Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

virtumonde virus [RESOLVED]


  • This topic is locked This topic is locked

#1
gvskw

gvskw

    New Member

  • Member
  • Pip
  • 6 posts
Hi,

I have read your directions of how to post a problem and am adding some logs for you to look at.
My pc got infected a while ago and I cannot seem to get it straigt.
Please take a look at the added loggs and let me know what I should do.

Thanks


Malwarebytes' Anti-Malware 1.19
Database version: 930
Windows 5.1.2600 Service Pack 2

21:50:11 08/07/2008
mbam-log-7-8-2008 (21-50-11).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 156437
Time elapsed: 1 hour(s), 22 minute(s), 28 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


ANALYSIS: 2008-07-12 10:37:24
PROTECTIONS: 2
MALWARE: 5
SUSPECTS: 0
;*******************************************************************************
*********************************************************************************
*******************
PROTECTIONS
Description Version Active Updated
;===============================================================================
=================================================================================
===================
ThreatFire 3.5.0.21 Yes Yes
Windows Live OneCare 1.0.0 Yes Yes
;===============================================================================
=================================================================================
===================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===============================================================================
=================================================================================
===================
00172449 Cookie/MetriWeb TrackingCookie No 0 Yes No C:\Documents and Settings\Gunter - Shawn\Cookies\[email protected][2].txt
00194327 Cookie/Go TrackingCookie No 0 Yes No C:\Documents and Settings\Gunter - Shawn\Cookies\[email protected][2].txt
00207862 Cookie/did-it TrackingCookie No 0 Yes No C:\My Backup -- 29-06-08 1050\Documents and Settings\Guest\Cookies\[email protected][1].txt
00293517 Cookie/AdDynamix TrackingCookie No 0 Yes No C:\Documents and Settings\Gunter - Shawn\Cookies\[email protected][1].txt
03173565 Spyware/Virtumonde Spyware No 1 Yes No C:\System Volume Information\_restore{4A29620B-0973-4CDA-BBC9-4088620A8365}\RP10\A0003494.dll

Uninstall list hijack

Adobe Flash Player ActiveX
Adobe Flash Player Plugin
Adobe Reader 6.0
AOL Connectivity Services
AOL Spyware Protection
AOL UK (Choose which version to remove)
BigFix
CCleaner (remove only)
Digital Media Reader
Google Toolbar for Internet Explorer
GTOneCare
HijackThis 2.0.2
Intel® Extreme Graphics Driver
Intel® PRO Network Adapters and Drivers
Java 2 Runtime Environment, SE v1.4.2
Java™ 6 Update 6
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office 2000 Premium
Microsoft Office XP Professional with FrontPage
Microsoft Protection Service
Microsoft Visual C++ 2005 Redistributable
Microsoft Windows Live OneCare Resources v2.5.2900.03
Microsoft Windows OneCare Live AntiSpyware and AntiVirus
Microsoft Windows OneCare Live v2.5.2900.03
Microsoft Windows OneCare Live v2.5.2900.03 Idcrl Install
MSXML 4.0 SP2 (KB936181)
Multimedia Keyboard Driver
Opera 9.51
Panda ActiveScan 2.0
PowerDVD
PX Engine
Security Update for Microsoft .NET Framework 2.0 (KB928365)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB951748)
Skype™ 3.8
Smart Link 56K Voice Modem
Spybot - Search & Destroy
SUPERAntiSpyware Free Edition
Update for Windows XP (KB951978)
Viewpoint Media Player
Windows Backup Utility
Windows Live OneCare
Windows Media Format Runtime
Windows Media Player 10
Windows XP Service Pack 3
WinRAR archiver

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 07/10/2008 at 09:57 PM

Application Version : 4.15.1000

Core Rules Database Version : 3500
Trace Rules Database Version: 1491

Scan type : Quick Scan
Total Scan Time : 00:31:02

Memory items scanned : 343
Memory threats detected : 0
Registry items scanned : 342
Registry threats detected : 0
File items scanned : 15069
File threats detected : 8

Adware.Tracking Cookie
C:\Documents and Settings\Gunter - Shawn\Cookies\[email protected][1].txt
C:\Documents and Settings\Gunter - Shawn\Cookies\[email protected][2].txt
C:\Documents and Settings\Gunter - Shawn\Cookies\[email protected][1].txt
C:\Documents and Settings\Gunter - Shawn\Cookies\[email protected][1].txt
C:\Documents and Settings\Gunter - Shawn\Cookies\[email protected][1].txt
C:\Documents and Settings\Gunter - Shawn\Cookies\[email protected][2].txt
C:\Documents and Settings\Gunter - Shawn\Cookies\[email protected][1].txt
C:\Documents and Settings\Gunter - Shawn\Cookies\[email protected][1].txt


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:57:12, on 13/07/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\slserv.exe
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
C:\Program Files\Microsoft Windows OneCare Live\winss.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Windows OneCare Live\WinSSUI.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {3D88759D-1F2C-416E-86E1-07F5A07EAAB4} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5DBEDE02-F6A0-4CBB-AF1F-656812D6CAB7} - C:\WINDOWS\system32\iifFVlmm.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [OneCareUI] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoft...s/as2stubie.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1215411105468
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe

--
End of file - 3750 bytes



Thank you y
  • 0

Advertisements


#2
fenzodahl512

fenzodahl512

  • Malware Removal
  • 9,863 posts
Hello, my name is fenzodahl512 and welcome to Geekstogo.. Please do the following....



Please download Deckard's System Scanner (DSS) from HERE or HERE and save it to your Desktop.
  • Close all other windows before proceeding.
  • Double-click on dss.exe and follow the prompts.
  • Please let your firewall allow the scanning/downloading process.
  • When it has finished, dss will open two Notepads main.txt and extra.txt -- please copy (CTRL+A and then CTRL+C) and paste (CTRL+V) the contents of main.txt and extra.txt in your next reply.
If you are using Vista, you need to right-click at dss.exe icon and choose Run as Administrator



Regards
fenzodahl512
  • 0

#3
gvskw

gvskw

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
Thank you for looking at this Fenzodahl

Here is the log as requested


Run by Gunter - Shawn on 2008-07-14 17:45:16
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Successfully created a Deckard's System Scanner Restore Point.


-- Last 5 Restore Point(s) --
18: 2008-07-14 16:45:37 UTC - RP18 - Deckard's System Scanner Restore Point
17: 2008-07-13 22:33:24 UTC - RP17 - Software Distribution Service 3.0
16: 2008-07-13 22:24:17 UTC - RP16 - Installed HPSU306Stub
15: 2008-07-13 18:51:57 UTC - RP15 - ComboFix created restore point
14: 2008-07-13 17:27:58 UTC - RP14 - Software Distribution Service 3.0

and the second one


Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------

-- System Information ----------------------------------------------------------

Microsoft Windows XP Home Edition (build 2600) SP 3.0
Architecture: X86; Language: English

CPU 0: Intel® Celeron® CPU 2.80GHz
Percentage of Memory in Use: 74%
Physical Memory (total/avail): 246.73 MiB / 64 MiB
Pagefile Memory (total/avail): 976.47 MiB / 519.98 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1881.8 MiB

C: is Fixed (NTFS) - 73.65 GiB total, 58.73 GiB free.
D: is Fixed (FAT32) - 3.03 GiB total, 1.43 GiB free.
E: is CDROM (CDFS)
F: is Removable (No Media)
G: is Removable (No Media)
H: is Removable (No Media)
I: is Removable (No Media)

\\.\PHYSICALDRIVE0 - HDS728080PLAT20 - 76.69 GiB - 2 partitions
\PARTITION0 (bootable) - Installable File System - 73.65 GiB - C:
\PARTITION1 - Unknown - 3.03 GiB - D:

\\.\PHYSICALDRIVE2 - Generic USB CF Reader USB Device

\\.\PHYSICALDRIVE4 - Generic USB MS Reader USB Device

\\.\PHYSICALDRIVE1 - Generic USB SD Reader USB Device

\\.\PHYSICALDRIVE3 - Generic USB SM Reader USB Device



-- Security Center -------------------------------------------------------------

AUOptions is scheduled to auto-install.


-- Environment Variables -------------------------------------------------------

ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Gunter - Shawn\Application Data
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=GVSKVWPC
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Gunter - Shawn
LOGONSERVER=\\GVSKVWPC
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 4 Stepping 1, GenuineIntel
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=0401
ProgramFiles=C:\Program Files
PROMPT=$P$G
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\GUNTER~1\LOCALS~1\Temp
TMP=C:\DOCUME~1\GUNTER~1\LOCALS~1\Temp
USERDOMAIN=GVSKVWPC
USERNAME=Gunter - Shawn
USERPROFILE=C:\Documents and Settings\Gunter - Shawn
windir=C:\WINDOWS


-- User Profiles ---------------------------------------------------------------

Gunter - Shawn (admin)
Audrey (new local, admin)
Administrator (new local, admin)


-- Add/Remove Programs ---------------------------------------------------------

Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player Plugin --> C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 6.0 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-000000000001}
AOL Connectivity Services --> C:\PROGRA~1\COMMON~1\AOL\ACS\AcsUninstall.exe /c
AOL Spyware Protection --> C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\UNWISE.EXE C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\INSTALL.LOG
AOL UK (Choose which version to remove) --> C:\Program Files\Common Files\aolshare\Aolunins_uk.exe
BigFix --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{34FF0741-EC67-4C05-AC2A-6D257123DF2E}\setup.exe" -l0x9 -uninst -f"C:\Program Files\BigFix\Uninst.isu" -c"C:\Program Files\BigFix\Lib\UninstallHelper.dll"
CCleaner (remove only) --> "C:\Program Files\CCleaner\uninst.exe"
Digital Media Reader --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{81EED1A1-AE78-4B11-BE47-C6AE9F5E87F1}
Google Toolbar for Internet Explorer --> regsvr32 /u /s "c:\program files\google\googletoolbar1.dll"
GTOneCare --> MsiExec.exe /X{8B21B9EF-6DBF-4F63-8CC7-9F6A56D1EE8E}
HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
HP Customer Participation Program 7.0 --> C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
HP Document Viewer 7.0 --> C:\Program Files\HP\Digital Imaging\DocumentViewer\hpzscr01.exe -datfile hpqbud04.dat
HP Imaging Device Functions 7.0 --> C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
HP Photosmart Premier Software 6.5 --> C:\Program Files\HP\Digital Imaging\uninstall\hpzscr01.exe -datfile hpqscr01.dat
HP Photosmart, Officejet and Deskjet 7.0.A --> C:\Program Files\HP\Digital Imaging\{BDBE2F3E-42DB-4d4a-8CB1-19BA765DBC6C}\setup\hpzscr01.exe -datfile hposcr11.dat
HP Software Update --> MsiExec.exe /X{BB85ED9C-AFC9-43BD-B8DC-258C3C7DF72E}
HP Solution Center 7.0 --> C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
Intel® Extreme Graphics Driver --> RUNDLL32.EXE C:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx PCI\VEN_8086&DEV_2562
Intel® PRO Network Adapters and Drivers --> Prounstl.exe
Java 2 Runtime Environment, SE v1.4.2 --> MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142000}
Java™ 6 Update 6 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160060}
Malwarebytes' Anti-Malware --> "C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Microsoft Office 2000 Premium --> MsiExec.exe /I{00000409-78E1-11D2-B60F-006097C998E7}
Microsoft Office XP Professional with FrontPage --> MsiExec.exe /I{90280409-6000-11D3-8CFE-0050048383C9}
Microsoft Protection Service --> MsiExec.exe /I{85CFDC2D-710E-49D5-B799-F3743CA506BA}
Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Windows Live OneCare Resources v2.5.2900.03 --> MsiExec.exe /I{5660022E-F3F2-4126-8CC5-9726C47150EB}
Microsoft Windows OneCare Live AntiSpyware and AntiVirus --> MsiExec.exe /I{AB65455A-059F-41C3-AAD6-2EFAFB38B19B}
Microsoft Windows OneCare Live v2.5.2900.03 --> MsiExec.exe /I{D07A8E7E-D324-4945-BA8C-E532AD008FF3}
Microsoft Windows OneCare Live v2.5.2900.03 Idcrl Install --> MsiExec.exe /I{3851147E-5A91-4469-BA4D-13FFFCC8A920}
Multimedia Keyboard Driver --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FF262740-C85A-11D5-BBEC-00D0B740900A}\Setup.exe" -l0x9
OCR Software by I.R.I.S 7.0 --> C:\Program Files\HP\Digital Imaging\OCR\hpzscr01.exe -datfile hpqbud11.dat
Opera 9.51 --> MsiExec.exe /X{88A081BE-AF75-4556-9AD1-EE2B1A61BDF5}
Panda ActiveScan 2.0 --> C:\Program Files\Panda Security\ActiveScan 2.0\as2uninst.exe
Picasa 2 --> "C:\Program Files\Picasa2\Uninstall.exe"
PowerDVD --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\Setup.exe" -uninstall
PX Engine --> MsiExec.exe /I{6513E869-647F-40FD-A55D-CFC92579B9BA}
Skype™ 3.8 --> MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
Smart Link 56K Voice Modem --> C:\WINDOWS\Modio\SLAMR2KV\Setup.exe /Remove
Spybot - Search & Destroy --> "C:\Program Files\Spybot - Search & Destroy\unins000.exe"
SUPERAntiSpyware Free Edition --> MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}
Viewpoint Media Player --> C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u
Windows Backup Utility --> MsiExec.exe /I{76EFFC7C-17A6-479D-9E47-8E658C1695AE}
Windows Live OneCare --> "C:\Program Files\Microsoft Windows OneCare Live\OCSetup.exe" /u
Windows XP Service Pack 3 --> "C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
WinRAR archiver --> C:\Program Files\WinRAR\uninstall.exe


-- Application Event Log -------------------------------------------------------

Event Record #/Type571 / Warning
Event Submitted/Written: 07/13/2008 11:49:24 PM
Event ID/Source: 1015 / MsiInstaller
Event Description:
Failed to connect to server. Error: 0x800401F0

Event Record #/Type570 / Warning
Event Submitted/Written: 07/13/2008 11:49:24 PM
Event ID/Source: 1015 / MsiInstaller
Event Description:
Failed to connect to server. Error: 0x800401F0

Event Record #/Type568 / Warning
Event Submitted/Written: 07/13/2008 11:48:33 PM
Event ID/Source: 1015 / MsiInstaller
Event Description:
Failed to connect to server. Error: 0x800401F0

Event Record #/Type565 / Warning
Event Submitted/Written: 07/13/2008 11:48:30 PM
Event ID/Source: 1015 / MsiInstaller
Event Description:
Failed to connect to server. Error: 0x800401F0

Event Record #/Type563 / Warning
Event Submitted/Written: 07/13/2008 11:48:20 PM
Event ID/Source: 1015 / MsiInstaller
Event Description:
Failed to connect to server. Error: 0x800401F0



-- Security Event Log ----------------------------------------------------------

No Errors/Warnings found.


-- System Event Log ------------------------------------------------------------

Event Record #/Type164817 / Warning
Event Submitted/Written: 07/14/2008 03:38:33 PM
Event ID/Source: 20 / Print
Event Description:
Printer Driver HP Photosmart C4100 series for Windows NT x86 Version-3 was added or updated. Files:- UNIDRV.DLL, UNIDRVUI.DLL, hpac4103.GPD, UNIDRV.HLP, hpac410a.ini, hpzst054.dll, hpac4103.xml, hpzsc054.dtd, hpzui054.dll, hpz3r054.dll, hpzpr054.dll, hpcdmc32.dll, hpbcfgre.dll, hpahc410.exp, hpzsm054.gpd, hpz3m054.gpd, hpzev054.dll, hpzhl054.cab, STDNAMES.GPD, hpz3a054.dll, hpzss054.dll, hpfie054.dll, hpfig054.dll, hpfrs054.dll, UNIRES.DLL.

Event Record #/Type164816 / Warning
Event Submitted/Written: 07/14/2008 03:37:36 PM
Event ID/Source: 20 / Print
Event Description:
Printer Driver HP Photosmart C4100 series for Windows NT x86 Version-3 was added or updated. Files:- UNIDRV.DLL, UNIDRVUI.DLL, hpac4103.GPD, UNIDRV.HLP, hpac410a.ini, hpzst054.dll, hpac4103.xml, hpzsc054.dtd, hpzui054.dll, hpz3r054.dll, hpzpr054.dll, hpcdmc32.dll, hpbcfgre.dll, hpahc410.exp, hpzsm054.gpd, hpz3m054.gpd, hpzev054.dll, hpzhl054.cab, STDNAMES.GPD, hpz3a054.dll, hpzss054.dll, hpfie054.dll, hpfig054.dll, hpfrs054.dll, UNIRES.DLL.

Event Record #/Type164815 / Warning
Event Submitted/Written: 07/14/2008 09:43:25 AM
Event ID/Source: 36 / W32Time
Event Description:
The time service has not been able to synchronize the system time
for 49152 seconds because none of the time providers has been able to
provide a usable time stamp. The system clock is unsynchronized.

Event Record #/Type164804 / Error
Event Submitted/Written: 07/13/2008 11:35:15 PM / 07/13/2008 11:35:16 PM
Event ID/Source: 20 / Windows Update Agent
Event Description:
Installation Failure: Windows failed to install the following update with error 0x80070652: Office XP Service Pack 3.

Event Record #/Type164776 / Error
Event Submitted/Written: 07/13/2008 10:30:24 PM
Event ID/Source: 7016 / Service Control Manager
Event Description:
The SmartLinkService service has reported an invalid current state 0.



-- End of Deckard's System Scanner: finished at 2008-07-14 17:50:16 ------------



-- First Restore Point --
1: 2008-07-07 20:52:57 UTC - RP1 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.

Total Physical Memory: 247 MiB (512 MiB recommended).


-- HijackThis (run as Gunter - Shawn.exe) --------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:46:42, on 14/07/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
C:\Program Files\Microsoft Windows OneCare Live\winss.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\HP\digital imaging\bin\hpqtra08.exe
C:\Program Files\BigFix\BigFix.exe
C:\Documents and Settings\Gunter - Shawn\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Gunter - Shawn.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [OneCareUI] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoft...s/as2stubie.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1215411105468
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe

--
End of file - 4610 bytes

-- File Associations -----------------------------------------------------------

.cpl - cplfile - shell\cplopen\command - rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.cpl - cplfile - shell\runas\command - rundll32.exe shell32.dll,Control_RunDLLAsUser "%1",%*
.txt - txtfile - shell\open\command - NOTEPAD.EXE %1


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R3 SunkFilt (Alcor Micro Corp Reader) - c:\windows\system32\drivers\sunkfilt.sys <Not Verified; Alcor Micro Corp.; SunkFilt>

S3 ATE_PROCMON - c:\program files\anti trojan elite\atepmon.sys (file missing)


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

S4 ThreatFire - c:\program files\threatfire\tfservice.exe service (file missing)


-- Device Manager: Disabled ----------------------------------------------------

Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Generic Digital camera
Device ID: USB\VID_04FC&PID_0561\5&FCDEEB7&0&1
Manufacturer:
Name: Generic Digital camera
PNP Device ID: USB\VID_04FC&PID_0561\5&FCDEEB7&0&1
Service:

Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Base System Device
Device ID: PCI\VEN_14F1&DEV_1610&SUBSYS_5506141B&REV_01\4&29817089&0&00F0
Manufacturer:
Name: Base System Device
PNP Device ID: PCI\VEN_14F1&DEV_1610&SUBSYS_5506141B&REV_01\4&29817089&0&00F0
Service:

Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: ATM Network Controller
Device ID: PCI\VEN_14F1&DEV_1611&SUBSYS_5507141B&REV_01\4&29817089&0&01F0
Manufacturer:
Name: ATM Network Controller
PNP Device ID: PCI\VEN_14F1&DEV_1611&SUBSYS_5507141B&REV_01\4&29817089&0&01F0
Service:


-- Files created between 2008-06-14 and 2008-07-14 -----------------------------

2008-07-13 23:49:39 0 d-------- C:\Documents and Settings\All Users\Application Data\HP
2008-07-13 23:47:47 0 d-------- C:\bin
2008-07-13 23:45:54 0 d-------- C:\Program Files\Common Files\Sonic Shared
2008-07-13 23:45:54 0 d-------- C:\Documents and Settings\All Users\Application Data\Sonic
2008-07-13 23:37:50 0 d-------- C:\Program Files\Common Files\HP
2008-07-13 23:20:54 0 d-------- C:\Program Files\Hewlett-Packard
2008-07-13 23:19:12 0 d-------- C:\Program Files\Common Files\Hewlett-Packard
2008-07-13 22:52:29 0 d-------- C:\WINDOWS\LastGood
2008-07-13 22:51:24 0 d-------- C:\Program Files\HP
2008-07-13 22:50:04 117013 --a------ C:\WINDOWS\hpoins11.dat
2008-07-13 22:47:42 0 d-------- C:\Program Files\Picasa2
2008-07-13 19:49:37 161792 --a------ C:\WINDOWS\swreg.exe <Not Verified; SteelWerX; SteelWerX Registry Editor>
2008-07-13 19:49:36 68096 --a------ C:\WINDOWS\zip.exe
2008-07-13 19:49:36 49152 --a------ C:\WINDOWS\VFind.exe
2008-07-13 19:49:36 136704 --a------ C:\WINDOWS\swsc.exe <Not Verified; SteelWerX; SteelWerX Service Controller>
2008-07-13 19:49:36 98816 --a------ C:\WINDOWS\sed.exe
2008-07-13 19:49:36 80412 --a------ C:\WINDOWS\grep.exe
2008-07-13 19:49:36 89504 --a------ C:\WINDOWS\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-07-13 19:49:35 212480 --a------ C:\WINDOWS\swxcacls.exe <Not Verified; SteelWerX; SteelWerX Extended Configurator ACLists>
2008-07-13 18:55:04 0 d-------- C:\Program Files\Trend Micro
2008-07-13 09:07:31 0 dr-h----- C:\Documents and Settings\Gunter - Shawn\Recent
2008-07-10 22:12:28 0 d-------- C:\Program Files\Panda Security
2008-07-09 21:54:32 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-07-09 21:53:05 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-07-09 21:53:05 0 d-------- C:\Documents and Settings\Gunter - Shawn\Application Data\SUPERAntiSpyware.com
2008-07-09 17:54:59 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-07-09 11:55:48 0 d-------- C:\WINDOWS\Prefetch
2008-07-09 07:50:58 0 d-------- C:\WINDOWS\system32\scripting
2008-07-09 07:50:57 0 d-------- C:\WINDOWS\l2schemas
2008-07-09 07:50:55 0 d-------- C:\WINDOWS\system32\en
2008-07-09 07:46:22 0 d-------- C:\WINDOWS\ServicePackFiles
2008-07-09 07:16:30 0 d-------- C:\WINDOWS\EHome
2008-07-08 22:53:16 0 d-------- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2008-07-07 22:05:03 0 d-------- C:\Documents and Settings\Gunter - Shawn\Application Data\Malwarebytes
2008-07-07 22:04:54 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-07 22:04:50 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-07 22:04:23 0 d-------- C:\Program Files\Common Files\Download Manager
2008-07-07 14:07:56 0 d-------- C:\Documents and Settings\Gunter - Shawn\Application Data\AdobeUM
2008-07-07 14:07:33 0 d-------- C:\Program Files\Common Files\Adobe
2008-07-06 09:46:36 0 d-------- C:\WINDOWS\system32\bits
2008-07-06 07:26:09 0 d-------- C:\Program Files\Microsoft Windows OneCare Live
2008-07-05 17:41:00 0 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-05 17:25:49 0 dr------- C:\Documents and Settings\Audrey\Favorites
2008-07-05 17:25:49 0 d-------- C:\Documents and Settings\Audrey\Desktop
2008-07-05 17:25:49 0 d--hs---- C:\Documents and Settings\Audrey\Cookies
2008-07-05 17:25:49 0 dr-h----- C:\Documents and Settings\Audrey\Application Data
2008-07-05 17:25:49 0 d-------- C:\Documents and Settings\Audrey\Application Data\Sun
2008-07-05 17:25:49 0 d-------- C:\Documents and Settings\Audrey\Application Data\SampleView
2008-07-05 17:25:49 0 d---s---- C:\Documents and Settings\Audrey\Application Data\Microsoft
2008-07-05 17:25:49 0 d-------- C:\Documents and Settings\Audrey\Application Data\Identities
2008-07-05 17:25:48 0 d-------- C:\Documents and Settings\Audrey\WINDOWS
2008-07-05 17:25:48 0 d--h----- C:\Documents and Settings\Audrey\Templates
2008-07-05 17:25:48 0 dr------- C:\Documents and Settings\Audrey\Start Menu
2008-07-05 17:25:48 0 dr-h----- C:\Documents and Settings\Audrey\SendTo
2008-07-05 17:25:48 0 dr-h----- C:\Documents and Settings\Audrey\Recent
2008-07-05 17:25:48 0 d--h----- C:\Documents and Settings\Audrey\PrintHood
2008-07-05 17:25:48 0 d--h----- C:\Documents and Settings\Audrey\NetHood
2008-07-05 17:25:48 0 dr------- C:\Documents and Settings\Audrey\My Documents
2008-07-05 17:25:48 0 d--h----- C:\Documents and Settings\Audrey\Local Settings
2008-07-05 17:25:47 2097152 --ah----- C:\Documents and Settings\Audrey\NTUSER.DAT
2008-07-05 04:24:13 0 d-------- C:\Documents and Settings\Gunter - Shawn\Application Data\FRISK Software
2008-07-05 04:05:58 0 d------c- C:\WINDOWS\system32\DRVSTORE
2008-07-05 04:05:16 0 d-------- C:\Documents and Settings\All Users\Application Data\FRISK Software
2008-07-04 00:44:16 0 d-------- C:\Documents and Settings\Administrator\Application Data\Adobe
2008-07-03 17:08:52 0 d-------- C:\Documents and Settings\Administrator\Application Data\Skype
2008-07-03 16:57:02 0 d-------- C:\fsaua.data
2008-07-03 15:33:55 0 d-------- C:\Documents and Settings\Administrator\Application Data\Macromedia
2008-07-03 15:17:14 0 d-------- C:\Documents and Settings\Administrator\Application Data\WinRAR
2008-07-03 14:58:44 0 d-------- C:\Documents and Settings\Administrator\Application Data\Opera
2008-07-03 14:56:12 0 d--h----- C:\Documents and Settings\Administrator\Local Settings
2008-07-03 14:56:12 0 dr------- C:\Documents and Settings\Administrator\Favorites
2008-07-03 14:56:12 0 d-------- C:\Documents and Settings\Administrator\Desktop
2008-07-03 14:56:12 0 d--hs---- C:\Documents and Settings\Administrator\Cookies
2008-07-03 14:56:12 0 dr-h----- C:\Documents and Settings\Administrator\Application Data
2008-07-03 14:56:12 0 d-------- C:\Documents and Settings\Administrator\Application Data\Sun
2008-07-03 14:56:12 0 d-------- C:\Documents and Settings\Administrator\Application Data\SampleView
2008-07-03 14:56:12 0 d---s---- C:\Documents and Settings\Administrator\Application Data\Microsoft
2008-07-03 14:56:12 0 d-------- C:\Documents and Settings\Administrator\Application Data\Identities
2008-07-03 14:56:11 0 d-------- C:\Documents and Settings\Administrator\WINDOWS
2008-07-03 14:56:11 0 d--h----- C:\Documents and Settings\Administrator\Templates
2008-07-03 14:56:11 0 dr------- C:\Documents and Settings\Administrator\Start Menu
2008-07-03 14:56:11 0 dr-h----- C:\Documents and Settings\Administrator\SendTo
2008-07-03 14:56:11 0 dr-h----- C:\Documents and Settings\Administrator\Recent
2008-07-03 14:56:11 0 d--h----- C:\Documents and Settings\Administrator\PrintHood
2008-07-03 14:56:11 2359296 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT
2008-07-03 14:56:11 0 d--h----- C:\Documents and Settings\Administrator\NetHood
2008-07-03 14:56:11 0 dr------- C:\Documents and Settings\Administrator\My Documents
2008-07-03 11:57:36 0 d-------- C:\Documents and Settings\LocalService\Start Menu
2008-07-03 03:02:38 0 d-------- C:\Documents and Settings\Gunter - Shawn\Application Data\Adobe
2008-07-02 09:09:09 0 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-01 16:43:00 0 d-------- C:\Documents and Settings\Gunter - Shawn\Application Data\Microsoft Web Folders
2008-07-01 13:58:02 0 d-------- C:\Documents and Settings\Gunter - Shawn\Application Data\Opera
2008-07-01 13:50:05 0 d-------- C:\Program Files\Opera
2008-06-30 15:27:08 56 --ah----- C:\WINDOWS\system32\ezsidmv.dat
2008-06-30 15:27:05 0 d-------- C:\Documents and Settings\Gunter - Shawn\Application Data\skypePM
2008-06-30 15:22:01 0 d-------- C:\Temp
2008-06-30 15:21:33 0 d-------- C:\Documents and Settings\Gunter - Shawn\Application Data\Skype
2008-06-30 13:21:21 0 d-------- C:\Program Files\Skype
2008-06-30 13:15:51 0 d-------- C:\Program Files\Common Files\Skype
2008-06-30 12:17:38 0 d-------- C:\WINDOWS\network diagnostic
2008-06-30 12:02:32 0 d-------- C:\Program Files\Microsoft ActiveSync
2008-06-30 11:58:57 0 d-------- C:\WINDOWS\ShellNew
2008-06-30 00:50:35 0 d-------- C:\Documents and Settings\All Users\Application Data\Skype
2008-06-30 00:03:52 0 d-------- C:\Documents and Settings\Gunter - Shawn\Application Data\WinRAR
2008-06-29 19:14:28 135168 --a------ C:\WINDOWS\system32\SLMOHServ.dll <Not Verified; ; SLMOHServ Dynamic Link Library>
2008-06-29 19:14:28 368640 --a------ C:\WINDOWS\system32\slmh.exe <Not Verified; ; Modem Helper>
2008-06-29 19:14:28 528384 --a------ C:\WINDOWS\system32\SLLights.dll <Not Verified; ; SLLights>
2008-06-29 19:14:28 167936 --a------ C:\WINDOWS\system32\minirec.exe <Not Verified; ; MiniRec>
2008-06-29 19:14:28 14968 --a------ C:\WINDOWS\system32\drivers\winddx.sys <Not Verified; ; Modem>
2008-06-29 19:14:28 208896 --a------ C:\WINDOWS\system32\amr_cpl.dll <Not Verified; ; Modem>
2008-06-29 19:14:28 65536 --a------ C:\WINDOWS\SmCfg.exe <Not Verified; ; Modem>
2008-06-29 19:14:28 0 d-------- C:\WINDOWS\Modio
2008-06-29 19:11:58 0 d--hs---- C:\System Volume Information
2008-06-29 18:57:54 0 d-------- C:\WINDOWS\creator
2008-06-29 18:57:43 0 d-------- C:\WINDOWS\SMINST
2008-06-29 18:56:53 0 dr------- C:\Program Files
2008-06-29 18:56:38 0 dr------- C:\Documents and Settings\Default User\Start Menu
2008-06-29 18:56:38 0 dr-h----- C:\Documents and Settings\Default User\SendTo
2008-06-29 18:56:38 0 d--h----- C:\Documents and Settings\Default User\Local Settings
2008-06-29 18:56:38 0 dr-h----- C:\Documents and Settings\Default User\Application Data
2008-06-29 18:56:38 0 dr------- C:\Documents and Settings\All Users\Start Menu
2008-06-29 18:56:37 0 dr------- C:\Documents and Settings\All Users\Documents
2008-06-29 18:56:37 0 dr-h----- C:\Documents and Settings\All Users\Application Data
2008-06-29 18:56:15 0 dr------- C:\WINDOWS\Offline Web Pages
2008-06-29 18:53:00 0 dr-hs--c- C:\WINDOWS\system32\dllcache
2008-06-29 18:51:50 60 --a------ C:\MOVE_RECOVERY
2008-06-29 18:50:10 0 d-------- C:\My Backup -- 29-06-08 1050
2008-06-29 13:06:40 0 d-------- C:\Program Files\AVG
2008-06-29 12:44:41 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-06-29 12:30:50 0 d-------- C:\Documents and Settings\Gunter - Shawn\Application Data\LimeWire
2008-06-29 12:10:55 0 d-------- C:\Program Files\CCleaner
2008-06-29 11:57:42 0 d-------- C:\WINDOWS\system32\PreInstall
2008-06-29 11:54:15 0 d--hs---- C:\Documents and Settings\Gunter - Shawn\UserData
2008-06-29 11:46:29 0 d-------- C:\Documents and Settings\Gunter - Shawn\Application Data\Macromedia
2008-06-29 11:43:00 0 d--h----- C:\WINDOWS\$hf_mig$
2008-06-29 11:38:04 0 dr------- C:\Documents and Settings\Gunter - Shawn\Favorites
2008-06-29 11:38:04 0 d-------- C:\Documents and Settings\Gunter - Shawn\Desktop
2008-06-29 11:38:04 0 d--hs---- C:\Documents and Settings\Gunter - Shawn\Cookies
2008-06-29 11:38:04 0 d--h----- C:\Documents and Settings\Gunter - Shawn\Application Data
2008-06-29 11:38:04 0 d-------- C:\Documents and Settings\Gunter - Shawn\Application Data\Sun
2008-06-29 11:38:04 0 d-------- C:\Documents and Settings\Gunter - Shawn\Application Data\SampleView
2008-06-29 11:38:04 0 d-------- C:\Documents and Settings\Gunter - Shawn\Application Data\Identities
2008-06-29 11:38:03 0 d-------- C:\Documents and Settings\Gunter - Shawn\WINDOWS
2008-06-29 11:38:03 0 d--h----- C:\Documents and Settings\Gunter - Shawn\Templates
2008-06-29 11:38:03 0 dr------- C:\Documents and Settings\Gunter - Shawn\Start Menu
2008-06-29 11:38:03 0 dr-h----- C:\Documents and Settings\Gunter - Shawn\SendTo
2008-06-29 11:38:03 0 d--h----- C:\Documents and Settings\Gunter - Shawn\PrintHood
2008-06-29 11:38:03 2883584 --ah----- C:\Documents and Settings\Gunter - Shawn\NTUSER.DAT
2008-06-29 11:38:03 0 d--h----- C:\Documents and Settings\Gunter - Shawn\NetHood
2008-06-29 11:38:03 0 dr------- C:\Documents and Settings\Gunter - Shawn\My Documents
2008-06-29 11:38:03 0 d--h----- C:\Documents and Settings\Gunter - Shawn\Local Settings
2008-06-29 11:37:14 0 d-------- C:\Documents and Settings\Default User\WINDOWS
2008-06-29 11:37:14 0 d-------- C:\Documents and Settings\Default User\Application Data\Sun
2008-06-29 11:37:14 0 d-------- C:\Documents and Settings\Default User\Application Data\SampleView
2008-06-29 11:37:14 0 d-------- C:\Documents and Settings\Default User\Application Data\Identities
2008-06-29 11:35:47 0 d-------- C:\WINDOWS\system32\SoftwareDistribution
2008-06-29 11:24:26 0 d-------- C:\WINDOWS\RegisteredPackages
2008-06-29 11:24:15 0 d-------- C:\Program Files\CyberLink
2008-06-29 11:24:14 0 d-------- C:\Documents and Settings\All Users\Application Data\CyberLink
2008-06-29 11:24:11 20480 --a------ C:\WINDOWS\system32\Marker32.exe <Not Verified; Gateway; Marker32>
2008-06-29 11:24:09 471300 --a------ C:\WINDOWS\wallpe.exe <Not Verified; ; wallpe>
2008-06-29 11:23:59 212480 -ra------ C:\WINDOWS\system32\PCDLIB32.DLL <Not Verified; Eastman Kodak; Kodak Photo CD Access Developer Toolkit>
2008-06-29 11:23:59 37888 -ra------ C:\WINDOWS\system32\ochlp30e.dll <Not Verified; Microsoft Corporation; Microsoft Multimedia Controls>
2008-06-29 11:23:59 82432 --a------ C:\WINDOWS\system32\msxml4r.dll <Not Verified; Microsoft Corporation; Microsoft® MSXML 4.0 SP1>
2008-06-29 11:23:59 91136 -ra------ C:\WINDOWS\system32\msls2.dll <Not Verified; Microsoft Corporation; Microsoft® Line Services>
2008-06-29 11:23:59 31744 -ra------ C:\WINDOWS\system32\hlp95en.dll <Not Verified; Microsoft Corporation; Microsoft Office>
2008-06-29 11:23:18 67072 --a------ C:\WINDOWS\POWERCFG.EXE <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-06-29 11:21:56 262144 --a------ C:\Documents and Settings\All Users\NTUSER.DAT
2008-06-29 11:21:38 0 d-------- C:\Program Files\BigFix
2008-06-29 11:21:04 0 d-------- C:\WINDOWS\Drivers
2008-06-29 11:20:54 0 d-------- C:\Program Files\Intel
2008-06-29 11:20:12 0 d-------- C:\WINDOWS\system32\ReinstallBackups
2008-06-29 11:19:13 0 d-------- C:\Program Files\Digital Media Reader
2008-06-29 11:19:07 0 d-------- C:\WINDOWS\Downloaded Installations
2008-06-29 11:18:53 0 d-------- C:\Program Files\AOL Companion
2008-06-29 11:18:47 368912 --a------ C:\WINDOWS\system32\vbar332.dll <Not Verified; Microsoft Corporation; Microsoft Visual Basic for Applications>
2008-06-29 11:18:47 102400 --a------ C:\WINDOWS\system32\SimpleRegistry.dll <Not Verified; 4Developers LLC; SimpleRegistry Control>
2008-06-29 11:18:47 118784 --a------ C:\WINDOWS\system32\Msstdfmt.dll <Not Verified; Microsoft Corporation; MSSTDFMT Object Library>
2008-06-29 11:18:47 10752 --a------ C:\WINDOWS\system32\aamd532.dll <Not Verified; Almeida & Andrade Ltda; MD5 Maker DLL>
2008-06-29 11:18:45 0 d-------- C:\WINDOWS\occache
2008-06-29 11:18:44 0 d-------- C:\Program Files\Viewpoint
2008-06-29 11:18:44 0 d-------- C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-06-29 11:18:31 86016 --a------ C:\WINDOWS\unvise32qt.exe <Not Verified; MindVision; Installer VISE 2.8.3>
2008-06-29 11:18:24 0 d-------- C:\Program Files\QuickTime
2008-06-29 11:18:24 0 d-------- C:\Documents and Settings\All Users\Application Data\QuickTime
2008-06-29 11:18:20 0 d-------- C:\Program Files\Common Files\Nullsoft
2008-06-29 11:17:56 0 d-------- C:\My Music
2008-06-29 11:17:52 0 d-------- C:\Program Files\Common Files\Real
2008-06-29 11:17:32 153088 --a------ C:\WINDOWS\system32\jgdwmie.dll <Not Verified; America Online; JG Decoder>
2008-06-29 11:17:30 1044480 --a------ C:\WINDOWS\system32\roboex32.dll <Not Verified; eHelp Corporation.; RoboHELP for WinHelp 9>
2008-06-29 11:17:30 54784 --a------ C:\WINDOWS\system32\Inetwh32.dll <Not Verified; Blue Sky Software Corporation.; Blue Sky Software - INETWH32>
2008-06-29 11:17:11 225280 --a------ C:\WINDOWS\system32\AOLDial.dll <Not Verified; America Online, Inc; AOL Connectivity Service>
2008-06-29 11:17:09 0 d-------- C:\Program Files\Common Files\aolshare
2008-06-29 11:17:07 0 d-------- C:\Program Files\AOL 9.0
2008-06-29 11:17:07 0 d-------- C:\Documents and Settings\All Users\Application Data\AOL
2008-06-29 11:16:58 0 d-------- C:\Program Files\Common Files\AOL
2008-06-29 11:16:57 335 --a------ C:\WINDOWS\nsreg.dat
2008-06-29 11:16:56 532544 --a------ C:\WINDOWS\PIC.dll
2008-06-29 11:16:56 3927 --a------ C:\WINDOWS\mHotkey.reg
2008-06-29 11:16:56 24576 --a------ C:\WINDOWS\HKNTDLL.dll
2008-06-29 11:16:55 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-06-29 11:16:55 0 d-------- C:\Program Files\Common Files\InstallShield
2008-06-29 11:16:55 0 d-------- C:\Documents and Settings\All Users\Application Data\Prism Deploy
2008-06-29 11:16:54 0 d-------- C:\Program Files\Common Files\New Boundary
2008-06-29 11:16:51 0 d-------- C:\Program Files\Google


-- Find3M Report ---------------------------------------------------------------

2008-07-13 23:45:54 0 d-------- C:\Program Files\Common Files
2008-07-09 07:51:35 0 d-------- C:\Program Files\Messenger
2008-07-09 07:50:54 0 d-------- C:\Program Files\Movie Maker
2008-07-09 07:45:52 0 d-------- C:\Program Files\Windows NT
2008-07-01 16:40:50 0 d-------- C:\Program Files\microsoft frontpage
2008-06-29 12:28:03 0 d-------- C:\Program Files\Java


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OneCareUI"="C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe" [25/06/2008 06:48]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [19/02/2006 02:41]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [14/04/2008 01:12]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [28/01/2008 11:43]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [28/05/2008 10:33]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [26/02/2008 02:23]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [19/02/2006 04:21:22]
HP Photosmart Premier Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [10/02/2006 07:56:20]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=0 (0x0)
"HideStartupScripts"=0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=0 (0x0)
"HideStartupScripts"=0 (0x0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [13/05/2008 10:13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 19/04/2007 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
C:\WINDOWS\System32\dimsntfy.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\OneCareMP]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
eapsvcs eaphost
dot3svc dot3svc

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
napagent
hkmsvc


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d714aa36-45c5-11dd-883b-806d6172696f}]
AutoRun\command- E:\setup.exe




-- End of Deckard's System Scanner: finished at 2008-07-14 17:50:16 ------------
  • 0

#4
fenzodahl512

fenzodahl512

  • Malware Removal
  • 9,863 posts
Hello, thanks for the reply...


Please uninstall Viewpoint Media Player from your computer..



Please go to Start >> Run and type or copy/paste the following in the run box: "%userprofile%\desktop\dss.exe" /daft . Then press Enter
  • Click on the Scan button.
  • Select everything it is displaying there
  • Click the Fix button.
  • Then rescan with DAFT again - it should say now that "All associations are OK"
  • Close DAFT if you receive that message. This means that it is fixed now.




NEXT


Please show hidden files and folders. Please visit HERE if you don't know how.

Jotti File Submission:
  • Please go to Jotti's malware scan
  • Copy and paste the following file path into the "File to upload & scan"box on the top of the page:

    • C:\WINDOWS\HKNTDLL.dll
  • Click on the submit button
  • Please post the results in your next reply.
If Jotti server is too busy, please submit the file to VirusTotal instead.




NEXT


Please do an online scan with Kaspersky WebScanner

Click on Accept

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.



Please post the following logs in your next reply...

1. Jotti/VirusTotal
2. Kaspersky Webscanner


Regards
fenzodahl512
  • 0

#5
gvskw

gvskw

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
Hi here is the first log

KASPERSKY ONLINE SCANNER REPORT
Tuesday, July 15, 2008 6:58:21 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 3 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 14/07/2008
Kaspersky Anti-Virus database records: 953481


Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true

Scan Target My Computer
C:\
D:\
E:\
F:\
G:\
H:\
I:\

Scan Statistics
Total number of scanned objects 137203
Number of viruses found 0
Number of infected objects 0
Number of suspicious objects 0
Duration of the scan process 03:40:57

Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\OneCare Protection\Support\MPLog-07122008-200659.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Protection Service\edb.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Protection Service\edbtmp.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Protection Service\MPSSVCPolicyIdLog.etl Object is locked skipped

C:\Documents and Settings\Gunter - Shawn\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\AppLogs\SUPERANTISPYWARE-7-13-2008( 22-21-0 ).LOG Object is locked skipped

C:\Documents and Settings\Gunter - Shawn\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\Gunter - Shawn\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\Gunter - Shawn\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\Gunter - Shawn\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Gunter - Shawn\Local Settings\Temp\hpodvd09.log Object is locked skipped

C:\Documents and Settings\Gunter - Shawn\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped

C:\Documents and Settings\Gunter - Shawn\Local Settings\Temporary Internet Files\Content.IE5\6XCKR4UT\bind[1].htm Object is locked skipped

C:\Documents and Settings\Gunter - Shawn\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Gunter - Shawn\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\Gunter - Shawn\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\cc_20080615_0853.reg Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\cc_20080621_0613.reg Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Council tax 1.doc Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Council tax 1.rtf Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\desktop.ini Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\DivX Movies\DivX Author – Create DivX Movies.lnk Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\DivX Movies\DivX.com.lnk Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\DivX Movies\Enhance your video soundtracks.lnk Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\DivX Movies\Temporary Downloaded Files\divxlogo_splash_v2.divx.part Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Hannah Grace\DSC01437.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Hannah Grace\DSC01438.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Hannah Grace\DSC01440.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Hannah Grace\DSC01441.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Hannah Grace\DSC01442.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Hannah Grace\DSC02127.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Hannah Grace\DSC02130.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Hannah Grace\DSC02131.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Hannah Grace\DSC02132.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Hannah Grace\DSC02134.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Hannah Grace\DSC02179.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Hannah Grace\DSC02181.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Hannah Grace\DSC02182.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Hannah Grace\DSC02220.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Hannah Grace\DSC02221.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Hannah Grace\DSC02223.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Hannah Grace\DSC02224.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Hannah Grace\DSC02244.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Hannah Grace\Picasa.ini Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude\IMG_3744.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude\IMG_3745.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude\IMG_3746.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude\IMG_3754.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude\IMG_3782.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude\IMG_3783.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude\IMG_3786.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude\IMG_3787.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude\IMG_3792.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude\IMG_3793.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude\IMG_3794.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude\IMG_3795.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude\IMG_3797.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude\IMG_3798.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude\IMG_3799.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude\IMG_3800.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude\IMG_3801.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude\June 2008 001.jpg Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude\June 2008 002.jpg Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude\June 2008 003.jpg Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude\June 2008 004.jpg Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude\June 2008 005.jpg Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude\June 2008 014.jpg Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude\Picasa.ini Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude being born\IMG_3648.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude being born\IMG_3660.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude being born\IMG_3661.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude being born\IMG_3668.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude being born\IMG_3669.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude being born\IMG_3670.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude being born\IMG_3671.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude being born\IMG_3672.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude being born\IMG_3673.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude being born\IMG_3674.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude being born\IMG_3675.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude being born\IMG_3676.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude being born\IMG_3687.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude being born\IMG_3689.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude being born\IMG_3690.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude being born\IMG_3694.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude being born\IMG_3695.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude being born\IMG_3696.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude being born\IMG_3697.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude being born\IMG_3698.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude being born\IMG_3699.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude being born\IMG_3701.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude being born\IMG_3716.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude being born\IMG_3717.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude being born\IMG_3718.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude being born\IMG_3720.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude being born\IMG_3721.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude being born\IMG_3722.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude being born\IMG_3723.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Jude being born\Picasa.ini Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Liam\Picasa.ini Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Liam 1\may 18 2008 011.jpg Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Liam 1\may 18 2008 047.jpg Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Liam 1\may 18 2008 056.jpg Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Liam 1\may 26 2008 012.jpg Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Liam 1\may 26 2008 024.jpg Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Liam 1\may 26 2008 040.jpg Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Liam 1\Picasa.ini Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Liam again\Picasa.ini Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\London 230507\DSC04999.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\London 230507\DSC05000.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\London 230507\DSC05003.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\London 230507\DSC05005.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\London 230507\DSC05006.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\London 230507\DSC05007.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\London 230507\DSC05008.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\London 230507\DSC05009.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\London 230507\DSC05010.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\London 230507\DSC05011.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\London 230507\DSC05012.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\London 230507\DSC05013.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\London 230507\DSC05015.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\London 230507\DSC05016.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\London 230507\DSC05017.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\London 230507\DSC05018.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\London 230507\DSC05019.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\London 230507\DSC05020.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\London 230507\DSC05023.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\London 230507\DSC05024.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\London 230507\DSC05025.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\London 230507\DSC05026.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\London 230507\DSC05027.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\London 230507\DSC05028.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\London 230507\DSC05029.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\London 230507\DSC05030.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\London 230507\DSC05031.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\London 230507\DSC05032.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\London 230507\DSC05035.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\London 230507\DSC05037.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\London 230507\DSC05038.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\London 230507\DSC05039.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\London 230507\DSC05040.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\London 230507\DSC05041.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\London 230507\DSC05042.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\London 230507\DSC05043.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\London 230507\DSC05044.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\London 230507\DSC05045.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\London 230507\Picasa.ini Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\My Music\Desktop.ini Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\My Pictures\Desktop.ini Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\My Scans\Picasa.ini Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\My Shapes\desktop.ini Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\My Shapes\Favorites.vss Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\My Shapes\_private\folder.ico Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\My Sharing Folders.lnk Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\My Videos\Desktop.ini Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\New Settings File.OPS Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Picasa Edits\picasabackground.bmp Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\radway\Picasa.ini Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\radway 1\Originals\Picasa.ini Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\radway 1\Picasa.ini Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Radway 2\DSC04599.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Radway 2\DSC04601.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Radway 2\DSC04605.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Radway 2\DSC04606.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Radway 2\DSC04607.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Radway 2\DSC04608.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Radway 2\DSC04609.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Radway 2\DSC04610.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Radway 2\DSC04612.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Radway 2\DSC04614.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Radway 2\DSC04615.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Radway 2\DSC04616.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Radway 2\DSC04617.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Radway 2\DSC04618.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Radway 2\DSC04619.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Radway 2\DSC04620.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Radway 2\DSC04621.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Radway 2\DSC04622.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Radway 2\DSC04623.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Radway 2\DSC04624.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Radway 2\DSC04625.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Radway 2\DSC04626.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Radway 2\DSC04628.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Radway 2\DSC04630.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Radway 2\DSC04631.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Radway 2\DSC04634.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Radway 2\DSC04635.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Radway 2\DSC04636.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Radway 2\DSC04637.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Radway 2\DSC04638.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Radway 2\DSC04639.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Radway 2\DSC04640.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Radway 2\DSC04641.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Radway 2\DSC04642.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Radway 2\DSC04643.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Radway 2\DSC04644.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Radway 2\DSC04645.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Radway 2\DSC04649.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Radway 2\DSC04654.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Radway 2\DSC04655.JPG Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\Radway 2\Picasa.ini Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\SharePoint Drafts\desktop.ini Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\SharePoint Drafts\_private\folder.ico Object is locked skipped

C:\My Backup -- 29-06-08 1050\Documents and Settings\Tilden\My Documents\~WRL2262.tmp Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc11\Picasa.ini Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc12\Picasa.ini Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc13\Picasa.ini Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc14\Picasa.ini Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc15\Picasa.ini Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc16\Picasa.ini Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc17\Picasa.ini Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc18\Picasa.ini Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc19\Picasa.ini Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc20\Picasa.ini Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc21\Picasa.ini Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc22\Picasa.ini Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc23\Picasa.ini Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc24\Picasa.ini Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc25\Picasa.ini Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc26\Picasa.ini Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc27\Picasa.ini Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc28\Picasa.ini Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc29\Picasa.ini Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\admparse.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\admparse.dll.mui Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\advpack.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\advpack.dll.mui Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\browseui.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\corpol.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\custsat.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\dxtmsft.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\dxtrans.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\extmgr.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\extmgr.dll.mui Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\feeddisc.wav Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\hmmapi.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\hmmapi.dll.mui Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\html.iec Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\html.iec.mui Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\icardie.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\icardie.dll.mui Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\icrav03.rat Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\ie4uinit.exe Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\ie4uinit.exe.mui Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\ieakeng.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\ieakeng.dll.mui Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\ieakmmc.chm Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\ieaksie.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\ieaksie.dll.mui Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\ieakui.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\ieakui.dll.mui Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\ieapfltr.dat Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\ieapfltr.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\iedkcs32.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\iedkcs32.dll.mui Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\iedw.exe Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\iedw.exe.mui Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\ieencode.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\ieeula.chm Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\ieframe.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\ieframe.dll.mui Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\iepeers.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\iepeers.dll.mui Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\ieproxy.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\iernonce.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\iernonce.dll.mui Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\iertutil.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\iesetup.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\iesetup.dll.mui Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\iesupp.chm Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\ieudinit.exe Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\ieui.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\ieui.dll.mui Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\ieuinit.inf Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\ieunatt.exe.mui Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\iexplore.chm Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\iexplore.exe Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\iexplore.exe.mui Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\imgutil.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\inetcorp.iem Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\inetcpl.cpl Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\inetcpl.cpl.mui Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\inetres.adm Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\inetset.iem Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\infobar.wav Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\inseng.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\inseng.dll.mui Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\install.ins Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\jscript.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\jsproxy.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\licmgr10.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\licmgr10.dll.mui Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\msfeeds.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\msfeeds.mof Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\msfeedsbs.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\msfeedsbs.dll.mui Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\msfeedsbs.mof Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\msfeedssync.exe Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\mshta.exe Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\mshta.exe.mui Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\mshtml.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\mshtml.dll.mui Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\mshtml.tlb Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\mshtmled.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\mshtmled.dll.mui Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\mshtmler.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\mshtmler.dll.mui Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\msls31.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\msrating.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\msrating.dll.mui Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\mstime.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\navstart.wav Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\occache.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\occache.dll.mui Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\occache.ini Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\pngfilt.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\popupblk.wav Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\shdocvw.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\shlwapi.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\spmsg.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\spuninst.exe Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\spupdsvc.exe Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\tdc.ocx Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\ticrf.rat Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\update\eula.rtf Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\update\idndl.exe Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\update\ie7.cat Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\update\iecustom.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\update\iereseticons.exe Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\update\iesetup.exe Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\update\legitlibm.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\update\nlsdl.exe Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\update\update.exe Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\update\update.exe.manifest Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\update\update.inf Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\update\update.ver Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\update\updspapi.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\update\xmllitesetup.exe Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\url.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\urlmon.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\urlmon.dll.mui Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\vbscript.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\vgx.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\webcheck.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\webcheck.dll.mui Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\webcheck.ini Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\winfxdocobj.exe Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\winfxdocobj.exe.mui Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\wininet.dll Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc3\wininet.dll.mui Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc30\Picasa.ini Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc31\Picasa.ini Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc32\Picasa.ini Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc33\image0-1.jpg Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc33\image0-10.jpg Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc33\image0-11.jpg Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc33\image0-12.jpg Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc33\image0-13.jpg Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc33\image0-14.jpg Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc33\image0-15.jpg Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc33\image0-16.jpg Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc33\image0-17.jpg Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc33\image0-18.jpg Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc33\image0-19.jpg Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc33\image0-2.jpg Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc33\image0-20.jpg Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc33\image0-21.jpg Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc33\image0-3.jpg Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-21-3708963277-3854607386-4258065404-1008\Dc33\image0-4.jpg Object is locked skipped

C:\My Backup -- 29-06-08 1050\RECYCLER\S-1-5-
  • 0

#6
gvskw

gvskw

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
And the online malware scan is here, thanks for your help

Jotti's malware scan 2.99-TRANSITION_TO_3.00-R1

File to upload & scan:
Service
Service load: 0% 100%

File: HKNTDLL.dll
Status: OK
MD5: 9d711d318be62ac3245afd4a7d555fbf
Packers detected: -

Scanner results
Scan taken on 14 Jul 2008 21:36:28 (GMT)
A-Squared Found nothing
AntiVir Found nothing
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
CPsecure Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
F-Secure Anti-Virus Found nothing
Fortinet Found nothing
Ikarus Found nothing
Kaspersky Anti-Virus Found nothing
NOD32 Found nothing
Norman Virus Control Found nothing
Panda Antivirus Found nothing
Sophos Antivirus Found nothing
VirusBuster Found nothing
VBA32 Found nothing
  • 0

#7
fenzodahl512

fenzodahl512

  • Malware Removal
  • 9,863 posts
Ermm... Your log looks clean to my eyes.. Do you have anymore computer problem?


Regards
fenzodahl512
  • 0

#8
gvskw

gvskw

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
Hi Fenzodahl52,

The problem seems to be gone.

Thanks so much for your help.

Best regards

GVSKW
  • 0

#9
fenzodahl512

fenzodahl512

  • Malware Removal
  • 9,863 posts
Please Install/Update Sun Java

Updating Java:
  • Go to Start --> Control Panel --> Add or Remove Programs.
  • Search in the list for all previous installed versions of Java. (J2SE Runtime Environment.... )
  • It should have next icon next to it: Posted Image
  • Select it and click Remove. This will uninstall the previous (outdated) version of Java.
  • Then Download and install the newest version from here: Java Runtime Environment (JRE) 6 Update 7




NEXT


Let's clean your Restore Points and set a new one:

Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs from changing those files. This is the only way to clean these files: (You will lose all previous Restore Points which are likely to be infected)
To create a new Restore Point.
  • On the Desktop, right-click My Computer.
  • Click Properties.
  • Click the System Restore tab.
  • Check Turn off System Restore.
  • Click Apply, and then click OK. This will flush your old System Restore.
  • Then please UNCHECK the Turn off System Restore.
  • Click again on Apply, and then click OK. This will create a new Restore Point
System Restore will now be active again

If you are using Windows Vista, please go HERE for tutorial on how to use, disable and enable System Restore




NEXT


I haven't seen any antivirus in your logs.. Antivirus is extremely crucial as without it you will get re-infected again! Do you have any? If you don't, please install ONLY ONE of these free and excellent antivirus below:



Lastly, to keep your operating system up to date please visit the link below monthly

To learn more about how to protect yourself while on the internet read this excellent article by Tony Klein: So how did I get infected in the first place?

Please also read an excellent article by miekiemoes :Help! My computer is slow!

And another excellent article by CastleCops Malware Prevention: Prevent Re-infection

Please reply to this thread once more and tell us about the computer behaviour before we can close this thread :)



Have a safe and happy computing day!


Regards
fenzodahl512

Edited by fenzodahl512, 15 July 2008 - 02:29 PM.

  • 0

#10
gvskw

gvskw

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
Hi Fenzodahl512,

I have installed avast and performed the checkpoint operation.
The articles you provided are very usefull.
The problems seems to be gone.
Thank you so much for your assistance
  • 0

#11
fenzodahl512

fenzodahl512

  • Malware Removal
  • 9,863 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP