPlayer --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
Shockwave --> C:\WINDOWS\SYSTEM32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\SYSTEM32\Macromed\SHOCKW~1\Install.log
SoundMAX --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F0A37341-D692-11D4-A984-009027EC0A9C}\SETUP.exe" -l0x9 -removeonly
Uinstall Aze Bar --> regsvr32 /u /s "C:\WINDOWS\system32\azesearch4.ocx"
URGE --> MsiExec.exe /I{8BBF6DFD-0AD9-43A7-9FBD-BF065E3866AF}
VeohTV BETA --> C:\Program Files\InstallShield Installation Information\{D1B11537-EA51-4DD8-BF1E-098BEE48868D}\setup.exe -runfromtemp -l0x0409
VideoLAN VLC media player 0.8.1 --> C:\Documents and Settings\Owner.HOME\My Documents\My Received Files\VLC\uninstall.exe
Viewpoint Media Player --> C:\Program Files\Viewpoint\Viewpoint Media Player\mtsAxInstaller.exe /u
Windows Communication Foundation --> MsiExec.exe /X{491DD792-AD81-429C-9EB4-86DD3D22E333}
Windows Imaging Component --> "C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
Windows Live Messenger --> MsiExec.exe /I{571700F0-DB9D-4B3A-B03D-35A14BB5939F}
Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Presentation Foundation --> MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}
Windows Workflow Foundation --> MsiExec.exe /I{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}
WinRAR archiver --> C:\Program Files\WinRAR\uninstall.exe
XML Paper Specification Shared Components Pack 1.0 -->
Yahoo! Internet Mail --> C:\WINDOWS\system32\regsvr32 /u /s C:\PROGRA~1\Yahoo!\Common\ymmapi.dll
Yahoo! Messenger --> C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE /U C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG
Zune --> MsiExec.exe /X{7583239A-D4BE-48CA-A253-396122B3D3E9}
Zune Language Pack (ES) --> MsiExec.exe /X{EE4ACABF-531E-419A-9225-B8E0FA4955AF}
Zune Language Pack (FR) --> MsiExec.exe /X{0076E1AC-9E7B-4B9F-A62A-4CC9511AD8E3}
-- Application Event Log -------------------------------------------------------
Event Record #/Type9022 / Error
Event Submitted/Written: 03/29/2008 09:46:12 PM
Event ID/Source: 1002 / Application Hang
Event Description:
Hanging application firefox.exe, version 1.8.20080.31114, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Event Record #/Type9021 / Error
Event Submitted/Written: 03/29/2008 09:46:06 PM
Event ID/Source: 1002 / Application Hang
Event Description:
Hanging application firefox.exe, version 1.8.20080.31114, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Event Record #/Type9020 / Error
Event Submitted/Written: 03/29/2008 01:22:30 AM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application iexplore.exe, version 7.0.6000.16608, faulting module unknown, version 0.0.0.0, fault address 0x10001525.
Processing media-specific event for [iexplore.exe!ws!]
Event Record #/Type9018 / Error
Event Submitted/Written: 03/29/2008 00:12:39 AM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application iexplore.exe, version 7.0.6000.16608, faulting module flash9.ocx, version 9.0.16.0, fault address 0x0010e590.
Processing media-specific event for [iexplore.exe!ws!]
Event Record #/Type9017 / Error
Event Submitted/Written: 03/29/2008 00:11:39 AM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application iexplore.exe, version 7.0.6000.16608, faulting module flash9.ocx, version 9.0.16.0, fault address 0x0010e590.
Processing media-specific event for [iexplore.exe!ws!]
-- Security Event Log ----------------------------------------------------------
No Errors/Warnings found.
-- System Event Log ------------------------------------------------------------
Event Record #/Type45372 / Error
Event Submitted/Written: 03/31/2008 00:50:16 AM
Event ID/Source: 7026 / Service Control Manager
Event Description:
The following boot-start or system-start driver(s) failed to load:
szkg
Event Record #/Type45330 / Error
Event Submitted/Written: 03/30/2008 11:58:05 PM
Event ID/Source: 7026 / Service Control Manager
Event Description:
The following boot-start or system-start driver(s) failed to load:
szkg
Event Record #/Type45329 / Error
Event Submitted/Written: 03/30/2008 11:57:53 PM
Event ID/Source: 7023 / Service Control Manager
Event Description:
The System Restore Service service terminated with the following error:
%%2
Event Record #/Type45328 / Error
Event Submitted/Written: 03/30/2008 11:57:39 PM
Event ID/Source: 104 / SRService
Event Description:
The System Restore initialization process failed.
Event Record #/Type45323 / Error
Event Submitted/Written: 03/30/2008 11:35:12 PM
Event ID/Source: 10005 / DCOM
Event Description:
DCOM got error "%%1084" attempting to start the service StiSvc with arguments ""
in order to run the server:
{A1F4E726-8CF1-11D1-BF92-0060081ED811}
-- End of Deckard's System Scanner: finished at 2008-03-31 01:17:27 ------------
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Monday, March 31, 2008 3:18:07 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 31/03/2008
Kaspersky Anti-Virus database records: 674580
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
Scan Statistics:
Total number of scanned objects: 111265
Number of viruses found: 28
Number of infected objects: 75
Number of suspicious objects: 0
Duration of the scan process: 02:15:30
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users.WINDOWS\Application Data\Avg7\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Crypto\DSS\MachineKeys\6ccffeebf26f3b53bf560ce3ebc894a3_ef35bc80-eedb-44ba-9c3a-c8eb399b470b Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Documents\Games\morrowind\CSUninstall\setup.ilg Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Owner.HOME\.idlerc\recent-files.lst Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Adobe\Acrobat\7.0\AdobeCMapFnt07.lst Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Adobe\Acrobat\7.0\AdobeSysFnt07.lst Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Adobe\Acrobat\7.0\Collab\RSS Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Adobe\Acrobat\7.0\JavaScripts\glob.settings.js Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Adobe\Acrobat\7.0\JSADM.exv Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Adobe\Acrobat\7.0\Messages\ENU\read0600win_ENUyhoo0010.pdf Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Adobe\Acrobat\7.0\Messages\ENU\read0700win_ENUadbe0060.pdf Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Adobe\Acrobat\7.0\Preferences\AutoFillDefaults.dat Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Adobe\Acrobat\7.0\Preferences\defaultHeuristics.dat Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Adobe\Acrobat\7.0\Updater\udlog.txt Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Adobe\Acrobat\7.0\Updater\udstore.js Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Adobe\Acrobat\7.0\UserCache.bin Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Adobe\Acrobat\8.0\AdobeCMapFnt08.lst Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Adobe\Acrobat\8.0\AdobeSysFnt08.lst Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Adobe\Acrobat\8.0\UserCache.bin Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Adobe\Photoshop Album\Log.txt Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Adobe\Photoshop Album\psa.prf Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Adobe\Photoshop Album\status.dat Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\AdobeAUM\pase201winen_US.aum Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\AdobeAUM\pase201winen_US_meta.txt Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\AdobeDLM.log Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\AVG7\log.idx Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\AVG7\l_000110.log Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\AVG7\sched-0001.cfg Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\AVG7\sched-0002.cfg Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\AVG7\test-0001.cfg Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\AVG7\test-0002.cfg Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\AVG7\test-0003.cfg Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\AVG7\test-0004.cfg Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\AVG7\test-0005.cfg Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\AVG7\test-0006.cfg Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\AVG7\test-0007.cfg Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\AVG7\test-0008.cfg Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\AVG7\test-0009.cfg Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\AVG7\test-0011.cfg Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\AVG7\test-0012.cfg Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\AVG7\test-0013.cfg Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\AVG7\user-0000.cfg Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectExpert\11\Custom WP Templates\bluterra.gif Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectExpert\11\Custom WP Templates\greenbrk.gif Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectExpert\11\Custom WP Templates\hatch.gif Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectExpert\11\Custom WP Templates\lace1.gif Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectExpert\11\Custom WP Templates\lace2.gif Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectExpert\11\Custom WP Templates\marble1.gif Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectExpert\11\Custom WP Templates\marble2.gif Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectExpert\11\Custom WP Templates\oil1.gif Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectExpert\11\Custom WP Templates\oil2.gif Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectExpert\11\Custom WP Templates\paper1.gif Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectExpert\11\Custom WP Templates\paper2.gif Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectExpert\11\Custom WP Templates\pine.gif Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectExpert\11\Custom WP Templates\poly.gif Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectExpert\11\Custom WP Templates\poplar.gif Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectExpert\11\Custom WP Templates\qw11en.wpt Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectExpert\11\Custom WP Templates\rock.gif Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectExpert\11\Custom WP Templates\stucco1.gif Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectExpert\11\Custom WP Templates\stucco2.gif Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectExpert\11\Custom WP Templates\tile.gif Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectExpert\11\Custom WP Templates\water.gif Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectExpert\11\Custom WP Templates\wp11US.wpt Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectExpert\11\Custom WP Templates\wrinkle.gif Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectExpert\11\Custom WP Templates\XML\app-a50.wpt Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectExpert\11\Custom WP Templates\XML\app-d30.wpt Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectExpert\11\Custom WP Templates\XML\docbook2.wpt Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectExpert\11\Custom WP Templates\XML\docbook3.wpt Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectExpert\11\Custom WP Templates\XML\html.wpt Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectExpert\11\Custom WP Templates\XML\html32ip.wpt Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectExpert\11\Custom WP Templates\XML\html3_2.wpt Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectExpert\11\Custom WP Templates\XML\overview.wpt Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectExpert\11\Custom WP Templates\XML\sample1.wpt Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectExpert\11\Custom WP Templates\XML\sample2.wpt Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectExpert\11\Custom WP Templates\XML\teilite.wpt Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectExpert\11\Custom WP Templates\XML\XML.wpt Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectExpert\11\Custom WP Templates\XML\xmlnews.wpt Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectExpert\11\Custom WP Templates\_autotmp.wpx Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectScript\11\WordPerfect\ABBREV.WCM Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectScript\11\WordPerfect\adrs2mrg.wcm Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectScript\11\WordPerfect\ALLFONTS.WCM Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectScript\11\WordPerfect\checkbox.wcm Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectScript\11\WordPerfect\closeall.wcm Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectScript\11\WordPerfect\CTRLM.WCM Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectScript\11\WordPerfect\cvtdocs11.wcm Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectScript\11\WordPerfect\DCConvert.wcm Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectScript\11\WordPerfect\ender01.wpg Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectScript\11\WordPerfect\ender02.wpg Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectScript\11\WordPerfect\ender03.wpg Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectScript\11\WordPerfect\ender04.wpg Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectScript\11\WordPerfect\ender05.wpg Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectScript\11\WordPerfect\ender06.wpg Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectScript\11\WordPerfect\ender07.wpg Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectScript\11\WordPerfect\ender08.wpg Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectScript\11\WordPerfect\ender09.wpg Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectScript\11\WordPerfect\ender10.wpg Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectScript\11\WordPerfect\endfoot.wcm Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectScript\11\WordPerfect\EXPNDALL.WCM Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectScript\11\WordPerfect\FILESTMP.WCM Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectScript\11\WordPerfect\flipenv.wcm Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectScript\11\WordPerfect\FONTDN.WCM Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectScript\11\WordPerfect\FONTUP.WCM Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectScript\11\WordPerfect\footend.wcm Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectScript\11\WordPerfect\LONGNAME.WCM Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectScript\11\WordPerfect\nomacro.wcm Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectScript\11\WordPerfect\PARABRK.WCM Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectScript\11\WordPerfect\pleading.wcm Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectScript\11\WordPerfect\prompts.wcm Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectScript\11\WordPerfect\reverse.wcm Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectScript\11\WordPerfect\saveall.wcm Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectScript\11\WordPerfect\SAVETOA.WCM Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectScript\11\WordPerfect\tconvert.wcm Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectScript\11\WordPerfect\uawp11en.wcm Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectScript\11\WordPerfect\wp_org.wcm Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\PerfectScript\11\WordPerfect\wp_pr.wcm Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\Presentations\11\Config\Standard.prt Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\Scrapbook\11\Primary.srb Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\WordPerfect Office 11\User Color\icmprof.cat Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\WordPerfect Office 11\User Config\CdrConv.ini Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\WordPerfect Office 11\User Config\Color.ini Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\WordPerfect Office 11\User Config\CorelApp.ini Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\WordPerfect Office 11\User Config\Corelflt.ini Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\WordPerfect Office 11\User Config\CORELPDF.INI Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\WordPerfect Office 11\User Config\FILTERS.INI Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\WordPerfect Office 11\User Custom Data\coreldrw.tpa Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Corel\WordPerfect Office 11\User Workspace\CorelDRAW11\_default.CW_ Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\desktop.ini Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\dm.ini Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Google\Local Search History\google%2Eweb.w Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Help\WinHlp32.BMK Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Leadertech\PowerRegister\PowerReg.dat Object is locked skipped
C:\Documents and Settings\Owner.HOME\Application Data\Macromedia\Flash Player\#SharedObjects\P5QDRG25\64.156.213.193\view.swf\Us
Edited by Illerhas, 31 March 2008 - 02:55 PM.