Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

need assistance with my son's pc... [RESOLVED]


  • This topic is locked This topic is locked

#1
crybaby

crybaby

    Member

  • Member
  • PipPipPip
  • 175 posts
Upon checking my son's computer, I noticed that there was minimum to no virus protection running. I decided to come here, and would really just like to know if everything is okay, or if there is more that I need to do. Thanks so much for your help.


4.18.08
*After posting this we are now experiencing difficulty accessing the internet. Neither Firefox of IE seem to cooperate.*



SuperAntniSpyware Scan Log:

SUPERAntiSpyware Scan Log
Generated 04/15/2008 at 11:35 PM

Application Version : 3.6.1000

Core Rules Database Version : 3437
Trace Rules Database Version: 1429

Scan type : Complete Scan
Total Scan Time : 11:09:53

Memory items scanned : 659
Memory threats detected : 0
Registry items scanned : 6399
Registry threats detected : 0
File items scanned : 749999
File threats detected : 1790

Adware.Tracking Cookie

C:\Documents and Settings\John\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Low\Cookies\john@casalemedia[1].txt
C:\Documents and Settings\John\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Low\Cookies\john@doubleclick[1].txt
C:\Documents and Settings\John\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Low\Cookies\john@imrworldwide[2].txt
C:\Documents and Settings\John\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Low\Cookies\john@tribalfusion[1].txt
C:\Documents and Settings\John\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Low\Cookies\john@casalemedia[1].txt
C:\Documents and Settings\John\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Low\Cookies\[email protected][1].txt
C:\Documents and Settings\John\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Low\Cookies\john@doubleclick[1].txt
C:\Documents and Settings\John\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Low\Cookies\john@imrworldwide[2].txt
C:\Documents and Settings\John\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Low\Cookies\john@tribalfusion[1].txt
C:\Documents and Settings\John\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Low\Cookies\john@casalemedia[1].txt
C:\Documents and Settings\John\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Low\Cookies\[email protected][1].txt
C:\Documents and Settings\John\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Low\Cookies\john@doubleclick[1].txt
C:\Documents and Settings\John\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Low\Cookies\john@imrworldwide[2].txt
C:\Documents and Settings\John\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Low\Cookies\john@tribalfusion[1].txt
C:\Documents and Settings\John\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Low\Cookies\john@casalemedia[1].txt
C:\Documents and Settings\John\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Low\Cookies\[email protected][1].txt
C:\Documents and Settings\John\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Low\Cookies\john@doubleclick[1].txt
C:\Documents and Settings\John\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Low\Cookies\john@imrworldwide[2].txt
C:\Documents and Settings\John\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Low\Cookies\john@tribalfusion[1].txt
C:\Documents and Settings\John\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Low\Cookies\john@casalemedia[1].txt
C:\Documents and Settings\John\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Low\Cookies\[email protected][1].txt
C:\Documents and Settings\John\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Low\Cookies\john@doubleclick[1].txt
C:\Documents and Settings\John\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Low\Cookies\john@imrworldwide[2].txt
C:\Documents and Settings\John\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Low\Cookies\john@tribalfusion[1].txt
C:\Documents and Settings\John\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Low\Cookies\john@casalemedia[1].txt
C:\Documents and Settings\John\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Low\Cookies\[email protected][1].txt
C:\Documents and Settings\John\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Low\Cookies\john@doubleclick[1].txt
C:\Documents and Settings\John\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Low\Cookies\john@imrworldwide[2].txt
C:\Documents and Settings\John\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Low\Cookies\john@tribalfusion[1].txt
C:\Documents and Settings\John\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\Low\Cookies\john@casalemedia[1].txt
C:\Documents and Settings\John\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\Low\Cookies\[email protected][1].txt
C:\Documents and Settings\John\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\Low\Cookies\john@doubleclick[1].txt
C:\Documents and Settings\John\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\Low\Cookies\john@imrworldwide[2].txt
C:\Documents and Settings\John\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\Low\Cookies\john@tribalfusion[1].txt
C:\Documents and Settings\John\AppData\Local\Application Data\Application Data\Application Data\Temp\Low\Cookies\john@casalemedia[1].txt
C:\Documents and Settings\John\AppData\Local\Application Data\Application Data\Application Data\Temp\Low\Cookies\[email protected][1].txt
C:\Documents and Settings\John\AppData\Local\Application Data\Application Data\Application Data\Temp\Low\Cookies\john@doubleclick[1].txt
C:\Documents and Settings\John\AppData\Local\Application Data\Application Data\Application Data\Temp\Low\Cookies\john@imrworldwide[2].txt
C:\Documents and Settings\John\AppData\Local\Application Data\Application Data\Application Data\Temp\Low\Cookies\john@tribalfusion[1].txt
C:\Documents and Settings\John\AppData\Local\Application Data\Application Data\Temp\Low\Cookies\john@casalemedia[1].txt
C:\Documents and Settings\John\AppData\Local\Application Data\Application Data\Temp\Low\Cookies\[email protected][1].txt
C:\Documents and Settings\John\AppData\Local\Application Data\Application Data\Temp\Low\Cookies\john@doubleclick[1].txt
C:\Documents and Settings\John\AppData\Local\Application Data\Application Data\Temp\Low\Cookies\john@imrworldwide[2].txt
C:\Documents and Settings\John\AppData\Local\Application Data\Application Data\Temp\Low\Cookies\john@tribalfusion[1].txt
C:\Documents and Settings\John\AppData\Local\Application Data\Temp\Low\Cookies\john@casalemedia[1].txt
C:\Documents and Settings\John\AppData\Local\Application Data\Temp\Low\Cookies\[email protected][1].txt
C:\Documents and Settings\John\AppData\Local\Application Data\Temp\Low\Cookies\john@doubleclick[1].txt
C:\Documents and Settings\John\AppData\Local\Application Data\Temp\Low\Cookies\john@imrworldwide[2].txt
C:\Documents and Settings\John\AppData\Local\Application Data\Temp\Low\Cookies\john@tribalfusion[1].txt
C:\Documents and Settings\John\AppData\Local\Temp\Low\Cookies\john@casalemedia[1].txt
C:\Documents and Settings\John\AppData\Local\Temp\Low\Cookies\[email protected][1].txt
C:\Documents and Settings\John\AppData\Local\Temp\Low\Cookies\john@doubleclick[1].txt
C:\Documents and Settings\John\AppData\Local\Temp\Low\Cookies\john@imrworldwide[2].txt
C:\Documents and Settings\John\AppData\Local\Temp\Low\Cookies\john@tribalfusion[1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\john@adinterax[1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\john@adrevolver[1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\john@atdmt[2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\john@doubleclick[1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\john@hitbox[2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\john@insightexpressai[2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\john@mediaplex[2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\john@questionmarket[1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\john@serving-sys[2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\john@specificclick[2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\john@windowsmedia[2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@2o7[2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][3].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@adbrite[1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@adbureau[1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@adinterax[2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@adlegend[1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@adrevolver[1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@adtech[1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@advertising[1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@apmebf[1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@atdmt[2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@atwola[2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@bluestreak[1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@burstnet[1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@casalemedia[2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@collective-media[1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@counter-strike-dl[2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@doubleclick[1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@eyewonder[1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@fastclick[1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@focalex[2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@fortunecity[2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@hitbox[1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@honoluluadvertiser[1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@imrworldwide[2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@indexstats[2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@indextools[1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@insightexpressai[1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@interclick[1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@kontera[1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][3].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@mediaplex[2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@onlinerewardcenter[1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@overture[1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@popularscreensavers[2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@precisionclick[2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@questionmarket[2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@realmedia[1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@revenue[2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@revsci[1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][3].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][3].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@serving-sys[2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@spamblockerutility[1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@specificclick[1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@spylog[1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@statcounter[2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@tacoda[2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@trafficmp[1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@tribalfusion[1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][3].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@virginmedia[2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][3].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][4].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][5].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@xiti[1].txt
C:\Documents and Settings\John\AppData\Roaming\Microsoft\Windows\Cookies\Low\john@zedo[2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\john@adinterax[1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\[email protected][2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\john@adrevolver[1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\[email protected][2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\john@atdmt[2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\john@doubleclick[1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\john@hitbox[2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\john@insightexpressai[2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\[email protected][2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\john@mediaplex[2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\john@questionmarket[1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\john@serving-sys[2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\john@specificclick[2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\john@windowsmedia[2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@2o7[2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][3].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@adbrite[1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@adbureau[1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@adinterax[2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@adlegend[1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@adrevolver[1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@adtech[1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@advertising[1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@apmebf[1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@atdmt[2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@atwola[2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@bluestreak[1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@burstnet[1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@casalemedia[2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@collective-media[1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@counter-strike-dl[2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@doubleclick[1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@eyewonder[1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@fastclick[1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@focalex[2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@fortunecity[2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@hitbox[1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@honoluluadvertiser[1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@imrworldwide[2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@indexstats[2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@indextools[1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@insightexpressai[1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@interclick[1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@kontera[1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][3].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@mediaplex[2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@onlinerewardcenter[1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@overture[1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@popularscreensavers[2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@precisionclick[2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@questionmarket[2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@realmedia[1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@revenue[2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@revsci[1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][3].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][3].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@serving-sys[2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@spamblockerutility[1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@specificclick[1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@spylog[1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@statcounter[2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@tacoda[2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@trafficmp[1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@tribalfusion[1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][3].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@virginmedia[2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][3].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][4].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][5].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@xiti[1].txt
C:\Documents and Settings\John\Application Data\Microsoft\Windows\Cookies\Low\john@zedo[2].txt
C:\Documents and Settings\John\Cookies\[email protected][1].txt
C:\Documents and Settings\John\Cookies\john@adinterax[1].txt
C:\Documents and Settings\John\Cookies\[email protected][2].txt
C:\Documents and Settings\John\Cookies\john@adrevolver[1].txt
C:\Documents and Settings\John\Cookies\[email protected][2].txt
C:\Documents and Settings\John\Cookies\[email protected][1].txt
C:\Documents and Settings\John\Cookies\john@atdmt[2].txt
C:\Documents and Settings\John\Cookies\[email protected][1].txt
C:\Documents and Settings\John\Cookies\john@doubleclick[1].txt
C:\Documents and Settings\John\Cookies\[email protected][1].txt
C:\Documents and Settings\John\Cookies\john@hitbox[2].txt
C:\Documents and Settings\John\Cookies\john@insightexpressai[2].txt
C:\Documents and Settings\John\Cookies\[email protected][1].txt
C:\Documents and Settings\John\Cookies\[email protected][2].txt
C:\Documents and Settings\John\Cookies\john@mediaplex[2].txt
C:\Documents and Settings\John\Cookies\john@questionmarket[1].txt
C:\Documents and Settings\John\Cookies\[email protected][1].txt
C:\Documents and Settings\John\Cookies\john@serving-sys[2].txt
C:\Documents and Settings\John\Cookies\john@specificclick[2].txt
C:\Documents and Settings\John\Cookies\john@windowsmedia[2].txt
C:\Documents and Settings\John\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\Cookies\Low\john@2o7[2].txt
C:\Documents and Settings\John\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Cookies\Low\[email protected][1].txt
C:\Documents and Settings\John\Cookies\Low\[email protected][2].txt
C:\Documents and Settings\John\Cookies\Low\[email protected][3].txt
C:\Documents and Settings\John\Cookies\Low\john@adbrite[1].txt
C:\Documents and Settings\J

Edited by crybaby, 18 April 2008 - 06:11 PM.

  • 0

Advertisements


#2
sarahw

sarahw

    Malware Staff

  • Member
  • PipPipPipPipPip
  • 2,781 posts
Hi,
Welcome to the site. Sorry about the delay.

I will be handling your log to help you get cleaned up. Please give me some time to look it over and I will get back to you as soon as possible.

I want you to show hidden files. There are instructions HERE to help you do this.
You should have Administrator rights to perform the fixes. Some of the instructions I give may need to be printed or saved for reference during the fix. Some of the fix will be done in Safe Mode so you will be unable to access this thread at that time.
Please dont use any of the tools without specific instructions. Some of them are dangerous (and could leave your computer in worse condition that it is when infected) if used incorrectly.
These instructions should be read first, then followed. If you do not understand something, don't be afraid to ask, or see if I'm on chat. :)

As it has been a few days, can you please post a Hijack This log. This is because your computers condidtion may have changed.
  • 0

#3
crybaby

crybaby

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 175 posts
No worries, and thanks for taking me on. I will let you know that since my original post, we have been having a few issues. As I said before, the internet is not always available. Sometimes I have to reset the IP address, and sometimes, I have to reboot the pc altogether. It also seems to be running a bit on the slow side. Here is the new HJT log you requested. While running the scan, a message popped up:
For some reason your system denied write access to the Hosts file. If any hijacked domains are in this file, HJT may NOT be able to fix this. IF this happens you will have to edit the file yourself.
notepadC:\Windows\System32\drivers\host
...

not sure what all that means :)
Thanks again for looking into this for me!

New HJT:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:02:47 PM, on 4/16/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16643)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe
C:\Program Files\Dell Photo AIO Printer 926\memcard.exe
C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://login.yahoo....mp;.partner=sbc
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.c...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.c...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.c...//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe"
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [dscactivate] c:\dell\dsca.exe 3
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Dell PC Fax\fm3032.exe" /s
O4 - HKLM\..\Run: [dlcxmon.exe] "C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe"
O4 - HKLM\..\Run: [MemoryCardManager] "C:\Program Files\Dell Photo AIO Printer 926\memcard.exe"
O4 - HKLM\..\Run: [DLCXCATS] rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NielsenOnline] C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O13 - Gopher Prefix:
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoft...s/as2stubie.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: dlcx_device - - C:\Windows\system32\dlcxcoms.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\Windows\System32\LEXBCES.EXE
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 10275 bytes
  • 0

#4
sarahw

sarahw

    Malware Staff

  • Member
  • PipPipPipPipPip
  • 2,781 posts
Hi,
Thanks for telling me about the error. Are you sure you were given this location?
C:\Windows\System32\drivers\host

Please download Deckard's System Scanner (DSS) and save it to your Desktop.
  • Close all other windows before proceeding.
  • Double-click on dss.exe and follow the prompts.
  • When it has finished, dss will open two Notepads main.txt and extra.txt -- please copy (CTRL+A and then CTRL+C) and paste (CTRL+V) the contents of main.txt and extra.txt in your next reply.

  • 0

#5
sarahw

sarahw

    Malware Staff

  • Member
  • PipPipPipPipPip
  • 2,781 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0

#6
sarahw

sarahw

    Malware Staff

  • Member
  • PipPipPipPipPip
  • 2,781 posts
User has returned.


:)
  • 0

#7
sarahw

sarahw

    Malware Staff

  • Member
  • PipPipPipPipPip
  • 2,781 posts
Hi,
Can you please post a fresh Hijack This log.
  • 0

#8
crybaby

crybaby

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 175 posts
Thanks so much for re-opening my thread! Sorry again for my absence. :)
I ran HJT and recieved the same error message as before.
Here is the logfile. I am unsure why the date and time are incorrect. Ran it twice to be sure.
Thanks again!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:02:47 PM, on 4/16/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16643)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe
C:\Program Files\Dell Photo AIO Printer 926\memcard.exe
C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://login.yahoo....mp;.partner=sbc
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.c...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.c...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.c...//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe"
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [dscactivate] c:\dell\dsca.exe 3
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Dell PC Fax\fm3032.exe" /s
O4 - HKLM\..\Run: [dlcxmon.exe] "C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe"
O4 - HKLM\..\Run: [MemoryCardManager] "C:\Program Files\Dell Photo AIO Printer 926\memcard.exe"
O4 - HKLM\..\Run: [DLCXCATS] rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NielsenOnline] C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O13 - Gopher Prefix:
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoft...s/as2stubie.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: dlcx_device - - C:\Windows\system32\dlcxcoms.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\Windows\System32\LEXBCES.EXE
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 10275 bytes

Edited by crybaby, 07 May 2008 - 09:43 AM.

  • 0

#9
sarahw

sarahw

    Malware Staff

  • Member
  • PipPipPipPipPip
  • 2,781 posts
Please download Deckard's System Scanner (DSS) and save it to your Desktop.
  • Close all other windows before proceeding.
  • Double-click on dss.exe and follow the prompts.
  • When it has finished, dss will open two Notepads main.txt and extra.txt -- please copy (CTRL+A and then CTRL+C) and paste (CTRL+V) the contents of main.txt and extra.txt in your next reply.

  • 0

#10
crybaby

crybaby

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 175 posts
Here are the DSS logs


Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------

-- System Information ----------------------------------------------------------

Microsoft® Windows Vista™ Home Basic (build 6000)
Architecture: X86; Language: English

CPU 0: AMD Athlon™ 64 X2 Dual Core Processor 4000+
Percentage of Memory in Use: 69%
Physical Memory (total/avail): 957.88 MiB / 294.81 MiB
Pagefile Memory (total/avail): 2172.23 MiB / 1009.76 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1912.05 MiB

C: is Fixed (NTFS) - 222.78 GiB total, 175.14 GiB free.
D: is Fixed (NTFS) - 10 GiB total, 6.44 GiB free.
E: is CDROM (No Media)

\\.\PHYSICALDRIVE0 - Hitachi HDT725025VLA SCSI Disk Device - 232.83 GiB - 3 partitions
\PARTITION0 - Unknown - 47.03 MiB
\PARTITION1 - Installable File System - 10 GiB - D:
\PARTITION2 (bootable) - Installable File System - 222.78 GiB - C:



-- Security Center -------------------------------------------------------------

AUOptions is scheduled to auto-install.
Windows Internal Firewall is disabled.

FW: PC-cillin Internet Security - Firewall v14 (Trend Micro, Inc.)
AV: AVG 7.5.524 v7.5.524 (Grisoft)
AV: PC-cillin Internet Security - Virus Protection v14.60.1195 (Trend Micro, Inc.) Outdated
AS: PC-cillin Internet Security - Spyware Protection v14.60.1195 (Trend Micro, Inc.) Outdated
AS: Windows Defender v1.1.1505.0 (Microsoft Corporation)

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


-- Environment Variables -------------------------------------------------------

ALLUSERSPROFILE=C:\ProgramData
APPDATA=C:\Users\Shayla\AppData\Roaming
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=MASON-PC
ComSpec=C:\Windows\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Users\Shayla
LOCALAPPDATA=C:\Users\Shayla\AppData\Local
LOGONSERVER=\\MASON-PC
NUMBER_OF_PROCESSORS=2
OS=Windows_NT
Path=C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 107 Stepping 1, AuthenticAMD
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=6b01
ProgramData=C:\ProgramData
ProgramFiles=C:\Program Files
PROMPT=$P$G
PUBLIC=C:\Users\Public
RoxioCentral=C:\Program Files\Common Files\Roxio Shared\9.0\Roxio Central33\
SystemDrive=C:
SystemRoot=C:\Windows
TEMP=C:\Users\Shayla\AppData\Local\Temp
TMP=C:\Users\Shayla\AppData\Local\Temp
USERDOMAIN=Mason-PC
USERNAME=Shayla
USERPROFILE=C:\Users\Shayla
windir=C:\Windows


-- User Profiles ---------------------------------------------------------------

Mason
John
Shayla
Guest (guest)


-- Add/Remove Programs ---------------------------------------------------------

--> C:\Program Files\Yahoo!\Yahoo! Music Jukebox\oggcodecs\uninst.exe
--> MsiExec.exe /I{95D9B4D8-B091-4fab-80EA-313EB4B82FD6}
--> MsiExec.exe /I{EB997E90-5EB0-4eb5-90D0-90B1D2F0CA03}
ABBYY FineReader 5.0 Sprint --> MsiExec.exe /X{D1696920-9794-4BBC-8A30-7A88763DE5A2}
ABBYY FineReader 6.0 Sprint --> MsiExec.exe /X{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}
Adobe Flash Player ActiveX --> C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player Plugin --> C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 8.1.2 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81200000003}
American Civil War Gettysburg --> MsiExec.exe /I{996F1BF8-D7BB-40A1-80E3-13DF6C2866F0}
AVG 7.5 --> C:\Program Files\Grisoft\AVG7\setup.exe /UNINSTALL
Better Homes and Gardens Home Designer 6.0 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{27B49720-BF6E-476B-B86A-63AD5FE7E34A}\setup.exe" -l0x9
Browser Address Error Redirector --> MsiExec.exe /I{62230596-37E5-4618-A329-0D21F529A86F}
Conexant D850 PCI V.92 Modem --> C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200F14F1\HXFSETUP.EXE -U -IDel200fz.inf
Dell DataSafe Online --> MsiExec.exe /I{2C6C74C2-042F-4D36-B7B0-0C538FCF01AB}
Dell Getting Started Guide --> MsiExec.exe /I{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}
Dell PC Fax --> C:\Program Files\Dell PC Fax\Install\x86\Uninst.exe /R:faxunst
Dell Photo AIO Printer 926 --> C:\Program Files\Dell Photo AIO Printer 926\Install\x86\Uninst.exe
Dell Support Center --> MsiExec.exe /X{B8C54AB1-7E1A-40E8-B794-EDB6E8921F3A}
DellSupport --> MsiExec.exe /X{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}
Digital Line Detect --> C:\Program Files\InstallShield Installation Information\{E646DCF0-5A68-11D5-B229-002078017FBF}\setup.exe -runfromtemp -l0x0009 -removeonly
Disney Pirates of the Caribbean Online --> C:\Program Files\Disney\Disney Online\PiratesOnline\uninst.exe
Disney Toontown Online --> C:\Program Files\Disney\Disney Online\ToontownOnline\uninst.exe
FaxTools --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F45298E5-0083-426F-A668-1A2C5F04B8A0}\setup.exe" -l0x9 ControlPanel
Google Desktop --> C:\Program Files\Google\Google Desktop Search\GoogleDesktopSetup.exe -uninstall
Google Earth --> MsiExec.exe /I{1E04F83B-2AB9-4301-9EF7-E86307F79C72}
Google Toolbar for Internet Explorer --> MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29}
Google Toolbar for Internet Explorer --> regsvr32 /u /s "c:\program files\google\googletoolbar1.dll"
Google Updater --> "C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Java™ SE Runtime Environment 6 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160000}
Lexmark X1100 Series --> C:\Windows\system32\spool\drivers\w32x86\3\LXBKUN5C.EXE -dLexmark X1100 Series
Malwarebytes' Anti-Malware --> "C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Mickey Mouse Preschool --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{411C452C-7F92-405E-B9A0-EA6BD3C4A630}\setup.exe" -l0x9 Mickey Mouse Preschool
Microsoft Works --> MsiExec.exe /I{6D52C408-B09A-4520-9B18-475B81D393F1}
Modem Diagnostic Tool --> MsiExec.exe /I{F63A3748-B93D-4360-9AD4-B064481A5C7B}
Mozilla Firefox (2.0.0.14) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSXML 4.0 SP2 (KB936181) --> MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB941833) --> MsiExec.exe /I{C523D256-313D-4866-B36A-F3DE528246EF}
Music, Photos & Videos Launcher --> MsiExec.exe /I{D7769185-9A7C-48D4-8874-5388743A1DE2}
MyPoints Toolbar --> C:\Program Files\mypoints\uninstall.exe
NetWaiting --> C:\Program Files\InstallShield Installation Information\{3F92ABBB-6BBF-11D5-B229-002078017FBF}\setup.exe -runfromtemp -l0x0009 -removeonly
Nielsen//NetRatings --> C:\PROGRA~1\NETRAT~1\NetSight\NSSetup.exe /uninstall
NVIDIA Drivers --> C:\Windows\system32\NVUNINST.EXE UninstallGUI
NVIDIANetworkDiagnostic --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{EFAD4066-CAF3-4B27-9669-12EED352C376}
Panda ActiveScan 2.0 --> C:\Program Files\Panda Security\ActiveScan 2.0\as2uninst.exe
PowerDVD --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{281ECE39-F043-492B-8337-F2E546B5604A}\Setup.exe" -l0x9 -cluninstall
Product Documentation Launcher --> MsiExec.exe /I{89CEAE14-DD0F-448E-9554-15781EC9DB24}
Realtek High Definition Audio Driver --> RtlUpd.exe -r -m
Roxio Creator Audio --> MsiExec.exe /I{83FFCFC7-88C6-41c6-8752-958A45325C82}
Roxio Creator BDAV Plugin --> MsiExec.exe /I{880AF49C-34F7-4285-A8AD-8F7A3D1C33DC}
Roxio Creator Copy --> MsiExec.exe /I{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}
Roxio Creator Data --> MsiExec.exe /I{0D397393-9B50-4c52-84D5-77E344289F87}
Roxio Creator DE --> MsiExec.exe /I{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}
Roxio Creator Tools --> MsiExec.exe /I{0394CDC8-FABD-4ed8-B104-03393876DFDF}
Roxio Express Labeler --> MsiExec.exe /I{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
Roxio MyDVD DE --> MsiExec.exe /I{D639085F-4B6E-4105-9F37-A0DBB023E2FB}
Roxio Update Manager --> MsiExec.exe /I{30465B6C-B53F-49A1-9EBA-A3F187AD502E}
Sonic Activation Module --> MsiExec.exe /I{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}
SUPERAntiSpyware Free Edition --> MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}
Trend Micro PC-cillin Internet Security 14 --> C:\PROGRA~1\TRENDM~1\INTERN~1\remove.exe
Trend Micro PC-cillin Internet Security 14 --> MsiExec.exe /X{EA8C73AA-3D75-44C9-87A2-8E945FC5FEE6}
User's Guides --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5CD29180-A95E-11D3-A4EB-00C04F7BDB2C}\setup.exe"
VNC Mirror Driver 1.7.1 --> "C:\Program Files\RealVNC\VNC4\Mirror Driver\unins000.exe"
VNC Personal Edition P4.3.2 --> "C:\Program Files\RealVNC\VNC4\unins000.exe"
Winnie the Pooh Preschool --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BDAC64EB-F3CF-47EC-AB54-42D3BD3A8633}\setup.exe" -l0x9 Winnie the Pooh Preschool
Yahoo! Browser Services --> C:\PROGRA~1\Yahoo!\Common\UNIN_Y~1.EXE /S
Yahoo! Install Manager --> C:\Windows\system32\regsvr32 /u C:\PROGRA~1\Yahoo!\Common\YINSTH~1.DLL
Yahoo! Internet Mail --> C:\Windows\system32\regsvr32 /u /s C:\PROGRA~1\Yahoo!\Common\YMMAPI.dll
Yahoo! Messenger --> C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE /U C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG
Yahoo! Music Jukebox --> MsiExec.exe /X{EC3B8CA2-49B8-4D38-BE9C-ABD0F6029168}
Yahoo! Toolbar --> C:\PROGRA~1\Yahoo!\Common\unyt.exe


-- Application Event Log -------------------------------------------------------

Event Record #/Type4814 / Success
Event Submitted/Written: 05/09/2008 08:01:45 AM
Event ID/Source: 5617 / WinMgmt
Event Description:


Event Record #/Type4813 / Success
Event Submitted/Written: 05/09/2008 08:01:32 AM
Event ID/Source: 5615 / WinMgmt
Event Description:


Event Record #/Type4808 / Success
Event Submitted/Written: 05/09/2008 08:00:34 AM
Event ID/Source: 902 / Software Licensing Service
Event Description:
The Software Licensing service has started.

Event Record #/Type4800 / Warning
Event Submitted/Written: 05/08/2008 05:02:53 PM
Event ID/Source: 882 / Microsoft-Windows-SoftwareRestrictionPolicies
Event Description:
C:\Program Files\Google\Google Updater\GoogleUpdater.exe{8C2BF56D-D649-4B87-8177-8C2FE0838029}

Event Record #/Type4799 / Warning
Event Submitted/Written: 05/08/2008 05:02:47 PM
Event ID/Source: 882 / Microsoft-Windows-SoftwareRestrictionPolicies
Event Description:
C:\Program Files\Grisoft\AVG7\avgw.exe{8C2BF56D-D649-4B87-8177-8C2FE0838029}



-- Security Event Log ----------------------------------------------------------

No Errors/Warnings found.


-- System Event Log ------------------------------------------------------------

Event Record #/Type18080 / Error
Event Submitted/Written: 05/09/2008 08:02:52 AM
Event ID/Source: 4321 / netbt
Event Description:
The name "POTTERSHOME :1d" could not be registered on the interface with IP address 169.254.116.78.
The computer with the IP address 192.168.1.78 did not allow the name to be claimed by
this computer.

Event Record #/Type18037 / Error
Event Submitted/Written: 05/09/2008 08:02:09 AM
Event ID/Source: 7000 / Service Control Manager
Event Description:
Parallel port driver%%1058

Event Record #/Type18003 / Error
Event Submitted/Written: 05/09/2008 08:01:36 AM
Event ID/Source: 4321 / netbt
Event Description:
The name "POTTERSHOME :1d" could not be registered on the interface with IP address 169.254.116.78.
The computer with the IP address 192.168.1.78 did not allow the name to be claimed by
this computer.

Event Record #/Type18001 / Warning
Event Submitted/Written: 05/09/2008 08:00:58 AM
Event ID/Source: 1003 / Dhcp
Event Description:
Your computer was not able to renew its address from the network (from the DHCP Server) for the Network Card with network address 001AA06945F1. The following error occurred:
%%121. Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.

Event Record #/Type17997 / Error
Event Submitted/Written: 05/09/2008 08:00:30 AM
Event ID/Source: 6008 / EventLog
Event Description:
The previous system shutdown at 5:44:33 PM on 5/8/2008 was unexpected.



-- End of Deckard's System Scanner: finished at 2008-05-09 09:26:00 ------------



Deckard's System Scanner v20071014.68
Run by Shayla on 2008-05-09 09:19:45
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- Last 5 Restore Point(s) --
20: 2008-05-09 13:38:31 UTC - RP173 - Scheduled Checkpoint
19: 2008-05-08 00:37:53 UTC - RP172 - Scheduled Checkpoint
18: 2008-05-07 05:00:11 UTC - RP171 - Scheduled Checkpoint
17: 2008-05-06 05:00:10 UTC - RP170 - Scheduled Checkpoint
16: 2008-05-05 16:16:57 UTC - RP169 - Installed Mickey Mouse Preschool


-- First Restore Point --
1: 2008-04-22 14:36:10 UTC - RP151 - Scheduled Checkpoint


Backed up registry hives.
Performed disk cleanup.

Total Physical Memory: 958 MiB (1024 MiB recommended).


-- HijackThis (run as Shayla.exe) ----------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:21:59 AM, on 5/9/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16643)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe
C:\Program Files\Dell Photo AIO Printer 926\memcard.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Grisoft\AVG7\avgw.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Users\Shayla\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Shayla.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://login.yahoo....mp;.partner=sbc
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.c...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.c...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.c...//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: MYPOINTS - {A057A204-BACC-4D26-CEC4-75A487FD6484} - C:\PROGRA~1\mypoints\mypoints.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: MYPOINTS - {A057A204-BACC-4D26-CEC4-75A487FD6484} - C:\PROGRA~1\mypoints\mypoints.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe"
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [dscactivate] c:\dell\dsca.exe 3
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Dell PC Fax\fm3032.exe" /s
O4 - HKLM\..\Run: [dlcxmon.exe] "C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe"
O4 - HKLM\..\Run: [MemoryCardManager] "C:\Program Files\Dell Photo AIO Printer 926\memcard.exe"
O4 - HKLM\..\Run: [DLCXCATS] rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NielsenOnline] C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O13 - Gopher Prefix:
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoft...s/as2stubie.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {5E92F538-B50B-46C5-9C5F-C6EECED3F6C6} - http://www.infospace...pointsSetup.exe
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: dlcx_device - - C:\Windows\system32\dlcxcoms.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\Windows\System32\LEXBCES.EXE
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 10657 bytes

-- File Associations -----------------------------------------------------------

All associations okay.


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R1 nnrnstdi - c:\windows\system32\drivers\nnrnstdi.sys <Not Verified; NetRatings, Inc.; NielsenOnline>
R1 SASDIFSV - \??\c:\program files\superantispyware\sasdifsv.sys
R1 SASKUTIL - \??\c:\program files\superantispyware\saskutil.sys
R3 DSproct - \??\c:\program files\dellsupport\gtaction\triggers\dsproct.sys

S3 SASENUM - \??\c:\program files\superantispyware\sasenum.sys


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

S3 DSBrokerService - "c:\program files\dellsupport\brkrsvc.exe" <Not Verified; ; Gteko BrkrSvc Application>
S3 stllssvr - "c:\program files\common files\surething shared\stllssvr.exe" <Not Verified; MicroVision Development, Inc.; SureThing CD Labeler>


-- Device Manager: Disabled ----------------------------------------------------

No disabled devices found.


-- Files created between 2008-04-09 and 2008-05-09 -----------------------------

2008-05-05 09:56:06 0 dr-h----- C:\$VAULT$.AVG
2008-05-05 09:38:17 0 d-------- C:\Program Files\Disney Interactive
2008-04-25 14:00:28 0 d-------- C:\Windows\Sun
2008-04-25 13:58:06 0 d-------- C:\Program Files\mypoints
2008-04-16 20:18:13 0 d-------- C:\Users\All Users\Grisoft
2008-04-16 20:18:13 0 d-------- C:\Users\All Users\avg7
2008-04-16 17:05:21 0 d-------- C:\Program Files\Panda Security
2008-04-16 13:06:03 13312 --a------ C:\Windows\system32\drivers\nnrnstdi.sys <Not Verified; NetRatings, Inc.; NielsenOnline>
2008-04-16 13:02:45 49152 --a------ C:\Windows\nswatchdog.exe
2008-04-16 13:02:45 0 d-------- C:\Program Files\NetRatingsNetSight
2008-04-14 12:23:16 0 d-------- C:\Users\All Users\SUPERAntiSpyware.com
2008-04-14 12:23:05 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-04-14 12:22:11 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-14 12:12:40 0 d-------- C:\Users\All Users\Malwarebytes
2008-04-14 12:12:39 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-04-11 21:34:20 0 d-------- C:\Users\All Users\Google Updater
2008-04-11 07:56:54 0 d-------- C:\Program Files\Common Files\Adobe
2008-04-10 19:12:26 0 d-------- C:\Program Files\MSXML 4.0
2008-04-10 17:12:23 0 d-------- C:\Program Files\ABBYY FineReader 6.0
2008-04-10 17:12:23 0 d-------- C:\Program Files\ABBYY FineReader 5.0 Sprint
2008-04-10 17:11:42 0 d-------- C:\Users\All Users\BVRP Software
2008-04-10 17:11:42 0 d-------- C:\Program Files\FaxTools
2008-04-10 13:21:17 0 d-------- C:\Users\Shayla\{f1767691-b537-4b75-b137-02b0c8a8e390}
2008-04-10 13:20:49 0 d-------- C:\Program Files\Lexmark X1100 Series
2008-04-10 13:17:58 299520 --a------ C:\Windows\uninst.exe <Not Verified; InstallShield Corporation, Inc.; InstallShield unInstaller>
2008-04-10 13:17:52 0 -rahs---- C:\MSDOS.SYS
2008-04-10 13:17:52 0 -rahs---- C:\IO.SYS
2008-04-09 17:38:59 0 --a------ C:\Windows\nsreg.dat


-- Find3M Report ---------------------------------------------------------------

2008-05-09 09:17:58 0 d-------- C:\Users\Shayla\AppData\Roaming\AVG7
2008-05-05 11:16:10 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-05-05 09:38:48 0 d-------- C:\Users\Shayla\AppData\Roaming\Leadertech
2008-04-23 20:09:27 0 d-------- C:\Users\Shayla\AppData\Roaming\Google
2008-04-20 11:49:48 0 d-------- C:\Program Files\Dl_cats
2008-04-16 23:02:18 0 d-------- C:\Program Files\Trend Micro
2008-04-15 10:13:34 0 d-------- C:\Users\Shayla\AppData\Roaming\Adobe
2008-04-14 12:23:05 0 d-------- C:\Users\Shayla\AppData\Roaming\SUPERAntiSpyware.com
2008-04-14 12:22:11 0 d-------- C:\Program Files\Common Files
2008-04-14 12:12:46 0 d-------- C:\Users\Shayla\AppData\Roaming\Malwarebytes
2008-04-14 12:12:28 0 d-------- C:\Users\Shayla\AppData\Roaming\Download Manager
2008-04-11 21:37:34 0 d-------- C:\Program Files\Google
2008-04-11 21:34:26 0 d-------- C:\Users\Shayla\AppData\Roaming\Yahoo!
2008-04-11 19:55:47 296 --a------ C:\Users\Shayla\AppData\Roaming\wklnhst.dat
2008-04-10 21:07:03 0 d-------- C:\Program Files\Windows Mail
2008-04-10 21:07:01 0 d-------- C:\Program Files\Windows Sidebar
2008-04-10 13:27:18 0 d-------- C:\Users\Shayla\AppData\Roaming\Template
2008-04-09 17:38:54 0 d-------- C:\Users\Shayla\AppData\Roaming\Mozilla


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-CEC4-75A487FD6484}]
10/02/2007 03:31 PM 1909248 --a------ C:\PROGRA~1\mypoints\mypoints.dll

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{A057A204-BACC-4D26-CEC4-75A487FD6484}"= C:\PROGRA~1\mypoints\mypoints.dll [10/02/2007 03:31 PM 1909248]

[-HKEY_CLASSES_ROOT\CLSID\{A057A204-BACC-4D26-CEC4-75A487FD6484}]
[HKEY_CLASSES_ROOT\mypoints.MYPOINTS]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [11/21/2007 06:40 PM]
"ECenter"="C:\Dell\E-Center\EULALauncher.exe" [05/25/2007 01:03 AM]
"RtHDVCpl"="RtHDVCpl.exe" [09/24/2007 04:41 AM C:\Windows\RtHDVCpl.exe]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [09/22/2007 11:11 PM]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [09/22/2007 11:11 PM]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [09/22/2007 11:11 PM]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [10/03/2006 11:37 AM]
"@"="" []
"pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 14\pccguide.exe" [11/21/2006 03:02 PM]
"PDVDDXSrv"="C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [10/20/2006 05:23 PM]
"dscactivate"="c:\dell\dsca.exe" [07/30/2007 02:40 PM]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [11/21/2007 11:21 AM]
"FaxCenterServer"="C:\Program Files\Dell PC Fax\fm3032.exe" [11/03/2006 05:09 PM]
"dlcxmon.exe"="C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe" [01/12/2007 11:57 AM]
"MemoryCardManager"="C:\Program Files\Dell Photo AIO Printer 926\memcard.exe" [11/03/2006 05:04 PM]
"DLCXCATS"="C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCXtime.dll" [10/16/2006 12:31 AM]
"WPCUMI"="C:\Windows\system32\WpcUmi.exe" [11/02/2006 07:34 AM]
"Lexmark X1100 Series"="C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" []
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [01/11/2008 10:16 PM]
"NielsenOnline"="C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe" [11/16/2007 06:55 PM]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [04/16/2008 08:18 PM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [03/15/2007 12:09 PM]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [11/21/2007 11:21 AM]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [11/02/2006 07:34 AM]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [11/21/2007 11:05:16 AM]
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [4/11/2008 9:34:19 PM]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"=2 (0x2)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"LogonHoursAction"=2 (0x2)
"DontDisplayLogonHoursWarnings"=1 (0x1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [12/20/2006 12:55 PM 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 02/27/2007 11:39 AM 282624 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgwlntf]
avgwlntf.dll 04/16/2008 08:18 PM 9216 C:\Windows\System32\avgwlntf.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
@="IEEE 1394 Bus host controllers"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
@="SBP2 IEEE 1394 Devices"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
@="SecurityDevices"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalService nsi lltdsvc SSDPSRV upnphost SCardSvr w32time EventSystem RemoteRegistry WinHttpAutoProxySvc lanmanworkstation TBS SLUINotify THREADORDER fdrespub netprofm fdphost wcncsvc QWAVE WebClient
LocalSystemNetworkRestricted hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc wlansvc EMDMgmt TabletInputService WPDBusEnum
LocalServiceNoNetwork PLA DPS BFE mpssvc


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
C:\Windows\system32\unregmp2.exe /ShowWMP

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
%SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI



-- End of Deckard's System Scanner: finished at 2008-05-09 09:26:00 ------------
  • 0

#11
sarahw

sarahw

    Malware Staff

  • Member
  • PipPipPipPipPip
  • 2,781 posts
Hi,

1.
Can you please uninstall this:
MyPoints Toolbar
Click Start, then Control Panel, then open Programs and Features. Locate it in the list, then click Uninstall.

2.
Updating Java and Clearing Cache
  • Go to Start > Control Panel double-click on the Java Icon (coffee cup) in the Control Panel.
  • It will say "Java Plug-in" under the icon.
    Please find the update button or tab in the Java Control Panel. Update your Java then reboot.
  • If you are unable to update you can manually update by going here:
  • After the reboot, go back into the Control Panel and double-click the Java Icon.
  • Under Temporary Internet Files, click the Delete Files button.
  • There are three options in the window to clear the cache - Leave ALL 3 Checked
    Downloaded Applets
    Downloaded Applications
    Other Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Java Control Panel.


3.
Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 onlyDouble-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.


4.
Please download Malwarebytes' Anti-Malware to your desktop.

Double-click mbam-setup.exe and follow the prompts to install the program.
At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select Perform full scan (Full scan is optional. According to the program's creator Quick Scan will do just fine.).
Click Scan.
When the scan is complete, click OK, then Show Results to view the results.

If Malware is found...
Be sure that everything is checked, and click Remove Selected.
When completed, a log will open in Notepad.
Please save it to your desktop.

NOTE: Logs can be retrieved at a later date from the Malwarebytes' Anti-Malware main screen:

Launch Malwarebytes' Anti-Malware.
Click the Logs tab.
Double-click log-mm.dd.yyyy [xxxxxx].txt.

In your next reply post the Malwarebytes' Anti-Malware log.


5.
Click HERE and run an online scan with Kaspersky WebScanner
  • Click on Kaspersky Online Scanner
  • You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
  • Scan Options:
    Scan Archives
    Scan Mail Bases
[*]Click OK
[*]Now under select a target to scan:Select My Computer
[*]This will program will start and scan your system.
[*]The scan will take a while so be patient and let it run.
[*]Once the scan is complete it will display if your system has been infected.
Now click on the Save as Text button:
[*]Save the file to your desktop.
[*]Copy and paste that information into your next post.
[/list]
  • 0

#12
crybaby

crybaby

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 175 posts
ok, here are the new logs you asked for. Sorry it took so long! Hope you had a nice holiday this past weekend! Thanks again! :)

Malwarebytes' Anti-Malware 1.11
Database version: 625

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 134078
Time elapsed: 28 minute(s), 13 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)




KASPERSKY ONLINE SCANNER REPORT
Monday, May 12, 2008 7:47:20 PM
Operating System: Microsoft Windows Vista Home Edition, (Build 6000)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 12/05/2008
Kaspersky Anti-Virus database records: 763380


Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true

Scan Target My Computer
C:\
D:\
E:\

Scan Statistics
Total number of scanned objects 83583
Number of viruses found 0
Number of infected objects 0
Number of suspicious objects 0
Duration of the scan process 00:47:27

Infected Object Name Virus Name Last Action
C:\Boot\BCD Object is locked skipped

C:\Boot\BCD.LOG Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\DMI5938.tmp Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080416-070149-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080416-070200-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080416-154211-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080416-154226-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080416-210547-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080416-210600-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080417-071827-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080417-071841-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080417-114904-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080417-114917-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080417-175651-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080417-175704-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080417-214243-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080417-214257-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080418-175605-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080418-175618-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080419-004715-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080419-004728-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080419-153704-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080419-153717-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080420-101625-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080420-101638-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080421-100115-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080421-100127-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080421-132842-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080421-132855-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080421-175922-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080421-180013-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080422-072954-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080422-073007-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080422-130944-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080422-130956-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080423-160201-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080423-160214-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080424-071524-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080424-071538-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080424-172047-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080424-172101-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080425-065758-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080425-065810-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080425-131814-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080425-131828-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080425-153902-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080425-153914-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080425-221426-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080425-221440-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080426-072743-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080426-072755-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080426-171321-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080426-171334-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080427-114614-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080427-114628-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080428-165040-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080428-165054-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080429-193504-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080429-193516-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080429-202548-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080429-202601-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080430-174653-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080430-174708-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080506-105730-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080506-105743-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080507-104644-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080507-104657-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080509-081533-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\lpksetup-20080509-081545-0.log Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\SPL6834.tmp Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\SPLCC81.tmp Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\WER926D.tmp.version.txt Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\WER927D.tmp.appcompat.txt Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\WERC40C.tmp.version.txt Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\WERC41C.tmp.appcompat.txt Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\WERD28E.tmp.version.txt Object is locked skipped

C:\Deckard\System Scanner\backup\Windows\temp\WERD29E.tmp.appcompat.txt Object is locked skipped

C:\Program Files\InstallShield Installation Information\{5CD29180-A95E-11D3-A4EB-00C04F7BDB2C}\setup.ilg Object is locked skipped

C:\Program Files\InstallShield Installation Information\{F45298E5-0083-426F-A668-1A2C5F04B8A0}\setup.ilg Object is locked skipped

C:\Program Files\Trend Micro\Internet Security 14\Quarantine\71DA.tmp Object is locked skipped

C:\Program Files\Trend Micro\Internet Security 14\Quarantine\91E9.tmp Object is locked skipped

C:\ProgramData\avg7\Log\emc.log Object is locked skipped

C:\ProgramData\Grisoft\Avg7Data\avg7log.log Object is locked skipped

C:\ProgramData\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped

C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\dell.txt Object is locked skipped

C:\ProgramData\Microsoft\User Account Pictures\Guest.dat Object is locked skipped

C:\ProgramData\Microsoft\User Account Pictures\John.dat Object is locked skipped

C:\ProgramData\Microsoft\User Account Pictures\Mason.dat Object is locked skipped

C:\ProgramData\Microsoft\Windows\DRM\Cache\Indiv01.tmp Object is locked skipped

C:\ProgramData\Microsoft\Windows\DRM\drmstore.hds Object is locked skipped

C:\ProgramData\Trend Micro\PC-cillin\log\pcc_S-1-5-21-1260561122-373576474-2963483527-1000.log Object is locked skipped

C:\ProgramData\Trend Micro\PC-cillin\log\pcc_S-1-5-21-1260561122-373576474-2963483527-1000u.log Object is locked skipped

C:\ProgramData\Trend Micro\PC-cillin\log\pcc_S-1-5-21-1260561122-373576474-2963483527-1002.log Object is locked skipped

C:\ProgramData\Trend Micro\PC-cillin\log\pcc_S-1-5-21-1260561122-373576474-2963483527-1002u.log Object is locked skipped

C:\ProgramData\Trend Micro\PC-cillin\log\pcc_S-1-5-21-1260561122-373576474-2963483527-500.log Object is locked skipped

C:\ProgramData\Trend Micro\PC-cillin\log\pcc_S-1-5-21-1260561122-373576474-2963483527-501.log Object is locked skipped

C:\ProgramData\Trend Micro\PC-cillin\log\TmPfw_S-1-5-21-1260561122-373576474-2963483527-500.log Object is locked skipped

C:\ProgramData\Trend Micro\PC-cillin\Temp\scan_S-1-5-21-1260561122-373576474-2963483527-1000.ini Object is locked skipped

C:\ProgramData\Trend Micro\PC-cillin\Temp\scan_S-1-5-21-1260561122-373576474-2963483527-1002.ini Object is locked skipped

C:\ProgramData\Trend Micro\PC-cillin\Temp\spyscan_S-1-5-21-1260561122-373576474-2963483527-1002.ini Object is locked skipped

C:\Users\Shayla\AppData\Local\Google\Google Desktop\74f0b1a0cc6d\dbc2e.ht1 Object is locked skipped

C:\Users\Shayla\AppData\Local\Google\Google Desktop\74f0b1a0cc6d\dbdam Object is locked skipped

C:\Users\Shayla\AppData\Local\Google\Google Desktop\74f0b1a0cc6d\dbdao Object is locked skipped

C:\Users\Shayla\AppData\Local\Google\Google Desktop\74f0b1a0cc6d\dbeam Object is locked skipped

C:\Users\Shayla\AppData\Local\Google\Google Desktop\74f0b1a0cc6d\dbeao Object is locked skipped

C:\Users\Shayla\AppData\Local\Google\Google Desktop\74f0b1a0cc6d\dbm Object is locked skipped

C:\Users\Shayla\AppData\Local\Google\Google Desktop\74f0b1a0cc6d\dbu2d.ht1 Object is locked skipped

C:\Users\Shayla\AppData\Local\Google\Google Desktop\74f0b1a0cc6d\dbvm.cf1 Object is locked skipped

C:\Users\Shayla\AppData\Local\Google\Google Desktop\74f0b1a0cc6d\dbvmh.ht1 Object is locked skipped

C:\Users\Shayla\AppData\Local\Google\Google Desktop\74f0b1a0cc6d\fii.cf1 Object is locked skipped

C:\Users\Shayla\AppData\Local\Google\Google Desktop\74f0b1a0cc6d\fiih.ht1 Object is locked skipped

C:\Users\Shayla\AppData\Local\Google\Google Desktop\74f0b1a0cc6d\hp Object is locked skipped

C:\Users\Shayla\AppData\Local\Google\Google Desktop\74f0b1a0cc6d\hpt2i.ht1 Object is locked skipped

C:\Users\Shayla\AppData\Local\Google\Google Desktop\74f0b1a0cc6d\rpm.cf1 Object is locked skipped

C:\Users\Shayla\AppData\Local\Google\Google Desktop\74f0b1a0cc6d\rpm1m.cf1 Object is locked skipped

C:\Users\Shayla\AppData\Local\Google\Google Desktop\74f0b1a0cc6d\rpm1mh.ht1 Object is locked skipped

C:\Users\Shayla\AppData\Local\Google\Google Desktop\74f0b1a0cc6d\rpmh.ht1 Object is locked skipped

C:\Users\Shayla\AppData\Local\Google\Google Desktop\74f0b1a0cc6d\safeweb\goog-black-enchashm.cf1 Object is locked skipped

C:\Users\Shayla\AppData\Local\Google\Google Desktop\74f0b1a0cc6d\safeweb\goog-black-enchashmh.ht1 Object is locked skipped

C:\Users\Shayla\AppData\Local\Google\Google Desktop\74f0b1a0cc6d\safeweb\goog-black-urlm.cf1 Object is locked skipped

C:\Users\Shayla\AppData\Local\Google\Google Desktop\74f0b1a0cc6d\safeweb\goog-black-urlmh.ht1 Object is locked skipped

C:\Users\Shayla\AppData\Local\Google\Google Desktop\74f0b1a0cc6d\safeweb\goog-malware-domainm.cf1 Object is locked skipped

C:\Users\Shayla\AppData\Local\Google\Google Desktop\74f0b1a0cc6d\safeweb\goog-malware-domainmh.ht1 Object is locked skipped

C:\Users\Shayla\AppData\Local\Google\Google Desktop\74f0b1a0cc6d\safeweb\goog-white-domainm.cf1 Object is locked skipped

C:\Users\Shayla\AppData\Local\Google\Google Desktop\74f0b1a0cc6d\safeweb\goog-white-domainmh.ht1 Object is locked skipped

C:\Users\Shayla\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat Object is locked skipped

C:\Users\Shayla\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008051220080513\index.dat Object is locked skipped

C:\Users\Shayla\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.dat Object is locked skipped

C:\Users\Shayla\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Users\Shayla\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped

C:\Users\Shayla\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.dat Object is locked skipped

C:\Users\Shayla\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT Object is locked skipped

C:\Users\Shayla\AppData\Local\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Users\Shayla\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 Object is locked skipped

C:\Users\Shayla\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2 Object is locked skipped

C:\Users\Shayla\AppData\Local\Microsoft\Windows\UsrClass.dat{e89dcb33-a104-11dc-b119-001aa06945f1}.TM.blf Object is locked skipped

C:\Users\Shayla\AppData\Local\Microsoft\Windows\UsrClass.dat{e89dcb33-a104-11dc-b119-001aa06945f1}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped

C:\Users\Shayla\AppData\Local\Microsoft\Windows\UsrClass.dat{e89dcb33-a104-11dc-b119-001aa06945f1}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped

C:\Users\Shayla\AppData\Local\Microsoft\Feeds Cache\index.dat Object is locked skipped

C:\Users\Shayla\AppData\Local\Temp\Low\~DF17E9.tmp Object is locked skipped

C:\Users\Shayla\AppData\Local\Temp\Low\~DF85B7.tmp Object is locked skipped

C:\Users\Shayla\AppData\Local\Temp\Low\~DF85BF.tmp Object is locked skipped

C:\Users\Shayla\AppData\Local\Temp\~DFC1BA.tmp Object is locked skipped

C:\Users\Shayla\AppData\Local\Temp\~DFE0D4.tmp Object is locked skipped

C:\Users\Shayla\AppData\Local\Temp\~DFFF4B.tmp Object is locked skipped

C:\Users\Shayla\AppData\Roaming\GTek\GTUpdate\AUpdate\DellSupport\DSAgnt.log Object is locked skipped

C:\Users\Shayla\AppData\Roaming\GTek\GTUpdate\AUpdate\DellSupport\DSAgnt_GTActions.log Object is locked skipped

C:\Users\Shayla\AppData\Roaming\GTek\GTUpdate\AUpdate\DellSupport\gdql_d_DSAgnt.log Object is locked skipped

C:\Users\Shayla\AppData\Roaming\GTek\GTUpdate\AUpdate\DellSupport\glog.log Object is locked skipped

C:\Users\Shayla\AppData\Roaming\Microsoft\Windows\Cookies\index.dat Object is locked skipped

C:\Users\Shayla\AppData\Roaming\Microsoft\Windows\Cookies\Low\index.dat Object is locked skipped

C:\Users\Shayla\NTUSER.DAT Object is locked skipped

C:\Users\Shayla\ntuser.dat.LOG1 Object is locked skipped

C:\Users\Shayla\ntuser.dat.LOG2 Object is locked skipped

C:\Users\Shayla\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TM.blf Object is locked skipped

C:\Users\Shayla\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped

C:\Users\Shayla\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped

C:\Windows\Debug\PASSWD.LOG Object is locked skipped

C:\Windows\Debug\sam.log Object is locked skipped

C:\Windows\Debug\WIA\wiatrace.log Object is locked skipped

C:\Windows\Logs\CBS\CBS.log Object is locked skipped

C:\Windows\Logs\DPX\setupact.log Object is locked skipped

C:\Windows\Logs\DPX\setuperr.log Object is locked skipped

C:\Windows\MEMORY.DMP Object is locked skipped

C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe.config Object is locked skipped

C:\Windows\Panther\setupact.log Object is locked skipped

C:\Windows\Panther\setuperr.log Object is locked skipped

C:\Windows\Panther\UnattendGC\diagerr.xml Object is locked skipped

C:\Windows\Panther\UnattendGC\diagwrn.xml Object is locked skipped

C:\Windows\Panther\UnattendGC\setupact.bld Object is locked skipped

C:\Windows\Panther\UnattendGC\setupact.log Object is locked skipped

C:\Windows\Panther\UnattendGC\setuperr.bld Object is locked skipped

C:\Windows\Panther\UnattendGC\setuperr.log Object is locked skipped

C:\Windows\security\database\secedit.sdb Object is locked skipped

C:\Windows\SoftwareDistribution\EventCache\{E2BCF4B9-89A5-4E18-BAC4-B04E51AFC78B}.bin Object is locked skipped

C:\Windows\SoftwareDistribution\ReportingEvents.log Object is locked skipped

C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 Object is locked skipped

C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 Object is locked skipped

C:\Windows\System32\catroot2\edb.log Object is locked skipped

C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb Object is locked skipped

C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb Object is locked skipped

C:\Windows\System32\config\COMPONENTS Object is locked skipped

C:\Windows\System32\config\COMPONENTS.LOG1 Object is locked skipped

C:\Windows\System32\config\COMPONENTS.LOG2 Object is locked skipped

C:\Windows\System32\config\DEFAULT Object is locked skipped

C:\Windows\System32\config\DEFAULT.LOG1 Object is locked skipped

C:\Windows\System32\config\DEFAULT.LOG2 Object is locked skipped

C:\Windows\System32\config\SAM Object is locked skipped

C:\Windows\System32\config\SAM.LOG1 Object is locked skipped

C:\Windows\System32\config\SAM.LOG2 Object is locked skipped

C:\Windows\System32\config\SECURITY Object is locked skipped

C:\Windows\System32\config\SECURITY.LOG1 Object is locked skipped

C:\Windows\System32\config\SECURITY.LOG2 Object is locked skipped

C:\Windows\System32\config\SOFTWARE Object is locked skipped

C:\Windows\System32\config\SOFTWARE.LOG1 Object is locked skipped

C:\Windows\System32\config\SOFTWARE.LOG2 Object is locked skipped

C:\Windows\System32\config\SYSTEM Object is locked skipped

C:\Windows\System32\config\SYSTEM.LOG1 Object is locked skipped

C:\Windows\System32\config\SYSTEM.LOG2 Object is locked skipped

C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.0.regtrans-ms Object is locked skipped

C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.1.regtrans-ms Object is locked skipped

C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.2.regtrans-ms Object is locked skipped

C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.blf Object is locked skipped

C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TM.blf Object is locked skipped

C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped

C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped

C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000003.regtrans-ms Object is locked skipped

C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000004.regtrans-ms Object is locked skipped

C:\Windows\System32\LogFiles\Scm\SCM.EVM Object is locked skipped

C:\Windows\System32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped

C:\Windows\System32\restore\MachineGuid.txt Object is locked skipped

C:\Windows\System32\spool\SpoolerETW.etl Object is locked skipped

C:\Windows\System32\sysprep\Panther\diagerr.xml Object is locked skipped

C:\Windows\System32\sysprep\Panther\diagwrn.xml Object is locked skipped

C:\Windows\System32\sysprep\Panther\setupact.bld Object is locked skipped

C:\Windows\System32\sysprep\Panther\setupact.log Object is locked skipped

C:\Windows\System32\sysprep\Panther\setuperr.bld Object is locked skipped

C:\Windows\System32\sysprep\Panther\setuperr.log Object is locked skipped

C:\Windows\System32\wbem\AutoRecover\3460B7617E0429A960E481B197F238A3.mof Object is locked skipped

C:\Windows\System32\wbem\Logs\WMITracing.log Object is locked skipped

C:\Windows\System32\wbem\Repository\INDEX.BTR Object is locked skipped

C:\Windows\System32\wbem\Repository\MAPPING1.MAP Object is locked skipped

C:\Windows\System32\wbem\Repository\MAPPING2.MAP Object is locked skipped

C:\Windows\System32\wbem\Repository\OBJECTS.DATA Object is locked skipped

C:\Windows\System32\winevt\Logs\Application.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\DFS Replication.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\HardwareEvents.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Internet Explorer.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Key Management Service.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnostics-Networking%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-DiskDiagnosticDataCollector%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-DriverFrameworks-UserMode%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-Help%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-International%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-WHEA.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-LanguagePackSetup%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-MUI%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-NetworkAccessProtection%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-ParentalControls%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReliabilityAnalysisComponent%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Resolver%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Leak-Diagnostic%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-RestartManager%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-TaskScheduler%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-UAC%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-UAC-FileVirtualization%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-WindowsUpdateClient%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-Winlogon%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-Winsock-WS2HELP%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Security.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Setup.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\System.evtx Object is locked skipped

C:\Windows\Tasks\SCHEDLGU.TXT Object is locked skipped

C:\Windows\WindowsUpdate.log Object is locked skipped

C:\Windows\winsxs\x86_microsoft-windows-n..n_service_datastore_31bf3856ad364e35_6.0.6000.16386_none_cef7ceb03914a67f\dnary.xsd Object is locked skipped

D:\Windows\security\database\secedit.sdb Object is locked skipped

Scan process completed.
  • 0

#13
sarahw

sarahw

    Malware Staff

  • Member
  • PipPipPipPipPip
  • 2,781 posts
Hi,

Sorry about the delay.
Your Trend Micro Anti Virus is outdated, as it includes a Firewall I would recommend updateing it, it has much better protection than AVG.

There is nothing else wrong with the computer as far as I can see. Make sure that you don't have both Anti Virus programs running in the memory at the same time.


Here is a list of tools I like to recommend to people that will help ensure safe surfing on the internet, and to help you from getting infected again.
Note: DO NOT install more than one antivirus or Firewall program. They will conflict, and provide less protection, not more. Uninstall any existing Anti Virus\Firewall programs if you're going to install a new one.




Free Online Scans:
Free Active X and Java based online scans. You can use these scans from other companies and it will not interfere with your current Anti Virus. If you find that you are infected, post a Hijack This log in the forums.

Free Temp Cleaners:
Use these tools to clean temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders. ATF cleaner recommended.

Free Firewall Downloads:
You must have a Firewall installed on your computer. This helps stop anything from leaving or entering your computer without your permission.

Free Anti Spyware Downloads:
An Antispyware is a great tool that can help remove infections along side your Anti Virus. Some include real time protection, scheduled scans and automatic definition updates.

Free Anti Virus Downloads:
A must have for all computers. Avast! recommended.

Other:
  • SpywareGuard
    Works as a Spyware "Shield" to protect your computer from getting malware in the first place.
  • IE-SpyAd
    This tool puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.
  • Memtest86
    Great memory testing software.
  • CPU-Z
    This application gives detailed information about your system in a nice layout
  • Speedfan
    Returns and monitors system temperatures.
  • Windows Updates
    It is very important to make sure that both Internet Explorer and Windows are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there.
You can now Rehide your system files by using the reversal of these instructions HERE



To find out more information about how you got infected in the first place and some great guidelines to follow to prevent future infections you can read THIS article by Tony Klein.
  • 0

#14
crybaby

crybaby

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 175 posts
OK, I will update the TrendMicro. Thank you so much for all your time and expertise! I don't know where I would be without you guys! Thanks again!
~S~
  • 0

#15
sarahw

sarahw

    Malware Staff

  • Member
  • PipPipPipPipPip
  • 2,781 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP