Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Virus W32.Spybot.Worm -> Screwed up my computer!


  • This topic is locked This topic is locked

#16
chunkymunkyluva2

chunkymunkyluva2

    Member

  • Topic Starter
  • Member
  • PipPip
  • 16 posts
I went through the instructions on the page.. and everything went as it said it would. The scan took about 2 hours and found alot of trojans, but i couldnt see the one mentioned on the page. My computer is stil acting strangely, and it took 10mins to open up mozilla. I turned the AV program that it told me to download off and everything was back to normal, well normal before the scan. I still cannot open WMP series 10 as i get the error:

Can't Perform Operation, Low Memory

and i cannot minimize things to go onto the toolbar at the bottom of the screen, so i have to use the Alt + Tab shortcut to navigate between programs.

I still cannot copy and paste into or from browsers.

Should i uninstall Kapersky now that it has done the scan?

I have got the Zone Alarm firewall and AVG AV installed.

Windows install does not work, and i get error 101, 'The service could not be accessed...'

Here is my HJT log, please help me sort out the problems!!

Logfile of HijackThis v1.99.1
Scan saved at 20:24:11, on 17/05/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton Internet Security\NISUM.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Norton Internet Security\ccPxySvc.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\gearsec.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\SECRETMAKER\secretmaker.exe
C:\Program Files\iTunes\iTunes.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\James Lawrence\My Documents\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.timesupport.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: IeHelper Class - {A491D208-B353-490F-B81A-A8A3DC97042D} - C:\WINDOWS\System32\smiehlp.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: SECRETMAKER.lnk = C:\Program Files\SECRETMAKER\secretmaker.exe
O4 - Global Startup: blueyonder Instant Support Tool.lnk = C:\Program Files\blueyonder IST\bin\matcli.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.timesupport.com
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zon...kr.cab28578.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zon...MineSweeper.cab
O16 - DPF: {3AE9ED90-4B59-47A0-873B-7B71554B3C3E} (JoystickCtl Class) - http://www.miniclip....ll/joystick.cab
O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} (Microsoft.WinRep) - https://webresponse....iveX/winrep.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefend...bitdefender.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...StatsClient.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
O16 - DPF: {A7E092C3-692A-11D0-A7E5-08002B322F3B} (WebResponseAttachments Control) - https://webresponse....eX/FileXfer.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zon...ro.cab32846.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) - http://www.windowsec...scan/axscan.cab
O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://www.blueyonde...tivePreQual.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zon...ss.cab31267.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abac...abasetup156.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Proxy Service (ccPxySvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPxySvc.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Internet Security Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Internet Security\NISUM.EXE
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZONELABS\vsmon.exe

Do you want the log from the scan? it is very big, about 60 pages long..

! :tazz: !
  • 0

Advertisements


#17
chunkymunkyluva2

chunkymunkyluva2

    Member

  • Topic Starter
  • Member
  • PipPip
  • 16 posts
sorry one more thing..

should i uninstall Norton Internet Security? it doesnt seem to startup properly and i have an AV and firewall so i dont really need it, but i need to make sure that its safe to get rid of it

the problems i have are a bit random and are probably due to a number of viruses and malware, so thankyou for taking the time to help and trying to fix them :tazz:
  • 0

#18
Guest_thatman_*

Guest_thatman_*
  • Guest
Hi please post the pages from the scan

Uninstall Norton Internet Security when done install you firewall

Post a new HJT.log

Kc :tazz:
  • 0

#19
chunkymunkyluva2

chunkymunkyluva2

    Member

  • Topic Starter
  • Member
  • PipPip
  • 16 posts
Ahhh! I cannot uninstall Norton Internet Security because 'The Windows Installer service could not be accessed'! Why can't i use it and how do i fix this?

Here is my scan log.. very long: (by the way can i unistall this AV program now because it is slowing my computer down, or do i still need it?)

Statistics:
Task start time: 17/05/2005 18:40:27
Task completion time: 17/05/2005 19:27:42
Objects scanned: 133779
Viruses detected: 66
Viruses disinfected: 0
Objects deleted: 66
Objects quarantined: 0

Settings:
Objects to be scanned:
My Computer
If an infected object is found:
Perform recommended action
Scan level:
Recommended
Objects to be excluded from the scan scope:
Option not used

Report:
C:\aawsepersonal.exe/WISE0022.BIN\arrow1.bmp password protected, has not been processed 17/05/2005 18:42:06
C:\aawsepersonal.exe/WISE0022.BIN\arrow2.bmp password protected, has not been processed 17/05/2005 18:42:06
C:\aawsepersonal.exe/WISE0022.BIN\bck1.bmp password protected, has not been processed 17/05/2005 18:42:06
C:\aawsepersonal.exe/WISE0022.BIN\bck2.bmp password protected, has not been processed 17/05/2005 18:42:06
C:\aawsepersonal.exe/WISE0022.BIN\bt11.bmp password protected, has not been processed 17/05/2005 18:42:06
C:\aawsepersonal.exe/WISE0022.BIN\bt12.bmp password protected, has not been processed 17/05/2005 18:42:06
C:\aawsepersonal.exe/WISE0022.BIN\bt13.bmp password protected, has not been processed 17/05/2005 18:42:06
C:\aawsepersonal.exe/WISE0022.BIN\bt21.bmp password protected, has not been processed 17/05/2005 18:42:06
C:\aawsepersonal.exe/WISE0022.BIN\bt22.bmp password protected, has not been processed 17/05/2005 18:42:06
C:\aawsepersonal.exe/WISE0022.BIN\bt23.bmp password protected, has not been processed 17/05/2005 18:42:06
C:\aawsepersonal.exe/WISE0022.BIN\bt31.bmp password protected, has not been processed 17/05/2005 18:42:06
C:\aawsepersonal.exe/WISE0022.BIN\bt32.bmp password protected, has not been processed 17/05/2005 18:42:06
C:\aawsepersonal.exe/WISE0022.BIN\bt33.bmp password protected, has not been processed 17/05/2005 18:42:06
C:\aawsepersonal.exe/WISE0022.BIN\bt41.bmp password protected, has not been processed 17/05/2005 18:42:06
C:\aawsepersonal.exe/WISE0022.BIN\bt42.bmp password protected, has not been processed 17/05/2005 18:42:06
C:\aawsepersonal.exe/WISE0022.BIN\bt43.bmp password protected, has not been processed 17/05/2005 18:42:06
C:\aawsepersonal.exe/WISE0022.BIN\bt51.bmp password protected, has not been processed 17/05/2005 18:42:06
C:\aawsepersonal.exe/WISE0022.BIN\bt52.bmp password protected, has not been processed 17/05/2005 18:42:06
C:\aawsepersonal.exe/WISE0022.BIN\bt53.bmp password protected, has not been processed 17/05/2005 18:42:06
C:\aawsepersonal.exe/WISE0022.BIN\bt61.bmp password protected, has not been processed 17/05/2005 18:42:06
C:\aawsepersonal.exe/WISE0022.BIN\bt62.bmp password protected, has not been processed 17/05/2005 18:42:06
C:\aawsepersonal.exe/WISE0022.BIN\checkbox1.bmp password protected, has not been processed 17/05/2005 18:42:06
C:\aawsepersonal.exe/WISE0022.BIN\checkbox2.bmp password protected, has not been processed 17/05/2005 18:42:06
C:\aawsepersonal.exe/WISE0022.BIN\checkbox3.bmp password protected, has not been processed 17/05/2005 18:42:06
C:\aawsepersonal.exe/WISE0022.BIN\checkbox4.bmp password protected, has not been processed 17/05/2005 18:42:06
C:\aawsepersonal.exe/WISE0022.BIN\default.skn password protected, has not been processed 17/05/2005 18:42:06
C:\aawsepersonal.exe/WISE0022.BIN\defbtn1.bmp password protected, has not been processed 17/05/2005 18:42:06
C:\aawsepersonal.exe/WISE0022.BIN\defbtn2.bmp password protected, has not been processed 17/05/2005 18:42:06
C:\aawsepersonal.exe/WISE0022.BIN\defbtn3.bmp password protected, has not been processed 17/05/2005 18:42:06
C:\aawsepersonal.exe/WISE0022.BIN\glyph1.bmp password protected, has not been processed 17/05/2005 18:42:06
C:\aawsepersonal.exe/WISE0022.BIN\glyph2.bmp password protected, has not been processed 17/05/2005 18:42:06
C:\aawsepersonal.exe/WISE0022.BIN\glyph3.bmp password protected, has not been processed 17/05/2005 18:42:06
C:\aawsepersonal.exe/WISE0022.BIN\glyph4.bmp password protected, has not been processed 17/05/2005 18:42:06
C:\aawsepersonal.exe/WISE0022.BIN\glyph5.bmp password protected, has not been processed 17/05/2005 18:42:06
C:\aawsepersonal.exe/WISE0022.BIN\glyph6.bmp password protected, has not been processed 17/05/2005 18:42:06
C:\aawsepersonal.exe/WISE0022.BIN\glyph7.bmp password protected, has not been processed 17/05/2005 18:42:06
C:\aawsepersonal.exe/WISE0022.BIN\main.bmp password protected, has not been processed 17/05/2005 18:42:06
C:\aawsepersonal.exe/WISE0022.BIN\preview.bmp password protected, has not been processed 17/05/2005 18:42:06
C:\aawsepersonal.exe/WISE0022.BIN\sprite1.bmp password protected, has not been processed 17/05/2005 18:42:06
C:\aawsepersonal.exe/WISE0022.BIN\tab1.bmp password protected, has not been processed 17/05/2005 18:42:06
C:\aawsepersonal.exe/WISE0022.BIN\tab2.bmp password protected, has not been processed 17/05/2005 18:42:06
C:\WINDOWS\system32\y is infected with a virus Trojan-Downloader.BAT.Ftp.ab 17/05/2005 18:43:01
C:\WINDOWS\system32\y moved to the backup storage 17/05/2005 18:43:01
C:\WINDOWS\system32\y deleted 17/05/2005 18:43:01
C:\WINDOWS\system32\intlmain.dll is a Trojan Trojan.Win32.StartPage.iv 17/05/2005 18:43:23
C:\WINDOWS\system32\intlmain.dll moved to the backup storage 17/05/2005 18:43:23
C:\WINDOWS\system32\intlmain.dll deleted 17/05/2005 18:43:23
C:\WINDOWS\system32\iegfxfrw.dll is a Trojan Trojan.Win32.StartPage.iv 17/05/2005 18:44:28
C:\WINDOWS\system32\iegfxfrw.dll moved to the backup storage 17/05/2005 18:44:28
C:\WINDOWS\system32\iegfxfrw.dll deleted 17/05/2005 18:44:28
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCA.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCA.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM82.zip\Gamecube.url password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM82.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM83.zip\Computer game.url password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM83.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM84.zip\Working From Home.url password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM84.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCA1.zip\wsem302.dll password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCA1.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit1.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit1.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM85.zip\Internet.url password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM85.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM86.zip\Instant Messenger.url password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM86.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCA2.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCA2.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit2.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit2.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM87.zip\Inkjet Cartridge.url password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM87.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM88.zip\Hosting.url password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM88.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCA3.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCA3.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit3.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit3.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM89.zip\Dvd.url password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM89.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM90.zip\Domain Hosting.url password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM90.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCA4.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCA4.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit4.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit4.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM91.zip\Computer Programming.url password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM91.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM92.zip\Computer Jobs .url password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM92.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM93.zip\Communication Technology.url password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM93.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM94.zip\Antivirus.url password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM94.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM95.zip\Website Hosting.lnk password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM95.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM96.zip\Printer Cartridges.lnk password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM96.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM97.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCA5.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCA5.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit5.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit5.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM98.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM99.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCA6.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCA6.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit6.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit6.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM100.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM101.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\nCase.zip\salm.exe password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\nCase.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit7.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit7.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM102.zip\Fun Stuff/Pass Drug Test.url password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM102.zip\Fun Stuff/Video Surveillance.url password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM102.zip\Fun Stuff/Online Pharmacy.url password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM102.zip\Fun Stuff/Descrambler.url password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM102.zip\Fun Stuff/Scratch Card.url password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM102.zip\Fun Stuff/Dvd To Cd.url password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM102.zip\Fun Stuff/Dating.url password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM102.zip\Fun Stuff/Printer Cartridge.url password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM102.zip\Fun Stuff/Satellite Television.url password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM102.zip\Fun Stuff/Mp3.url password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM102.zip\Home/Home Equity Loan.url password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM102.zip\Home/Home Security.url password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM102.zip\Home/Home Improvements.url password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM102.zip\Home/Home Refinancing.url password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM102.zip\Home/Working From Home.url password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM102.zip\Home/Interior Decorating .url password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM102.zip\Home/Outdoor Furniture.url password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM102.zip\Home/Timeshare.url password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM102.zip\Home/Office Space.url password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM102.zip\Home/Satellite Television.url password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM102.zip\Home/Health Plan.url password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM102.zip\Home/Food Nutrition.url password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM102.zip\Home/Outdoor Cooking.url password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM102.zip\Home/Sleep Aids.url password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM102.zip\Home/Adjustable Bed.url password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM102.zip\Home/Phone System.url password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM102.zip\Online Pharmacy/Buy Adipex.url password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM102.zip\Online Pharmacy/Buy Meridia .url password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM102.zip\Online Pharmacy/Buy Fidrex.url password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM102.zip\Online Pharmacy/Buy Ionamin.url password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM102.zip\Online Pharmacy/Buy Tenuate.url password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM102.zip\Online Pharmacy/Buy Phentermine.url password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM102.zip\Online Pharmacy/Buy Viagra.url password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM102.zip\Online Pharmacy/Buy Celebrex.url password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM102.zip\Online Pharmacy/Buy Xenical.url password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM102.zip\Online Pharmacy/Buy Soma.url password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM102.zip\Online Pharmacy/Buy Ultram Online.url password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM102.zip\Online Pharmacy/Buy Propecia.url password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM102.zip\Online Pharmacy/Mexican Pharmacy.url password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM102.zip\Online Pharmacy/Pharmacy Online.url password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM102.zip\Online Pharmacy/Pass Drug Test.url password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM102.zip\Online Pharmacy/Consumer Consulting.url password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM102.zip\Online Pharmacy/Doctor.url password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM102.zip\Online Pharmacy/Pet Med.url password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM102.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM103.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\nCase1.zip\otqp.exe password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\nCase1.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit8.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit8.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchSmallM104.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCAInternetOptimizer1.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\TIBS1.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit9.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit9.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit30.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit30.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit31.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit31.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\nCase2.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\nCase2.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit10.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit10.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit32.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit32.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit33.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit33.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\nCase3.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\nCase3.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit11.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit11.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit34.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit34.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCAInternetOptimizer.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCAInternetOptimizer.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\TIBS2.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\TIBS2.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit12.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit12.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechISTsvc.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCAInternetOptimizer2.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCAInternetOptimizer2.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\TIBS3.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit13.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit13.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCAInternetOptimizer3.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCAInternetOptimizer3.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCAInternetOptimizer4.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCAInternetOptimizer4.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit14.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit14.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechPowerScan1.zip\powerscan.exe password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechPowerScan1.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Hotbar.zip\hotbar.inf password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Hotbar.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechISTsvc1.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechISTsvc1.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Hotbar1.zip\Hotbar.log password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Hotbar1.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechPowerScan.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechPowerScan.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Hotbar2.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCAInternetOptimizer5.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCAInternetOptimizer5.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCAInternetOptimizer6.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCAInternetOptimizer6.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit15.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit15.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCAInternetOptimizer7.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCAInternetOptimizer7.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechPowerScan2.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\TIBS4.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit16.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit16.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechSideFind.zip\sfbho.dll password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechSideFind.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechPowerScan3.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechPowerScan3.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\nCase4.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\nCase4.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit17.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit17.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechPowerScan4.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechPowerScan4.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechPowerScan5.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechPowerScan5.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\nCase5.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\nCase5.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit18.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit18.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechPowerScan6.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechPowerScan6.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechPowerScan7.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechPowerScan7.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\nCase6.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\nCase6.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit19.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit19.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechPowerScan8.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechPowerScan8.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\TIBS5.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\nCase7.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\nCase7.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit20.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit20.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechSideFind1.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechSideFind1.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechSideFind2.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechSideFind2.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit21.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit21.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechSideFind3.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechSideFind3.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechSideFind4.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechSideFind4.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Spex.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Spex.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit22.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit22.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechSideFind5.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechSideFind5.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechSideFind6.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechSideFind6.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Spex1.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Spex1.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit23.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit23.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechSideFind7.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechSideFind7.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechSideFind8.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechSideFind8.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Spex2.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Spex2.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit24.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit24.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechSideFind9.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechSideFind9.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechSlotch.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechSlotch.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\nCase8.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\nCase8.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit25.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DSOExploit25.zip\sbRecovery.ini password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechSlotch1.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechSlotch1.zip\sbRecovery.ini password protected, has not been processed 17/
  • 0

#20
chunkymunkyluva2

chunkymunkyluva2

    Member

  • Topic Starter
  • Member
  • PipPip
  • 16 posts
Here is my HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 18:48:15, on 18/05/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton Internet Security\NISUM.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Norton Internet Security\ccPxySvc.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\gearsec.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\SECRETMAKER\secretmaker.exe
C:\Program Files\blueyonder IST\bin\mpbtn.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\James Lawrence\My Documents\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.timesupport.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.timesupport.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: IeHelper Class - {A491D208-B353-490F-B81A-A8A3DC97042D} - C:\WINDOWS\System32\smiehlp.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: SECRETMAKER.lnk = C:\Program Files\SECRETMAKER\secretmaker.exe
O4 - Global Startup: blueyonder Instant Support Tool.lnk = C:\Program Files\blueyonder IST\bin\matcli.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.timesupport.com
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zon...kr.cab28578.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zon...MineSweeper.cab
O16 - DPF: {3AE9ED90-4B59-47A0-873B-7B71554B3C3E} (JoystickCtl Class) - http://www.miniclip....ll/joystick.cab
O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} (Microsoft.WinRep) - https://webresponse....iveX/winrep.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefend...bitdefender.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...StatsClient.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
O16 - DPF: {A7E092C3-692A-11D0-A7E5-08002B322F3B} (WebResponseAttachments Control) - https://webresponse....eX/FileXfer.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zon...ro.cab32846.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) - http://www.windowsec...scan/axscan.cab
O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://www.blueyonde...tivePreQual.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zon...ss.cab31267.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abac...abasetup156.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Proxy Service (ccPxySvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPxySvc.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Internet Security Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Internet Security\NISUM.EXE
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZONELABS\vsmon.exe
  • 0

#21
Guest_thatman_*

Guest_thatman_*
  • Guest
Hi chunkymunkyluva2

All of the files listed in your post#19 can be deleted from your system
C:\aawsepersonal.exe/WISE0022.BIN\arrow1.bmp password protected, has not been processed 17/05/2005 18:42:06

C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCA2.zip\sbRecovery.reg password protected, has not been processed 17/05/2005 19:04:44

Now it time to update your copy of windows if it is a legal copy

Kc :tazz:
  • 0

#22
chunkymunkyluva2

chunkymunkyluva2

    Member

  • Topic Starter
  • Member
  • PipPip
  • 16 posts
how do i delete them all? do i have to go to each one one by one?? that will take forever
by the way, i have a reload/backup CD which says it will return the computer to its 'factory state', will this get rid of the virus(es) and/or the spyware?

I cannot copy and paste, so i cannot move any files, which means that i cannot backup my files!

How do i fix this problem??
  • 0

#23
Guest_thatman_*

Guest_thatman_*
  • Guest
Hi chunkymunkyluva2

Spybot Tutorial

Disable Spybot Tutorial

Kc :tazz:
  • 0

#24
chunkymunkyluva2

chunkymunkyluva2

    Member

  • Topic Starter
  • Member
  • PipPip
  • 16 posts
u want me to disable spybot? then what?

how do i fix my copy and paste problem?
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP