Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

TR VUNDO virus [RESOLVED]


  • This topic is locked This topic is locked

#1
bggb

bggb

    Member

  • Member
  • PipPip
  • 43 posts
I'm new to this forum and from the looks of things I should post my problem here instead of studying what has worked for the other people who have encountered this virus. So I'll start with my problem and will look at what other people have gone through until I get a response. About 24 hours ago I was trying to download a resume template from microsoft.com of all places when I ran into some ActiveX problems. The template would not download until ActiveX would download so I changed a few settings to get it to download. About 20 minutes later I started getting a lot of spyware alerts and system alerts stating I had a virus and spyware, none of which came from my norton 360 or my cyberdender. Instead the alerts came from some other source which offered there own solution to these attacks. After homepage and background changed and a scan from Norton found nothing I knew I was in trouble. Some investigating led me to another virus scan by another program which claims that TR VUNDO.GEN was the culprit. I have been trying ever since to find and remove this viscious virus.

Any help would be appreciated. In the mean time I'm going to continue roving this forum to see what has helped others and download things such as hijackthis. The only thing I have done thus far is is download a process explorer, pocket killbox, and a registry editor. I was unable to locate the vrus key with the registry editerand am at a stopping point with that. I'm running Windows XP service pack 2 with a router installed.
  • 0

Advertisements


#2
BHowett

BHowett

    OT Moderator

  • Moderator
  • 4,649 posts
Hi bggb,

Hello and welcome to Geeks To Go! My name is BHowett and I will be helping you to get sorted. If for any reason you do not understand any of the instructions, or are just unsure then please do not guess , simply post back with your question, and we will go through it again.

The fixes may take several attempts and my replies may take some time but stick with it, and we will be sure to get you sorted.


Please do not use pocket killbox to delete anything or edit the registry, unless you are instructed by me here in this topic.



lets get a Hijackthis log to take a look at.....



Click here to download HJTInstall.exe
  • Save HJTInstall.exe to your desktop.
  • Doubleclick on the HJTInstall.exe icon on your desktop.
  • By default it will install to C:\Program Files\Trend Micro\HijackThis .
  • Click on Install.
  • It will create a HijackThis icon on the desktop.
  • Once installed, it will launch Hijackthis.
  • Click on the Do a system scan and save a logfile button. It will scan and the log should open in notepad.
  • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
  • Come back here to this thread and Paste the log in your next reply.
  • DO NOT have Hijackthis fix anything yet. Most of what it finds will be harmless or even required.

  • 0

#3
bggb

bggb

    Member

  • Topic Starter
  • Member
  • PipPip
  • 43 posts
Thanks for the help BHOWETT here is the hjt log:



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:02:41 PM, on 4/17/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\eFax Messenger 4.3\J2GTray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\InterVideo\WinDVD Media Center\SchSvr.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\Program Files\Symantec\LiveUpdate\luall.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityrespo...r/fix_homepage/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://securityrespo...r/fix_homepage/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.c...rch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityrespo...r/fix_homepage/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft....k/?LinkId=74005
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - ~CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: CyberDefender safeSEARCH - {F35CE83E-9EBF-40d5-AE87-53F982389740} - C:\Documents and Settings\winkylocc\Local Settings\Application Data\CyberDefender\ssstbar.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O3 - Toolbar: CyberDefender safeSEARCH - {F35CE83E-9EBF-40d5-AE87-53F982389740} - C:\Documents and Settings\winkylocc\Local Settings\Application Data\CyberDefender\ssstbar.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\UIBHO.dll
O3 - Toolbar: qtvglped - {C130E860-7C1C-44F0-996C-1F995C10B61E} - C:\WINDOWS\qtvglped.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [CyberDefender Early Detection Center] "C:\Program Files\CyberDefender\AntiSpyware\ISSIntro.exe"
O4 - HKLM\..\Run: [5893ec0f] rundll32.exe "C:\WINDOWS\system32\nkfrlfnd.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKLM\..\Policies\Explorer\Run: [] 
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: eFax 4.3.lnk = C:\Program Files\eFax Messenger 4.3\J2GTray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: InterVideo Scheduler server.lnk = C:\Program Files\InterVideo\WinDVD Media Center\SchSvr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - http://www.symantec....abs/tgctlsr.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace....ploader1006.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail....es/MSNPUpld.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://www.slide.com...ageUploader.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symant...ex/symdlmgr.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - http://www.nick.com/.../GrooveAX27.cab
O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} - http://imikimi.com/d...kimi_plugin.cab
O21 - SSODL: pmsoarbf - {68D2C92F-4957-4F16-BB95-BDD0EC7C11A6} - C:\WINDOWS\pmsoarbf.dll
O21 - SSODL: omlbpkaw - {C1C4537D-C4C2-4995-BDD3-527B63B24ACF} - C:\WINDOWS\omlbpkaw.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISHJVZZUJOTLC - Unknown owner - C:\DOCUME~1\TURKLO~1\LOCALS~1\Temp\ISHJVZZUJOTLC.exe (file missing)
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec RemoteAssist - Unknown owner - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe (file missing)
O23 - Service: TiVo Install Helper (TivoInstallHelper) - Unknown owner - C:\Documents.exe (file missing)
O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm

--
End of file - 11118 bytes
  • 0

#4
BHowett

BHowett

    OT Moderator

  • Moderator
  • 4,649 posts
Hi bggb,

Sure enough it looks like Vundo is present in your log…. :)



ComboFix

Please download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
  • Please, never rename Combofix unless instructed.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    -----------------------------------------------------------

    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

      -----------------------------------------------------------

    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

    -----------------------------------------------------------

  • Double click on combofix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review.
**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**
===============================================


Deckard's System Scanner

Please download Deckard's System Scanner (DSS) and save it to your Desktop.
  • Close all other windows before proceeding.
  • Double-click on dss.exe and follow the prompts.
  • When it has finished, dss will open two Notepads main.txt and extra.txt -- please copy (CTRL+A and then CTRL+C) and paste (CTRL+V) the contents of main.txt and extra.txt in your next reply.
===============================================

Needed in your next reply:

ComboFix log
Deckards main.txt and extra.txt



*Note* the logs may be to long for one post, so you may need to use two or more posts.
  • 0

#5
bggb

bggb

    Member

  • Topic Starter
  • Member
  • PipPip
  • 43 posts
downloaded combofix but it asks what program to use to open with. In the meantime here is DSS log:


115: 2008-04-15 16:42:49 UTC - RP435 - Removed Kilmist Registry Editor 2.5
114: 2008-04-15 16:36:07 UTC - RP434 - Installed Kilmist Registry Editor 2.5
113: 2008-04-15 16:34:47 UTC - RP433 - Removed Kilmist Registry Editor 2.5
112: 2008-04-15 16:32:57 UTC - RP432 - Installed Kilmist Registry Editor 2.5


-- First Restore Point --
1: 2008-04-15 07:03:06 UTC - RP321 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.

Total Physical Memory: 480 MiB (512 MiB recommended).


-- HijackThis (run as winkylocc.exe) -------------------------------------------

Unable to find log (file not found); running clone.
-- HijackThis Clone ------------------------------------------------------------


Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-04-18 07:31:34
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\eFax Messenger 4.3\J2GTray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\InterVideo\WinDVD Media Center\SchSvr.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\MMDiag.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\alg.exe
C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
C:\Program Files\Microsoft ActiveSync\rapimgr.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE
C:\Program Files\Symantec\LiveUpdate\LUALL.EXE
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Documents and Settings\winkylocc\Desktop\dss.exe
C:\Program Files\Trend Micro\HijackThis\winkylocc.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityrespo...r/fix_homepage/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft....k/?LinkId=74005
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://securityrespo...r/fix_homepage/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.c...rch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityrespo...r/fix_homepage/
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
R3 - URLSearchHook: (no name) - ~CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: CyberDefender safeSEARCH - {F35CE83E-9EBF-40d5-AE87-53F982389740} - C:\Documents and Settings\winkylocc\Local Settings\Application Data\CyberDefender\sssTbar.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {038D2921-2595-4D3B-A05E-84FE76F2C8ED} - C:\WINDOWS\system32\rqRLCUli.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\NppBHO.dll
O2 - BHO: DVA Storm - {5B434315-59C8-4480-8E72-058282FAAF1E} - C:\WINDOWS\lgmxvpatqgl.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: (no name) - {C14E6230-757D-4246-81CE-B34E2940C722} - C:\WINDOWS\system32\rqRJDtSI.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\Program Files\FlashFXP\IEFlash.dll
O2 - BHO: CyberDefender safeSEARCH - {F35CE83E-9EBF-40d5-AE87-53F982389740} - C:\Documents and Settings\winkylocc\Local Settings\Application Data\CyberDefender\sssTbar.dll
O3 - Toolbar: CyberDefender safeSEARCH - {F35CE83E-9EBF-40d5-AE87-53F982389740} - C:\Documents and Settings\winkylocc\Local Settings\Application Data\CyberDefender\sssTbar.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\UIBHO.dll
O3 - Toolbar: qtvglped - {C130E860-7C1C-44F0-996C-1F995C10B61E} - C:\WINDOWS\qtvglped.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [CyberDefender Early Detection Center] "C:\Program Files\CyberDefender\AntiSpyware\ISSIntro.exe"
O4 - HKLM\..\Run: [5893ec0f] rundll32.exe "C:\WINDOWS\system32\nkfrlfnd.dll",b
O4 - HKLM\..\RunOnceEx: [Flags] 128
O4 - HKLM\..\RunOnceEx: [Title] UnHackMe Rootkit Check
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: eFax 4.3.lnk = C:\Program Files\eFax Messenger 4.3\J2GTray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: InterVideo Scheduler server.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableTaskMgr=1
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: https://online.musicmatch.com (HKLM)
O15 - Trusted Zone: http://office.microsoft.com (HKCU)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macr...director/sw.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - http://www.symantec....abs/tgctlsr.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace....ploader1006.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail....es/MSNPUpld.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://www.slide.com...ageUploader.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symant...ex/symdlmgr.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} () - http://www.nick.com/.../GrooveAX27.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} () - http://fpdownload.ma...ent/swflash.cab
O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} () - http://imikimi.com/d...kimi_plugin.cab
O18 - Protocol: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL
O18 - Protocol: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: rqRJDtSI - C:\WINDOWS\system32\rqRJDtSI.dll
O21 - SSODL: pmsoarbf - {68D2C92F-4957-4F16-BB95-BDD0EC7C11A6} - C:\WINDOWS\pmsoarbf.dll
O21 - SSODL: omlbpkaw - {C1C4537D-C4C2-4995-BDD3-527B63B24ACF} - C:\WINDOWS\omlbpkaw.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISHJVZZUJOTLC - Unknown owner - C:\DOCUME~1\TURKLO~1\LOCALS~1\Temp\ISHJVZZUJOTLC.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec RemoteAssist - Unknown owner - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe
O23 - Service: TiVo Install Helper (TivoInstallHelper) - Unknown owner - C:\Documents and Settings\Turk loCC\Local Settings\Temp\MSI7.tmp
O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm

--
End of file - 13479 bytes

-- File Associations -----------------------------------------------------------

.bat - batfile - shell\edit\command - %SystemRoot%\System32\NOTEPAD.EXE %1"
.ini - inifile - shell\open\command - %SystemRoot%\System32\NOTEPAD.EXE %1"


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R2 MCSTRM - c:\windows\system32\drivers\mcstrm.sys <Not Verified; RealNetworks, Inc.; RealNetworks Virtual Path Manager® (32-bit)>

S3 ALABULK (Fujifilm USB MemoryCard ReaderWriter device driver) - c:\windows\system32\drivers\alabulk2.sys <Not Verified; Copyright © Fuji Photo film Co.,Ltd.; Fujifilm USB MemoryCard ReaderWriter USB Class Driver Win2K/XP>
S3 PsSdk30 - c:\windows\system32\drivers\pssdk30.drv (file missing)


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
R2 Bonjour Service - "c:\program files\bonjour\mdnsresponder.exe" <Not Verified; Apple Inc.; Bonjour>

S2 TivoInstallHelper (TiVo Install Helper) - "c:\documents and settings\turk locc\local settings\temp\msi7.tmp" /service (file missing)
S3 ISHJVZZUJOTLC - c:\docume~1\turklo~1\locals~1\temp\ishjvzzujotlc.exe (file missing)
S3 Symantec RemoteAssist - "c:\program files\common files\symantec shared\support controls\ssrc.exe" (file missing)


-- Device Manager: Disabled ----------------------------------------------------

No disabled devices found.


-- Files created between 2008-03-18 and 2008-04-18 -----------------------------

2008-04-18 02:45:51 9 --a------ C:\WINDOWS\system32\5893fe81
2008-04-17 23:32:44 0 d-------- C:\VundoFix Backups
2008-04-17 22:47:56 0 d-------- C:\Program Files\Trend Micro
2008-04-17 22:39:54 88128 --a------ C:\WINDOWS\system32\nkfrlfnd.dll
2008-04-15 12:47:58 0 d-------- C:\Program Files\RegCOPA
2008-04-15 12:47:58 0 d-------- C:\Program Files\Common Files\InterVations
2008-04-15 12:47:58 0 d-------- C:\Documents and Settings\All Users\Application Data\InterVations
2008-04-15 12:21:13 0 d-------- C:\Program Files\CCleaner
2008-04-15 11:05:53 0 d-------- C:\Program Files\RegistryFix
2008-04-15 10:57:43 0 d-------- C:\Documents and Settings\winkylocc\Application Data\Ahead
2008-04-15 10:57:27 0 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-15 09:45:21 0 d-------- C:\!KillBox
2008-04-15 04:38:30 0 d-------- C:\Documents and Settings\LocalService\Application Data\AdobeUM
2008-04-15 04:33:16 0 d-------- C:\Documents and Settings\LocalService\Application Data\Adobe
2008-04-15 04:30:50 0 d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-04-15 03:03:49 0 d-------- C:\WINDOWS\privacy_danger
2008-04-15 03:03:45 0 d-------- C:\Documents and Settings\winkylocc\Application Data\TmpRecentIcons
2008-04-15 02:59:52 0 d-------- C:\Program Files\Bonjour
2008-04-15 02:59:41 0 d-------- C:\Program Files\akl
2008-04-14 21:49:42 2359296 --a------ C:\Documents and Settings\winkylocc\ntuser.dat
2008-04-14 21:49:39 233472 --a------ C:\Documents and Settings\LocalService\ntuser.dat
2008-04-14 21:48:17 186820 --ahs---- C:\WINDOWS\system32\ilUCLRqr.ini2
2008-04-14 21:48:09 273408 --a------ C:\WINDOWS\system32\rqRLCUli.dll
2008-04-14 21:14:25 4096 --a------ C:\WINDOWS\userconfig9x.dll
2008-04-14 21:14:25 4096 --a------ C:\WINDOWS\system32winlogonpc.exe
2008-04-14 21:14:25 4096 --a------ C:\WINDOWS\system32hoproxy.dll
2008-04-14 21:14:25 4096 --a------ C:\WINDOWS\FVProtect.exe
2008-04-14 21:14:24 4096 --a------ C:\WINDOWS\system32taack.exe
2008-04-14 21:14:24 4096 --a------ C:\WINDOWS\system32taack.dat
2008-04-14 21:14:24 4096 --a------ C:\WINDOWS\system32sncntr.exe
2008-04-14 21:14:24 4096 --a------ C:\WINDOWS\system32psoft1.exe
2008-04-14 21:14:24 4096 --a------ C:\WINDOWS\system32psof1.exe
2008-04-14 21:14:24 4096 --a------ C:\WINDOWS\system32ps1.exe
2008-04-14 21:14:24 4096 --a------ C:\WINDOWS\system32mwin32.exe
2008-04-14 21:14:24 4096 --a------ C:\WINDOWS\system32msnbho.dll
2008-04-14 21:14:24 4096 --a------ C:\WINDOWS\system32hxiwlgpm.exe
2008-04-14 21:14:24 4096 --a------ C:\WINDOWS\system32hxiwlgpm.dat
2008-04-14 21:14:24 4096 --a------ C:\WINDOWS\system32bsva-egihsg52.exe
2008-04-14 21:14:24 4096 --a------ C:\WINDOWS\iTunesMusic.exe
2008-04-14 21:14:24 4096 --a------ C:\WINDOWS\a.bat
2008-04-14 21:14:24 0 d-------- C:\Documents and Settings\winkylocc\Desktopvirii
2008-04-14 21:14:23 4096 --a------ C:\WINDOWS\system32temp#01.exe
2008-04-14 21:14:23 4096 --a------ C:\WINDOWS\system32ssvchost.exe
2008-04-14 21:14:23 4096 --a------ C:\WINDOWS\system32ssvchost.com
2008-04-14 21:14:23 4096 --a------ C:\WINDOWS\system32ssurf022.dll
2008-04-14 21:14:23 0 d-------- C:\WINDOWS\system32smp
2008-04-14 21:14:23 4096 --a------ C:\WINDOWS\system32regm64.dll
2008-04-14 21:14:23 4096 --a------ C:\WINDOWS\system32regc64.dll
2008-04-14 21:14:23 4096 --a------ C:\WINDOWS\system32netode.exe
2008-04-14 21:14:23 4096 --a------ C:\WINDOWS\system32mtr2.exe
2008-04-14 21:14:23 4096 --a------ C:\WINDOWS\system32msvchost.exe
2008-04-14 21:14:23 4096 --a------ C:\WINDOWS\system32msgp.exe
2008-04-14 21:14:23 4096 --a------ C:\WINDOWS\system32medup020.dll
2008-04-14 21:14:23 4096 --a------ C:\WINDOWS\system32medup012.dll
2008-04-14 21:14:23 4096 --a------ C:\WINDOWS\system32h@tkeysh@@k.dll
2008-04-14 21:14:23 4096 --a------ C:\WINDOWS\system32dpcproxy.exe
2008-04-14 21:14:23 0 d-------- C:\Program Files\Inet Delivery
2008-04-14 21:14:22 4096 --a------ C:\WINDOWS\winsystem.exe
2008-04-14 21:14:22 4096 --a------ C:\WINDOWS\system32winsystem.exe
2008-04-14 21:14:22 4096 --a------ C:\WINDOWS\system32vcatchpi.dll
2008-04-14 21:14:22 4096 --a------ C:\WINDOWS\system32thun32.dll
2008-04-14 21:14:22 4096 --a------ C:\WINDOWS\system32thun.dll
2008-04-14 21:14:22 4096 --a------ C:\WINDOWS\system32Rundl1.exe
2008-04-14 21:14:22 4096 --a------ C:\WINDOWS\system32newsd32.exe
2008-04-14 21:14:22 4096 --a------ C:\WINDOWS\system32mssecu.exe
2008-04-14 21:14:22 4096 --a------ C:\WINDOWS\system32emesx.dll
2008-04-14 21:14:22 4096 --a------ C:\WINDOWS\system32anticipator.dll
2008-04-14 21:14:22 4096 --a------ C:\WINDOWS\system32akttzn.exe
2008-04-14 21:14:22 4096 --a------ C:\WINDOWS\mssecu.exe
2008-04-14 21:14:22 4096 --a------ C:\WINDOWS\bdn.com
2008-04-14 21:14:22 4096 --a------ C:\Documents and Settings\winkylocc\DesktopFWebdEditor.exe
2008-04-14 21:14:22 4096 --a------ C:\Documents and Settings\winkylocc\Desktopfwebd.exe
2008-04-14 21:14:22 4096 --a------ C:\Documents and Settings\winkylocc\Desktopfilemanagerclient.exe
2008-04-14 21:14:21 4096 --a------ C:\WINDOWS\system32WINWGPX.EXE
2008-04-14 21:14:21 4096 --a------ C:\WINDOWS\system32vbsys2.dll
2008-04-14 21:14:21 4096 --a------ C:\WINDOWS\system32sysreq.exe
2008-04-14 21:14:21 4096 --a------ C:\WINDOWS\system32bdn.com
2008-04-14 21:14:21 4096 --a------ C:\WINDOWS\system32awtoolb.dll
2008-04-14 21:14:21 0 d-------- C:\WINDOWS\mslagent
2008-04-14 21:14:18 98304 --a------ C:\WINDOWS\rtqmekwg.exe
2008-04-14 21:14:18 200704 --a------ C:\WINDOWS\qtvglped.dll
2008-04-14 21:14:18 188416 --a------ C:\WINDOWS\pmsoarbf.dll
2008-04-14 21:14:18 217088 --a------ C:\WINDOWS\omlbpkaw.dll
2008-04-14 21:14:18 94208 --a------ C:\WINDOWS\npqtsrak.exe
2008-04-14 21:14:18 245760 --a------ C:\WINDOWS\lgmxvpatqgl.dll
2008-04-14 21:14:10 0 d-------- C:\Documents and Settings\All Users\Application Data\qfsfuncr
2008-04-14 21:13:51 40448 --a------ C:\WINDOWS\system32\rqRJDtSI.dll
2008-03-31 11:37:59 0 d-------- C:\Documents and Settings\winkylocc\Application Data\Printer Info Cache
2008-03-31 11:37:56 0 d-------- C:\Documents and Settings\winkylocc\Application Data\Image Zone Express


-- Find3M Report ---------------------------------------------------------------

2008-04-18 00:17:20 0 d-------- C:\Program Files\Spyware Doctor
2008-04-15 12:47:58 0 d-------- C:\Program Files\Common Files
2008-04-15 12:36:08 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-04-15 10:44:59 0 d-------- C:\Documents and Settings\winkylocc\Application Data\HP
2008-04-10 10:28:16 0 d-------- C:\Program Files\Norton 360
2008-03-18 10:52:32 0 d-------- C:\Documents and Settings\winkylocc\Application Data\Adobe
2008-03-16 14:02:16 0 d-------- C:\Program Files\Java
2008-03-16 13:44:24 0 d-------- C:\Program Files\Common Files\Symantec Shared
2008-03-14 10:02:43 0 d-------- C:\Program Files\BearShare Applications
2008-03-14 00:16:38 0 d-------- C:\Documents and Settings\winkylocc\Application Data\BitTorrent
2008-03-12 12:43:58 0 d-------- C:\Documents and Settings\winkylocc\Application Data\AdobeAUM
2008-03-12 12:41:22 0 d-------- C:\Documents and Settings\winkylocc\Application Data\DivX
2008-03-05 14:28:05 0 d-------- C:\Documents and Settings\winkylocc\Application Data\Real
2008-03-01 09:50:19 130496 --a------ C:\WINDOWS\HPHins13.dat
2008-03-01 03:02:09 0 d-------- C:\Program Files\Common Files\HP
2008-03-01 02:54:04 0 d-------- C:\Program Files\HP
2008-02-28 22:38:52 0 d-------- C:\Program Files\Microsoft Works
2008-02-28 20:40:08 0 d-------- C:\Documents and Settings\winkylocc\Application Data\Help
2008-02-26 18:24:50 0 d-------- C:\Documents and Settings\winkylocc\Application Data\Sun
2008-02-22 13:14:52 0 d-------- C:\Documents and Settings\winkylocc\Application Data\eFax Messenger
2008-02-21 17:32:36 0 d-------- C:\Program Files\eFax Messenger 4.3
2008-02-21 17:31:51 0 --a------ C:\WINDOWS\system32\eFax_4_3_Port
2008-02-18 20:26:37 2508 --a------ C:\Documents and Settings\winkylocc\Application Data\$_hpcst$.hpc
2008-02-18 20:03:36 0 d-------- C:\Documents and Settings\winkylocc\Application Data\Yahoo!
2008-02-18 18:44:38 0 d-------- C:\Documents and Settings\winkylocc\Application Data\AdobeUM
2008-02-16 00:13:01 225604497 --a------ C:\WINDOWS\system32\xpocache.dll


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{038D2921-2595-4D3B-A05E-84FE76F2C8ED}]
04/14/2008 09:48 PM 273408 --a------ C:\WINDOWS\system32\rqRLCUli.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5B434315-59C8-4480-8E72-058282FAAF1E}]
04/14/2008 03:11 PM 245760 --a------ C:\WINDOWS\lgmxvpatqgl.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C14E6230-757D-4246-81CE-B34E2940C722}]
04/14/2008 09:13 PM 40448 --a------ C:\WINDOWS\system32\rqRJDtSI.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [07/17/2007 09:54 PM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [02/01/2008 12:13 AM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [02/04/2008 03:18 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe" [05/03/2006 02:56 AM]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [01/29/2008 06:38 PM]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [12/10/2006 10:52 PM]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [06/07/2005 12:46 AM]
"RegistryMechanic"="" []
"MMTray"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [01/19/2006 11:06 AM]
"MimBoot"="C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe" [01/19/2006 11:06 AM]
"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" []
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe" [05/14/2003 03:01 AM]
"CyberDefender Early Detection Center"="C:\Program Files\CyberDefender\AntiSpyware\ISSIntro.exe" [02/10/2008 09:10 PM]
"5893ec0f"="C:\WINDOWS\system32\nkfrlfnd.dll" [04/17/2008 10:39 PM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 08:00 AM]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [10/18/2006 08:05 PM]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"MySpaceIM"=C:\Program Files\MySpace\IM\MySpaceIM.exe

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [9/23/2005 10:05:26 PM]
eFax 4.3.lnk - C:\Program Files\eFax Messenger 4.3\J2GTray.exe [2/21/2008 5:31:34 PM]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [1/2/2007 10:40:10 PM]
InterVideo Scheduler server.lnk - C:\Program Files\InterVideo\WinDVD Media Center\SchSvr.exe [6/22/2006 2:48:25 AM]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2/13/2001 2:01:04 AM]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableCMD"=0 (0x0)
"DisableRegistryTools"=0 (0x0)
"DisableTaskMgr"=0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"=1 (0x1)
"DisableRegistryTools"=0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
@=1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoFind"=0 (0x0)
"NoFolderOptions"=0 (0x0)
"NoLogoff"=0 (0x0)
"NoSetFolders"=0 (0x0)
"NoViewContextMenu"=0 (0x0)
"Norun"=0 (0x0)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoFind"=0 (0x0)
"NoFolderOptions"=0 (0x0)
"NoLogoff"=0 (0x0)
"NoSetFolders"=0 (0x0)
"NoViewContextMenu"=0 (0x0)
"Norun"=0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= file:///C:\WINDOWS\privacy_danger\index.htm
FriendlyName= Privacy Protection

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{C14E6230-757D-4246-81CE-B34E2940C722}"= C:\WINDOWS\system32\rqRJDtSI.dll [04/14/2008 09:13 PM 40448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"pmsoarbf"= {68D2C92F-4957-4F16-BB95-BDD0EC7C11A6} - C:\WINDOWS\pmsoarbf.dll [04/14/2008 03:11 PM 188416]
"omlbpkaw"= {C1C4537D-C4C2-4995-BDD3-527B63B24ACF} - C:\WINDOWS\omlbpkaw.dll [04/14/2008 03:11 PM 217088]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rqRJDtSI]
rqRJDtSI.dll 04/14/2008 09:13 PM 40448 C:\WINDOWS\system32\rqRJDtSI.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\rqRLCUli

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"UleadBurningHelper"=2 (0x2)
"SPBBCSvc"=2 (0x2)
"ITMRTSVC"=2 (0x2)
"SNDSrvc"=2 (0x2)
"SAVScan"=3 (0x3)
"rpcapd"=3 (0x3)
"NSCService"=3 (0x3)
"NPFMntor"=2 (0x2)
"navapsvc"=2 (0x2)
"gusvc"=3 (0x3)
"AVGEMS"=2 (0x2)
"Avg7UpdSvc"=2 (0x2)
"Avg7Alrt"=2 (0x2)
"Automatic LiveUpdate Scheduler"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt hpqcxs08 hpqddsvc


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
AutoRun\command- D:\setup.exe

*Newly Created Service* - COMHOST



-- End of Deckard's System Scanner: finished at 2008-04-18 08:02:54 ------------

There is a extra.text notepad but im struggling to open it.
  • 0

#6
bggb

bggb

    Member

  • Topic Starter
  • Member
  • PipPip
  • 43 posts
Here is the rest of dss:

Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------

-- System Information ----------------------------------------------------------

Microsoft Windows XP Professional (build 2600) SP 2.0
Architecture: X86; Language: English

CPU 0: AMD Athlon™ XP 2400+
Percentage of Memory in Use: 55%
Physical Memory (total/avail): 479.48 MiB / 215.03 MiB
Pagefile Memory (total/avail): 1122.08 MiB / 443.37 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1936.25 MiB

A: is Removable (No Media)
C: is Fixed (NTFS) - 149.05 GiB total, 58.85 GiB free.
D: is CDROM (CDFS)
E: is CDROM (No Media)

\\.\PHYSICALDRIVE0 - WDC WD1600JB-00REA0 - 149.05 GiB - 1 partition
\PARTITION0 (bootable) - Installable File System - 149.05 GiB - C:



-- Security Center -------------------------------------------------------------

AUOptions is scheduled to auto-install.
Windows Internal Firewall is enabled.

FirstRunDisabled is set.

FW: Norton 360 v2007 (SYMANTEC Corporation)
AV: Norton 360 v2007 (SYMANTEC Corperation)
AV: CyberDefender Internet Security v2008 (CyberDefender)

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"="C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"C:\\Program Files\\FlashFXP\\FlashFXP.exe"="C:\\Program Files\\FlashFXP\\FlashFXP.exe:*:Enabled:FlashFXP v3"

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\\WINDOWS\\system32\\usmt\\migwiz.exe"="C:\\WINDOWS\\system32\\usmt\\migwiz.exe:*:Enabled:Files and Settings Transfer Wizard"
"C:\\Program Files\\Kazaa\\kazaa.exe"="C:\\Program Files\\Kazaa\\kazaa.exe:*:Enabled:Kazaa"
"C:\\Program Files\\InterVideo\\WinDVD Media Center\\IHT.exe"="C:\\Program Files\\InterVideo\\WinDVD Media Center\\IHT.exe:*:Enabled:Home Theater"
"C:\\Program Files\\InterVideo\\IMCSvr\\IMCSvr.exe"="C:\\Program Files\\InterVideo\\IMCSvr\\IMCSvr.exe:*:Enabled:InterVideo IMC Server"
"C:\\Program Files\\XLink Kai Evolution VII\\kaiLaunch.exe"="C:\\Program Files\\XLink Kai Evolution VII\\kaiLaunch.exe:*:Enabled:XLink Kai Evolution 7 Launcher"
"C:\\Program Files\\XLink Kai Evolution VII\\kaiEngine.exe"="C:\\Program Files\\XLink Kai Evolution VII\\kaiEngine.exe:*:Enabled:XLink Kai Evolution 7 Engine"
"C:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"="C:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe:*:Disabled:Nero Home"
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"="C:\\Program Files\\Real\\RealPlayer\\realplay.exe:*:Enabled:RealPlayer"
"C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"="C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"C:\\Program Files\\Warez\\Warez.exe"="C:\\Program Files\\Warez\\Warez.exe:*:Enabled:Warez3"
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"="C:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe:*:Enabled:AOL TopSpeed"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"="C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE:*:Disabled:Internet Explorer"
"C:\\Program Files\\SmartXX\\RemoteFlasher\\Smartxx.exe"="C:\\Program Files\\SmartXX\\RemoteFlasher\\Smartxx.exe:*:Enabled:SmartXX Remote Tool v1"
"C:\\Program Files\\FlashFXP\\FlashFXP.exe"="C:\\Program Files\\FlashFXP\\FlashFXP.exe:*:Enabled:FlashFXP v3"
"C:\\Program Files\\mIRC\\mirc.exe"="C:\\Program Files\\mIRC\\mirc.exe:*:Enabled:mIRC"
"C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"="C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe:*:Enabled:MySpaceIM"
"C:\\WINDOWS\\LMI17.tmp\\lmi_rescue.exe"="C:\\WINDOWS\\LMI17.tmp\\lmi_rescue.exe:*:Enabled:LogMeIn Rescue"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\DNA\\btdna.exe"="C:\\Program Files\\DNA\\btdna.exe:*:Enabled:DNA"
"C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
"C:\\Program Files\\Microsoft Office\\Office12\\WINWORD.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\WINWORD.EXE:*:Enabled:Microsoft Office Word"
"C:\\WINDOWS\\system32\\ftp.exe"="C:\\WINDOWS\\system32\\ftp.exe:*:Enabled:File Transfer Program"
"C:\\Program Files\\CyberDefender\\AntiSpyware\\CyberDefenderEDC.exe"="C:\\Program Files\\CyberDefender\\AntiSpyware\\CyberDefenderEDC.exe:*:Enabled:CyberDefender Internet Security"


-- Environment Variables -------------------------------------------------------

ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\winkylocc\Application Data
CLASSPATH=.;C:\Program Files\Java\jre1.5.0_07\lib\ext\QTJava.zip
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=USN-1817DA3CE2C
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\winkylocc
LOGONSERVER=\\USN-1817DA3CE2C
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\Program Files\Internet Explorer;;C:\WINDOWS\system32;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\QuickTime\QTSystem\
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 6 Model 8 Stepping 1, AuthenticAMD
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=0801
ProgramFiles=C:\Program Files
PROMPT=$P$G
QTJAVA=C:\Program Files\Java\jre1.5.0_07\lib\ext\QTJava.zip
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\WINKYL~1\LOCALS~1\Temp
TMP=C:\DOCUME~1\WINKYL~1\LOCALS~1\Temp
USERDOMAIN=USN-1817DA3CE2C
USERNAME=winkylocc
USERPROFILE=C:\Documents and Settings\winkylocc
windir=C:\WINDOWS


-- User Profiles ---------------------------------------------------------------

Turk loCC (admin)
Cee-Cee (admin)
Ce (admin)
winkylocc (admin)
Guest (guest)


-- Add/Remove Programs ---------------------------------------------------------

--> "C:\Program Files\CyberDefender\cdinstx.exe" /u "C:\Program Files\CyberDefender\earlySpam\cdinstx.log" /t "CyberDefender Early Detection Center - AntiSpam"
--> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
--> C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-0016-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-0018-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-001A-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-001B-0409-0000-0000000FF1CE} /uninstall {4CA4ECC1-DBD4-4591-8F4C-AA12AD2D3E59}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {3EC77D26-799B-4CD8-914F-C1565E796173}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {430971B1-C31E-45DA-81E0-72C095BAB72C}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {F7A31780-33C4-4E39-951A-5EC9B91D7BF1}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {FAD8A83E-9BAC-4179-9268-A35948034D85}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {90120000-0115-0409-0000-0000000FF1CE} /uninstall {FAD8A83E-9BAC-4179-9268-A35948034D85}
2007 Microsoft Office Suite Service Pack 1 (SP1) --> msiexec /package {91120000-0012-0000-0000-0000000FF1CE} /uninstall {BEE75E01-DD3F-4D5F-B96C-609E6538D419}
Adobe Reader 7.0.9 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70900000002}
Adobe Shockwave Player --> C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
Adobe® Photoshop® Album Starter Edition 3.0 --> MsiExec.exe /I{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}
Adobe® Photoshop® Album Starter Edition 3.0.1 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C9618743-1A5C-461E-91C4-E013A3D70F3C}\Setup.exe" -l0x9
AppCore --> MsiExec.exe /I{EFB5B3B5-A280-4E25-BE1C-634EEFE32C1B}
Apple Mobile Device Support --> MsiExec.exe /I{D8AB8F0C-CEEB-4A29-8EF5-219B064813F4}
Apple Software Update --> MsiExec.exe /I{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}
AV --> MsiExec.exe /I{F4DB525F-A986-4249-B98B-42A8066251CA}
Bonjour --> MsiExec.exe /I{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}
ccCommon --> MsiExec.exe /I{3CCAD2EF-CFF2-4637-82AA-AABF370282D3}
CCleaner (remove only) --> "C:\Program Files\CCleaner\uninst.exe"
ChessRally 2.5 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{235B3B96-A129-411C-A0DE-DA154590F5D3}\setup.exe" -l0x9 -removeonly
CuteFTP 8 Professional --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{91F34319-08DE-457A-99C0-0BCDFAC145B9}\Setup.exe" -l0x9
CyberDefender Early Detection Center --> C:\Program Files\CyberDefender\cdinstx.exe /u
DivX Codec --> C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
DivX Content Uploader --> C:\Program Files\DivX\DivXContentUploaderUninstall.exe /CUPLOADER
DivX Converter --> C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
DivX Player --> C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
DivX Web Player --> C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
eFax Messenger 4.3 --> C:\Program Files\eFax Messenger 4.3\Uninstall.exe
FlashFXP v3 --> "C:\Program Files\FlashFXP\Uninstall.exe" "C:\Program Files\FlashFXP\install.log" -u
Fujifilm USB MemoryCard ReaderWriter --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{F87F471C-66C0-4F70-B493-6E59E4D402E6} /l1033
GearDrvs --> MsiExec.exe /I{206FD69B-F9FE-4164-81BD-D52552BC9C23}
HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
HP Customer Participation Program 8.0 --> C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
hp deskjet 3320 series --> rundll32 hpzcon07.dll,VendorJettison hp deskjet 3320 series
hp deskjet 3320 series (Remove only) --> C:\Program Files\hp deskjet 3320 series\hpfiui.exe -c -vdivid=HPF -vpnum=95 -vinstport=USB001 -vproduct=3320 -huninstall
HP Deskjet 8.0 Software --> C:\Program Files\HP\Digital Imaging\{58535A90-1788-44f5-80BB-CFF62D9CE6D5}\setup\hpzscr01.exe -datfile hphscr13.dat -showdisconnect -forcereboot
HP Imaging Device Functions 8.0 --> C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
HP Photosmart Essential --> MsiExec.exe /X{EB21A812-671B-4D08-B974-2A347F0D8F70}
HP Solution Center 8.0 --> C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
HP Update --> MsiExec.exe /X{8C6027FD-53DC-446D-BB75-CACD7028A134}
HPSSupply --> MsiExec.exe /X{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}
IHT3 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9BE1F9C6-DDC3-43FD-BC59-59524C5B0927}\setup.exe"
iTunes --> MsiExec.exe /I{02DFB3FD-CF52-4183-8BCA-2A127D4888F4}
J2SE Runtime Environment 5.0 Update 7 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150070}
Java™ 6 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
Java™ 6 Update 5 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
Java™ SE Runtime Environment 6 Update 1 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
LiveUpdate 3.2 (Symantec Corporation) --> "C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U
LiveUpdate Notice (Symantec Corporation) --> MsiExec.exe /X{DBA4DB9D-EE51-4944-A419-98AB1F1249C8}
Magic ISO Maker v5.4 (build 0239) --> C:\PROGRA~1\MagicISO\UNWISE.EXE C:\PROGRA~1\MagicISO\INSTALL.LOG
Microsoft ActiveSync 4.0 --> MsiExec.exe /I{B208806F-A231-4FA0-AB3F-5C1B8979223E}
Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Office Excel MUI (English) 2007 --> MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE}
Microsoft Office Outlook MUI (English) 2007 --> MsiExec.exe /X{90120000-001A-0409-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (English) 2007 --> MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007 --> MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007 --> MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007 --> MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (English) 2007 --> MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
Microsoft Office Shared MUI (English) 2007 --> MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
Microsoft Office Shared Setup Metadata MUI (English) 2007 --> MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
Microsoft Office Standard 2007 --> MsiExec.exe /X{91120000-0012-0000-0000-0000000FF1CE}
Microsoft Office Standard 2007 Trial --> "C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall STANDARDR /dll OSETUP.DLL
Microsoft Office Word MUI (English) 2007 --> MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
Microsoft Outlook 2002 --> MsiExec.exe /I{911A0409-6000-11D3-8CFE-0050048383C9}
Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
mIRC --> "C:\Program Files\mIRC\mirc.exe" -uninstall
Musicmatch® Jukebox --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{85D3CC30-8859-481A-9654-FD9B74310BEF}\setup.exe" -l0x9 -uninst
Nero 6 Ultra Edition --> C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
Nero Digital --> C:\WINDOWS\UNNeroVision.exe /UNINSTALL
Norton 360 --> MsiExec.exe /I{21829177-4DED-4209-AD08-490B3AC9C01A}
Norton 360 --> MsiExec.exe /I{2D617065-1C52-4240-B5BC-C0AE12157777}
Norton 360 --> MsiExec.exe /I{63A6E9A9-A190-46D4-9430-2DB28654AFD8}
Norton 360 (Symantec Corporation) --> "C:\Program Files\Common Files\Symantec Shared\SymSetup\{2D617065-1C52-4240-B5BC-C0AE12157777}_1_3_0_24\{2D617065-1C52-4240-B5BC-C0AE12157777}.exe" /X
Norton 360 Help --> MsiExec.exe /I{1CA941F1-5006-487E-9FD4-09F812A7D6B8}
Norton Confidential Browser Component --> MsiExec.exe /I{4843B611-8FCB-4428-8C23-31D0A5EAE164}
Norton Confidential Web Authentification Component --> MsiExec.exe /I{3074EB89-1BCA-4AEF-AFF4-EFB4634C1923}
Norton Confidential Web Protection Component --> MsiExec.exe /I{D353CC51-430D-4C6F-9B7E-52003DA1E05A}
Protected Music Converter 0.99.29b --> "C:\Program Files\WMA-MP3.com\Protected Music Converter\unins000.exe"
QuickTime --> MsiExec.exe /I{BFD96B89-B769-4CD6-B11E-E79FFD46F067}
RealPlayer --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
RegCOPA --> C:\Program Files\RegCOPA\Uninst.exe /U "C:\Program Files\RegCOPA\uninst.log"
Registry Mechanic 7.0 --> "C:\Program Files\Registry Mechanic\unins000.exe"
RegistryFix v6.2 --> "C:\Program Files\RegistryFix\unins000.exe"
Rhapsody --> C:\PROGRA~1\Rhapsody\Unwise32.exe /A C:\PROGRA~1\Rhapsody\install.log
Rhapsody Player Engine --> MsiExec.exe /I{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}
safeSEARCH Toolbar (CyberDefender Corporation) --> C:\Documents and Settings\winkylocc\Local Settings\Application Data\CyberDefender\cdinstx.exe /u
Security Update for Excel 2007 (KB946974) --> msiexec /package {91120000-0012-0000-0000-0000000FF1CE} /uninstall {85E83E2E-AF9B-439B-B4F9-EB9B7EF6A00E}
Security Update for Office 2007 (KB947801) --> msiexec /package {91120000-0012-0000-0000-0000000FF1CE} /uninstall {02B5A17B-01BE-4BA6-95F1-1CBB46EBC76E}
Security Update for Outlook 2007 (KB946983) --> msiexec /package {91120000-0012-0000-0000-0000000FF1CE} /uninstall {66B9496E-C0C3-4065-9868-85CCA92126C3}
Security Update for Visio 2007 (KB947590) --> msiexec /package {91120000-0012-0000-0000-0000000FF1CE} /uninstall {6BAD036C-261F-4BEF-96CF-C20678D07A41}
Smart DVD Creator Pro --> "C:\Program Files\SmartDVDCreatorPro\unins000.exe"
SmartXX --> MsiExec.exe /I{627382CB-A214-4530-A91F-AB2F1D9EC254}
SPBBC 32bit --> MsiExec.exe /I{77772678-817F-4401-9301-ED1D01A8DA56}
Spyware Doctor 5.5 --> C:\Program Files\Spyware Doctor\unins000.exe /LOG
SuppSoft --> MsiExec.exe /I{022DA2C3-81C7-4003-A6BC-1BB147B20097}
Symantec Technical Support Controls --> MsiExec.exe /I{92B1B3CC-EC78-45B8-96D0-8B3F11495864}
Symantec Technical Support Web Controls --> MsiExec.exe /X{20C53FA2-4307-4671-A93F-9463B29DFCF1}
SymNet --> MsiExec.exe /I{2DA85B02-13C0-4E6D-9A76-22E6B3DD0CB2}
Update for Office 2007 (KB946691) --> msiexec /package {91120000-0012-0000-0000-0000000FF1CE} /uninstall {A420F522-7395-4872-9882-C591B4B92278}
Update for Outlook 2007 Junk Email Filter (kb949037) --> msiexec /package {91120000-0012-0000-0000-0000000FF1CE} /uninstall {B4F188C6-6DBF-42A5-A8A3-3086D1A384F2}
WebVideo Support --> C:\WINDOWS\rtqmekwg.exe
Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
WinMPG VideoConvert 6.8.0.4 --> "C:\Program Files\WinMPG VideoConvert\unins000.exe"
Yahoo! Internet Mail --> C:\WINDOWS\system32\regsvr32 /u /s C:\PROGRA~1\Yahoo!\Common\YMMAPI.dll


-- Application Event Log -------------------------------------------------------

Event Record #/Type22513 / Error
Event Submitted/Written: 04/18/2008 07:52:29 AM / 04/18/2008 07:52:30 AM
Event ID/Source: 1002 / Application Hang
Event Description:
Hanging application iexplore.exe, version 7.0.6000.16640, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

Event Record #/Type22512 / Error
Event Submitted/Written: 04/18/2008 06:46:55 AM
Event ID/Source: 1002 / Application Hang
Event Description:
Hanging application iexplore.exe, version 7.0.6000.16640, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

Event Record #/Type22461 / Warning
Event Submitted/Written: 04/15/2008 02:07:33 PM
Event ID/Source: 1524 / Userenv
Event Description:
Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use.

Event Record #/Type22460 / Error
Event Submitted/Written: 04/15/2008 11:39:44 AM
Event ID/Source: 1002 / Application Hang
Event Description:
Hanging application RegMech.exe, version 7.0.0.1010, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

Event Record #/Type22431 / Warning
Event Submitted/Written: 04/15/2008 10:44:57 AM
Event ID/Source: 4113 / Avira AntiVir
Event Description:
TR/Vundo.GenC:\WINDOWS\system32\rqRLCUli.dll



-- Security Event Log ----------------------------------------------------------

No Errors/Warnings found.


-- System Event Log ------------------------------------------------------------

Event Record #/Type28898 / Error
Event Submitted/Written: 04/18/2008 06:29:15 AM
Event ID/Source: 7011 / Service Control Manager
Event Description:
Timeout (30000 milliseconds) waiting for a transaction response from the stisvc service.

Event Record #/Type28885 / Error
Event Submitted/Written: 04/17/2008 11:47:44 PM
Event ID/Source: 10010 / DCOM
Event Description:
The server {0002DF01-0000-0000-C000-000000000046} did not register with DCOM within the required timeout.

Event Record #/Type28852 / Error
Event Submitted/Written: 04/17/2008 10:57:27 PM
Event ID/Source: 7000 / Service Control Manager
Event Description:
The TiVo Install Helper service failed to start due to the following error:
%%2

Event Record #/Type28846 / Error
Event Submitted/Written: 04/17/2008 10:56:13 PM / 04/17/2008 10:56:43 PM
Event ID/Source: 11 / Cdrom
Event Description:
The driver detected a controller error on \Device\CdRom1.

Event Record #/Type28845 / Error
Event Submitted/Written: 04/17/2008 10:56:13 PM / 04/17/2008 10:56:43 PM
Event ID/Source: 11 / Cdrom
Event Description:
The driver detected a controller error on \Device\CdRom1.



-- End of Deckard's System Scanner: finished at 2008-04-18 08:02:54 ------------
  • 0

#7
BHowett

BHowett

    OT Moderator

  • Moderator
  • 4,649 posts
Hi bggb,

Its very important that you run Combofix right from your desktop… Please delete the one you have now and, reinstall from my instruction below.

Download ComboFix from one of the locations below, and save it to your Desktop.

Link 1
Link 2
Link 3

Double click combofix.exe and follow the prompts. Please, never rename Combofix unless instructed.
When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix's window while its running. That may cause it to stall

===============================================


If that works, just post the ComboFix log in your next reply.


If that doesn’t work please follow the instruction below….



Please download VundoFix.exe to your desktop
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log in a reply to this thread.
Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button" when VundoFix appears upon rebooting.

===============================================

Needed in next reply:

Combofix log or Vundofix.txt
Fresh HijackThis log.
  • 0

#8
bggb

bggb

    Member

  • Topic Starter
  • Member
  • PipPip
  • 43 posts
It is working so far. Right now it is going through the completed stage and is on completed stage number 9.
  • 0

#9
BHowett

BHowett

    OT Moderator

  • Moderator
  • 4,649 posts
ahhh good to know, I will check back in a bit. :)
  • 0

#10
bggb

bggb

    Member

  • Topic Starter
  • Member
  • PipPip
  • 43 posts
OK here is the notepad log of combofix:


ComboFix 08-04-17.1 - winkylocc 2008-04-18 10:03:30.1 - NTFSx86
Running from: C:\Documents and Settings\winkylocc\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Ce\Application Data\ShoppingReport
C:\Documents and Settings\Ce\Application Data\ShoppingReport\cs\Config.xml
C:\Documents and Settings\Ce\Application Data\ShoppingReport\cs\db\Aliases.dbs
C:\Documents and Settings\Ce\Application Data\ShoppingReport\cs\db\Sites.dbs
C:\Documents and Settings\Ce\Application Data\ShoppingReport\cs\dwld\WhiteList.xip
C:\Documents and Settings\Ce\Application Data\ShoppingReport\cs\report\aggr_storage.xml
C:\Documents and Settings\Ce\Application Data\ShoppingReport\cs\report\send_storage.xml
C:\Documents and Settings\Ce\Application Data\ShoppingReport\cs\res1\WhiteList.dbs
C:\Documents and Settings\Guest\Application Data\FunWebProducts
C:\Documents and Settings\Guest\Application Data\FunWebProducts\Data\Guest\avatar.dat
C:\Documents and Settings\Guest\Favorites\Online Security Test.url
C:\Documents and Settings\winkylocc\Desktop\Error Cleaner.url
C:\Documents and Settings\winkylocc\Desktop\Privacy Protector.url
C:\Documents and Settings\winkylocc\Desktop\Spyware&Malware Protection.url
C:\Documents and Settings\winkylocc\Desktopblackbird.jpg
C:\Documents and Settings\winkylocc\DesktopEditorFKWP1.5.exe
C:\Documents and Settings\winkylocc\DesktopEditorFKWP2.0.exe
C:\Documents and Settings\winkylocc\Desktopfilemanagerclient.exe
C:\Documents and Settings\winkylocc\Desktopfkwp1.5.exe
C:\Documents and Settings\winkylocc\Desktopfkwp2.0.exe
C:\Documents and Settings\winkylocc\Desktopfwebd.exe
C:\Documents and Settings\winkylocc\DesktopFWebdEditor.exe
C:\Documents and Settings\winkylocc\DesktopTrojan.Win32.BlackBird.exe
C:\Documents and Settings\winkylocc\Desktopvirii
C:\Documents and Settings\winkylocc\Favorites\Error Cleaner.url
C:\Documents and Settings\winkylocc\Favorites\Privacy Protector.url
C:\Documents and Settings\winkylocc\Favorites\Spyware&Malware Protection.url
C:\Program Files\akl
C:\Program Files\akl\akl.dll
C:\Program Files\akl\akl.exe
C:\Program Files\akl\uninstall.exe
C:\Program Files\akl\unsetup.exe
C:\Program Files\Inet Delivery
C:\Program Files\Inet Delivery\inetdl.exe
C:\Program Files\Inet Delivery\intdel.exe
C:\WINDOWS\a.bat
C:\WINDOWS\base64.tmp
C:\WINDOWS\bdn.com
C:\WINDOWS\FVProtect.exe
C:\WINDOWS\iTunesMusic.exe
C:\WINDOWS\mslagent
C:\WINDOWS\mslagent\2_mslagent.dll
C:\WINDOWS\mslagent\mslagent.exe
C:\WINDOWS\mslagent\uninstall.exe
C:\WINDOWS\mssecu.exe
C:\WINDOWS\privacy_danger
C:\WINDOWS\privacy_danger\images\capt.gif
C:\WINDOWS\privacy_danger\images\danger.jpg
C:\WINDOWS\privacy_danger\images\down.gif
C:\WINDOWS\privacy_danger\images\spacer.gif
C:\WINDOWS\privacy_danger\index.htm
C:\WINDOWS\system32\dnflrfkn.ini
C:\WINDOWS\system32\nkfrlfnd.dll
C:\WINDOWS\system32\UpMedia
C:\WINDOWS\system32akttzn.exe
C:\WINDOWS\system32anticipator.dll
C:\WINDOWS\system32awtoolb.dll
C:\WINDOWS\system32bdn.com
C:\WINDOWS\system32bsva-egihsg52.exe
C:\WINDOWS\system32dpcproxy.exe
C:\WINDOWS\system32emesx.dll
C:\WINDOWS\system32h@tkeysh@@k.dll
C:\WINDOWS\system32hoproxy.dll
C:\WINDOWS\system32hxiwlgpm.dat
C:\WINDOWS\system32hxiwlgpm.exe
C:\WINDOWS\system32medup012.dll
C:\WINDOWS\system32medup020.dll
C:\WINDOWS\system32msgp.exe
C:\WINDOWS\system32msnbho.dll
C:\WINDOWS\system32mssecu.exe
C:\WINDOWS\system32msvchost.exe
C:\WINDOWS\system32mtr2.exe
C:\WINDOWS\system32mwin32.exe
C:\WINDOWS\system32netode.exe
C:\WINDOWS\system32newsd32.exe
C:\WINDOWS\system32ps1.exe
C:\WINDOWS\system32psof1.exe
C:\WINDOWS\system32psoft1.exe
C:\WINDOWS\system32regc64.dll
C:\WINDOWS\system32regm64.dll
C:\WINDOWS\system32Rundl1.exe
C:\WINDOWS\system32smp
C:\WINDOWS\system32smp\msrc.exe
C:\WINDOWS\system32sncntr.exe
C:\WINDOWS\system32ssurf022.dll
C:\WINDOWS\system32ssvchost.com
C:\WINDOWS\system32ssvchost.exe
C:\WINDOWS\system32sysreq.exe
C:\WINDOWS\system32taack.dat
C:\WINDOWS\system32taack.exe
C:\WINDOWS\system32temp#01.exe
C:\WINDOWS\system32thun.dll
C:\WINDOWS\system32thun32.dll
C:\WINDOWS\system32VBIEWER.OCX
C:\WINDOWS\system32vbsys2.dll
C:\WINDOWS\system32vcatchpi.dll
C:\WINDOWS\system32winlogonpc.exe
C:\WINDOWS\system32winsystem.exe
C:\WINDOWS\system32WINWGPX.EXE
C:\WINDOWS\userconfig9x.dll
C:\WINDOWS\Web\def.htm
C:\WINDOWS\winsystem.exe
C:\WINDOWS\zip1.tmp
C:\WINDOWS\zip2.tmp
C:\WINDOWS\zip3.tmp
C:\WINDOWS\zipped.tmp

.
((((((((((((((((((((((((( Files Created from 2008-03-18 to 2008-04-18 )))))))))))))))))))))))))))))))
.

2008-04-18 09:22 . 2008-04-18 09:37 <DIR> d-------- C:\327882R2FWJFW
2008-04-18 07:16 . 2008-04-18 07:16 <DIR> d-------- C:\Deckard
2008-04-18 02:45 . 2008-04-18 02:45 9 --a------ C:\WINDOWS\system32\5893fe81
2008-04-17 23:32 . 2008-04-17 23:32 <DIR> d-------- C:\VundoFix Backups
2008-04-17 22:47 . 2008-04-17 22:47 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-15 12:47 . 2008-04-15 12:48 <DIR> d-------- C:\Program Files\RegCOPA
2008-04-15 12:47 . 2008-04-15 12:47 <DIR> d-------- C:\Program Files\Common Files\InterVations
2008-04-15 12:47 . 2008-04-15 12:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\InterVations
2008-04-15 12:21 . 2008-04-15 12:21 <DIR> d-------- C:\Program Files\CCleaner
2008-04-15 11:05 . 2008-04-15 11:05 <DIR> d-------- C:\Program Files\RegistryFix
2008-04-15 10:57 . 2008-04-15 10:57 <DIR> d-------- C:\Documents and Settings\winkylocc\Application Data\Ahead
2008-04-15 10:57 . 2008-04-18 12:49 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-15 10:57 . 2008-04-18 12:51 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-04-15 10:57 . 2008-04-15 10:57 1,409 --a------ C:\WINDOWS\QTFont.for
2008-04-15 09:45 . 2008-04-15 09:45 <DIR> d-------- C:\!KillBox
2008-04-15 04:38 . 2008-04-15 04:38 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AdobeUM
2008-04-15 04:30 . 2008-04-15 10:51 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-04-15 03:06 . 2008-04-15 03:06 708,376 --ahs---- C:\WINDOWS\system32\oqslphub.ini
2008-04-15 03:03 . 2008-04-17 22:58 <DIR> d-------- C:\Documents and Settings\winkylocc\Application Data\TmpRecentIcons
2008-04-15 02:59 . 2008-04-15 02:59 <DIR> d-------- C:\Program Files\Bonjour
2008-04-14 21:48 . 2008-04-18 12:46 190,664 --ahs---- C:\WINDOWS\system32\ilUCLRqr.ini2
2008-04-14 21:48 . 2008-04-18 12:46 190,664 --ahs---- C:\WINDOWS\system32\ilUCLRqr.ini
2008-04-14 21:14 . 2008-04-15 04:41 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\qfsfuncr
2008-04-14 21:14 . 2008-04-14 15:11 245,760 --a------ C:\WINDOWS\lgmxvpatqgl.dll
2008-04-14 21:14 . 2008-04-14 15:11 217,088 --a------ C:\WINDOWS\omlbpkaw.dll
2008-04-14 21:14 . 2008-04-14 15:11 200,704 --a------ C:\WINDOWS\qtvglped.dll
2008-04-14 21:14 . 2008-04-14 15:11 188,416 --a------ C:\WINDOWS\pmsoarbf.dll
2008-04-14 21:14 . 2008-04-14 15:11 98,304 --a------ C:\WINDOWS\rtqmekwg.exe
2008-04-14 21:14 . 2008-04-14 15:11 94,208 --a------ C:\WINDOWS\npqtsrak.exe
2008-03-31 11:37 . 2008-03-31 11:38 <DIR> d-------- C:\Documents and Settings\winkylocc\Application Data\Printer Info Cache
2008-03-31 11:37 . 2008-03-31 11:38 <DIR> d-------- C:\Documents and Settings\winkylocc\Application Data\Image Zone Express
2008-03-18 10:05 . 2004-05-14 16:53 462,848 --a------ C:\WINDOWS\system32\ltkrn13n.dll
2008-03-18 10:05 . 2004-05-14 16:53 450,560 --a------ C:\WINDOWS\system32\ltimg13n.dll
2008-03-18 10:05 . 2004-05-14 16:53 401,408 --a------ C:\WINDOWS\system32\lfcmp13n.dll
2008-03-18 10:05 . 2004-05-14 16:53 299,008 --a------ C:\WINDOWS\system32\ltdis13n.dll
2008-03-18 10:05 . 2004-01-12 02:09 206,336 --a------ C:\WINDOWS\system32\ltefx13n.dll
2008-03-18 10:05 . 2004-05-14 16:53 163,840 --a------ C:\WINDOWS\system32\ltfil13n.dll
2008-03-18 10:05 . 2003-11-04 15:10 69,632 --a------ C:\WINDOWS\system32\lfgif13n.dll
2008-03-18 10:05 . 2004-05-14 16:53 57,344 --a------ C:\WINDOWS\system32\lfbmp13n.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-18 16:52 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-04-18 15:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-04-18 04:17 --------- d-----w C:\Program Files\Spyware Doctor
2008-04-15 16:36 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-15 14:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\InterVideo
2008-04-15 14:44 --------- d-----w C:\Documents and Settings\winkylocc\Application Data\HP
2008-04-10 14:28 --------- d-----w C:\Program Files\Norton 360
2008-04-10 03:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-03-16 18:02 --------- d-----w C:\Program Files\Java
2008-03-14 14:02 --------- d-----w C:\Program Files\BearShare Applications
2008-03-14 04:16 --------- d-----w C:\Documents and Settings\winkylocc\Application Data\BitTorrent
2008-03-14 03:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\BearShare Applications
2008-03-12 16:43 --------- d-----w C:\Documents and Settings\winkylocc\Application Data\AdobeAUM
2008-03-12 16:41 --------- d-----w C:\Documents and Settings\winkylocc\Application Data\DivX
2008-03-07 01:32 706 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-03-07 01:32 23,904 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-03-07 01:32 10,537 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.cat
2008-03-03 22:29 --------- d-----w C:\Documents and Settings\Ce\Application Data\HP
2008-03-01 13:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\WEBREG
2008-03-01 07:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\HP
2008-03-01 07:02 --------- d-----w C:\Program Files\Common Files\HP
2008-03-01 06:54 --------- d-----w C:\Program Files\HP
2008-03-01 06:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\HPSSUPPLY
2008-03-01 00:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
2008-02-29 02:38 --------- d-----w C:\Program Files\Microsoft Works
2008-02-22 17:14 --------- d-----w C:\Documents and Settings\winkylocc\Application Data\eFax Messenger
2008-02-21 21:32 --------- d-----w C:\Program Files\eFax Messenger 4.3
2008-02-21 21:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\eFax Messenger 4.3 Setup
2008-02-21 21:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\eFax Messenger 4.3 Output
2008-02-19 18:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\Napster
2008-02-19 00:03 --------- d-----w C:\Documents and Settings\winkylocc\Application Data\Yahoo!
2008-02-18 22:44 --------- d-----w C:\Documents and Settings\winkylocc\Application Data\AdobeUM
2007-07-23 02:24 5,430,056 ----a-w C:\Program Files\SmartFTP.exe
2007-03-11 00:00 774,144 ----a-w C:\Program Files\RngInterstitial.dll
.

((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5B434315-59C8-4480-8E72-058282FAAF1E}]
2008-04-14 15:11 245760 --a------ C:\WINDOWS\lgmxvpatqgl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{C130E860-7C1C-44F0-996C-1F995C10B61E}"= "C:\WINDOWS\qtvglped.dll" [2008-04-14 15:11 200704]

[HKEY_CLASSES_ROOT\clsid\{c130e860-7c1c-44f0-996c-1f995c10b61e}]
[HKEY_CLASSES_ROOT\qtvglped.1]
[HKEY_CLASSES_ROOT\TypeLib\{0515CA46-05CC-4C72-9AD4-F2F57DE9331F}]
[HKEY_CLASSES_ROOT\qtvglped]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 08:00 15360]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 20:05 204288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-07-17 21:54 116072]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-02-01 00:13 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-04 15:18 267048]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe" [2006-05-03 02:56 36975]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 18:38 583048]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 22:52 49152]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-07 00:46 57344]
"RegistryMechanic"="" []
"MMTray"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2006-01-19 11:06 110592]
"MimBoot"="C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe" [2006-01-19 11:06 11776]
"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [ ]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe" [2003-05-14 03:01 188416]
"CyberDefender Early Detection Center"="C:\Program Files\CyberDefender\AntiSpyware\ISSIntro.exe" [2008-02-10 21:10 501064]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 08:00 15360]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [ ]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
eFax 4.3.lnk - C:\Program Files\eFax Messenger 4.3\J2GTray.exe [2008-02-21 17:31:34 629248]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-01-02 22:40:10 210520]
InterVideo Scheduler server.lnk - C:\Program Files\InterVideo\WinDVD Media Center\SchSvr.exe [2006-06-22 02:48:25 98304]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 02:01:04 83360]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoLogoff"= 0 (0x0)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoFind"= 0 (0x0)
"NoLogoff"= 0 (0x0)
"NoSetFolders"= 0 (0x0)
"NoViewContextMenu"= 0 (0x0)
"Norun"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"pmsoarbf"= {68D2C92F-4957-4F16-BB95-BDD0EC7C11A6} - C:\WINDOWS\pmsoarbf.dll [2008-04-14 15:11 188416]
"omlbpkaw"= {C1C4537D-C4C2-4995-BDD3-527B63B24ACF} - C:\WINDOWS\omlbpkaw.dll [2008-04-14 15:11 217088]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"UleadBurningHelper"=2 (0x2)
"SPBBCSvc"=2 (0x2)
"ITMRTSVC"=2 (0x2)
"SNDSrvc"=2 (0x2)
"SAVScan"=3 (0x3)
"rpcapd"=3 (0x3)
"NSCService"=3 (0x3)
"NPFMntor"=2 (0x2)
"navapsvc"=2 (0x2)
"gusvc"=3 (0x3)
"AVGEMS"=2 (0x2)
"Avg7UpdSvc"=2 (0x2)
"Avg7Alrt"=2 (0x2)
"Automatic LiveUpdate Scheduler"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"C:\\Program Files\\InterVideo\\WinDVD Media Center\\IHT.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=
"C:\\Program Files\\SmartXX\\RemoteFlasher\\Smartxx.exe"=
"C:\\Program Files\\FlashFXP\\FlashFXP.exe"=
"C:\\Program Files\\mIRC\\mirc.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\WINWORD.EXE"=
"C:\\WINDOWS\\system32\\ftp.exe"=
"C:\\Program Files\\CyberDefender\\AntiSpyware\\CyberDefenderEDC.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"33956:TCP"= 33956:TCP:gnutella
"1214:TCP"= 1214:TCP:file sharing

S2 TivoInstallHelper;TiVo Install Helper;"C:\Documents and Settings\Turk loCC\Local Settings\Temp\MSI7.tmp" /service []
S3 ALABULK;Fujifilm USB MemoryCard ReaderWriter device driver;C:\WINDOWS\system32\Drivers\ALABULK2.sys [2002-09-19 21:33]
S3 CDAVFS;CDAVFS;C:\WINDOWS\system32\DRIVERS\CDAVFS.sys [2008-02-10 21:09]
S3 ISHJVZZUJOTLC;ISHJVZZUJOTLC;C:\DOCUME~1\TURKLO~1\LOCALS~1\Temp\ISHJVZZUJOTLC.exe []
S3 MR97310_VGA_DUAL_CAMERA;VGA Dual Camera;C:\WINDOWS\system32\DRIVERS\mr97310v.sys [2004-03-17 02:54]
S3 PsSdk30;PsSdk30;C:\WINDOWS\system32\Drivers\PsSdk30.drv []

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\setup.exe

*Newly Created Service* - COMHOST
.
**************************************************************************
scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PsSdk30]
"ImagePath"="\??\C:\WINDOWS\system32\Drivers\PsSdk30.drv"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\TivoInstallHelper]
"ImagePath"="\"C:\Documents and Settings\Turk loCC\Local Settings\Temp\MSI7.tmp\" /service"
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Real\RealPlayer\realplay.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\Real\RealPlayer\rphelperapp.exe
C:\Program Files\Real\RealPlayer\rphelperapp.exe
.
**************************************************************************
.
Completion time: 2008-04-18 12:58:05 - machine was rebooted [winkylocc]
ComboFix-quarantined-files.txt 2008-04-18 16:57:57

Pre-Run: 63,110,795,264 bytes free
Post-Run: 63,170,322,432 bytes free
.
2008-04-09 07:06:23 --- E O F ---


By the way the computer is running better since the reboot after combo fix. For some reason realplayer opens up with combofix, is this normal?
  • 0

Advertisements


#11
BHowett

BHowett

    OT Moderator

  • Moderator
  • 4,649 posts
Hi bggb,


That cleaned a lot out…. But we still have some more to go. :)


1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.

2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\327882R2FWJFW
C:\WINDOWS\system32\5893fe81
C:\WINDOWS\system32\oqslphub.ini
C:\Documents and Settings\All Users\Application Data\qfsfuncr
C:\WINDOWS\lgmxvpatqgl.dll
C:\WINDOWS\omlbpkaw.dll
C:\WINDOWS\qtvglped.dll
C:\WINDOWS\pmsoarbf.dll
C:\WINDOWS\rtqmekwg.exe
C:\WINDOWS\npqtsrak.exe.
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5B434315-59C8-4480-8E72-058282FAAF1E}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{C130E860-7C1C-44F0-996C-1F995C10B61E}"=-
[-HKEY_CLASSES_ROOT\clsid\{c130e860-7c1c-44f0-996c-1f995c10b61e}]
[-HKEY_CLASSES_ROOT\qtvglped.1]
[-HKEY_CLASSES_ROOT\TypeLib\{0515CA46-05CC-4C72-9AD4-F2F57DE9331F}]
[-HKEY_CLASSES_ROOT\qtvglped]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"pmsoarbf"=-
"omlbpkaw"=-



3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

Posted Image


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.

  • 0

#12
bggb

bggb

    Member

  • Topic Starter
  • Member
  • PipPip
  • 43 posts
OK here is the combofix log:

ComboFix 08-04-17.1 - winkylocc 2008-04-18 19:13:06.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.126 [GMT -4:00]
Running from: C:\Documents and Settings\winkylocc\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\winkylocc\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\327882R2FWJFW
C:\Documents and Settings\All Users\Application Data\qfsfuncr
C:\WINDOWS\lgmxvpatqgl.dll
C:\WINDOWS\npqtsrak.exe.
C:\WINDOWS\omlbpkaw.dll
C:\WINDOWS\pmsoarbf.dll
C:\WINDOWS\qtvglped.dll
C:\WINDOWS\rtqmekwg.exe
C:\WINDOWS\system32\5893fe81
C:\WINDOWS\system32\oqslphub.ini
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\lgmxvpatqgl.dll
C:\WINDOWS\npqtsrak.exe.
C:\WINDOWS\omlbpkaw.dll
C:\WINDOWS\pmsoarbf.dll
C:\WINDOWS\qtvglped.dll
C:\WINDOWS\rtqmekwg.exe
C:\WINDOWS\system32\5893fe81
C:\WINDOWS\system32\oqslphub.ini

.
((((((((((((((((((((((((( Files Created from 2008-03-18 to 2008-04-18 )))))))))))))))))))))))))))))))
.

2008-04-18 07:16 . 2008-04-18 07:16 <DIR> d-------- C:\Deckard
2008-04-17 23:32 . 2008-04-17 23:32 <DIR> d-------- C:\VundoFix Backups
2008-04-17 22:47 . 2008-04-17 22:47 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-15 12:47 . 2008-04-15 12:48 <DIR> d-------- C:\Program Files\RegCOPA
2008-04-15 12:47 . 2008-04-15 12:47 <DIR> d-------- C:\Program Files\Common Files\InterVations
2008-04-15 12:47 . 2008-04-15 12:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\InterVations
2008-04-15 12:21 . 2008-04-15 12:21 <DIR> d-------- C:\Program Files\CCleaner
2008-04-15 11:05 . 2008-04-15 11:05 <DIR> d-------- C:\Program Files\RegistryFix
2008-04-15 10:57 . 2008-04-15 10:57 <DIR> d-------- C:\Documents and Settings\winkylocc\Application Data\Ahead
2008-04-15 10:57 . 2008-04-18 13:07 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-15 10:57 . 2008-04-18 12:51 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-04-15 10:57 . 2008-04-15 10:57 1,409 --a------ C:\WINDOWS\QTFont.for
2008-04-15 09:45 . 2008-04-15 09:45 <DIR> d-------- C:\!KillBox
2008-04-15 04:38 . 2008-04-15 04:38 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AdobeUM
2008-04-15 04:30 . 2008-04-15 10:51 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-04-15 03:03 . 2008-04-17 22:58 <DIR> d-------- C:\Documents and Settings\winkylocc\Application Data\TmpRecentIcons
2008-04-15 02:59 . 2008-04-15 02:59 <DIR> d-------- C:\Program Files\Bonjour
2008-04-14 21:48 . 2008-04-18 12:46 190,664 --ahs---- C:\WINDOWS\system32\ilUCLRqr.ini2
2008-04-14 21:48 . 2008-04-18 12:46 190,664 --ahs---- C:\WINDOWS\system32\ilUCLRqr.ini
2008-04-14 21:14 . 2008-04-15 04:41 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\qfsfuncr
2008-03-31 11:37 . 2008-03-31 11:38 <DIR> d-------- C:\Documents and Settings\winkylocc\Application Data\Printer Info Cache
2008-03-31 11:37 . 2008-03-31 11:38 <DIR> d-------- C:\Documents and Settings\winkylocc\Application Data\Image Zone Express
2008-03-18 10:05 . 2004-05-14 16:53 462,848 --a------ C:\WINDOWS\system32\ltkrn13n.dll
2008-03-18 10:05 . 2004-05-14 16:53 450,560 --a------ C:\WINDOWS\system32\ltimg13n.dll
2008-03-18 10:05 . 2004-05-14 16:53 401,408 --a------ C:\WINDOWS\system32\lfcmp13n.dll
2008-03-18 10:05 . 2004-05-14 16:53 299,008 --a------ C:\WINDOWS\system32\ltdis13n.dll
2008-03-18 10:05 . 2004-01-12 02:09 206,336 --a------ C:\WINDOWS\system32\ltefx13n.dll
2008-03-18 10:05 . 2004-05-14 16:53 163,840 --a------ C:\WINDOWS\system32\ltfil13n.dll
2008-03-18 10:05 . 2003-11-04 15:10 69,632 --a------ C:\WINDOWS\system32\lfgif13n.dll
2008-03-18 10:05 . 2004-05-14 16:53 57,344 --a------ C:\WINDOWS\system32\lfbmp13n.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-18 23:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-04-18 16:52 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-04-18 04:17 --------- d-----w C:\Program Files\Spyware Doctor
2008-04-15 16:36 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-15 14:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\InterVideo
2008-04-15 14:44 --------- d-----w C:\Documents and Settings\winkylocc\Application Data\HP
2008-04-10 14:28 --------- d-----w C:\Program Files\Norton 360
2008-04-10 03:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-03-16 18:02 --------- d-----w C:\Program Files\Java
2008-03-14 14:02 --------- d-----w C:\Program Files\BearShare Applications
2008-03-14 04:16 --------- d-----w C:\Documents and Settings\winkylocc\Application Data\BitTorrent
2008-03-14 03:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\BearShare Applications
2008-03-12 16:43 --------- d-----w C:\Documents and Settings\winkylocc\Application Data\AdobeAUM
2008-03-12 16:41 --------- d-----w C:\Documents and Settings\winkylocc\Application Data\DivX
2008-03-07 01:32 706 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-03-07 01:32 23,904 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-03-07 01:32 10,537 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.cat
2008-03-03 22:29 --------- d-----w C:\Documents and Settings\Ce\Application Data\HP
2008-03-01 13:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\WEBREG
2008-03-01 07:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\HP
2008-03-01 07:02 --------- d-----w C:\Program Files\Common Files\HP
2008-03-01 06:54 --------- d-----w C:\Program Files\HP
2008-03-01 06:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\HPSSUPPLY
2008-03-01 00:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
2008-02-29 02:38 --------- d-----w C:\Program Files\Microsoft Works
2008-02-22 17:14 --------- d-----w C:\Documents and Settings\winkylocc\Application Data\eFax Messenger
2008-02-21 21:32 --------- d-----w C:\Program Files\eFax Messenger 4.3
2008-02-21 21:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\eFax Messenger 4.3 Setup
2008-02-21 21:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\eFax Messenger 4.3 Output
2008-02-19 18:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\Napster
2008-02-19 00:03 --------- d-----w C:\Documents and Settings\winkylocc\Application Data\Yahoo!
2008-02-18 22:44 --------- d-----w C:\Documents and Settings\winkylocc\Application Data\AdobeUM
2007-07-23 02:24 5,430,056 ----a-w C:\Program Files\SmartFTP.exe
2007-03-11 00:00 774,144 ----a-w C:\Program Files\RngInterstitial.dll
.

((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 08:00 15360]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 20:05 204288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-07-17 21:54 116072]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-02-01 00:13 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-04 15:18 267048]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe" [2006-05-03 02:56 36975]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 18:38 583048]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 22:52 49152]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-07 00:46 57344]
"RegistryMechanic"="" []
"MMTray"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2006-01-19 11:06 110592]
"MimBoot"="C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe" [2006-01-19 11:06 11776]
"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [ ]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe" [2003-05-14 03:01 188416]
"CyberDefender Early Detection Center"="C:\Program Files\CyberDefender\AntiSpyware\ISSIntro.exe" [2008-02-10 21:10 501064]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 08:00 15360]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [ ]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
eFax 4.3.lnk - C:\Program Files\eFax Messenger 4.3\J2GTray.exe [2008-02-21 17:31:34 629248]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-01-02 22:40:10 210520]
InterVideo Scheduler server.lnk - C:\Program Files\InterVideo\WinDVD Media Center\SchSvr.exe [2006-06-22 02:48:25 98304]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 02:01:04 83360]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoLogoff"= 0 (0x0)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoFind"= 0 (0x0)
"NoLogoff"= 0 (0x0)
"NoSetFolders"= 0 (0x0)
"NoViewContextMenu"= 0 (0x0)
"Norun"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"pmsoarbf"= {D6003161-597F-4D9F-AF41-CEFF1A5A3372} - C:\WINDOWS\pmsoarbf.dll [ ]
"omlbpkaw"= {15B2000C-6980-494F-A731-D1B770914BE5} - C:\WINDOWS\omlbpkaw.dll [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"UleadBurningHelper"=2 (0x2)
"SPBBCSvc"=2 (0x2)
"ITMRTSVC"=2 (0x2)
"SNDSrvc"=2 (0x2)
"SAVScan"=3 (0x3)
"rpcapd"=3 (0x3)
"NSCService"=3 (0x3)
"NPFMntor"=2 (0x2)
"navapsvc"=2 (0x2)
"gusvc"=3 (0x3)
"AVGEMS"=2 (0x2)
"Avg7UpdSvc"=2 (0x2)
"Avg7Alrt"=2 (0x2)
"Automatic LiveUpdate Scheduler"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"C:\\Program Files\\InterVideo\\WinDVD Media Center\\IHT.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=
"C:\\Program Files\\SmartXX\\RemoteFlasher\\Smartxx.exe"=
"C:\\Program Files\\FlashFXP\\FlashFXP.exe"=
"C:\\Program Files\\mIRC\\mirc.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\WINWORD.EXE"=
"C:\\WINDOWS\\system32\\ftp.exe"=
"C:\\Program Files\\CyberDefender\\AntiSpyware\\CyberDefenderEDC.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"33956:TCP"= 33956:TCP:gnutella
"1214:TCP"= 1214:TCP:file sharing

S2 TivoInstallHelper;TiVo Install Helper;"C:\Documents and Settings\Turk loCC\Local Settings\Temp\MSI7.tmp" /service []
S3 ALABULK;Fujifilm USB MemoryCard ReaderWriter device driver;C:\WINDOWS\system32\Drivers\ALABULK2.sys [2002-09-19 21:33]
S3 CDAVFS;CDAVFS;C:\WINDOWS\system32\DRIVERS\CDAVFS.sys [2008-02-10 21:09]
S3 ISHJVZZUJOTLC;ISHJVZZUJOTLC;C:\DOCUME~1\TURKLO~1\LOCALS~1\Temp\ISHJVZZUJOTLC.exe []
S3 MR97310_VGA_DUAL_CAMERA;VGA Dual Camera;C:\WINDOWS\system32\DRIVERS\mr97310v.sys [2004-03-17 02:54]
S3 PsSdk30;PsSdk30;C:\WINDOWS\system32\Drivers\PsSdk30.drv []

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\setup.exe

*Newly Created Service* - COMHOST
.
**************************************************************************
scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\PsSdk30]
"ImagePath"="\??\C:\WINDOWS\system32\Drivers\PsSdk30.drv"

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\TivoInstallHelper]
"ImagePath"="\"C:\Documents and Settings\Turk loCC\Local Settings\Temp\MSI7.tmp\" /service"
.
Completion time: 2008-04-18 19:24:35
ComboFix-quarantined-files.txt 2008-04-18 23:24:28
ComboFix2.txt 2008-04-18 16:58:07

Pre-Run: 63,966,515,200 bytes free
Post-Run: 63,992,524,800 bytes free
.
2008-04-09 07:06:23 --- E O F ---

Here is HJT:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:28:48 PM, on 4/18/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\alg.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\eFax Messenger 4.3\J2GTray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\InterVideo\WinDVD Media Center\SchSvr.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\MMDiag.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityrespo...r/fix_homepage/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.c...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityrespo...r/fix_homepage/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft....k/?LinkId=74005
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - ~CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: CyberDefender safeSEARCH - {F35CE83E-9EBF-40d5-AE87-53F982389740} - C:\Documents and Settings\winkylocc\Local Settings\Application Data\CyberDefender\ssstbar.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\NppBho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
O2 - BHO: CyberDefender safeSEARCH - {F35CE83E-9EBF-40d5-AE87-53F982389740} - C:\Documents and Settings\winkylocc\Local Settings\Application Data\CyberDefender\ssstbar.dll
O3 - Toolbar: CyberDefender safeSEARCH - {F35CE83E-9EBF-40d5-AE87-53F982389740} - C:\Documents and Settings\winkylocc\Local Settings\Application Data\CyberDefender\ssstbar.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [CyberDefender Early Detection Center] "C:\Program Files\CyberDefender\AntiSpyware\ISSIntro.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: eFax 4.3.lnk = C:\Program Files\eFax Messenger 4.3\J2GTray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: InterVideo Scheduler server.lnk = C:\Program Files\InterVideo\WinDVD Media Center\SchSvr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - http://www.symantec....abs/tgctlsr.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace....ploader1006.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail....es/MSNPUpld.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://www.slide.com...ageUploader.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symant...ex/symdlmgr.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - http://www.nick.com/.../GrooveAX27.cab
O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} - http://imikimi.com/d...kimi_plugin.cab
O21 - SSODL: pmsoarbf - {F58292E8-8894-441C-A1CB-AA5655213461} - C:\WINDOWS\pmsoarbf.dll (file missing)
O21 - SSODL: omlbpkaw - {903D91E1-EA2A-4AF7-9EB4-A316E256F98B} - C:\WINDOWS\omlbpkaw.dll (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISHJVZZUJOTLC - Unknown owner - C:\DOCUME~1\TURKLO~1\LOCALS~1\Temp\ISHJVZZUJOTLC.exe (file missing)
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec RemoteAssist - Unknown owner - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe (file missing)
O23 - Service: TiVo Install Helper (TivoInstallHelper) - Unknown owner - C:\Documents.exe (file missing)

--
End of file - 11045 bytes
  • 0

#13
BHowett

BHowett

    OT Moderator

  • Moderator
  • 4,649 posts
Hello bggb,

Things should be running much better now… :) just a few more steps and we should be good to go!


Fix with HijackThis

Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below.

R3 - URLSearchHook: (no name) - ~CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)

O21 - SSODL: pmsoarbf - {F58292E8-8894-441C-A1CB-AA5655213461} - C:\WINDOWS\pmsoarbf.dll (file missing)
O21 - SSODL: omlbpkaw - {903D91E1-EA2A-4AF7-9EB4-A316E256F98B} - C:\WINDOWS\omlbpkaw.dll (file missing)

O23 - Service: ISHJVZZUJOTLC - Unknown owner - C:\DOCUME~1\TURKLO~1\LOCALS~1\Temp\ISHJVZZUJOTLC.exe (file missing)



Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis.


===============================================

Kaspersky WebScanner

Please do an online scan with Kaspersky WebScanner

Click on Accept

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
===============================================

Needed in your next reply;

Kaspersky results

Fresh HijackThhis log

Please let me know how your system is running :)
  • 0

#14
bggb

bggb

    Member

  • Topic Starter
  • Member
  • PipPip
  • 43 posts
Saturday, April 19, 2008 6:19:08 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 19/04/2008
Kaspersky Anti-Virus database records: 714923


Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true

Scan Target My Computer
A:\
C:\
D:\
E:\

Scan Statistics
Total number of scanned objects 84831
Number of viruses found 34
Number of infected objects 91
Number of suspicious objects 0
Duration of the scan process 01:50:37

Infected Object Name Virus Name Last Action
C:\caa2b0e9ecaf82f3db7e93\baseline.dat Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\deffactory.dat Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\DeleteTemp.exe Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\dlmgr.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\DW20.EXE Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\DWINTL20.DLL Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\eula.1025.rtf Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\eula.1028.rtf Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\eula.1029.rtf Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\eula.1030.rtf Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\eula.1031.rtf Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\eula.1032.rtf Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\eula.1033.rtf Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\eula.1035.rtf Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\eula.1036.rtf Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\eula.1037.rtf Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\eula.1038.rtf Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\eula.1040.rtf Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\eula.1041.rtf Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\eula.1042.rtf Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\eula.1043.rtf Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\eula.1044.rtf Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\eula.1045.rtf Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\eula.1046.rtf Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\eula.1049.rtf Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\eula.1053.rtf Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\eula.1055.rtf Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\eula.2052.rtf Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\eula.2070.rtf Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\eula.3082.rtf Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\gencomp.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\HtmlLite.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\LocData.1025.ini Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\LocData.1028.ini Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\LocData.1029.ini Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\LocData.1030.ini Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\LocData.1031.ini Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\LocData.1032.ini Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\LocData.1035.ini Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\LocData.1036.ini Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\LocData.1037.ini Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\LocData.1038.ini Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\LocData.1040.ini Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\LocData.1041.ini Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\LocData.1042.ini Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\LocData.1043.ini Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\LocData.1044.ini Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\LocData.1045.ini Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\LocData.1046.ini Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\LocData.1049.ini Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\LocData.1053.ini Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\LocData.1055.ini Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\LocData.2052.ini Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\LocData.2070.ini Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\LocData.3076.ini Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\LocData.3082.ini Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\LocData.ini Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\logo.bmp Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\RebootStub.exe Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\runmsi.exe Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\setup.exe Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\setup.sdb Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\setupres.1025.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\setupres.1028.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\setupres.1029.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\setupres.1030.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\setupres.1031.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\setupres.1032.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\setupres.1035.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\setupres.1036.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\setupres.1037.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\setupres.1038.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\setupres.1040.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\setupres.1041.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\setupres.1042.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\setupres.1043.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\setupres.1044.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\setupres.1045.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\setupres.1046.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\setupres.1049.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\setupres.1053.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\setupres.1055.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\setupres.2052.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\setupres.2070.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\setupres.3082.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\setupres.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\SITSetup.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\vs70uimgr.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\vsbasereqs.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\vsscenario.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\vs_setup.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\vs_setup.msi Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\vs_setup.pdi Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\WapRes.1025.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\WapRes.1028.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\WapRes.1029.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\WapRes.1030.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\WapRes.1031.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\WapRes.1032.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\WapRes.1035.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\WapRes.1036.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\WapRes.1037.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\WapRes.1038.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\WapRes.1040.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\WapRes.1041.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\WapRes.1042.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\WapRes.1043.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\WapRes.1044.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\WapRes.1045.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\WapRes.1046.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\WapRes.1049.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\WapRes.1053.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\WapRes.1055.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\WapRes.2052.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\WapRes.2070.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\WapRes.3082.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\WapRes.dll Object is locked skipped

C:\caa2b0e9ecaf82f3db7e93\WapUI.dll Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBConfig.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBDebug.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBDetect.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBNotify.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBRefr.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetCfg.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetCfg2.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetDev.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetLoc.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetUsr.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBStHash.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBValid.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPPolicy.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPStart.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPStop.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtErEvt.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\E153E1B7.TMP Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp(2)\A2653BFC.TMP Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtMoEvt.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtNvEvt.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtScEvt.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtTxFEvt.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtViEvt.log Object is locked skipped

C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\$_hpcst$.hpc Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Adobe\Acrobat\7.0\AdobeCMapFnt07.lst Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Adobe\Acrobat\7.0\AdobeSysFnt07.lst Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Adobe\Acrobat\7.0\Collab\RSS Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Adobe\Acrobat\7.0\JavaScripts\glob.settings.js Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Adobe\Acrobat\7.0\JSADM.exv Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Adobe\Acrobat\7.0\Messages\ENU\read0600win_ENUadbe0700.pdf Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Adobe\Acrobat\7.0\Preferences\AutoFillDefaults.dat Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Adobe\Acrobat\7.0\Preferences\defaultHeuristics.dat Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Adobe\Acrobat\7.0\Security\addressbook.acrodata Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Adobe\Acrobat\7.0\TMDocs.sav Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Adobe\Acrobat\7.0\TMGrpPrm.sav Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Adobe\Acrobat\7.0\Updater\AdbeRdr709_en_US.exe Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Adobe\Acrobat\7.0\Updater\udlog.txt Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Adobe\Acrobat\7.0\Updater\udstore.js Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Adobe\Acrobat\7.0\UserCache.bin Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Adobe\Linguistics\Dictionaries\Adobe Custom Dictionary\all\added.clam Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Adobe\Linguistics\Dictionaries\Adobe Custom Dictionary\eng\added.clam Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Adobe\Linguistics\Dictionaries\Adobe Custom Dictionary\eng\exception.txt Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Adobe\Online Services\Photoshop Album Starter Edition\cache\cache.dat Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Adobe\Online Services\Photoshop Album Starter Edition\cache\entry.dat Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Adobe\Online Services\Photoshop Album Starter Edition\clients\Photoshop Album Starter Edition\notifications.dat Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Adobe\Online Services\Photoshop Album Starter Edition\clients\Photoshop Album Starter Edition\preferences.dat Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Adobe\Photoshop Album\3.0\apd.prf Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Adobe\Photoshop Album\3.0\customevents.dat Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Adobe\Photoshop Album\3.0\email.xml Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Adobe\Photoshop Album\3.0\jpegviewer.xml Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Adobe\Photoshop Album\3.0\Logse30.txt Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Adobe\Photoshop Album\3.0\print.xml Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Adobe\Photoshop Album\3.0\psa.prf Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Adobe\Photoshop Album\3.0\psase30.xml Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Adobe\Photoshop Album\3.0\status.dat Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\AdobeAUM\pase30xpwinen_US.aum Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\AdobeAUM\pase30xpwinen_US_meta.txt Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\AdobeUM\AcRdB7_0_9.sta Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Ahead\Nero Wave Editor\73a712b4-d614426e-bd00e28a-2680e483.pre Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Ahead\Nero Wave Editor\8c3d0948-7044dc-8325bbcd-3a3a56ce.pre Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Ahead\Nero Wave Editor\b12dd394-8ac74eb1-95c9d1ec-2bf2ee19.pre Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Ahead\Nero Wave Editor\c62798c7-f50a4226-a88470d-37015a98.pre Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Ahead\Nero Wave Editor\e450dd9d-ff584493-9bfcd356-9d10547c.pre Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Ahead\NeroShowTime.bmk Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Ahead\NeroVision\GCHWCfg.bak Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Ahead\NeroVision\GCHWCfg.xml Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Ahead\NeroVision\NeroVisionLog.txt Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Ahead\NeroVision\nve-am.bin Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Ahead\NeroVision\nve-mtmpl.bin Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Ahead\NeroVision\nve-vobmap.bin Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Ahead\NeroVision\NVFACache\11CCEE0EF6FED5B5A934940F7D0E9F02.FAC Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Ahead\NeroVision\NVFACache\1397FFA03D7467754C50CEA7565EE932.FAC Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Ahead\NeroVision\NVFACache\185CD5E927AAF122F812C05897842A83.FAC Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Ahead\NeroVision\NVFACache\1EDE0F1BD99A787BB20CFCF1B0B9E228.FAC Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Ahead\NeroVision\NVFACache\25481FEE85CDC4DF4240BFF3AD412A40.FAC Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Ahead\NeroVision\NVFACache\43EDBB675BEC90B94BD3096ED9E4AF95.FAC Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Ahead\NeroVision\NVFACache\4BDBD65FB8EE30D0B5607BD845BC90F4.FAC Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Ahead\NeroVision\NVFACache\4DA3EA58321C2FF118C11545A0F87F32.FAC Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Ahead\NeroVision\NVFACache\5A55728D81FA32DF89844667D18F8608.FAC Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Ahead\NeroVision\NVFACache\67D2B13C967412DC55D6DB7C0D9AF83B.FAC Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Ahead\NeroVision\NVFACache\8284055C01DFFAC6E45E63D2A09499C9.FAC Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Ahead\NeroVision\NVFACache\8990079A2E85A43462CD87475CFB7EAF.FAC Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Ahead\NeroVision\NVFACache\939E4C86EE6BAB5D12CE7F8EC3BAAB50.FAC Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Ahead\NeroVision\NVFACache\951AFE0932DC87C2CA785069CDA63DA2.FAC Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Ahead\NeroVision\NVFACache\9A6D701176AB93A3E6547F32ACBA9400.FAC Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Ahead\NeroVision\NVFACache\9D69705B4A2720CAD20CE1446D0E33F8.FAC Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Ahead\NeroVision\NVFACache\A77C5D7E72C35DC596F18DAE0455C656.FAC Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Ahead\NeroVision\NVFACache\BCF92555407BE7D5ACC61183181F6062.FAC Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Ahead\NeroVision\NVFACache\BE18C4E47D20952DE473151A00C9FBF6.FAC Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Ahead\NeroVision\NVFACache\C4820C2237FD9871FC8D531D377BB464.FAC Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Ahead\NeroVision\NVFACache\C58058FBD21EBDFFB5483AB28D0A79AC.FAC Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Ahead\NeroVision\NVFACache\D09B4629C1FC583576E0474F6DF3FCFB.FAC Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Ahead\NeroVision\NVFACache\DA767A3882C22F7B2D5D35D9B69929D0.FAC Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Ahead\NeroVision\NVFACache\DC66DC0D8D5E3D27CA9B6762AD47A6FD.FAC Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Ahead\NeroVision\NVFACache\E027444A3A94067CCA95FCFEB0BAD264.FAC Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Ahead\NeroVision\NVFACache\FAEEC5133B148D34D7F7442F0C28766E.FAC Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Apple Computer\iTunes\CD Info.cidb Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Apple Computer\iTunes\iPod Software Updates\iPod_7.1.4.1.ipsw Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Apple Computer\iTunes\iPod Software Updates\iPod_7.1.4.1.ipsw.signature Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Apple Computer\iTunes\iPod Updater Logs\iPodUpdater.log Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Apple Computer\iTunes\iTunesPrefs.xml Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Apple Computer\QuickTime\QTPlayerSession.xml Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\desktop.ini Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\DivX\DivX Player\Database.dat Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\DivX\DivX Player\DownloadQueue.dlq Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\FrostWire\.NetworkShare\LimeWireWin4.12.11.exe Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\FrostWire\createtimes.cache Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\FrostWire\data.ser Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\FrostWire\fileurns.bak Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\FrostWire\fileurns.cache Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\FrostWire\filters.props Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\FrostWire\frostwire.props Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\FrostWire\gnutella.net Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\FrostWire\installation.props Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\FrostWire\library.dat Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\FrostWire\pub1.key Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\FrostWire\public.key Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\FrostWire\questions.props Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\FrostWire\responses.cache Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\FrostWire\secureMessage.key Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\FrostWire\spam.dat Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\FrostWire\tables.props Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\FrostWire\themes\frostwire_theme\kill.png Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\FrostWire\themes\frostwire_theme\kill_on.png Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\FrostWire\themes\frostwire_theme\theme.txt Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\FrostWire\themes\frostwire_theme.skin Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\FrostWire\ttree.cache Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\FrostWire\version.key Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\FrostWire\version.xml Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\FrostWire\xml\data\audio.sxml Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\FrostWire\xml\data\delete_me Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\FrostWire\xml\data\video.sxml Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\FrostWire\xml\misc\application.gif Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\FrostWire\xml\misc\audio.gif Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\FrostWire\xml\misc\document.gif Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\FrostWire\xml\misc\image.gif Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\FrostWire\xml\misc\video.gif Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\FrostWire\xml\schemas\application.xsd Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\FrostWire\xml\schemas\audio.xsd Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\FrostWire\xml\schemas\document.xsd Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\FrostWire\xml\schemas\image.xsd Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\FrostWire\xml\schemas\video.xsd Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\GlobalSCAPE\CuteFTP Pro\8.0\CIS_Queue.dat Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\GlobalSCAPE\CuteFTP Pro\8.0\Scripts\sample.vbs Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\GlobalSCAPE\CuteFTP Pro\8.0\sm.dat Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\HP\CRMLogs\BrandAuthentication.htm Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\internaldb41.dat Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\internaldb6334.dat Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\internaldb8467.dat Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\InterVideo\WinDVD\7.5\Bookmark\THE_NEVERENDING_STORY-525319488_Auto.bmk Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Leadertech\PowerRegister\PowerReg.dat Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\149.memecounter.com\sessions.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\a.dolimg.com\fspVolume.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\a405.g.akamai.net\f\405\11649\1h\pepsicoinc.download.akamai.com\11649\sites\transformers\game\md_tf_game.swf\MDTransformersGame.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\a405.g.akamai.net\f\405\11649\1h\pepsicoinc.download.akamai.com\11649\sites\transformers\game\md_tf_game.swf\TestMovie_Config_Info.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\acvs.mediaonenetwork.net\MediaOne.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\agame.com\mirror\flash\h\hardcourt_basketball.swf\jycNoypBasketbol.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\andkon.com\arcade\adventureaction\thingthingarena2\thingthingarena2.swf\userData.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\andkon.com\arcade\other\southparkcreator\southparkcreator.swf\char354.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\andkon.com\arcade\sport\lightningbreakpool\lightning_break1.swf\user_data.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\andkon.com\gamemobike_v1.505.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\atv.disney.go.com\hsm2DownloadPointsLSO.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\atv.disney.go.com\hsm2yearbook.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\babystrology.com\tickers\baby-ticker-glass.swf\babyCounterState.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\bankofamerica.com\sas\sas-docs\html\pmfso.swf\PassMark.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\bin.clearspring.com\clearspring.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\blastmymusic.com\shopping_cart.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\cdn.gigya.com\WildFire\swf\wildfire.swf\gigya_SNAccountsStatus.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\content.yieldmanager.edgesuite.net\atoms\61\1d\611df091a68499e9aecc2c96d4f09966.swf\FlashBoxCookie.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\content.yieldmanager.edgesuite.net\atoms\6b\65\6b65c69962a5c01b7c0f5db79576c157.swf\FlashBoxCookie.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\content.yieldmanager.edgesuite.net\atoms\95\99\9599e18768ca028057dec48150030754.swf\FlashBoxCookie.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\content.yieldmanager.edgesuite.net\atoms\bd\a9\bda9b1762248aeb8b4e9f8acd4864657.swf\FlashBoxCookie.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\content.yieldmanager.edgesuite.net\atoms\f7\7a\f77adb012137547cc10432b8b3fd1e74.swf\views.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\cosmosweb01.bcst.mud.yahoo.com\COSMOSPrefs.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\d.yimg.com\COSMOSPrefs.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\disney.go.com\disneychannel\KimpossibleEmailTicker.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\disney.go.com\disneychannel\kimpossiblePoll.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\disney.go.com\disneychannel\LiloAndStitchEmailTicker.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\disney.go.com\disneychannel\media\global\dc_base.swf\LondonQuotes.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\disney.go.com\disneychannel\media\global\dc_base.swf\RavenQuotes.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\disney.go.com\disneychannel\suitelifePoll.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\dizzler.com\player\pod.swf\noobness.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\embed.snapvine.com\flash\Recorder_9a.swf\snapvine.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\en.www.bonus.com\sapbox\common\Code.swf\ActivePlayerActiveX.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\en.www.bonus.com\sapbox\common\Code.swf\IsGuestActiveX.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\en.www.bonus.com\sapbox\common\Code.swf\urlGetInboxActiveX.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\en.www.bonus.com\sapbox\common\Code.swf\urlGetMatchStatisticsActiveX.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\en.www.bonus.com\sapbox\common\Code.swf\urlGetPlayerActiveX.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\flash.ngfiles.com\bytesize\bytesize_viewer.swf\bytesize.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\flash.quantserve.com\com.quantserve.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\i.ivillage.com\rightcol\rightcol.swf\ivillagee.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\img.maturescam.com\flash\freechat122.swf\jasminmember01.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\img.webmd.com\sc\SC2_43.swf\webmdCookie.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\inboxtag.com\tag.swf\inboxtag_52.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\inboxtag.com\tag.swf\inboxtag_global.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\interclick.com\ud.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\l.yimg.com\cosmos.bcst.yahoo.com\ver\230b\embed-2007-05-07-1251\swf\yup_embed_module.swf\TestMovie_Config_Info.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\l.yimg.com\cosmos.bcst.yahoo.com\ver\232\embed-2007-05-29-1529\swf\yup_embed_module.swf\TestMovie_Config_Info.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\l.yimg.com\cosmos.bcst.yahoo.com\ver\232\popup-2007-05-29-1529\swf\POP_tray.swf\TestMovie_Config_Info.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\l.yimg.com\cosmos.bcst.yahoo.com\ver\234\embed-2007-06-19-1259\swf\yup_embed_module.swf\TestMovie_Config_Info.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\l.yimg.com\cosmos.bcst.yahoo.com\ver\234\popup-2007-06-19-1259\swf\POP_tray.swf\TestMovie_Config_Info.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\l.yimg.com\cosmos.bcst.yahoo.com\ver\237\embed-2007-07-31-1718\swf\yup_embed_module.swf\TestMovie_Config_Info.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\l.yimg.com\cosmos.bcst.yahoo.com\ver\242\embed-2007-08-28-1213\swf\yup_embed_module.swf\TestMovie_Config_Info.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\l.yimg.com\cosmos.bcst.yahoo.com\ver\246\popup-2007-09-21-1543\swf\POP_meta.swf\TestMovie_Config_Info.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\l.yimg.com\cosmos.bcst.yahoo.com\ver\250.1\popup-2007-11-14-1422\swf\POP_meta.swf\TestMovie_Config_Info.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\l.yimg.com\cosmos.bcst.yahoo.com\ver\251.1\popup-2007-12-03-1552\swf\POP_meta.swf\TestMovie_Config_Info.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\l.yimg.com\LCOMMENGINEMGR.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\layouts1.lovemyflash.com\com.quantserve.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\localhost\core.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\login.yahoo.com\loginCache.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\m1.2mdn.net\OffermaticaFlashCookie.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\mail.yimg.com\websdkLogger.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\maps.yahoo.com\flash\loader.mxml.swf\YMaps.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\miniclip.com\games\alex-in-danger\en\alexindanger.swf\MiniclipLoaderAd.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\miniclip.com\games\bush-shoot-out\en\bushshootout_game.swf\MiniclipLoaderAd.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\miniclip.com\games\dance-2-the-beat\en\minibar.dcr\MiniclipLoaderAd.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\miniclip.com\games\hip-hop-debate\en\hip-hopdebate.swf\MiniclipLoaderAd.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\miniclip.com\games\police-chopper\en\heli.dcr\MiniclipLoaderAd.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\miniclip.com\games\rifleman\en\rifleman.dcr\MiniclipLoaderAd.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\miniclip.com\games\wakeboarding-xs\en\wakeboarding.swf\MiniclipLoaderAd.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\miniclip.com\games\wheels-of-salvation\en\wheelsofsalvation.swf\MiniclipLoaderAd.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\mlb.mlb.com\flash\gameday\y2007\gd2007.swf\gd2007.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\mlb.mlb.com\flash\team_video\team_video_v2.swf\mlb_homepage_video.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\mochibot.com\com.mochibot.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\mpsnare.iesnare.com\stm.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\musicbox.sonybmg.com\WEBTRENDS_USERID.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\myscene.everythinggirl.com\ChelseaFashionBook.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\myscene.everythinggirl.com\MS_Home_History.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\myscene.everythinggirl.com\MS_RM_Bedroom.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\myscene.everythinggirl.com\MS_RM_Party.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\myscene.everythinggirl.com\mysceneUserSettings.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\mysurvey4u.com\me9ntthe.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\newbieadguide.com\walkiron.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\newyork.mets.mlb.com\flash\team_video\team_video_v2.swf\mlb_homepage_video.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\nick.com\danny.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\nick.com\dp_fight.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\nick.com\games\data\loaders\hi_score_proxy_475x360.swf\tak.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\oddcast.com\vhsssecure.php\oddcast_vhss.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\pagead2.googlesyndication.com\pagead\googleadplayer.swf\mediaPlayerUserSettings.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\player.cdn.targetspot.com\ts_CBSRadio.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\precisionclick.com\insidemeintl372007.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\quantserve.com\com.quantserve.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\s7ondemand1.scene7.com\is-viewers\flash\genericzoomviewer.swf\#eFashion\BP%2DM2A00056%5F001%5Fzoom_init.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\s7ondemand1.scene7.com\is-viewers\flash\genericzoomviewer.swf\#eFashion\BP%2DN1C067FL%5F004%5Fzoom_init.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\s7ondemand1.scene7.com\is-viewers\flash\genericzoomviewer.swf\#eFashion\EN%2DEZMU2958%5F110%5Fzoom_init.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\s7ondemand1.scene7.com\s7_eFashion.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\slide.com\ratings.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\sodahead.com\enc_data.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\ssl-images-amazon.com\images\I\01PH5-tUHPL.swf\mercury.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\static.eventful.com\com.eventful.logging.spids.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\static.eventful.com\stickerVersion.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\static.nfl.com\static\site\flash\prepostplayer.swf\nfl.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HVZ\static.nfl.com\static\site\flash\rightRail.swf\nfl.sol Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\Macromedia\Flash Player\#SharedObjects\A6WS3HV
  • 0

#15
bggb

bggb

    Member

  • Topic Starter
  • Member
  • PipPip
  • 43 posts
C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_5ab609211e824c710cd9a84bd204ec0d.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_5b647fcf11c21b97c1d873fceb3ba008.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_5b6ade1b5b14a9fd82087ab5d48d2f59.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_5b6b31a5f15e1fd55d17aec082ceb681.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_5be53471bc56b21987d558659ba4ae4c.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_5c72c29da79bebdc9f3169598224f5cb.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_5c872b1278dac8e91a6682ba8a34ce0d.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_5ca48df3916c8642b718ca75962fc2ff.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_5caa3cd353f9410a48f314f386d29069.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_5cfabd9ad7cfc53782eb1575bc21e62c.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_5d31638bd62b709883b7dad6462a8da7.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_5d3c5e640ece7c7043f0388b3321f985.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_5d4a7a876a064faed7700aaefb6e0ead.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_5da7a311b5dddbf44f318edfd9d98ab6.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_5e4175a076835a0286b30217aa67283a.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_5e5c801ce8ccf30b0d525b7523894e89.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_5e978ba0738ed0fe2eebb39d40252ba8.gif Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_5ecceac29913b0c2ca2a7a51ccfd49d8.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_5ef3f6516d670daf283b9e6370b60c85.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_5f5e01606c58b3344ff24000fe3ea26b.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_5f8d86f4db4b68b279a0b3f8ad6a1fed.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_60204c99362909580057b5729b3a3e93.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_602bde7f8996b7a204abe1dbe843f128.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_603e632c2770f82d091e0ae77fb1ed5f.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_606aab361f952abb852eeeda062b8d05.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_607810229a1c8e2073c6a654067edf48.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_608e0ecf8427f975cd00e8c7475d927e.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_60e37ecd0c91264309a3aaf80fd6ee40.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_60eabbed179d9032b791bb8b329eec0d.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_60fab8e4417ed156bf26f3a6d4cc768e.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_6146c0503461958f43ce2b502d9a0a47.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_61777183374228c4f9f7bd40e33b65c9.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_61ab9a8f926d478d8385e84188cbad42.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_61b66e305883f6ba93a751fb8d23e863.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_6215e26fc84664969a47e288d7e16ba8.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_627b37c80c124b32c15d6946ad05b6f6.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_62a0addc71f7c0863cdcc6d640ba4097.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_62cdb8f257f7086b5b30b981ffae1b3a.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_62f271968926f960183379ac6f1305c6.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_63292839c29614ed5462539ce4864250.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_632d311570fc026fdb12541ef7c284b6.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_63577a55771a6f792e6500d5af99e6a7.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_637bc8250368b6782c8e7902c4547097.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_63b945124a67ad57610dce26074aeed1.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_63baff8a5c4f897c475c178efa2d3b25.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_63fb58627219da8d2e14650fd93821be.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_6401b0e51e62289c64224875cf1c4ae1.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_64334639640ff851da114b2e96c8348b.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_646e7f07cab3d377c85c4996f55d59a3.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_6482f5e8d033ca100a9ac3d9fc71b135.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_64b221ab5f5c0480ef324a111a5b7f76.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_64b2568d18e354af1bf5130c62f2e5ed.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_64f3ec89c9f35502046892a06556375c.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_6506656fdf79d431e41184e0f807b8fc.gif Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_6506656fdf79d431e41184e0f807b8fc.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_651b00bed9abbf60d1062b0fa222d0f2.gif Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_656691fe657f088b430bdf37508ed8ab.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_65711f1a05f56f732ab694ef7489c6e3.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_6587d5bd26b89fbba845cf1c7cc5bb91.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_6590f552bb3821a2a6205f5d897e9219.gif Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_6590f552bb3821a2a6205f5d897e9219.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_65a0729ce08a60d31afaaae0acf63a69.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_65ad2ef9284ab0c075cfac08efb09112.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_65bf6318af31b1cf074c7a72f16c45d2.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_65c84dda1525e3d67442b0f65fca60d1.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_65d7e94ff978aa6123dab6c2f64a28e6.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_65faf28d77f9aa7ac4b200c426e491e1.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_6607f00c211fa496249321957f0ace4b.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_661e79dfc9d8baf022dfc7910ecb33ea.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_6627363f97a97e1b9f74efe6ab6cb25d.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_6641ee795d18a39e080d63cf3d43683b.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_669a71fe21eaadb2f006d777e1bec0a7.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_66cee9c3a2e17a3f0a2e940d0cb6cdf0.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_66db0e882610b40a93e697233372a4e0.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_66f27d6acf1cb62bea66e73acc361db0.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_671355a5160af54931eec8e1e192f4a2.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_677ee4083c32cfccc2cda349bed1084e.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_679cccad908c6ecc1c5894afb9cce721.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_67b79bf4b22ac45f79a3abfb098c975f.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_6813f1ae6c756b56c2a9066b5e0c166b.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_682cb960a797f24bf67c6f9d9748cbbe.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_684f5918ab701544bdc124c62fa83fe2.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_686a75cf527fbc751cb9ee3db2f01ef6.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_688e96bc68e0d037aff971ee2a0200cf.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_68f4a877bf0dd4517baab4371200a5a8.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_6926b616ce2d05a9ab4275c655e3df46.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_6928e3773ae6ff073dcddf26b1afbc69.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_6948d0764999ff116fc82b4fca741c04.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_6961a3c4b124c299f562614e1061b496.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_69e14ff0b42f7af277772e3b38157480.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_6a147b032b62501be28d2706940600f6.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_6a275f21c33ef65f7a7595becadebab6.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_6a649cb7d3cf505b6db5aa02226e2f97.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_6a7e53ef45d7aa02284ec3de4e944a4b.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_6a9c78099a70f00a176c8c0503bea956.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_6aa397a0a566ec94ea3813e088d3bf55.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_6ae5aad974f2b8c1b90a7828de43afa1.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_6b9842df31cdf7b915ddce6b0133be22.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_6bc4730b033d6a6f6e3f7863af6291ba.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_6bc58aceb3ac5da1115c788f3ff8b6e0.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_6be370b92babd3e63b3e97cb3442f15a.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_6c1351409e4a17408bb3125d28550f3e.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_6c2b4574e8667977f0c30384cef70de7.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_6c6be24f898c94a994d325a931ab66d6.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_6c816bb3a1a596a31c956df44a688596.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_6d03ac51261232a36f142526b1d234e4.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_6d6508ad3b7f5cd8f6434d48c3673883.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_6d887c257a9915461edb9395fc402898.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_6dba95d76f57457eb5d85ba69192ad66.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_6e353ad819a4890029a1b3735f375a52.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_6e56c5f5d1b404b08fdd61ccf4b1b465.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_6e75a17f88db7f0dbcf9370730a3b766.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_6ecb02f8c6beaafbd6e2fa45b45cc78b.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_6ed4fbb0893924402f36575594763deb.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_6f1b2c778cf741905787891123187f39.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_6f3135e54c99447d20d4c5867c4cf3a0.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_6fa842ff151a8e691a06ddae2a3e2d91.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_6fb16484c1987691781365ae22f65009.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_6fda8f2d91efbd41eb729b0f11f22fbb.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_70b2f3a1fca98844cf2c502b1749379f.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_712350b0e19dca6edb5a82a438c22f3d.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_71bf822ab765cebd0fb1543b7a8273c6.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_720d9981dea22e01e1af36a2c94c20a7.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7240530ee787d744885611b319f68359.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_727e3544cbff00dcfb14915635146ae2.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7294c81627d89db25e23588a0a65719f.gif Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7294c81627d89db25e23588a0a65719f.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7299654eba61209b34d40d64bcb7b671.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_729d5e3b769a9364ba1587ee4a2bcd0a.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_72a9450d9ec4f191575ba5b85001bb5b.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_72ad148e098980b7d7f87d1996c100ab.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_72bd6dd150ad0732102fb157d0cb9b14.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7326ba62cd651aeed07dd74934bef11c.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_73289ae406ed8f6198d4c33990dc4d13.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_732ae9eabd07464cebe6477b3fc32d6b.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7339f99d7924c8fdcb980611c093d221.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_733f0e8a651b902e0d822b2ba2a5745d.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7347e85773e93a6d36d10dbed938cc11.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7374f38358ead66bec57fd8e6f21aa3e.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_73e559c39e5251d24cceb213795a8f33.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_73fb8ac1ef25b99de23297e233d558f4.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_73ffe0e8463e2640cbe626421c0dd93c.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7456bb5bf07f29d589b1509ad6ad21e1.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_747d0ff953d813a01cb8bb0b86ca34df.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_750211db11bb714a916ca2a92a2bd0bf.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_750703cee24812e042996157bd166f30.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_755467e18ce5f85c11ea0f4ddde97404.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7580ddeddbec94243a39a7114b8883cb.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_75a339deae525a7486898a0cd8dd746b.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_75c0a6b673745e30d700accc684e72e8.gif Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_75c66a46da7da7cfad22a8024bd497d5.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7607f809c0edea94f3fff0ad9d832700.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7647a2a759c2e27af6317db5669facd1.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_764e96618aec940c20588a5ce0763630.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7680d9af5fdff0a2ddfacb7b83ea8ea9.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_76b4cad4ea2ee9893f1f360fe44dbb53.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_76d6b884e10a1646400d855bc0a3a985.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7721206ec6adba373dd099b8cb88009f.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_774eb666617ccddc776e51becf8a851c.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7750bfa0ddc67faa73048ce396367bd4.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_77676b41b6f608212b4ff69d0f0d61cf.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_776883d3d65650a5911fb89ef17d7a31.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7776d42b6eabd3039a8e326f29c17ec2.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_77cee0fdb0c2df9497f5148690a04fa4.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_77d441cb15ea14bb30db971c82c950ab.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_77ece9efb59d17d7817f41936634b50e.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_78329495c79e366372866847e659184c.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_786d48629e7df46e9dca1c62d8050dd5.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_787fd33e1479730de574e9ffa8c0dd3c.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_78ceb55820422666c25eed770a4b4ecd.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7910d746e343ea53e3f9d788acadf5ce.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_795806a18ee6c577ce25aeab28066d0e.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_79bb346650b5033294fdc4c750c683ee.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_79c74dc1aa3cfe30c0bf6ef8f228cf4e.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_79e88e939141e09e2e4cdccea4fb743f.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_79f4372cb5952f2841609af7aca473af.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_79f45ee387a8f1400b97ea0b1cd20f08.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7aa5894a7589495eaf06a907241168df.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7ac6caf65ba0bf67791454d10b5fba6a.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7b1998f6b570f5687ea5cf86ccf27cb5.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7b31d8cf100fdd132db768a071bcd849.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7b519da460f49e32ca7042868b057816.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7b559503070e9c9220805222d76016ae.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7c3b06067bbe16740d85ef31301f28bc.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7c3f6402bd373a05fdea022c4b41d87a.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7c49ee98f05ed980baec3660f8ff535a.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7c6bfa35f25a54dde3086d7fa8fbe93d.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7ce5a33cf7377b1c785882b1f2306743.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7ce69d8fcc8ee68885a692aedc1357b3.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7d402db808971e0e532927a50cbf3a4e.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7d4e9aac21eaa0662da984a0db1daaa3.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7d5a4b07f444273cda56ce7e6ba80694.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7d8cb420764654f8aab339762cd7da3e.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7d90073aec99c0f906d83ff1b9081e56.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7df3262baf7b72e1eac4e541fa65560c.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7e23c9b6f2dffd56eb8ce56b1dacb3e8.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7e328c7af57879523dda13eca198e005.gif Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7e36cb4390f0b78f7f4af3788e465102.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7ebe12b305258e3d2f2d1b3751cf7675.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7ee23ec3e319a6d9676789261397ae6d.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7eea6842b9988bfb62c06b2f626eea98.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7f2102a85829fdf9075ee7a49c9ea1d9.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7f29f94bb8798f828eb5997e5fcbb642.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7f3269cf1a76dfd41f0d91eaada61e66.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7f35d248be519fb4503318c8a60c9b72.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7f3886510b034a26a9da9d2abe99e69a.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7f3c218dc4f7837746733d1560ba4fc3.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7f9025ffbcf21f457824d37929f4cac9.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7fa8a86f17a1332ef4cd831f2a27ab66.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7fcb527fac2f98fbc130b3ff146290df.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_7fe2f31c49f5c87800efaf300fd8e64d.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_803bc5107813a6172389b5a49994e726.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_805523dacc9578715184827ef40fe692.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_8081cdbbacbca4b4573793d783afbe14.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_809b9b1ebdb7f167647db8136c2e4ca3.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_80c4041bf79fa219c6259bcaa7f41324.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_812f7889ddf37db80d58eadee7159951.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_815172dd7aff878fe32ca89d2b3e47f8.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_81ce9d3945ba39a8230850f82c494fce.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_81cfd4469bde4942573c3fdcaba4c031.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_81feccd34bf84766b475c891dbd92099.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_8211bb4deb843b09a965d6074b435d37.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_8259536cc81b45f60e814030c91db206.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_8270e28a4150b17a7b16dc7ff95d54a9.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_82ffec506bb1d4ba44a343c86b033bfc.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_8375e4aaf9bfb4bb3d4997f1da4e687a.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_83dfe2ac1e9735569e452fb4b2e0b81b.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_8501ef05f4df1c4168c78102655ecced.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_8526d6da1127091e0598405e1b075d41.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_8537f4054b3a2de637cd528e610939f8.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_8562f6836bd94ec47bc618dbe8e288ce.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_85707eaf3ca0f476a18814d810c8a1c9.gif Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_858f8813fc480cf25741e3a209835004.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_85932a21fd80b72a735cf902d242a3d0.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_85f506eae9dd738ab4eae5aa38ff205e.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_86110bc7065c6f590386b2a79cc224a3.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_86592ed26cce37a7f15d987effbf2a09.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_86b8e793303beb959384bdc25a505f80.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_86c5391250ee3202daa1719a4dc7923b.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_871a266ed970b9ebb9b946919ce9056a.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_872fbd7483bed435a63e511bcabe86b5.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_875fc855ec2bef166c0a8d42fd8ea17d.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_885e39bea92ccecd4223f67c3343af0c.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_886faa3240b5ac1e00fc4a1db21503e6.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_887cc930edb24f4d2ede19c8b568903e.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_88e96cfcc778335cb340420af8622059.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_88fd0375b89a2a1ace88cccf4f095846.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_890b66ab99bbcd07fa091dbb6185e309.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_8965bf6e8817f89158efce74c5aba1e2.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_8a28892603f98b53d36f7538a52a2a88.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_8a719c45e84363c85dbf01e2a9bfe50a.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_8a9555c6e841fb56fe9017748f4961b1.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_8aafa1fe9cae11a103e7b3bfa5583fa3.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_8ab4a879b20c28b1cc1621e945661de5.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_8ac2b1d6fca76e84d11f337259b44dd7.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_8b27b6487c654caa9dd058662980b2fe.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_8b5f4a8edd38c03fe1217828e107daab.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_8b6f5530337dfa6929ac6ff3a9dfe977.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_8b72d6f4c9872713aed988e95a5bcdb8.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_8bab3c282c02f6245aa9ba8140bb9650.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_8be62e2c84456336edc862a7cf77e913.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_8c55a687d5ba1ce47813a71c1ca04e97.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_8c5709bff3452a4a22966431e7c5cae5.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_8cd7ab215b8333abe741f73f5282c18a.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_8d480a42d4e6a8cf6c9e14b5253c8633.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_8d508c8c48353323d7d4e42c818e6129.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_8d7d7f8a2cac25acba6b7bf000cf013a.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_8e7278f4e1e4f53ee8ec2deca933b601.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_8ed419fe29f2c25b2cbdb0f6d7ac0280.gif Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_8ef0de4395f5c206c8849cb09c0d2e18.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_8f2ebbd9dadc13825076e1e25933dd19.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_8fd5f5eb9e2509818fdbd40d5a7c0249.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_8ff1e47958b20f48eff09675b8c2c933.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_90292b06f51c99cbf4363a21286bc853.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_902bd73ed5c70b48918c255a9984e716.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_9048c6bedf8b3dbb0c42acabaf012b6a.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_906c84d22f3cd6d2826a4c4da4f3535d.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_9082f003da8c2d1425725943892b2c5b.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_90a57389393ca756e29c230caf2b6701.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_90e2342039f4a4288aef7a3370ea05d8.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_91217cb1fb2b043b5f267010f1a82f5e.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_91bf28fa8c283f44acea51297fe776ae.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_91d38cc7bf800478f92d05c16cc600e0.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_91de7b6ed3ea8c23204e7c1f7b71093f.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_921c8a0636da87a2b977e2fefb50fcff.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_9233434d34d50c0c11be4b6f26e9a091.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_923d4b5a9e90d9e97d4faeefe48a94da.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_92b68a802e9ccce09fcf2d0008717e18.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_92d3b2f8d424cb82687f0d43cf6957a3.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_93120d7ef4abb6af26adc18024e9fca5.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_9314b7bf5bfdae513dcb75b8be2450dc.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_931f89ae7121e1201681875893f4e745.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_933de46f6bc5fee0c52d6bfaadce0cf6.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_935a1684de419d210839c22a90620c8c.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_93d23f4e61bcb055e1328d9efc81a3be.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_94050dc137ff945550864c9dd1cf13f1.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_942d9625dfed2895fa5a3dbb680a9ffd.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_943b47b580253766cb07e549de385b6c.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_947793fd3a2aa9a81bfcde809fce675a.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_94e9b74836ac28d510df1b0bea5b5171.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_950301cdfa2b534cd58776b180a1af54.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_95141645328127313365ba2cae3622d4.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_954cc93b05fe62797d0d7c2d7e5ce58e.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_95d66fe12c88fca77bfe90990d58c606.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_95e6c626781f519158ff3b44db11e2a4.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_9603fff02a0ad9c4430a87c025c2959e.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_9643fd6227205acff00a113cbdf43f19.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_9671ee3a65aec77068405444f90d0532.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_96742f946965d86574cda7da78d1dafe.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_96796da0dcdd7a7433c4951974f1e9d2.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_975ed5a5365b5692758da9df40f38992.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_9780edf5634850ba415a816b3f344b99.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_97874dbbb3e685f1827378312804d1c0.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_97ae2460833a74da011e8deb9c3239a5.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_97ec348802b8b8c818a2bd7f8bd3611b.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_98240431ab7dd53bcfe5d0eb5fc37ff0.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_98bc92e75f32f1676e363cf83e22439e.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_98f607759392382d2e47504a8e8a2655.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_99099092b662a7b4946bf1783b52c09a.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_9933bb1dfc66a00065e6da483dd53bdf.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_999dddf22a738ce422bd9b1cca917679.gif Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_99a9652d59441c47719e938fa6b6bead.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_9a4794d71d6f53514d2b5b2207928c1d.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_9a6b5296f7545e2bb16d4c92c6f8c694.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_9adc06897ba480ddfcda5127ced3ceb6.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_9bbd9685035397c72c168233720a2c38.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_9c6acc1fa2f969fcea04d82a30e96b67.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_9cc1b830f8ecc5ffbbb1c1af5e98a072.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_9cefb7ea2dc3b695cb38370bc3fa41d2.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_9d26c5c005910dff6396e10925e646b7.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_9d3600cbb7cdf207944599079e310b0d.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_9d3bd1527086838e8c9cbb846cbba7db.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_9d47af0d921a3db69f154c982001f4b6.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_9da84ea77337b2a55c3cfa1fb2572121.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_9dded616f159638719b815620618306a.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_9df1a4687696e1cc04bdfdbf90f79ae1.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_9e1ace0f263a38f6cdf86a4f9b02b488.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_9eb028656c6c726bd4bbbf1ce08a08cc.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_9ebf277d9d50afdff2f92548399f95bf.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_9ee8da17aa4ca5504159a3854eebb2ca.gif Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_9ee8da17aa4ca5504159a3854eebb2ca.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_9f169f593171b5c499145beb19dc6e81.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_9f6f1fd85e2f46c3861f41acb48b35ef.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_a01031b669bae15b2046d0523dfef9d8.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_a06678a056b4d146cca7e890086f3a10.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_a103091db66aa783afad9083a53fcdd4.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_a1857909b93720f7875f95af8353d705.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_a1b11ef2ce9e46960106ebecdc6f21a9.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_a1ce6be553565133e739d61d6a468b80.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_a2658eba25342bf9ecc0dddce3f5be55.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_a294f7aa3f00dad78f0cf908588082f1.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application Data\MySpace\IM\Images\m_a2a6345a0eefb7042e797cd3f90323bb.jpg Object is locked skipped

C:\Documents and Settings\Turk loCC\Application
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP