Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

My computer is infected with the Backdoor VB EV Trojan [RESOLVED]


  • This topic is locked This topic is locked

#1
mairsy

mairsy

    Member

  • Member
  • PipPip
  • 14 posts
Can someone please help me to remove the Backdoor VB EV Trojan from my computer? I have removed it several times with XoftSpySE but it keeps coming back when I reboot.

I have pasted my HijackThis file below. Your help would be really appreciated. Thanks.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:02:17, on 03/05/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RunDLL32.exe
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\Program Files\btbb_wcm\McciTrayApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\BT Broadband Desktop Help\bin\BTHelpNotifier.exe
C:\Program Files\Adobe\Adobe Version Cue

CS2\ControlPanel\VersionCueCS2Tray.exe
C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Webshots\webshots.scr
C:\Program Files\BT Broadband Desktop Help\bin\mpbtn.exe
C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Adobe\Adobe Version Cue

CS2\data\database\bin\mysqld-nt.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\SiteAdvisor\6253\SAService.exe
C:\WINDOWS\system32\spupdsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spnpinst.exe
C:\WINDOWS\system32\Sysocmgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\XoftSpySE\XoftSpy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Yahoo!\browser\ybrowser.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =

www.google.co.uk
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

http://www.home.bt.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

http://home.bt.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =

http://uk.red.client...s/su/*http://uk

.search.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =

http://uk.red.client...s/sb/*http://uk

.docs.yahoo.com/info/bt_side.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =

http://www.home.bt.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

http://www.home.bt.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =

http://uk.red.client...s/su/*http://uk

.search.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet

Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88}

- (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -

C:\Program Files\Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program

Files\SiteAdvisor\6253\SiteAdv.dll
O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} -

c:\PROGRA~1\mcafee\msk\mcapbho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F}

- C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button -

{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} -

C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Flash Module - {669CFA6D-450B-4d88-A9D7-D2371E845370} -

btaskv.dll (file missing)
O2 - BHO: Canon Easy Web Print Helper -

{68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program

Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -

C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program

Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper -

{9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common

Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AcroIEToolbarHelper Class -

{AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe

Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D}

- C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} -

C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} -

C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} -

C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE

C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [btbb_wcm_McciTrayApp] C:\Program

Files\btbb_wcm\McciTrayApp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe"

-atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program

Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program

Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common

Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program

Files\SiteAdvisor\6253\SiteAdv.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common

Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft

Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program

Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program

Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [btbb_McciTrayApp] C:\Program Files\BT Broadband Desktop

Help\bin\BTHelpNotifier.exe
O4 - HKLM\..\Run: [Adobe Version Cue CS2] "C:\Program Files\Adobe\Adobe

Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Adobe

Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
O4 - HKLM\..\Run: [Winupdate] C:\WINDOWS\system32:svchost.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe

-quiet
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe"

/background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]

"C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &

Destroy\TeaTimer.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common

Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: BT Broadband Desktop Help.lnk = C:\Program Files\BT

Broadband Desktop Help\bin\matcli.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program

Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Add to Windows &Live Favorites -

http://favorites.liv...m/quickadd.aspx
O8 - Extra context menu item: Convert link target to Adobe PDF -

res://C:\Program Files\Adobe\Adobe Acrobat

7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF -

res://C:\Program Files\Adobe\Adobe Acrobat

7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF -

res://C:\Program Files\Adobe\Adobe Acrobat

7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF -

res://C:\Program Files\Adobe\Adobe Acrobat

7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF -

res://C:\Program Files\Adobe\Adobe Acrobat

7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF -

res://C:\Program Files\Adobe\Adobe Acrobat

7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program

Files\Adobe\Adobe Acrobat

7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program

Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel -

res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List -

res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print -

res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program

Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program

Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -

C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -

{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: BT Yahoo! Services -

{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} -

C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -

C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} -

C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration -

{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -

C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) -

C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4EC8E993-32C1-47F5-A07A-5B0574655AD4} (Software Center) -

http://us.dl1.yimg.c...tr/ysftcntr_cur

rent.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -

http://by136fd.bay13...es/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -

http://update.micros...86/client/wuweb

_site.cab?1171914783421
O16 - DPF: {AF2E62B6-F9E1-4D4F-A10A-9DC8E6DCBCC0} (VideoEgg ActiveX Loader)

- http://update.videoe...ggPublisher.exe
O20 - AppInit_DLLs: hadjajr.ini
O23 - Service: McAfee Application Installer Cleanup (0149341209807300)

(0149341209807300mcinstcleanup) - McAfee, Inc. -

C:\WINDOWS\TEMP\014934~1.EXE
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common

Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS2 - Adobe Systems Incorporated -

C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program

Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. -

C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program

files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. -

C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. -

c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. -

C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. -

C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc.

- C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. -

C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero

BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation -

C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program

Files\SiteAdvisor\6253\SAService.exe

--
End of file - 14197 bytes
  • 0

Advertisements


#2
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Hello mairsy

Welcome to G2Go. :)
=====================
Please download Deckard's System Scanner (DSS) and save it to your Desktop.
  • Close all other windows before proceeding.
  • Double-click on dss.exe and follow the prompts.
  • When it has finished, dss will open two Notepads main.txt and extra.txt -- please copy (CTRL+A and then CTRL+C) and paste (CTRL+V) the contents of main.txt and extra.txt in your next reply.

  • 0

#3
mairsy

mairsy

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
Hi Kahdah,

Thanks for the reply. I have done as you requested and am attaching the files below:

main.txt file

Deckard's System Scanner v20071014.68
Run by Billy on 2008-05-03 19:25:00
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

System Restore is disabled; attempting to re-enable...success.


-- Last 1 Restore Point(s) --
1: 2008-05-03 18:25:05 UTC - RP1 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.



-- HijackThis (run as Billy.exe) -----------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:28:58, on 03/05/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RunDLL32.exe
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\Program Files\btbb_wcm\McciTrayApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\BT Broadband Desktop Help\bin\BTHelpNotifier.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe
C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Webshots\webshots.scr
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\BT Broadband Desktop Help\bin\mpbtn.exe
C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Adobe\Adobe Version Cue CS2\data\database\bin\mysqld-nt.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\SiteAdvisor\6253\SAService.exe
C:\WINDOWS\system32\spupdsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spnpinst.exe
C:\WINDOWS\system32\Sysocmgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Documents and Settings\Billy\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Billy.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.co.uk
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.home.bt.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://home.bt.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://uk.red.client...arch.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.client...fo/bt_side.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.home.bt.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.home.bt.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.red.client...arch.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - c:\PROGRA~1\mcafee\msk\mcapbho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Flash Module - {669CFA6D-450B-4d88-A9D7-D2371E845370} - btaskv.dll (file missing)
O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [btbb_wcm_McciTrayApp] C:\Program Files\btbb_wcm\McciTrayApp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [btbb_McciTrayApp] C:\Program Files\BT Broadband Desktop Help\bin\BTHelpNotifier.exe
O4 - HKLM\..\Run: [Adobe Version Cue CS2] "C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
O4 - HKLM\..\Run: [Winupdate] C:\WINDOWS\system32:svchost.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe -quiet
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Macromed\SHOCKW~1\SWHELP~3.EXE -Update -1030024 -ybrowser.exe2006.8
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: BT Broadband Desktop Help.lnk = C:\Program Files\BT Broadband Desktop Help\bin\matcli.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.liv...m/quickadd.aspx
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: BT Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4EC8E993-32C1-47F5-A07A-5B0574655AD4} (Software Center) - http://us.dl1.yimg.c...ntr_current.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by136fd.bay13...es/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1171914783421
O16 - DPF: {AF2E62B6-F9E1-4D4F-A10A-9DC8E6DCBCC0} (VideoEgg ActiveX Loader) - http://update.videoe...ggPublisher.exe
O20 - AppInit_DLLs: hadjajr.ini
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS2 - Adobe Systems Incorporated - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6253\SAService.exe

--
End of file - 14126 bytes

-- File Associations -----------------------------------------------------------

.js - jsfile - DefaultIcon - unable to read value


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R1 PQNTDrv - c:\windows\system32\drivers\pqntdrv.sys <Not Verified; PowerQuest Corporation; PowerQuest product>
R1 SCDEmu - c:\windows\system32\drivers\scdemu.sys <Not Verified; PowerISO Computing, Inc.; scdemu>
R3 MRENDIS5 (MRENDIS5 NDIS Protocol Driver) - c:\program files\common files\motive\mrendis5.sys <Not Verified; Motive, Inc.; Motive Rawether for Windows>

S3 KBFiltr (Dritek HotKey Keyboard Filter Driver) - c:\windows\system32\drivers\kbfiltr.sys (file missing)
S3 MREMPR5 (MREMPR5 NDIS Protocol Driver) - c:\program files\common files\motive\mrempr5.sys <Not Verified; Motive, Inc.; Motive Rawether for Windows>


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

R2 Adobe Version Cue CS2 - "c:\program files\adobe\adobe version cue cs2\bin\versioncuecs2.exe" -win32service <Not Verified; Adobe Systems Incorporated; Adobe Version Cue CS2>

S3 NBService - c:\program files\nero\nero 7\nero backitup\nbservice.exe


-- Device Manager: Disabled ----------------------------------------------------

No disabled devices found.


-- Scheduled Tasks -------------------------------------------------------------

2008-05-03 17:07:52 432 --a------ C:\WINDOWS\Tasks\XoftSpySE 2.job
2008-05-03 17:00:01 438 --a------ C:\WINDOWS\Tasks\RegCure Program Check.job
2007-08-13 22:37:10 372 --a------ C:\WINDOWS\Tasks\RegCure.job
2007-05-03 17:33:56 362 --a------ C:\WINDOWS\Tasks\XoftSpySE.job
2007-04-30 14:22:57 264 --a------ C:\WINDOWS\Tasks\McDefragTask.job
2007-04-30 14:22:56 356 --a------ C:\WINDOWS\Tasks\McQcTask.job


-- Files created between 2008-04-03 and 2008-05-03 -----------------------------

2008-05-03 11:01:39 0 d-------- C:\Program Files\Trend Micro
2008-04-24 10:12:17 143360 --a------ C:\WINDOWS\system32\dunzip32.dll <Not Verified; Inner Media, Inc.; DynaZIP-32 Multi-Threading UnZIP DLL>


-- Find3M Report ---------------------------------------------------------------

2008-05-03 19:03:50 0 d-------- C:\Documents and Settings\Billy\Application Data\MahJong Suite
2008-05-03 13:49:20 0 d-------- C:\Program Files\McAfee
2008-04-24 10:13:34 0 d-------- C:\Program Files\SiteAdvisor
2008-04-19 20:53:38 0 d-------- C:\Program Files\William Hill Poker
2008-03-24 13:12:28 0 d-------- C:\Program Files\Java
2008-03-20 17:28:42 0 d-------- C:\Program Files\VideoProfessor
2008-03-17 22:33:29 0 d-------- C:\Program Files\Windows Media Connect 2
2008-03-17 12:58:25 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-03-17 12:24:31 0 d-------- C:\Program Files\Common Files\Adobe
2008-03-17 11:36:21 0 d-------- C:\Documents and Settings\Billy\Application Data\Adobe
2008-03-12 20:42:00 0 d-------- C:\Program Files\MahJong Suite
2008-03-12 20:00:29 14 --a------ C:\WINDOWS\popcinfo.dat


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{377C180E-6F0E-4D4C-980F-F45BD3D40CF4}]
26/11/2007 10:46 324936 --a------ c:\PROGRA~1\mcafee\msk\mcapbho.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{669CFA6D-450B-4d88-A9D7-D2371E845370}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [11/09/2006 18:58 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [15/05/2006 20:04 C:\WINDOWS\SkyTel.exe]
"Alcmtr"="ALCMTR.EXE" [02/05/2005 17:00 C:\WINDOWS\Alcmtr.exe]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [01/06/2006 18:22]
"nwiz"="nwiz.exe" [01/06/2006 18:22 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="NvMCTray.dll" [01/06/2006 18:22 C:\WINDOWS\system32\nvmctray.dll]
"YBrowser"="C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe" [21/07/2006 17:19]
"btbb_wcm_McciTrayApp"="C:\Program Files\btbb_wcm\McciTrayApp.exe" [30/11/2006 11:51]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [16/02/2007 11:54]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [02/03/2007 16:24]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [02/11/2004 21:24]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [22/02/2008 05:25]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [12/01/2006 16:40]
"PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [18/03/2006 03:24]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6253\SiteAdv.exe" [24/07/2006 21:28]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [26/09/2007 20:07]
"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [28/09/2006 13:16]
"OpwareSE4"="C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [11/10/2006 12:45]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [03/08/2007 23:33]
"btbb_McciTrayApp"="C:\Program Files\BT Broadband Desktop Help\bin\BTHelpNotifier.exe" [22/08/2007 14:34]
"Adobe Version Cue CS2"="C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe" [04/04/2005 19:58]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe" [14/12/2004 03:12]
"@"="" []
"McENUI"="C:\PROGRA~1\McAfee\MHN\McENUI.exe" [30/11/2007 05:42]
"Winupdate"="C:\WINDOWS\system32:svchost.exe" []

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [04/08/2004 08:56]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe" [31/08/2005 18:11]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [19/01/2007 13:54]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [01/06/2006 13:32]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [28/01/2008 12:43]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce]
"Shockwave Updater"=C:\WINDOWS\system32\Macromed\SHOCKW~1\SWHELP~3.EXE -Update -1030024 -ybrowser.exe2006.8

C:\Documents and Settings\Billy\Start Menu\Programs\Startup\
Webshots.lnk - C:\Program Files\Webshots\Launcher.exe [26/02/2007 12:13:02]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [17/03/2008 12:26:20]
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [16/03/2005 20:16:50]
BT Broadband Desktop Help.lnk - C:\Program Files\BT Broadband Desktop Help\bin\matcli.exe [16/12/2007 18:55:35]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [12/03/2007 20:13:53]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=hadjajr.ini

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D49A2992-890A-0494-1101-C070EA64EF23}]
C:\WINDOWS\system32:svchost.exe



-- Hosts -----------------------------------------------------------------------

127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com

8330 more entries in hosts file.


-- End of Deckard's System Scanner: finished at 2008-05-03 19:29:35 ------------

extra.txt file

Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------

-- System Information ----------------------------------------------------------

Microsoft Windows XP Professional (build 2600) SP 2.0
Architecture: X86; Language: English

CPU 0: AMD Athlon™ 64 Processor 3500+
Percentage of Memory in Use: 59%
Physical Memory (total/avail): 1023.23 MiB / 414.23 MiB
Pagefile Memory (total/avail): 2461.07 MiB / 1901.19 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1938.03 MiB

A: is Removable (No Media)
C: is Fixed (NTFS) - 232.88 GiB total, 197.02 GiB free.
D: is CDROM (No Media)
E: is CDROM (No Media)
F: is CDROM (No Media)
G: is CDROM (No Media)

\\.\PHYSICALDRIVE0 - WDC WD2500JD-00HBB0 - 232.88 GiB - 1 partition
\PARTITION0 (bootable) - Installable File System - 232.88 GiB - C:



-- Security Center -------------------------------------------------------------

AUOptions is scheduled to auto-install.
Windows Internal Firewall is enabled.

AntiVirusDisableNotify is set.
FirewallDisableNotify is set.

FW: McAfee Personal Firewall v (McAfee)
AV: McAfee VirusScan v (McAfee)

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\Adobe\\Adobe Version Cue CS2\\bin\\VersionCueCS2.exe"="C:\\Program Files\\Adobe\\Adobe Version Cue CS2\\bin\\VersionCueCS2.exe:*:Enabled:Adobe Version Cue CS2"
"C:\\Documents and Settings\\Billy\\Local Settings\\Temp\\CRY800.tmp\\install.exe"="C:\\Documents and Settings\\Billy\\Local Settings\\Temp\\CRY800.tmp\\install.exe:*:Enabled:setup wizard"
"C:\\Program Files\\William Hill Poker\\UA.exe"="C:\\Program Files\\William Hill Poker\\UA.exe:*:Enabled:UA Application"
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"="C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe:*:Enabled:McAfee Network Agent"


-- Environment Variables -------------------------------------------------------

ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Billy\Application Data
CLASSPATH=.;C:\Program Files\QuickTime\QTSystem\QTJava.zip
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=BILLY-A64-3500
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Billy
LOGONSERVER=\\BILLY-A64-3500
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\QuickTime\QTSystem\;C:\Program Files\Common Files\Adobe\AGL
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 47 Stepping 2, AuthenticAMD
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=2f02
ProgramFiles=C:\Program Files
PROMPT=$P$G
QTJAVA=C:\Program Files\QuickTime\QTSystem\QTJava.zip
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\Billy\LOCALS~1\Temp
TMP=C:\DOCUME~1\Billy\LOCALS~1\Temp
USERDOMAIN=BILLY-A64-3500
USERNAME=Billy
USERPROFILE=C:\Documents and Settings\Billy
windir=C:\WINDOWS


-- User Profiles ---------------------------------------------------------------

Billy (admin)


-- Add/Remove Programs ---------------------------------------------------------

--> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
--> C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL
--> C:\WINDOWS\Motive\btbb\UninstallHelper.exe
--> C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
--> C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
--> C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
--> C:\WINDOWS\UNNeroVision.exe /UNINSTALL
--> C:\WINDOWS\UNRecode.exe /UNINSTALL
--> msiexec /I {236BB7C4-4419-42FD-0409-1E257A25E34D}
--> msiexec /i {46548E80-0409-0000-7E8A-45000F855001}
--> msiexec /I {B2F5D08C-7E79-4FCD-AAF4-57AD35FF0601}
--> msiexec /I{7F4C8163-F259-49A0-A018-2857A90578BC}
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Bridge 1.0 --> MsiExec.exe /I{B74D4E10-6884-0000-0000-000000000103}
Adobe Common File Installer --> MsiExec.exe /I{8EDBA74D-0686-4C99-BFDD-F894678E5B39}
Adobe Creative Suite 2 --> C:\PROGRA~1\INSTAL~1\{0134A~1\setup.exe /relaunched/rootloc=e:\adobe creative suite 2.0/lang=0409
Adobe Flash Player 9 ActiveX --> C:\WINDOWS\System32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Help Center 1.0 --> MsiExec.exe /I{E9787678-1033-0000-8E67-000000000001}
Adobe Shockwave Player --> C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
Adobe Stock Photos 1.0 --> MsiExec.exe /I{786C5747-1033-0000-B58E-000000000001}
Adobe Stock Photos 1.0 --> MsiExec.exe /I{EE0D5DCD-2B97-4473-98DF-E93C0BD92F7A}
Adobe SVG Viewer 3.0 --> C:\Program Files\Common Files\Adobe\SVG Viewer 3.0\Uninstall\Winstall.exe -u -fC:\Program Files\Common Files\Adobe\SVG Viewer 3.0\Uninstall\Install.log
µTorrent --> "C:\Program Files\uTorrent\uninstall.exe"
Axialis IconWorkshop 6.10 --> C:\Program Files\Axialis\IconWorkshop\UnInstall.exe "IconWorkshop" "IconWorkshop.exe"
BookWorm Deluxe 1.03 --> C:\Program Files\PopCap Games\BookWorm Deluxe\PopUninstall.exe "C:\Program Files\PopCap Games\BookWorm Deluxe\Install.log"
BT Broadband Desktop Help --> C:\WINDOWS\Motive\btbb\MCCUninst.exe
BT Yahoo! Applications --> C:\PROGRA~1\Yahoo!\Common\uninstall.exe
Canon MP Drivers --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{58F8C6D9-5B55-486A-A322-4E8D87670031}\Setup.exe" -l0x9 -Uninstall
Canon MP Navigator 3.0 --> "C:\Program Files\Canon\MP Navigator 3.0\Maint.exe" /UninstallRemove C:\Program Files\Canon\MP Navigator 3.0\uninst.ini
Canon MP Toolbox 4.1.1.0.mp10 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4669544E-20E4-4E56-8B44-2E6E1200051F}\Setup.exe" -l0x9 -Uninstall
Canon MP180 --> "C:\WINDOWS\System32\CanonIJ Uninstaller Information\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP180\DelDrv.exe" /U:{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP180 /L0x0009
Canon MP180 User Registration --> C:\Program Files\Canon\IJEREG\MP180\UNINST.EXE
Canon Utilities Easy-PhotoPrint --> C:\Program Files\Canon\Easy-PhotoPrint\uninst.exe uninst.ini
Championship Manager 2008 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2F4E2C8A-B886-418E-BE49-0B867CBDA959}\Setup.exe" -l0x9 -removeonly
DVD Shrink 3.2 --> "C:\Program Files\DVD Shrink\unins000.exe"
Easy-WebPrint --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Canon\Easy-WebPrint\Uninst.isu"
GameShadow --> MsiExec.exe /I{6AEAD38B-383B-46FF-8A5D-00A822ADA77A}
High Definition Audio Driver Package - KB888111 --> "C:\WINDOWS\$NtUninstallKB888111WXP$\spuninst\spuninst.exe"
HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
iTunes --> MsiExec.exe /I{01B51908-02EF-453B-87A9-815182E8C2F2}
J2SE Runtime Environment 5.0 Update 11 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150110}
Java™ 6 Update 2 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
Java™ 6 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
Java™ 6 Update 5 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
Java™ SE Runtime Environment 6 Update 1 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
Macromedia Extension Manager --> MsiExec.exe /I{5546CDB5-2CE2-498B-B059-5B3BF81FC41F}
MahJong Suite 2007 v4.2 --> "C:\Program Files\MahJong Suite\unins000.exe"
MahJong Suite Graphics Pack Volume 1 - v1.7 --> "C:\Program Files\MahJong Suite\unins001.exe"
MahJong Suite Graphics Pack Volume 2 - v2.7 --> "C:\Program Files\MahJong Suite\unins002.exe"
McAfee SecurityCenter --> C:\Program Files\McAfee\MSC\mcuninst.exe
McAfee Uninstall Wizard --> C:\PROGRA~1\McAfee.com\Shared\mcappins.exe /v=3 /uninstall=1 /interact=1 /script_proactive=0 /start=c:\PROGRA~1\mcafee.com\agent\uninst\comrem.dll::uninstall.htm
Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Office Professional Edition 2003 --> MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Mozilla Firefox (2.0.0.14) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exe
Nero 7 Ultra Edition --> MsiExec.exe /I{692854CC-97EF-4307-B787-8C6787B91033}
NVIDIA Drivers --> C:\WINDOWS\System32\nvudisp.exe UninstallGUI
PowerDVD --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\Setup.exe" -uninstall
PowerISO --> "C:\Program Files\PowerISO\uninstall.exe"
PowerQuest PartitionMagic 8.0 --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{6BE2A4A4-99FB-48ED-AE1E-4E850389F804}
QuickTime --> MsiExec.exe /I{5E863175-E85D-44A6-8968-82507D34AE7F}
RealPlayer --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
Realtek High Definition Audio Driver --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\setup.exe" -l0x9 -removeonly
RegCure 1.5.0.0 --> C:\Program Files\RegCure\uninst.exe
ScanSoft OmniPage SE 4.0 --> MsiExec.exe /I{C1E693A4-B1D5-4DCD-B68D-2087835B7184}
Security Update for CAPICOM (KB931906) --> MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906) --> MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Spybot - Search & Destroy --> "C:\Program Files\Spybot - Search & Destroy\unins001.exe"
Suite Specific --> MsiExec.exe /I{C49DAA9C-5BA8-459A-8244-E57B69DF0F04}
Super TextTwist --> C:\PROGRA~1\GAMEHO~1\TEXTTW~1\UNWISE.EXE /U C:\PROGRA~1\GAMEHO~1\TEXTTW~1\INSTALL.LOG
TestOut Navigator (Stand-Alone Version) --> C:\Program Files\TESTOUT\UNWISE32.EXE
VIA Platform Device Manager --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{20D4A895-748C-4D88-871C-FDB1695B0169}
VIA Rhine-Family Fast Ethernet Adapter --> Rundll32.exe vuins32.dll,vuins32Ex $Rhine $VIA
VideoEgg Publisher --> C:\Program Files\VideoEgg\Uninstall.exe
Web CEO 7.0 --> "C:\Program Files\Web CEO\Uninstall\unins000.exe"
Webshots Desktop --> "C:\Program Files\Webshots\unins000.exe"
William Hill Poker --> C:\WINDOWS\system32\UnPoker.exe WilliamHillPokerXP
Windows Live Messenger --> MsiExec.exe /I{571700F0-DB9D-4B3A-B03D-35A14BB5939F}
Windows Live Sign-in Assistant --> MsiExec.exe /I{49672EC2-171B-47B4-8CE7-50D7806360D7}
Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
WinRAR archiver --> C:\Program Files\WinRAR\uninstall.exe
WinZip --> "C:\Program Files\WinZip\WINZIP32.EXE" /uninstall
XoftSpySE --> C:\Program Files\XoftSpySE\uninstall.exe


-- Application Event Log -------------------------------------------------------

Event Record #/Type14289 / Error
Event Submitted/Written: 05/03/2008 07:12:10 PM
Event ID/Source: 1090 / Userenv
Event Description:
Windows couldn't log the RSoP (Resultant Set of Policies) session status. An attempt to connect to WMI failed. No more RSoP logging will be done for this application of policy.

Event Record #/Type14288 / Error
Event Submitted/Written: 05/03/2008 06:54:10 PM
Event ID/Source: 1090 / Userenv
Event Description:
Windows couldn't log the RSoP (Resultant Set of Policies) session status. An attempt to connect to WMI failed. No more RSoP logging will be done for this application of policy.

Event Record #/Type14287 / Error
Event Submitted/Written: 05/03/2008 05:33:10 PM
Event ID/Source: 1090 / Userenv
Event Description:
Windows couldn't log the RSoP (Resultant Set of Policies) session status. An attempt to connect to WMI failed. No more RSoP logging will be done for this application of policy.

Event Record #/Type14286 / Error
Event Submitted/Written: 05/03/2008 04:59:10 PM
Event ID/Source: 1090 / Userenv
Event Description:
Windows couldn't log the RSoP (Resultant Set of Policies) session status. An attempt to connect to WMI failed. No more RSoP logging will be done for this application of policy.

Event Record #/Type14285 / Error
Event Submitted/Written: 05/03/2008 03:41:10 PM
Event ID/Source: 1090 / Userenv
Event Description:
Windows couldn't log the RSoP (Resultant Set of Policies) session status. An attempt to connect to WMI failed. No more RSoP logging will be done for this application of policy.



-- Security Event Log ----------------------------------------------------------

No Errors/Warnings found.


-- System Event Log ------------------------------------------------------------

Event Record #/Type76154 / Error
Event Submitted/Written: 05/03/2008 01:49:55 PM
Event ID/Source: 7023 / Service Control Manager
Event Description:
The HID Input Service service terminated with the following error:
%%2

Event Record #/Type76121 / Warning
Event Submitted/Written: 05/03/2008 01:28:52 PM
Event ID/Source: 8021 / BROWSER
Event Description:
The browser was unable to retrieve a list of servers from the browser master \\MARGIE-BTWS40CO on the network \Device\NwlnkNb.
The data is the error code.

Event Record #/Type76120 / Warning
Event Submitted/Written: 05/03/2008 01:28:52 PM
Event ID/Source: 8021 / BROWSER
Event Description:
The browser was unable to retrieve a list of servers from the browser master \\MARGIE-BTWS40CO on the network \Device\NetBT_Tcpip_{DD94181D-C619-4B80-A095-3EFF6A205FB6}.
The data is the error code.

Event Record #/Type75871 / Error
Event Submitted/Written: 05/03/2008 10:28:14 AM
Event ID/Source: 7023 / Service Control Manager
Event Description:
The HID Input Service service terminated with the following error:
%%2

Event Record #/Type75858 / Warning
Event Submitted/Written: 05/02/2008 09:00:54 PM
Event ID/Source: 8021 / BROWSER
Event Description:
The browser was unable to retrieve a list of servers from the browser master \\MARGIE-BTWS40CO on the network \Device\NetBT_Tcpip_{DD94181D-C619-4B80-A095-3EFF6A205FB6}.
The data is the error code.



-- End of Deckard's System Scanner: finished at 2008-05-03 19:29:35 ------------
  • 0

#4
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Download the HostsXpert 4.2 - Hosts File Manager.
  • Unzip HostsXpert 4.2 - Hosts File Manager to a convenient folder such as C:\HostsXpert 4.2 - Hosts File Manager
  • Run HostsXpert 4.2 - Hosts File Manager from its new home
  • Click on "File Handling".
  • Click on "Restore MS Hosts File".
  • Click OK on the Confirmation box.
  • Click on "Make Read Only?"
  • Click the X to exit the program.
  • Note: If you were using a custom Hosts file you will need to replace any of those entries yourself.
===================================================================
Please download the OTMoveIt2 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt2.exe to run it. (Vista users, please right click on OTMoveit2.exe and select "Run as an Administrator")
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\Winupdate
    @c:\windows\system32:svchost.exe
    C:\WINDOWS\System32\hadjajr.ini
    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D49A2992-890A-0494-1101-C070EA64EF23}
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{669CFA6D-450B-4d88-A9D7-D2371E845370}
    C:\Program Files\RegCure
  • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to be Moved" window (under the light Yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • OTMoveit2 will create a log of moved files in the C:\_OTMoveIt\MovedFiles folder. The log's name will appear as the date and time it was created, with the format mmddyyyy_hhmmss.log. Open this log in Notepad and post its contents in your next reply.
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.
==============================
Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatley.
  • 0

#5
mairsy

mairsy

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
Hi again Kahdah,

Started off OK and did the following:

Unzip HostsXpert 4.2 - Hosts File Manager to a convenient folder such as C:\HostsXpert 4.2 - Hosts File Manager
Run HostsXpert 4.2 - Hosts File Manager from its new home
Click on "File Handling".
Click on "Restore MS Hosts File".
Click OK on the Confirmation box.

but when I clicked OK on the Confirmation box I received the error message shown in the attached screenshot.

Kind regards
Mairsy

Attached Thumbnails

  • HostsXpert_4.2_Screenshot.jpg

  • 0

#6
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Ok I see why it is because Spybot has added those entries it didn't say so in the dss report but it does in your screenshot.
Please disregard those instructions and proceed with the rest please.
Thanks
  • 0

#7
mairsy

mairsy

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
Hi Kahdah,

Please see O2MoveIt2 results below:

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\Winupdate >
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\Winupdate deleted successfully.
< @c:\windows\system32:svchost.exe >
Unable to delete ADS c:\windows\system32:svchost.exe .
File/Folder C:\WINDOWS\System32\hadjajr.ini not found.
< HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D49A2992-890A-0494-1101-C070EA64EF23} >
Registry key HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D49A2992-890A-0494-1101-C070EA64EF23}\\ deleted successfully.
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{669CFA6D-450B-4d88-A9D7-D2371E845370} >
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{669CFA6D-450B-4d88-A9D7-D2371E845370}\\ deleted successfully.
C:\Program Files\RegCure\Logs moved successfully.
C:\Program Files\RegCure\Backup\RegCureBak_September_30_07_21_29_53 moved successfully.
C:\Program Files\RegCure\Backup\RegCureBak_September_29_07_13_43_08 moved successfully.
C:\Program Files\RegCure\Backup\RegCureBak_September_26_07_22_10_55 moved successfully.
C:\Program Files\RegCure\Backup\RegCureBak_September_25_07_22_18_39 moved successfully.
C:\Program Files\RegCure\Backup\RegCureBak_September_04_07_19_00_17 moved successfully.
C:\Program Files\RegCure\Backup\RegCureBak_October_29_07_22_26_21 moved successfully.
C:\Program Files\RegCure\Backup\RegCureBak_October_27_07_18_34_25 moved successfully.
C:\Program Files\RegCure\Backup\RegCureBak_October_26_07_20_33_41 moved successfully.
C:\Program Files\RegCure\Backup\RegCureBak_October_24_07_22_54_48 moved successfully.
C:\Program Files\RegCure\Backup\RegCureBak_October_22_07_22_49_20 moved successfully.
C:\Program Files\RegCure\Backup\RegCureBak_October_21_07_23_16_01 moved successfully.
C:\Program Files\RegCure\Backup\RegCureBak_October_21_07_00_00_27 moved successfully.
C:\Program Files\RegCure\Backup\RegCureBak_October_17_07_21_15_10 moved successfully.
C:\Program Files\RegCure\Backup\RegCureBak_October_16_07_21_54_18 moved successfully.
C:\Program Files\RegCure\Backup\RegCureBak_October_15_07_23_00_27 moved successfully.
C:\Program Files\RegCure\Backup\RegCureBak_October_12_07_22_54_41 moved successfully.
C:\Program Files\RegCure\Backup\RegCureBak_October_09_07_22_27_09 moved successfully.
C:\Program Files\RegCure\Backup\RegCureBak_October_08_07_17_28_08 moved successfully.
C:\Program Files\RegCure\Backup\RegCureBak_October_06_07_16_55_01 moved successfully.
C:\Program Files\RegCure\Backup\RegCureBak_October_05_07_23_41_03 moved successfully.
C:\Program Files\RegCure\Backup\RegCureBak_October_02_07_22_12_15 moved successfully.
C:\Program Files\RegCure\Backup\RegCureBak_November_24_07_15_04_29 moved successfully.
C:\Program Files\RegCure\Backup\RegCureBak_March_31_08_23_00_39 moved successfully.
C:\Program Files\RegCure\Backup\RegCureBak_March_21_08_16_33_16 moved successfully.
C:\Program Files\RegCure\Backup\RegCureBak_March_20_08_22_21_03 moved successfully.
C:\Program Files\RegCure\Backup\RegCureBak_March_16_08_22_06_02 moved successfully.
C:\Program Files\RegCure\Backup\RegCureBak_March_14_08_21_39_18 moved successfully.
C:\Program Files\RegCure\Backup\RegCureBak_March_09_08_22_08_59 moved successfully.
C:\Program Files\RegCure\Backup\RegCureBak_January_27_08_20_20_15 moved successfully.
C:\Program Files\RegCure\Backup\RegCureBak_January_22_08_17_37_38 moved successfully.
C:\Program Files\RegCure\Backup\RegCureBak_January_10_08_22_07_20 moved successfully.
C:\Program Files\RegCure\Backup\RegCureBak_January_02_08_21_00_29 moved successfully.
C:\Program Files\RegCure\Backup\RegCureBak_January_01_08_22_47_27 moved successfully.
C:\Program Files\RegCure\Backup\RegCureBak_February_12_08_19_32_34 moved successfully.
C:\Program Files\RegCure\Backup\RegCureBak_February_10_08_20_59_20 moved successfully.
C:\Program Files\RegCure\Backup\RegCureBak_February_09_08_19_08_15 moved successfully.
C:\Program Files\RegCure\Backup\RegCureBak_February_06_08_22_18_06 moved successfully.
C:\Program Files\RegCure\Backup\RegCureBak_December_17_07_21_17_56 moved successfully.
C:\Program Files\RegCure\Backup\RegCureBak_December_08_07_15_19_14 moved successfully.
C:\Program Files\RegCure\Backup\RegCureBak_April_19_08_23_14_54 moved successfully.
C:\Program Files\RegCure\Backup\RegCureBak_April_13_08_22_05_03 moved successfully.
C:\Program Files\RegCure\Backup moved successfully.
C:\Program Files\RegCure moved successfully.

OTMoveIt2 by OldTimer - Version 1.0.4.1 log created on 05032008_231517


Thank you for your help.
  • 0

#8
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
You are welcome:

Go ahead with Mbam instructions please and remove all selected items and post back with that log and a new Hijackthis log.
  • 0

#9
mairsy

mairsy

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
Hi Kahdah,

mbam log file below as requested:

Malwarebytes' Anti-Malware 1.11
Database version: 712

Scan type: Quick Scan
Objects scanned: 52432
Time elapsed: 25 minute(s), 39 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 26
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 27
Files Infected: 540

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{e282c728-189d-419e-8ee2-1601f4b39ba5} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{168dc258-1455-4e61-8590-9dac2f27b675} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{1a8642f1-dc80-4edc-a39d-0fb62a58b455} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{3f91eb90-ef62-44ee-a685-fac29af111cd} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{5c29c7e4-5321-4cad-be2e-877666bed5df} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{83dfb6ee-ab18-41b5-86d4-b544a141d67e} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{88d6cf0e-cf70-4c24-bf6e-e4e414bc649c} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{8f6a82a2-d7b1-443e-bb9f-f7dc887dd618} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{9856e2d8-ffb2-4fe5-8cad-d5ad6a35a804} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a3d06987-c35e-49e4-8fe2-ac67b9fbfb4c} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a58c497b-3ee2-45e7-9594-daca6be2a0d0} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{ad0a3058-fd49-4f98-a514-fd055201835e} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{ad5915ea-b61a-4dba-b5c8-ef4b2df0a3c7} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{af2e62b6-f9e1-4d4f-a10a-9dc8e6dcbcc0} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{af2e62b6-f9e1-4d4f-a10a-9dc8e6dcbcc0} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{bb187c0d-6f53-4f3e-9590-98fd3a7364a2} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{c5041fd9-4819-4dc4-b20e-c950b5b03d2a} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{d17726cc-d4dd-4c4a-9671-471d56e413b5} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{db8cce99-59c6-4552-8bfc-058feb38d6ce} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{dc3a04ee-cdd7-4407-915c-a5502f97eecd} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{e1a63484-a022-4d42-830a-fbd411514440} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\videoegg.activexloader (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\videoegg.activexloader.1 (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videoegg.com/Publisher,version=0.2.0 (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videoegg.com/Updater,version=0.2.0 (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\VideoEgg (Adware.VideoEgg) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Documents and Settings\All Users\Application Data\VideoEgg (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Updater (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329 (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124 (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03 (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4115 (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152 (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4520 (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329 (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\VideoEgg (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124 (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03 (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\VideoEgg\images (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\VideoEgg\messages (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4520\resources (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\messages (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Updater\4115 (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Updater\4458 (Adware.VideoEgg) -> Quarantined and deleted successfully.

Files Infected:
C:\Program Files\VideoEgg\Loader\4115\npvideoegg-loader.dll (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\VideoEgg\user.dat (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\report.log (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\aol_watermark.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\audio_combo.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\audio_source.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\bebo_tv_watermark.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\bebo_tv_watermark_1.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\big_gray_logo.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\big_logo_cropped.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\blank_slide.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\button_browse_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\button_browse_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\button_browse_up.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\camcorders_title.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\camcorder_btn_highlighted.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\camcorder_slide copy.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\camcorder_slide.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\corners_bottom_left.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\corners_bottom_left_curve.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\corners_bottom_right.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\corners_top_right.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\done.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\done_capture.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\done_capture_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\done_capture_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\done_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\done_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\dropshadow_bottom_left.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\dropshadow_horiz.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\dropshadow_vertical.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\dropzone.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\dv_fast_forward.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\dv_pause.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\dv_play.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\dv_rewind.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\dv_stop.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\email_instructions.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\email_sent.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\email_sent_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\email_sent_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\eraser.CUR (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\eraser_cursor.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\file_btn_highlighted.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\file_slide.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\help.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\icon_camcorders.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\icon_ff.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\icon_pause.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\icon_play.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\icon_rewind.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\icon_stop.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\icon_webcams.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\loading.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\loading_movie.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\locating.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\logo.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\logo_bottom.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\logo_middle.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\logo_top.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\mobile_btn_highlighted copy.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\mobile_btn_highlighted.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\mobile_slide.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\mobile_slide_disabled.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\movie_placeholder.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\ok.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\ok_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\ok_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\player_fast_forward.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\player_fast_forward_disabled.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\player_fill.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\player_pause.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\player_play.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\player_rewind.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\player_rewind_disabled.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\player_rewind_to_start.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\playhead.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\powered_by.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\progress.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\refresh_list_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\refresh_list_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\refresh_list_up.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\skin.ver (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\skin.zip (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\start_capture.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\start_capture_disabled.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\start_capture_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\start_capture_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\start_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\start_over_highlight.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\start_slider.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\stop_capture.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\stop_capture_disabled.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\stop_capture_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\stop_capture_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\stop_slider.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\tab_slide_deselected.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\tape_control.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\title.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\upload.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\uploading.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\uploading_fill.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\uploading_high.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\uploading_low.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\uploading_medium.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\uploading_thumbnail.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\upload_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\upload_from.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\upload_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\videoegg-large.ico (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\videoegg-small.ico (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\videoegg.ico (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\volume_gray.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\volume_green.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\volume_high.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\volume_low.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\volume_orange.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\volume_red.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\volume_slider.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\waiting_for_email.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\webcams_title.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\webcam_btn_highlighted.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Data\Resources\gid329\cid1124\bebo03\images\webcam_slide.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\publisher.ver (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4115\dbghelp.dll (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\avcodec.dll (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\crashRpt.dll (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\dataCollection.tmp (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\dbghelp.dll (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\FLVEncoder.dll (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\lame_enc.dll (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\LevelMeter.ax (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\libcurlve.dll (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\libpng.dll (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\npvideoegg-publisher.dll (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\report.log (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\VideoEgg_FLVWriter.ax (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\zlib.dll (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\aol_watermark.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\audio_combo.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\audio_source.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\bebo_tv_watermark.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\bebo_tv_watermark_1.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\big_gray_logo.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\big_logo_cropped.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\blank_slide.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\button_browse_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\button_browse_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\button_browse_up.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\camcorders_title.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\camcorder_btn_highlighted.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\camcorder_slide copy.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\camcorder_slide.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\corners_bottom_left.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\corners_bottom_left_curve.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\corners_bottom_right.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\corners_top_right.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\done.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\done_capture.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\done_capture_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\done_capture_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\done_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\done_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\dropshadow_bottom_left.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\dropshadow_horiz.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\dropshadow_vertical.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\dropzone.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\dv_fast_forward.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\dv_pause.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\dv_play.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\dv_rewind.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\dv_stop.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\email_instructions.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\email_sent.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\email_sent_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\email_sent_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\eraser.CUR (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\eraser_cursor.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\file_btn_highlighted.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\file_slide.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\help.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\icon_camcorders.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\icon_ff.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\icon_pause.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\icon_play.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\icon_rewind.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\icon_stop.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\icon_webcams.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\loading.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\loading_movie.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\locating.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\logo.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\logo_bottom.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\logo_middle.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\logo_top.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\mobile_btn_highlighted copy.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\mobile_btn_highlighted.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\mobile_slide.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\mobile_slide_disabled.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\movie_placeholder.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\ok.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\ok_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\ok_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\player_fast_forward.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\player_fast_forward_disabled.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\player_fill.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\player_pause.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\player_play.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\player_rewind.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\player_rewind_disabled.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\player_rewind_to_start.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\playhead.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\powered_by.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\progress.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\refresh_list_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\refresh_list_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\refresh_list_up.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\skin.ver (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\skin.zip (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\start_capture.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\start_capture_disabled.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\start_capture_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\start_capture_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\start_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\start_over_highlight.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\start_slider.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\stop_capture.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\stop_capture_disabled.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publisher\4152\resources\gid329\cid1124\bebo03\images\stop_capture_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
C:\Documents and Settings\Billy\Application Data\VideoEgg\Publ
  • 0

#10
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Hi could you post the rest it seems ti have gotten cut off thanks :)
  • 0

Advertisements


#11
mairsy

mairsy

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
HiJackThis file below:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 00:39:58, on 04/05/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RunDLL32.exe
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\Program Files\btbb_wcm\McciTrayApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\BT Broadband Desktop Help\bin\BTHelpNotifier.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe
C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Webshots\webshots.scr
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\BT Broadband Desktop Help\bin\mpbtn.exe
C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Adobe\Adobe Version Cue CS2\data\database\bin\mysqld-nt.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\SiteAdvisor\6253\SAService.exe
C:\WINDOWS\system32\spupdsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spnpinst.exe
C:\WINDOWS\system32\Sysocmgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.co.uk
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.home.bt.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://home.bt.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://uk.red.client...arch.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.client...fo/bt_side.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.home.bt.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.home.bt.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.red.client...arch.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - c:\PROGRA~1\mcafee\msk\mcapbho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [btbb_wcm_McciTrayApp] C:\Program Files\btbb_wcm\McciTrayApp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [btbb_McciTrayApp] C:\Program Files\BT Broadband Desktop Help\bin\BTHelpNotifier.exe
O4 - HKLM\..\Run: [Adobe Version Cue CS2] "C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
O4 - HKLM\..\Run: [Winupdate] C:\WINDOWS\system32:svchost.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe -quiet
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Macromed\SHOCKW~1\SWHELP~3.EXE -Update -1030024 -ybrowser.exe2006.8
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: BT Broadband Desktop Help.lnk = C:\Program Files\BT Broadband Desktop Help\bin\matcli.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.liv...m/quickadd.aspx
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: BT Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4EC8E993-32C1-47F5-A07A-5B0574655AD4} (Software Center) - http://us.dl1.yimg.c...ntr_current.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by136fd.bay13...es/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1171914783421
O20 - AppInit_DLLs: hadjajr.ini
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS2 - Adobe Systems Incorporated - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6253\SAService.exe

--
End of file - 13974 bytes

If some of the previous file was missing I don't know how to access the log as I closed it down thinking I had finished with it.

I hope this helps.
  • 0

#12
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
That is ok.

Please submit the following file to one of these online file scanners.
(All you have to do is copy and paste it in)

C:\WINDOWS\system32:svchost.exe

Jotti File Scan
VirusTotal File Scan

This will produce a report after the scan is complete, please copy and paste those results in your next post.
  • 0

#13
mairsy

mairsy

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
Hi Kahdah,

Copy of scan results below:

Jotti's malware scan 2.99-TRANSITION_TO_3.00-R1

File to upload & scan:
Service
Service load: 0% 100%

File: svchost.exe
Status: OK(Note: file has been scanned before. Therefore, this file's scan results will not be stored in the database)
MD5: 8f078ae4ed187aaabc0a305146de6716
Packers detected: -
Bit9 reports:

Scanner results
Scan taken on 03 May 2008 23:49:21 (GMT)
A-Squared Found nothing
AntiVir Found nothing
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
CPsecure Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
F-Secure Anti-Virus Found nothing
Fortinet Found nothing
Ikarus Found nothing
Kaspersky Anti-Virus Found nothing
NOD32 Found nothing
Norman Virus Control Found nothing
Panda Antivirus Found nothing
Sophos Antivirus Found nothing
VirusBuster Found nothing
VBA32 Found nothing

Powered by

Disclaimer
This service is by no means 100% safe. If this scanner says 'OK', it does not necessarily mean the file is clean. There could be a whole new virus on the loose. NEVER EVER rely on one single product only, not even this service, even though it utilizes several products. Therefore, We cannot and will not be held responsible for any damage caused by results presented by this non-profit online service.

Also, we are aware of the implications of a setup like this. We are sure this whole thing is by no means scientifically correct, since this is a fully automated service (although manual correction is possible). We are aware, in spite of efforts to proactively counter these, false positives might occur, for example. We do not consider this a very big issue, so please do not e-mail us about it. This is a simple online scan service, not the university of Wichita.

Scanning can take a while, since several scanners are being used, plus the fact some scanners use very high levels of (time consuming) heuristics. Scanners used are Linux versions, differences with Windows scanners may or may not occur. Another note: some scanners will only report one virus when scanning archives with multiple pieces of malware.

Virus definitions are updated every hour. There is a 10Mb limit per file. Please refrain from uploading tons of hex-edited or repacked variants of the same sample.

Please do not ask for viruses uploaded here, unless you work for an anti-virus vendor. They are not for trade. This is a legitimate service, not a VX site. Viruses uploaded here will be distributed to antivirus vendors without exception. Read more about this in our privacy policy. If you do not want your files to be distributed, please do not send them at all.

Sponsored by HotelScraper.com.
--------------------------------------------------------------------------------


Statistics
Last file scanned at least one scanner reported something about: Crack_Vista.zip (MD5: e91205f809a2bf048c1407bbdc5b60fd, size: 11597 bytes), detected by:

Scanner Malware name
A-Squared X
AntiVir TR/ActivCrk.B
ArcaVir X
Avast Win32:Rootkit-gen
AVG Antivirus X
BitDefender Trojan.Activcrk.B
ClamAV X
CPsecure Troj.Downloader.W32.Small.axy
Dr.Web X
F-Prot Antivirus X
F-Secure Anti-Virus X
Fortinet ActivCrk.A!tr
Ikarus Trojan.Activcrk.B
Kaspersky Anti-Virus X
NOD32 X
Norman Virus Control X
Panda Antivirus X
Sophos Antivirus Troj/ActivCrk-A
VirusBuster X
VBA32 X


You're free to (mis)interpret these automated, flawed statistics at your own discretion. For antivirus comparisons, visit AV comparatives
We are not affiliated with any third parties that conduct tests using this service.





Frequently asked questions - Feedback - Privacy policy



Page generated by JTPL

© 2004-2008 Jordi Bosveld <[email protected]>
  • 0

#14
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
  • Open HiJackThis
  • Click on Misc tools Section
  • Click on Open ADS Spy
  • Uncheck QUick scan and also Ignore safe infostreams
  • Click on "Scan"
  • Click on "Save Log..."
  • Copy and past the List from the notepad into your next post

  • 0

#15
mairsy

mairsy

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
HiJackThis log below:

C:\Documents and Settings\All Users\Documents\Beginning PHP and PostgreSQL 8 From Novice to Professional 2006\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\All Users\Documents\GreenBox\Works\My Projects\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\All Users\Documents\Loz\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\All Users\Documents\MagicISO\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\100A0655.JPG : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\100A0656.JPG : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\100A0681.JPG : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\100A0683.JPG : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Acme Dynamo 250.jpg : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Acme Dynamo STATIC.jpg : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Acme Puma 250 STATIC.jpg : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Acme Puma 250.jpg : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe Williams\Demos\Acme Dynamo 250.wmv : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe Williams\Demos\Acme Puma 250.wmv : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe Williams\Demos\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe Williams\Demos\Zoom Aurora Wildzap.wmv : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe Williams\images\images\images\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe Williams\images\images\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe Williams\images\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe Williams\karaokeTracks.pdf : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe Williams\songRequests.pdf : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe Williams\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe's Files\100A0357.JPG : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe's Files\100A0360.JPG : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe's Files\100A0366.JPG : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe's Files\100A0424.JPG : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe's Files\100A0428.JPG : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe's Files\100A0430.JPG : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe's Files\100A0469.JPG : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe's Files\100A0477.JPG : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe's Files\100A0495.JPG : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe's Files\100A0542.JPG : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe's Files\100A0545.JPG : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe's Files\102A0631.JPG : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe's Files\102A0632.JPG : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe's Files\102A0633.JPG : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe's Files\170628c.jpg : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe's Files\18th birthday 036.jpg : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe's Files\18th birthday 053.jpg : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe's Files\18th birthday 058.jpg : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe's Files\1_1.jpg : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe's Files\470243.jpg : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe's Files\73_1_b.jpg : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe's Files\98c8_1.jpg : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe's Files\aurbig.jpg : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe's Files\Citronic CD-1X.txt : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe's Files\Djamilla Wedding.jpg : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe's Files\FlyerPSA5 Final 2 (Web Address).pub : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe's Files\iStock_000001400961Small.jpg : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe's Files\iStock_000002237310Illustra.zip : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe's Files\iStock_000003531245XSmall.jpg : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe's Files\Kam Pro DVD.txt : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe's Files\Slideshow\100A0357.JPG : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe's Files\Slideshow\100A0366.JPG : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe's Files\Slideshow\100A0428.JPG : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe's Files\Slideshow\100A0469.JPG : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe's Files\Slideshow\100A0477.JPG : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe's Files\Slideshow\18th birthday 053.jpg : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe's Files\Slideshow\18th birthday 058.jpg : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe's Files\Slideshow\Djamilla Wedding.jpg : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe's Files\Slideshow\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Joe's Files\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\S2500004.JPG : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\S2500008.JPG : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Joe Williams KJDJ\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Marguerite Web Design\btcssbill20071213ref684620071215102348.pdf : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Marguerite Web Design\Buttons\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Marguerite Web Design\css_cheat_sheet.pdf : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Marguerite Web Design\css_layout_cheat_sheet.pdf : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Marguerite Web Design\Marguerite\public_html\images\images\images\images\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Marguerite Web Design\Marguerite\public_html\images\images\images\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Marguerite Web Design\Marguerite\public_html\images\images\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Marguerite Web Design\Marguerite\public_html\images\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Marguerite Web Design\Marguerite\public_html\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Marguerite Web Design\Marguerite\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Marguerite Web Design\Marguerite Images\Colour Schemes\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Marguerite Web Design\Marguerite Images\iStock Downloads\ColdWinter\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Marguerite Web Design\Marguerite Images\iStock Downloads\globe\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Marguerite Web Design\Marguerite Images\iStock Downloads\iStock_000000497745XSmall.jpg : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Marguerite Web Design\Marguerite Images\iStock Downloads\iStock_000001496298XXLarge.jpg : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Marguerite Web Design\Marguerite Images\iStock Downloads\iStock_000002415249XSmall.jpg : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Marguerite Web Design\Marguerite Images\iStock Downloads\iStock_000002787906Large.jpg : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Marguerite Web Design\Marguerite Images\iStock Downloads\iStock_000003135584XSmall.jpg : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Marguerite Web Design\Marguerite Images\iStock Downloads\iStock_000003247659XSmall.jpg : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Marguerite Web Design\Marguerite Images\iStock Downloads\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Marguerite Web Design\Marguerite Images\iStock_000000959604XSmall.jpg : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Marguerite Web Design\Marguerite Images\iStock_000002388977Illustra\iStock_000003135584XSmall.jpg : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Marguerite Web Design\Marguerite Images\iStock_000002388977Illustra\nature pictogram\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Marguerite Web Design\Marguerite Images\iStock_000002388977Illustra\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Marguerite Web Design\Marguerite Images\iStock_000002696475Illustra.zip : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Marguerite Web Design\Marguerite Images\iStock_000002840815Illustra.zip : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Marguerite Web Design\Marguerite Images\iStock_000003393339Illustra.zip : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Marguerite Web Design\Marguerite Images\nature pictogram\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Marguerite Web Design\Marguerite Images\psd files\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Marguerite Web Design\Marguerite Images\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Marguerite Web Design\Marguerite Images\xp-icons\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Marguerite Web Design\Marguerite New Site\files\Site Images\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Marguerite Web Design\Marguerite New Site\files\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Marguerite Web Design\Marguerite New Site\stripe_db3ace6f239a56360b1ea2f32e324f18.png : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Marguerite Web Design\Marguerite New Site\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Marguerite Web Design\Marguerite New Site\website\images\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Marguerite Web Design\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Twin Lakes\clubhouse.jpg : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Twin Lakes\Golf Club\images\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Twin Lakes\Horncastle Golf Club\images\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Twin Lakes\Images\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Twin Lakes\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\All Users\Documents\Margie's Files\Twin Lakes\Twin Lakes Centre\images\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\All Users\Documents\My Music\Sample Music\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\All Users\Documents\My Music\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Brushes\Grass.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Custom Shapes\jak_1flowers.csh : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Custom Shapes\pretty_floral.zip : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Custom Shapes\SoccerCups-Logos.csh : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Custom Shapes\Sports_Shapes.csh : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Actions\Marker.atn : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Actions\Pastel_sketch.atn : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Actions\PMXgolf2.atn : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Actions\Vectorize_by_JennyW.atn : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\142dotty.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\abstracts.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\AlexVectorCircles.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\artistsbrushes.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\AssortedAbstract.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\bmarco_grundge_border_set_1.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\bmarco_grundge_border_set_2.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\BoldDeclarations.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\botanicae_selectae.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\Brewer's_Brushes_II.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\bsilviaBRUSHES.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\canobeflowers.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\CC-ScatterelleColours.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\crosshatch-stippling.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\Dev`eaves.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\distress.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\DSH003brushes.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\Fancy.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\floral.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\flowers1.ABR : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\flowerscans.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\Flowers_&_Leave.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\GavaarRanstract.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\giatto.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\glassflowers.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\Gridlox.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\Gridworks.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\Grunge_Brushes_1.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\Grunge_Brushes_2.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\ild_grunge.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\ink_splashes_by_pietro.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\interpretive_signs4.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\intotrs2.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\jak_decor.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\jgibbs86-abstract.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\JRJ_Airbourne.ABR : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\JRJ_Art.ABR : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\jubs'_Paper_FX_v1.0.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\Kaleidoscope_set_1_sfg.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\Karl_S_Lens_Flare_Brushes.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\Layered.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\line_brushes.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\logo__shapes.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\marc_Xmas.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\mim-artdeco.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\mim-invariablytorn.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\mim-ragged.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\mim-tattered.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\mims-rectangles.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\Most_Useful_Linesquared.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\my_badaz_brushes.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\naturalworld.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\Petals.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\photo_edges_2.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\RedRed.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\roundedboxes.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\Ryans_Brushes_Set_2.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\schneichbrushes.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\scrollworks.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\sks_nbrushes.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\srbretro.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\stain.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\Tropical_Butterflies.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\TwistySwirlywurl_Brushes-II.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\urbangrunge.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\vered_frilled_brush.abr : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\void-flowers2.ABR : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Brushes\waterwisps.ABR : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Custom Shapes\Abstract_Custom_Shapes.csh : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Custom Shapes\Brewer_Shapes_2.csh : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Custom Shapes\Frames_Shapes.csh : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Custom Shapes\Initials.csh : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Custom Shapes\jak_1flowers.csh : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Custom Shapes\jak_decor.csh : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Custom Shapes\JessButterfilesShapes.csh : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Custom Shapes\LK_swirls.csh : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Custom Shapes\Sports_Shapes.csh : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Custom Shapes\waves_of_shapes.csh : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Patterns\d_boone_PA_woods+.pat : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Patterns\wood_cj.pat : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Styles\atl_2.asl : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Styles\atl_3.asl : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Styles\CCs-rich_gel.asl : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Styles\Explorer_Liquid_Gel.asl : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Styles\glit_gel.asl : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Styles\hellyz_gellious.asl : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Styles\OlympicGames.asl : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Styles\Skittless.asl : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Styles\TT_Uncommon_Styles.asl : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Styles\Web2dot0.asl : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Presets\Styles\XBOX.asl : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Styles\brass.asl : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Styles\clear_plastic.asl : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Styles\Dlewin-pearly.asl : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Styles\glit_gel.asl : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Styles\GSTPSPARKSTYLES.asl : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Styles\metalsheen.asl : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Styles\OlympicGames.asl : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Styles\PC_Glass.asl : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Styles\sks_porcelain.asl : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Styles\sks_softly.asl : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Styles\sks_softly2.asl : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Presets\Styles\Snapper's_Garden.asl : Zone.Identifier (26 bytes)
C:\Documents and Settings\All Users\Documents\Wisdom-soft ScreenHunter 5 Pro\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\Billy\Application Data\uTorrent\Adobe Photoshop Top Secret DVD Complete.torrent : Zone.Identifier (26 bytes)
C:\Documents and Settings\Billy\Desktop\bex\days\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\Billy\Desktop\bex\New Folder\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\Billy\Desktop\bex\New Folder (2)\New Folder\2\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\Billy\Desktop\bex\New Folder (2)\New Folder\2\weapons\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\Billy\Desktop\bex\New Folder (2)\New Folder\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\Billy\Desktop\bex\New Folder (2)\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\Billy\Desktop\bex\other\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\Billy\Desktop\bex\pandora\New Folder\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\Billy\Desktop\bex\pandora\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\Billy\Desktop\bex\photoshop\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\Billy\Desktop\bex\random day\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\Billy\Desktop\bex\school\New Folder\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\Billy\Desktop\bex\school\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\Billy\Desktop\bex\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\Billy\Desktop\Loz\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\Billy\Desktop\OTMoveIt2.exe : Zone.Identifier (26 bytes)
C:\Documents and Settings\Billy\Desktop\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\Billy\Local Settings\Temporary Internet Files\Content.IE5\4JEPCHUD\mbam-setup[1].exe : Zone.Identifier (26 bytes)
C:\Documents and Settings\Billy\Local Settings\Temporary Internet Files\Content.IE5\6WCFO0Z3\HJTInstall[1].exe : Zone.Identifier (26 bytes)
C:\Documents and Settings\Billy\Local Settings\Temporary Internet Files\Content.IE5\GHA70X2N\me_197[1][1].gif : Zone.Identifier (26 bytes)
C:\Documents and Settings\Billy\Local Settings\Temporary Internet Files\Content.IE5\TEF9X1KX\HJTInstall[1].exe : Zone.Identifier (26 bytes)
C:\Documents and Settings\Billy\Local Settings\Temporary Internet Files\Content.IE5\UW2C4EDZ\HostsXpert[1].zip : Zone.Identifier (26 bytes)
C:\Documents and Settings\Billy\My Documents\My Pictures\Billie Nativity 2007\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\Billy\My Documents\My Pictures\Microsoft Clip Organizer\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\Billy\My Documents\My Pictures\Thumbs.db : encryptable (0 bytes)
C:\Documents and Settings\Billy\My Documents\My Received Files\55y10A1.tmp.jpg : Zone.Identifier (26 bytes)
C:\Documents and Settings\Billy\My Documents\My Videos\Thumbs.db : encryptable (0 bytes)
C:\Lauren\000_0179.jpg : Zone.Identifier (26 bytes)
C:\Lauren\000_0181.jpg : Zone.Identifier (26 bytes)
C:\Lauren\000_0182.jpg : Zone.Identifier (26 bytes)
C:\Lauren\000_0183.jpg : Zone.Identifier (26 bytes)
C:\Lauren\100_0008.jpg : Zone.Identifier (26 bytes)
C:\Lauren\Picture 095.jpg : Zone.Identifier (26 bytes)
C:\Lauren\Picture 096.jpg : Zone.Identifier (26 bytes)
C:\Lauren\Picture 097.jpg : Zone.Identifier (26 bytes)
C:\Lauren\Picture 098.jpg : Zone.Identifier (26 bytes)
C:\Lauren\Picture 099.jpg : Zone.Identifier (26 bytes)
C:\Lauren\Picture 100.jpg : Zone.Identifier (26 bytes)
C:\Lauren\Picture 101.jpg : Zone.Identifier (26 bytes)
C:\Lauren\Picture 102.jpg : Zone.Identifier (26 bytes)
C:\Lauren\Picture 103.jpg : Zone.Identifier (26 bytes)
C:\Lauren\Picture 104.jpg : Zone.Identifier (26 bytes)
C:\Lauren\Picture 105.jpg : Zone.Identifier (26 bytes)
C:\Lauren\Thumbs.db : encryptable (0 bytes)
C:\Make Your Copy of Windows 100% Genuine\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Abstraxx\abstraxxLogo.png : Zone.Identifier (26 bytes)
C:\Margie's Files\Abstraxx\Files\'After the Apocalypse'.jpg : Zone.Identifier (26 bytes)
C:\Margie's Files\Abstraxx\Files\'alchemist bowl' (close up).jpg : Zone.Identifier (26 bytes)
C:\Margie's Files\Abstraxx\Files\'alchemist bowl' (close).jpg : Zone.Identifier (26 bytes)
C:\Margie's Files\Abstraxx\Files\'alchemist bowl' (top).jpg : Zone.Identifier (26 bytes)
C:\Margie's Files\Abstraxx\Files\'alchemist bowl'.jpg : Zone.Identifier (26 bytes)
C:\Margie's Files\Abstraxx\Files\'born of the tide'.jpg : Zone.Identifier (26 bytes)
C:\Margie's Files\Abstraxx\Files\alchemist bowl and wedge bowl.jpg : Zone.Identifier (26 bytes)
C:\Margie's Files\Abstraxx\Files\born of the tide.jpg : Zone.Identifier (26 bytes)
C:\Margie's Files\Abstraxx\Files\cherry and burr elm clock.jpg : Zone.Identifier (26 bytes)
C:\Margie's Files\Abstraxx\Files\elm and copper wall clock.jpg : Zone.Identifier (26 bytes)
C:\Margie's Files\Abstraxx\Files\elm sculpture.jpg : Zone.Identifier (26 bytes)
C:\Margie's Files\Abstraxx\Files\fusion.jpg : Zone.Identifier (26 bytes)
C:\Margie's Files\Abstraxx\Files\henge.jpg : Zone.Identifier (26 bytes)
C:\Margie's Files\Abstraxx\Files\lunar.jpg : Zone.Identifier (26 bytes)
C:\Margie's Files\Abstraxx\Files\mahogany clock.jpg : Zone.Identifier (26 bytes)
C:\Margie's Files\Abstraxx\Files\monolith.jpg : Zone.Identifier (26 bytes)
C:\Margie's Files\Abstraxx\Files\natural edge vessel.jpg : Zone.Identifier (26 bytes)
C:\Margie's Files\Abstraxx\Files\oak and aluminium clock.jpg : Zone.Identifier (26 bytes)
C:\Margie's Files\Abstraxx\Files\oak and brass clock.jpg : Zone.Identifier (26 bytes)
C:\Margie's Files\Abstraxx\Files\patinated mahogany clock.jpg : Zone.Identifier (26 bytes)
C:\Margie's Files\Abstraxx\Files\scorpion in stone.jpg : Zone.Identifier (26 bytes)
C:\Margie's Files\Abstraxx\Files\split in time.jpg : Zone.Identifier (26 bytes)
C:\Margie's Files\Abstraxx\Files\tall tower with copper.jpg : Zone.Identifier (26 bytes)
C:\Margie's Files\Abstraxx\Files\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Abstraxx\Files\walnut clock.jpg : Zone.Identifier (26 bytes)
C:\Margie's Files\Abstraxx\Files\waterfall bowl and Impact bowl.jpg : Zone.Identifier (26 bytes)
C:\Margie's Files\Abstraxx\Files\wedge bowl (no2).jpg : Zone.Identifier (26 bytes)
C:\Margie's Files\Abstraxx\Files\woman on all fours.jpg : Zone.Identifier (26 bytes)
C:\Margie's Files\Abstraxx\large\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Abstraxx\scorpion 1.jpg : Zone.Identifier (26 bytes)
C:\Margie's Files\Abstraxx\scorpion 2.jpg : Zone.Identifier (26 bytes)
C:\Margie's Files\Abstraxx\thumbs\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Abstraxx\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Abstraxx\Website\images\large\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Abstraxx\Website\images\thumbs\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Abstraxx\Website\images\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Abstraxx\Website\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Adobe Photoshop Top Secret DVD Complete\Photoshop Top Secret\Breaking Apart\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Adobe Photoshop Top Secret DVD Complete\Photoshop Top Secret\Dark Faces\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Adobe Photoshop Top Secret DVD Complete\Photoshop Top Secret\Dream Scene Montage\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Adobe Photoshop Top Secret DVD Complete\Photoshop Top Secret\Dream Skin\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Adobe Photoshop Top Secret DVD Complete\Photoshop Top Secret\Movie Poster\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Adobe Photoshop Top Secret DVD Complete\Photoshop Top Secret\Movie Poster 2\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Adobe Photoshop Top Secret DVD Complete\Photoshop Top Secret\Movie Poster Credits\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Adobe Photoshop Top Secret DVD Complete\Photoshop Top Secret\Special Effects\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Adobe Photoshop Top Secret DVD Complete\Photoshop Top Secret\Stone Portrait\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Adobe Photoshop Top Secret DVD Complete\Photoshop Top Secret\Surreal Mist\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Astroturf\Astroturf Files\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Astroturf\Horncastle Playing Fields\images\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Astroturf\Horncastle Rugby Club\images\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Astroturf\icons\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Astroturf\Rugby Club Files\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Astroturf\sports_template.psd : Zone.Identifier (26 bytes)
C:\Margie's Files\Astroturf\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Business Stuff\A Guide to running a business from home.pdf : Zone.Identifier (26 bytes)
C:\Margie's Files\Business Stuff\guide to applying for grants.pdf : Zone.Identifier (26 bytes)
C:\Margie's Files\Business Stuff\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Design Ideas\B&B\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Design Ideas\Miscellaneous\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Design Ideas\Personal\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Design Ideas\Sport\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Design Ideas\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Design Ideas\Travel\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Design Ideas\Web Design, Art & Design\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Design Ideas\Wedding\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Desktop\bex\bebo - blood\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Desktop\bex\homework\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Desktop\bex\icons\icond\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Desktop\bex\icons\my music\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Desktop\bex\icons\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Desktop\bex\jd.jpg : Zone.Identifier (26 bytes)
C:\Margie's Files\Desktop\bex\new\lara\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Desktop\bex\new\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Desktop\bex\peeps\man u\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Desktop\bex\peeps\New Folder\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Desktop\bex\peeps\Rebecca's last day at Tennyson\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Desktop\bex\peeps\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Desktop\bex\song words\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Desktop\bex\teh\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Desktop\bex\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Desktop\btcssbill20070913ref684620070918094210.pdf : Zone.Identifier (26 bytes)
C:\Margie's Files\Desktop\businessplan.doc : Zone.Identifier (26 bytes)
C:\Margie's Files\Desktop\Project Files\project files - dw-advanced\Lesson 01\Dive site\images\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Desktop\Project Files\project files - dw-advanced\Lesson 01\Dive site\thumbnails\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Desktop\Slideshow\images\large\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Desktop\Slideshow\images\thumbs\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Desktop\Slideshow\images\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Desktop\Slideshow\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Desktop\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Desktop\Wedding\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\e-books\Building Flash Websites for Dummies\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\e-books\Photoshop Anthology\chapter09\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\e-books\Photoshop Anthology\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\e-books\Project Files - Illustrator CS2\Part 1\Lesson 01\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\e-books\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Forum\public_html\yabbfiles\Buttons\English\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Forum\public_html\yabbfiles\Templates\Forum\default\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\Horncastle Theatre Group\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\bmp\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\gif\128x128\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\gif\16x16\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\gif\24x24\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\gif\256x256\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\gif\32x32\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\gif\48x48\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\Icelandic\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\icons\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\imac\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\Internet\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\metal\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\Misc\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\odd\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\OS\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\png\128x128\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\png\16x16\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\png\24x24\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\png\256x256\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\png\32x32\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\png\48x48\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\simple\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\Sports\NBA\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\Sports\NHL\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\Sports\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\TV & Cinema\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0001\gif\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0001\gif-i\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0001\gif-o\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0001\ico-32bit\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0001\ico-32bit-i\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0001\ico-32bit-o\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0001\ico-8bit\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0001\ico-8bit-i\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0001\ico-8bit-o\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0002\gif\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0002\gif-i\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0002\gif-o\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0002\ico-32bit\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0002\ico-32bit-i\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0002\ico-32bit-o\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0002\ico-8bit\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0002\ico-8bit-i\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0002\ico-8bit-o\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0003\gif\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0003\gif-i\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0003\gif-o\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0003\ico-32bit-i\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0003\ico-32bit-o\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0003\ico-8bit\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0003\ico-8bit-i\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0003\ico-8bit-o\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0004\gif\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0004\gif-i\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0004\gif-o\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0004\ico-32bit-i\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0004\ico-32bit-o\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0004\ico-8bit\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0004\ico-8bit-i\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0004\ico-8bit-o\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0005\gif\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0005\gif-i\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0005\gif-o\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0005\ico-32bit-i\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0005\ico-32bit-o\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0005\ico-8bit\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0005\ico-8bit-i\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0005\ico-8bit-o\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0005\png-o\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0006\gif\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0006\gif-i\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0006\gif-o\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0006\ico-32bit-i\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0006\ico-32bit-o\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0006\ico-8bit\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0006\ico-8bit-i\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0006\ico-8bit-o\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0007\gif\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0007\gif-i\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0007\gif-o\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0007\ico-32bit-i\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0007\ico-32bit-o\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0007\ico-8bit\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0007\ico-8bit-i\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0007\ico-8bit-o\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0008\gif\Thumbs.db : encryptable (0 bytes)
C:\Margie's Files\icons\xp-icons\fr0008\g
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP