Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Virus Alert!, Antivirus 2008, etc..I tried everything.. [CLOSED]


  • This topic is locked This topic is locked

#1
Keile

Keile

    New Member

  • Member
  • Pip
  • 7 posts
I've tried everything in a bid to rid myself of the Virus Alert! threat. I've used Malwarebytes Anti-Malware, I've used SuperSpyware and I've used AVG. They've seemingly gotten rid of the visual and hijacking aspect of the threat (as far as I know, beyond my desktop recovery not working, everything else is back and the Virus Alert! is no longer present in the toolbar). But on the other hand, my computer is freezing every time I try to login normally and its going much slower than before. I did a system recovery and it did nothing, then I again tried to remove everything, but the slowness and the freezing has persisted.

This is my hijack log as of now:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:16:01 AM, on 8/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Logitech\Video\AlbumDB2.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\SYSTEM32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.ca/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com...de_srchlft.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.ca/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.dell.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Windows Live OneCare Family Safety Browser Helper Class - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fssui.exe" -autorun
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [HiYo] C:\Program Files\HiYo\bin\HiYo.exe /RunFromStartup
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll (file missing)
O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zon...kr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zon...kr.cab56986.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zon...er.cab31267.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplane...DC_2.1.2.76.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcaf...96/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://taysholey.spa...ad/MsnPUpld.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {A2E05F45-F127-4092-B9F7-9A02C3E04C77} - http://gamedownload....GPlugin7USA.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zon...ro.cab47946.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcaf...,26/mcgdmgr.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zon...nt.cab56907.cab
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} - http://gamedownload....GPlugin9USA.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://www.carbonspa...n/msnchat45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{910978FA-D75C-4487-93E2-7775B90FE0B0}: NameServer = 192.168.0.1,192.168.0.2
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: geBrrRjJ - geBrrRjJ.dll (file missing)
O20 - Winlogon Notify: mljgffg - mljgffg.dll (file missing)
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Unknown owner - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe (file missing)
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Unknown owner - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: avp - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

--
End of file - 11491 bytes
  • 0

Advertisements


#2
fenzodahl512

fenzodahl512

  • Malware Removal
  • 9,863 posts
Hello, my name is fenzodahl512 and welcome to Geekstogo..

I noticed you already have three antiviruses (Antivir, AVG8, Kaspersky) in your computer.. This is not good.. It will only make your computer more vulnerable to infections.. Please uninstall two of your antivirus and leave only one behind.. Its up to you to remove which two and leave one of them..


After you accomplished that, please do below..


Please visit below webpage for instructions for downloading and running ComboFix

http://www.bleepingc...to-use-combofix

This includes installing the Windows XP Recovery Console in case you have not installed it yet.

For more information on the Windows XP Recovery Console read http://support.microsoft.com/kb/314058.

Once you install the Recovery Console, when you reboot your computer, you'll see the option for the Recovery Console now as well. DO NOT select Recovery Console as we don't need it. By default, your main OS is selected there. The screen stays for 2 seconds and then it proceeds to load Windows. That is normal.

Post the log from ComboFix (located in C:\combofix.txt) when you've accomplished that, along with a new HijackThis log.



Regards
fenzodahl512
  • 0

#3
Keile

Keile

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
New HijackThis log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:59:42 AM, on 8/15/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SYSTEM32\NOTEPAD.EXE
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.ca/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.ca/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.ca/myway
F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\userinit.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Windows Live OneCare Family Safety Browser Helper Class - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - (no file)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fssui.exe" -autorun
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [HiYo] C:\Program Files\HiYo\bin\HiYo.exe /RunFromStartup
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll (file missing)
O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zon...kr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zon...kr.cab56986.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zon...er.cab31267.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplane...DC_2.1.2.76.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcaf...96/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://taysholey.spa...ad/MsnPUpld.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {A2E05F45-F127-4092-B9F7-9A02C3E04C77} - http://gamedownload....GPlugin7USA.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zon...ro.cab47946.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcaf...,26/mcgdmgr.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zon...nt.cab56907.cab
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} - http://gamedownload....GPlugin9USA.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://www.carbonspa...n/msnchat45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{910978FA-D75C-4487-93E2-7775B90FE0B0}: NameServer = 192.168.0.1,192.168.0.2
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Unknown owner - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe (file missing)
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Unknown owner - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: avp - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

--
End of file - 10583 bytes

----

ComboFix Log - A few days old

ComboFix 08-08-13.02 - Administrator 2008-08-14 1:48:18.1 - NTFSx86 NETWORK
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Tyrelle\Application Data\macromedia\Flash Player\#SharedObjects\JDBX6WLM\interclick.com
C:\Documents and Settings\Tyrelle\Application Data\macromedia\Flash Player\#SharedObjects\JDBX6WLM\interclick.com\ud.sol
C:\Documents and Settings\Tyrelle\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\Tyrelle\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Documents and Settings\Tyrelle\Application Data\WeatherDPA
C:\Documents and Settings\Tyrelle\Application Data\WeatherDPA\Weather\WeatherStartup.xml
C:\Documents and Settings\Tyrelle\Application Data\Zango
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\030104_emte10_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\030104_emte11_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\030104_emte12_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\030104_emte13_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\030104_emte14_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\030104_emte19_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\030104_emte20_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\030104_emte21_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\030104_emte9_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\030203lib_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\033102angel_1_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\033102bigluf_1_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\033102bigsmile_1_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\033102birthday_1_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\033102cheers_1_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\033102flo_1_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\033102good_1_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\033102jump_1_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\033102king_1_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\033102lough_1_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\033102luf_1_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\033102smile_1_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\033102smiled_1_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\033102sor_1_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\033102thanx_1_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\033102uhu_1_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\040103ahh_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\040103wow_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\040104_emi2_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\042102_1134_112_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\050103big_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\050103gig_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\050103hm_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\050103nomail_emoti_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\050103norm_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\060104_ema15_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\060104_ema16_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\060104_ema17_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\060104_ema18_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\060104_ema19_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\060104_ema20_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\060104_ema21_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\060104_ema24_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\060104_ema25_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\060104_ema26_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\060104_ema30_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\060104_ema33_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\060104_ema34_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\062802hippi_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\062802jumpie_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\080402argh_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\080402oops_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\080402ouch_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\082502no_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\082502yes_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\110103_boring1_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\110103_confused_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\110103_crying_ugly_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\110103_fantastic_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\110103_feel_better_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\110103_gimme_break_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\110103_heehee_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\110103_hlopaet_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\110103_ign_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\110103_lol_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\110103_no_comment_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\110103_peace_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\110103_smashing_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\110103_talk2thehand_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\avatar.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\block_sm.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\block_sm2.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\block_smli.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\block_smli2.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\blocked.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\blocked2.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\btn_add-but.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\btn_back-but.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\btn_left_cut_enabled_1.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\btn_left_enabled_1.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\btn_left_pressed_1.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\btn_middle_enabled_1.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\btn_middle_pressed_1.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\btn_right_cut_enabled_1.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\btn_right_enabled_1.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\btn_right_pressed_1.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\business_promo.htm
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\buttondir.txt
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\components.cdf
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\css_cattree.css
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\css_flashpreview.css
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\css2_main.css
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\css2_pagingmodule.css
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\css2_topbuttons.css
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\cursors.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\delete.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\edit_clear_sound.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\edit_fs.htm
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\edit_select.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-511724-543450.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-511724-548964.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-511724-589306.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-511724-591943.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-511724-592579.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-511724-598579.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-511724-603763.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-511724-9595.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-511724-9696.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-511745-514279.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-backgrounds.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-bcards.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-ecards.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-emoticons.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-estationery.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-funny.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-help.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-images.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-info.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-more.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-my.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-new.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-new2.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-options.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-people.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-photo.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-tell.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-temp.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-text.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-voice.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def.cdf
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-premium-email-premium.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-t1-bg.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-temp-bg.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\estatationery.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\flashpatch.js
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\flashpreview.htm
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\fs3.htm
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\hotbar_promo.htm
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\icon_checked_1.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\icon_close_1.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\icon_close_pressed_1.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\icon_edit_preview.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\icon_edit_send.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\icon_flash_preview.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\icon_recently_used.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\icon_remove_1.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\icon_remove_pressed_1.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\icon_sand-clock2.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\icon_tell_1.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\icon_tell_pressed_1.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\icon_tree_null.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\icon_unchecked_1.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\icon_unchecked_pressed_1.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\img_barlayout.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\img_barlayout2.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\img_barlayout4.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\img_corner_left.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\img_local_logo.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\js2_basetemplate.js
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\js2_hbgroups.js
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\js2_hbobject3.js
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\js2_hbobjectset3.js
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\js2_hotbarwrapper.js
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\js2_iteratorsandreaders3nf.js
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\js2_pagingmoduleobj3.js
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\js2_texts3.js
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\js2_xmltree3nf.js
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\layout.cdf
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\linkpathlegal.txt
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\n.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\nav_b_2.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\nav_bb_2.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\nav_f_2.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\nav_ff_2.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\progress.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\sales_buttons.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\searchbtn.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\submit.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\tab_bg.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\tab_bga.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\tab_bgia.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\tab_l.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\tab_la.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\tab_lia.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\tab_r.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\tab_ra.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\tab_ria.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\tree_dots.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\tree_minus.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\tree_plus.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\treedata_animations.xml
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\treedata_backgrounds.xml
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\treedata_ecards.xml
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\treedata_emoticons.xml
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\treedata_notifiers.xml
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\treedata_text.xml
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\zango_btn.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\DownLoad\avatar.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\DownLoad\business_promo.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\DownLoad\buttondir.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\DownLoad\code.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\DownLoad\cursors.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\DownLoad\email-def.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\DownLoad\email-t1-bg.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\DownLoad\email-temp-bg.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\DownLoad\hotbar_promo.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\DownLoad\images.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\DownLoad\layout.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\DownLoad\linkpathlegal.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\DownLoad\localcontent.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\DownLoad\progress.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\DownLoad\sales_buttons.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\DownLoad\treexml.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\DownLoad\zango_btn.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\dynamic\1385288.sdf
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\dynamic\819382.sdf
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\dynamic\domains.txt
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\17025
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\427148
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\432053
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\44228
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\455563
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\455743
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\56412
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\68055
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\744207
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\747635
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\93110
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\95917
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\dynamic\ustat\370f.dat
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\avatar.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\btntrans.idx
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\btntrans1.dat
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\buttondir.txt
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\components.cdf
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\cursors.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\d_icons_buttons_1000.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\d_icons_buttons_2000.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\d_icons_buttons_3000.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\d_icons_buttons_bar.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\d_icons_buttons_bbar1.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\d_icons_buttons_logos.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\d_icons_buttons_other.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\d_icons_weather.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\default.cdf
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_511745-514279.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_bidzC_ZT_IE-ca.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_bidzC_ZT_IE-us.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_categorize.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_comparison.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_explorer-Mails.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_explorer-people.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_favorites.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_Games.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_Hide.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_hotbarcom.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_Hotmail.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_hsskin.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_jemster.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_jemsterie.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_jemsteruk.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_jobsearch.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_Mails.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_MobileSidewalk.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_new.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_premium.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_reun.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_ringtones.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_SearchBoxTrapper.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_searchfor.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_searchgo.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_weather.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_yellowpages.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\editblbuttons.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\email-def-511724-548964.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\email-def-511724-9595.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\email-t1-bg.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\icons2.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\ie_games_icon.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\ie_video.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\keywords.idx
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\keywords1.dat
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\layout.cdf
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\linkpathlegal.txt
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\progress.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\s_icons_buttons.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\sales_buttons.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\sdfmodifier.xml
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\t2_bg.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\theweb.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\top7.cdf
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Top7_theweb.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\tsd_bg.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\zango_btn.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\zango_ie_menu.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\avatar.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\BtnTrans.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\BtnTrans1.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\buttondir.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\cursors.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_1000.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_2000.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_3000.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_bar.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_bbar1.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_logos.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_other.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_weather.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\default.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\editblbuttons.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\email-t1-bg.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\icons2.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\ie_games_icon.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\ie_video.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\keywords.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\keywords1.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\layout.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\linkpathlegal.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\progress.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\s_icons_buttons.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\sales_buttons.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\sdfmodifier.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\t2_bg.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\top7.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\tsd_bg.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\zango_btn.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\zango_ie_menu.xip

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_TDSSSERV


((((((((((((((((((((((((( Files Created from 2008-07-14 to 2008-08-14 )))))))))))))))))))))))))))))))
.

2008-08-14 01:43 . 2008-08-14 01:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PC Tools
2008-08-14 01:43 . 2008-08-14 01:41 160,792 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\pctfw2.sys
2008-08-14 01:40 . 2008-08-14 01:40 <DIR> d-------- C:\Program

Edited by Keile, 15 August 2008 - 07:00 AM.

  • 0

#4
fenzodahl512

fenzodahl512

  • Malware Removal
  • 9,863 posts
Hello, your ComboFix log has been cut-off.. Please find its log at C:\combofix.txt and attach it here :)

Thank you..
  • 0

#5
Keile

Keile

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
[size=1]ComboFix 08-08-13.02 - Administrator 2008-08-14 1:48:18.1 - NTFSx86 NETWORK
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Tyrelle\Application Data\macromedia\Flash Player\#SharedObjects\JDBX6WLM\interclick.com
C:\Documents and Settings\Tyrelle\Application Data\macromedia\Flash Player\#SharedObjects\JDBX6WLM\interclick.com\ud.sol
C:\Documents and Settings\Tyrelle\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\Tyrelle\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Documents and Settings\Tyrelle\Application Data\WeatherDPA
C:\Documents and Settings\Tyrelle\Application Data\WeatherDPA\Weather\WeatherStartup.xml
C:\Documents and Settings\Tyrelle\Application Data\Zango
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\030104_emte10_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\030104_emte11_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\030104_emte12_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\030104_emte13_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\030104_emte14_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\030104_emte19_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\030104_emte20_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\030104_emte21_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\030104_emte9_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\030203lib_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\033102angel_1_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\033102bigluf_1_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\033102bigsmile_1_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\033102birthday_1_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\033102cheers_1_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\033102flo_1_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\033102good_1_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\033102jump_1_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\033102king_1_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\033102lough_1_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\033102luf_1_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\033102smile_1_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\033102smiled_1_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\033102sor_1_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\033102thanx_1_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\033102uhu_1_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\040103ahh_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\040103wow_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\040104_emi2_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\042102_1134_112_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\050103big_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\050103gig_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\050103hm_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\050103nomail_emoti_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\050103norm_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\060104_ema15_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\060104_ema16_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\060104_ema17_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\060104_ema18_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\060104_ema19_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\060104_ema20_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\060104_ema21_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\060104_ema24_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\060104_ema25_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\060104_ema26_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\060104_ema30_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\060104_ema33_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\060104_ema34_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\062802hippi_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\062802jumpie_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\080402argh_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\080402oops_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\080402ouch_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\082502no_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\082502yes_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\110103_boring1_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\110103_confused_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\110103_crying_ugly_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\110103_fantastic_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\110103_feel_better_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\110103_gimme_break_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\110103_heehee_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\110103_hlopaet_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\110103_ign_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\110103_lol_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\110103_no_comment_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\110103_peace_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\110103_smashing_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\110103_talk2thehand_prv.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\avatar.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\block_sm.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\block_sm2.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\block_smli.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\block_smli2.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\blocked.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\blocked2.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\btn_add-but.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\btn_back-but.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\btn_left_cut_enabled_1.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\btn_left_enabled_1.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\btn_left_pressed_1.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\btn_middle_enabled_1.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\btn_middle_pressed_1.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\btn_right_cut_enabled_1.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\btn_right_enabled_1.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\btn_right_pressed_1.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\business_promo.htm
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\buttondir.txt
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\components.cdf
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\css_cattree.css
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\css_flashpreview.css
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\css2_main.css
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\css2_pagingmodule.css
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\css2_topbuttons.css
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\cursors.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\delete.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\edit_clear_sound.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\edit_fs.htm
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\edit_select.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-511724-543450.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-511724-548964.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-511724-589306.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-511724-591943.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-511724-592579.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-511724-598579.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-511724-603763.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-511724-9595.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-511724-9696.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-511745-514279.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-backgrounds.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-bcards.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-ecards.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-emoticons.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-estationery.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-funny.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-help.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-images.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-info.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-more.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-my.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-new.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-new2.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-options.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-people.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-photo.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-tell.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-temp.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-text.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def-email-voice.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-def.cdf
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-premium-email-premium.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-t1-bg.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\email-temp-bg.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\estatationery.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\flashpatch.js
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\flashpreview.htm
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\fs3.htm
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\hotbar_promo.htm
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\icon_checked_1.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\icon_close_1.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\icon_close_pressed_1.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\icon_edit_preview.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\icon_edit_send.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\icon_flash_preview.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\icon_recently_used.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\icon_remove_1.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\icon_remove_pressed_1.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\icon_sand-clock2.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\icon_tell_1.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\icon_tell_pressed_1.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\icon_tree_null.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\icon_unchecked_1.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\icon_unchecked_pressed_1.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\img_barlayout.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\img_barlayout2.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\img_barlayout4.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\img_corner_left.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\img_local_logo.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\js2_basetemplate.js
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\js2_hbgroups.js
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\js2_hbobject3.js
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\js2_hbobjectset3.js
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\js2_hotbarwrapper.js
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\js2_iteratorsandreaders3nf.js
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\js2_pagingmoduleobj3.js
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\js2_texts3.js
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\js2_xmltree3nf.js
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\layout.cdf
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\linkpathlegal.txt
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\n.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\nav_b_2.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\nav_bb_2.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\nav_f_2.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\nav_ff_2.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\progress.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\sales_buttons.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\searchbtn.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\submit.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\tab_bg.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\tab_bga.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\tab_bgia.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\tab_l.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\tab_la.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\tab_lia.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\tab_r.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\tab_ra.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\tab_ria.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\tree_dots.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\tree_minus.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\tree_plus.gif
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\treedata_animations.xml
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\treedata_backgrounds.xml
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\treedata_ecards.xml
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\treedata_emoticons.xml
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\treedata_notifiers.xml
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\treedata_text.xml
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\1\zango_btn.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\DownLoad\avatar.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\DownLoad\business_promo.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\DownLoad\buttondir.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\DownLoad\code.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\DownLoad\cursors.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\DownLoad\email-def.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\DownLoad\email-t1-bg.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\DownLoad\email-temp-bg.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\DownLoad\hotbar_promo.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\DownLoad\images.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\DownLoad\layout.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\DownLoad\linkpathlegal.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\DownLoad\localcontent.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\DownLoad\progress.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\DownLoad\sales_buttons.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\DownLoad\treexml.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\HostWD\static\DownLoad\zango_btn.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\dynamic\1385288.sdf
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\dynamic\819382.sdf
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\dynamic\domains.txt
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\17025
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\427148
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\432053
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\44228
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\455563
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\455743
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\56412
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\68055
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\744207
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\747635
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\93110
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\dynamic\TooltipXML\95917
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\dynamic\ustat\370f.dat
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\avatar.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\btntrans.idx
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\btntrans1.dat
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\buttondir.txt
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\components.cdf
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\cursors.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\d_icons_buttons_1000.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\d_icons_buttons_2000.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\d_icons_buttons_3000.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\d_icons_buttons_bar.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\d_icons_buttons_bbar1.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\d_icons_buttons_logos.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\d_icons_buttons_other.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\d_icons_weather.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\default.cdf
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_511745-514279.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_bidzC_ZT_IE-ca.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_bidzC_ZT_IE-us.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_categorize.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_comparison.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_explorer-Mails.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_explorer-people.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_favorites.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_Games.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_Hide.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_hotbarcom.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_Hotmail.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_hsskin.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_jemster.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_jemsterie.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_jemsteruk.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_jobsearch.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_Mails.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_MobileSidewalk.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_new.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_premium.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_reun.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_ringtones.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_SearchBoxTrapper.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_searchfor.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_searchgo.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_weather.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Default_yellowpages.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\editblbuttons.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\email-def-511724-548964.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\email-def-511724-9595.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\email-t1-bg.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\icons2.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\ie_games_icon.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\ie_video.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\keywords.idx
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\keywords1.dat
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\layout.cdf
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\linkpathlegal.txt
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\progress.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\s_icons_buttons.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\sales_buttons.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\sdfmodifier.xml
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\t2_bg.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\theweb.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\top7.cdf
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\Top7_theweb.mnu
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\tsd_bg.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\zango_btn.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\1\zango_ie_menu.res
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\avatar.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\BtnTrans.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\BtnTrans1.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\buttondir.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\cursors.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_1000.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_2000.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_3000.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_bar.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_bbar1.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_logos.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_buttons_other.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\d_icons_weather.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\default.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\editblbuttons.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\email-t1-bg.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\icons2.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\ie_games_icon.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\ie_video.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\keywords.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\keywords1.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\layout.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\linkpathlegal.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\progress.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\s_icons_buttons.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\sales_buttons.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\sdfmodifier.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\t2_bg.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\top7.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\tsd_bg.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\zango_btn.xip
C:\Documents and Settings\Tyrelle\Application Data\Zango\v3.0\Zango\static\DownLoad\zango_ie_menu.xip

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_TDSSSERV


((((((((((((((((((((((((( Files Created from 2008-07-14 to 2008-08-14 )))))))))))))))))))))))))))))))
.

2008-08-14 01:43 . 2008-08-14 01:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PC Tools
2008-08-14 01:43 . 2008-08-14 01:41 160,792 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\pctfw2.sys
2008-08-14 01:40 . 2008-08-14 01:40 <DIR> d-------- C:\Program Files\Common Files\PC Tools
2008-08-14 01:10 . 2008-08-14 01:28 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\DivX
2008-08-14 01:08 . 2008-08-14 01:08 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Apple Computer
2008-08-14 01:05 . 2008-08-14 01:09 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Winamp
2008-08-14 00:36 . 2008-08-14 00:36 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\PC Tools
2008-08-14 00:36 . 2007-12-10 13:53 81,288 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\iksyssec.sys
2008-08-14 00:36 . 2007-12-10 13:53 66,952 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\iksysflt.sys
2008-08-14 00:36 . 2008-02-01 11:55 42,376 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\ikfilesec.sys
2008-08-14 00:36 . 2007-12-10 13:53 29,576 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\kcom.sys
2008-08-13 02:01 . 2008-08-14 01:46 <DIR> d-------- C:\Program Files\Spyware Doctor
2008-08-12 10:48 . 2008-08-14 01:43 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\uTorrent
2008-08-11 12:43 . 2008-08-11 12:43 244 --ah----- C:\sqmnoopt02.sqm
2008-08-10 07:53 . 2008-08-10 07:53 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\EasyJob Resume Builder
2008-08-10 06:44 . 2008-08-10 06:45 <DIR> d-------- C:\Program Files\EsetOnlineScanner
2008-08-10 06:20 . 2008-08-10 06:20 <DIR> d-------- C:\Deckard
2008-08-10 05:45 . 2008-08-10 05:45 <DIR> d-------- C:\Program Files\Trend Micro
2008-08-10 05:37 . 2008-08-10 05:37 7,680 --ahs---- C:\WINDOWS\Thumbs.db
2008-08-10 05:21 . 2005-08-16 01:34 <DIR> d-------- C:\Documents and Settings\New\Application Data\You've Got Pictures Screensaver
2008-08-10 05:21 . 2005-08-16 01:36 <DIR> d-------- C:\Documents and Settings\New\Application Data\Jasc Software Inc
2008-08-10 05:21 . 2008-08-10 05:21 <DIR> d-------- C:\Documents and Settings\New
2008-08-09 19:12 . 2008-08-14 01:14 664 --a------ C:\WINDOWS\SYSTEM32\d3d9caps.dat
2008-08-09 13:50 . 2008-08-09 13:50 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2008-08-08 00:10 . 2008-08-10 06:40 <DIR> d--h----- C:\$AVG8.VAULT$
2008-08-07 19:41 . 2008-08-07 19:41 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2008-08-07 17:33 . 2008-08-07 17:33 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-08-07 17:33 . 2008-08-07 17:33 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-07 17:33 . 2008-07-30 20:07 38,472 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mbamswissarmy.sys
2008-08-07 17:33 . 2008-07-30 20:07 17,144 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mbam.sys
2008-08-07 06:02 . 2008-08-07 06:02 <DIR> d-------- C:\KAV
2008-08-07 05:08 . 2008-08-07 05:08 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-08-07 05:07 . 2008-08-07 05:07 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-08-07 04:47 . 2008-08-07 04:47 <DIR> d-------- C:\Program Files\Opera
2008-08-07 04:01 . 2008-08-10 08:50 <DIR> d-------- C:\WINDOWS\SYSTEM32\DRIVERS\Avg
2008-08-07 04:01 . 2008-08-07 04:01 <DIR> d-------- C:\Program Files\AVG
2008-08-07 04:01 . 2008-08-07 04:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-08-07 04:01 . 2008-08-07 04:01 96,520 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\avgldx86.sys
2008-08-07 04:01 . 2008-08-07 04:01 76,040 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\avgtdix.sys
2008-08-07 04:01 . 2008-08-07 04:01 10,520 --a------ C:\WINDOWS\SYSTEM32\avgrsstx.dll
2008-08-07 01:38 . 2008-08-07 01:38 <DIR> d-------- C:\Documents and Settings\Tyrelle\Application Data\TmpRecentIcons
2008-08-06 18:13 . 2008-08-06 18:13 91,700 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\klin.dat
2008-08-06 18:13 . 2008-08-06 18:13 85,860 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\klick.dat
2008-08-06 18:10 . 2008-08-06 18:10 <DIR> d-------- C:\Program Files\Kaspersky Lab
2008-08-06 18:10 . 2008-08-13 03:31 2,971,168 --ahs---- C:\WINDOWS\SYSTEM32\DRIVERS\fidbox.dat
2008-08-06 18:10 . 2008-08-13 03:31 32,800 --ahs---- C:\WINDOWS\SYSTEM32\DRIVERS\fidbox2.dat
2008-08-06 18:10 . 2008-08-13 03:31 16,964 --ahs---- C:\WINDOWS\SYSTEM32\DRIVERS\fidbox.idx
2008-08-06 18:10 . 2008-08-13 03:31 3,908 --ahs---- C:\WINDOWS\SYSTEM32\DRIVERS\fidbox2.idx
2008-08-06 17:36 . 2008-08-06 17:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-08-06 02:37 . 2008-08-06 04:13 29,696 --a------ C:\Documents and Settings\Shinya.doc
2008-08-05 15:28 . 2008-08-05 15:28 <DIR> d-------- C:\Documents and Settings\Tyrelle\Application Data\HiYo
2008-08-05 13:40 . 2008-08-05 13:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\HiYo
2008-08-05 07:43 . 2008-08-05 07:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\CCP
2008-08-05 07:43 . 2007-07-19 18:14 3,727,720 --a------ C:\WINDOWS\SYSTEM32\d3dx9_35.dll
2008-08-05 07:33 . 2008-08-05 07:33 <DIR> d-------- C:\Program Files\CCP
2008-08-02 14:43 . 2008-08-02 14:43 4,096 --a------ C:\WINDOWS\d3dx.dat
2008-08-01 15:33 . 2008-08-01 15:33 <DIR> d-------- C:\Documents and Settings\Tyrelle\Application Data\Apple Computer
2008-07-26 07:24 . 2008-08-09 02:52 <DIR> d-------- C:\Program Files\WindSlayer
2008-07-24 23:42 . 2008-07-24 23:43 <DIR> d-------- C:\Program Files\EasyJob Resume Builder
2008-07-24 23:42 . 2008-07-24 23:43 <DIR> d-------- C:\Program Files\Common Files\AGBO Business Architecture S.L
2008-07-23 17:00 . 2007-05-16 16:45 1,124,720 --a------ C:\WINDOWS\SYSTEM32\D3DCompiler_34.dll
2008-07-23 17:00 . 2007-05-16 16:45 443,752 --a------ C:\WINDOWS\SYSTEM32\d3dx10_34.dll
2008-07-23 17:00 . 2007-06-20 20:46 266,088 --a------ C:\WINDOWS\SYSTEM32\xactengine2_8.dll
2008-07-23 17:00 . 2007-06-20 20:45 18,280 --a------ C:\WINDOWS\SYSTEM32\x3daudio1_2.dll
2008-07-23 16:59 . 2007-05-16 16:45 3,497,832 --a------ C:\WINDOWS\SYSTEM32\d3dx9_34.dll
2008-07-23 02:26 . 2008-07-23 20:49 <DIR> d-------- C:\Program Files\Xfire
2008-07-23 02:05 . 2007-03-12 16:42 1,123,696 --a------ C:\WINDOWS\SYSTEM32\D3DCompiler_33.dll
2008-07-23 02:05 . 2007-03-15 16:57 443,752 --a------ C:\WINDOWS\SYSTEM32\d3dx10_33.dll
2008-07-23 02:05 . 2007-04-04 18:55 261,480 --a------ C:\WINDOWS\SYSTEM32\xactengine2_7.dll
2008-07-23 02:05 . 2007-01-24 15:27 255,848 --a------ C:\WINDOWS\SYSTEM32\xactengine2_6.dll
2008-07-22 14:58 . 2008-07-22 14:58 <DIR> d-------- C:\Program Files\Firaxis Games
2008-07-22 02:55 . 2008-08-05 05:46 <DIR> d-------- C:\Program Files\uTorrent
2008-07-21 19:41 . 2008-07-21 19:41 42,320 --a------ C:\WINDOWS\SYSTEM32\xfcodec.dll
2008-07-19 10:49 . 2008-07-19 10:49 <DIR> d-------- C:\Program Files\SopCast

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-14 06:47 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-14 03:59 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-08-09 11:56 --------- d-----w C:\Program Files\Evrsoft First Page 2006
2008-08-09 07:52 --------- d-----w C:\Program Files\Sunbelt Software
2008-08-09 07:52 --------- d-----w C:\Program Files\McAfee
2008-08-09 07:52 --------- d-----w C:\Program Files\Electronic Arts
2008-08-09 07:51 --------- d-----w C:\Program Files\Warcraft III
2008-08-09 07:51 --------- d-----w C:\Program Files\City of Heroes
2008-08-09 07:47 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-08-08 03:37 --------- d-----w C:\Program Files\BYOND
2008-08-07 10:06 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-08-05 09:27 --------- d-----w C:\Program Files\FileZilla FTP Client
2008-08-02 18:49 --------- d-----w C:\Program Files\TC Digital
2008-07-26 12:22 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-24 04:02 --------- d-----w C:\Program Files\Outspark
2008-07-24 04:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\Outspark
2008-07-23 01:30 --------- d-----w C:\Program Files\Sports Interactive
2008-07-22 19:08 --------- d-----w C:\Program Files\Azureus
2008-07-18 19:29 --------- d-----w C:\Program Files\World of Warcraft
2008-07-07 17:51 --------- d-----w C:\Program Files\Trillian
2008-07-07 01:01 --------- d-----w C:\Program Files\Yahoo!
2008-07-07 01:01 --------- d-----w C:\Program Files\Crspace
2008-07-06 08:07 --------- d-----w C:\Program Files\DivX
2008-06-30 16:43 --------- d-----w C:\Program Files\iTunes
2008-06-30 16:42 --------- d-----w C:\Program Files\iPod
2008-06-30 16:41 --------- d-----w C:\Program Files\QuickTime
2008-06-30 16:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-06-30 16:38 --------- d-----w C:\Program Files\Common Files\Apple
2008-06-30 16:36 --------- d-----w C:\Program Files\Apple Software Update
2008-06-30 16:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2008-06-28 12:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-06-28 12:25 --------- d-----w C:\Program Files\Lavasoft
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-18 23:33 --------- d-----w C:\Program Files\EASEUS
2008-06-10 00:27 244 ---ha-w C:\Program Files\sqmnoopt02.sqm
2006-02-04 04:51 12,277,672 -c--a-w C:\Program Files\game.dat
2005-11-04 18:19 774,144 -c--a-w C:\Program Files\RngInterstitial.dll
2005-06-21 14:58 188,416 ----a-w C:\Documents and Settings\Akin Lake\lua.exe
2005-02-28 16:58 1,592 ----a-w C:\Documents and Settings\Akin Lake\Registry Keys.reg
2005-02-01 20:55 53,248 ----a-w C:\Documents and Settings\Akin Lake\npkpdb.dll
2005-02-01 20:55 37,009 ----a-w C:\Documents and Settings\Akin Lake\npkcusb.sys
2005-02-01 20:55 233,555 ----a-w C:\Documents and Settings\Akin Lake\npkcrypt.dll
2005-02-01 20:55 21,442 ----a-w C:\Documents and Settings\Akin Lake\npkcrypt.sys
2004-12-28 18:35 401,462 ----a-w C:\Documents and Settings\Akin Lake\msvcp60.dll
2003-11-25 13:20 81,920 ----a-w C:\Documents and Settings\Akin Lake\dinput.dll
2003-06-17 19:33 126,976 ----a-w C:\Documents and Settings\Akin Lake\NPX.DLL
2003-05-20 22:04 81,920 ----a-w C:\Documents and Settings\Akin Lake\npkeysdk.dll
2003-04-23 19:37 55,296 ----a-w C:\Documents and Settings\Akin Lake\NPCIPHER.DLL
2003-04-23 19:37 267,264 ----a-w C:\Documents and Settings\Akin Lake\FindHack.exe
2003-04-23 19:37 164,864 ----a-w C:\Documents and Settings\Akin Lake\NPUPDATE0.DLL
2002-10-02 04:11 358,963 ----a-w C:\Documents and Settings\Akin Lake\binkw32.dll
2002-10-02 04:11 230,455 ----a-w C:\Documents and Settings\Akin Lake\granny2.dll
2002-06-22 05:39 61,952 ----a-w C:\Documents and Settings\Akin Lake\NPCHK.DLL
2002-06-22 05:39 31,744 ----a-w C:\Documents and Settings\Akin Lake\NPPSK.DLL
2002-06-18 18:11 163,088 ----a-w C:\Documents and Settings\Akin Lake\dbghelp.dll
2002-04-25 15:51 73,728 ----a-w C:\Documents and Settings\Akin Lake\cps.dll
2001-04-15 16:20 156,672 ----a-w C:\Documents and Settings\Akin Lake\npupdate.dll
2001-03-31 16:41 346,624 ----a-w C:\Documents and Settings\Akin Lake\Mss32.dll
2001-03-21 14:35 372,736 ----a-w C:\Documents and Settings\Akin Lake\ijl15.dll
2006-08-27 20:28 56 -csh--r C:\WINDOWS\SYSTEM32\E0E182E7F4.sys
2008-02-02 15:16 848 -csha-w C:\WINDOWS\SYSTEM32\KGyGaAvL.sys
.
[code=auto:0]

Edited by Keile, 15 August 2008 - 11:59 AM.

  • 0

#6
Keile

Keile

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard downloader
"6112:TCP"= 6112:TCP:Blizzard Downloader
"6881:TCP"= 6881:TCP:Blizzard Downloader
"6999:TCP"= 6999:TCP:Blizzard Downloader
"6882:TCP"= 6882:TCP:Blizzard Downloader
"6883:TCP"= 6883:TCP:Blizzard Download
"6884:TCP"= 6884:TCP:Blizzard Downloader
"6885:TCP"= 6885:TCP:Blizzard Downloader
"6886:TCP"= 6886:TCP:Blizzard Downloader
"6887:TCP"= 6887:TCP:Blizzard Downloader
"6888:TCP"= 6888:TCP:Blizzard Downloader
"67:UDP"= 67:UDP:DHCP Discovery Service

R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\System32\Drivers\avgldx86.sys [2008-08-07 04:01]
R2 avg8emc;AVG Free8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-08-07 04:01]
R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-08-07 04:01]
R2 AvgTdiX;AVG Free8 Network Redirector;C:\WINDOWS\System32\Drivers\avgtdix.sys [2008-08-07 04:01]
R2 fssfltr;fssfltr;C:\WINDOWS\system32\DRIVERS\fssfltr.sys [2007-10-17 13:53]
R2 fsssvc;Windows Live OneCare Family Safety;C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2007-12-17 11:13]
R3 SUSCOM;Susteen Serial port driver;C:\WINDOWS\system32\DRIVERS\SUSCOM.SYS [2004-03-22 09:40]
R3 XDva143;XDva143;C:\WINDOWS\system32\XDva143.sys []
S1 pctfw2;pctfw2;C:\WINDOWS\SYSTEM32\DRIVERS\pctfw2.sys [2008-08-14 01:41]

.
Contents of the 'Scheduled Tasks' folder

2008-07-24 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:57]
.
- - - - ORPHANS REMOVED - - - -

Notify-geBrrRjJ - geBrrRjJ.dll
Notify-mljgffg - mljgffg.dll
Notify-NavLogon - (no file)


.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\4ucs6kgk.default\


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-14 01:59:22
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\tsd32.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
.
**************************************************************************
.
Completion time: 2008-08-14 2:08:44 - machine was rebooted [Administrator]
ComboFix-quarantined-files.txt 2008-08-14 07:08:29

Pre-Run: 9,823,526,912 bytes free
Post-Run: 10,083,074,048 bytes free

621 --- E O F --- 2008-08-13 08:30:43

----

I'm really sorry. I don't know if I'm retarded or something. But everytime I post half of the log, I see a different ending than what I originally determined it would be. Lol. xD. No worries..though..I'll have it figured out in like 5 mins..

should be okay..;S..

Edited by Keile, 15 August 2008 - 12:04 PM.

  • 0

#7
fenzodahl512

fenzodahl512

  • Malware Removal
  • 9,863 posts
Erm.. I think you need to attach the file... Please refer to the picture below.. Please use Add Reply button..

At the right-end corner at below of your reply page, you will see a picture like below.. Click it for further view..

Posted Image


Browse your C:\combofix.txt file and press the UPLOAD button next to it.. Wait untill the uploading attachment process is completed..

Then press Add Reply


Regards
fenzodahl512
  • 0

#8
Keile

Keile

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
Its in there.

Attached Files


  • 0

#9
fenzodahl512

fenzodahl512

  • Malware Removal
  • 9,863 posts
1. Please open Notepad
  • Click Start, then Run
  • Type notepad.exe in the Run Box.

2. Now copy/paste the entire content of the codebox below into the Notepad window:

KillAll::

RenV::
-c--a-w		 1,404,928 2008-03-02 14:54:11  C:\Program Files\Analog Devices\Core\smax4pnp .exe

File::
C:\Program Files\Analog Devices\Core\smax4pnp .exe

3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

Posted Image


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.

  • 0

#10
fenzodahl512

fenzodahl512

  • Malware Removal
  • 9,863 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP