Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

FOUR PHONE.exe and bone ante. exe


  • Please log in to reply

#1
ilikepie

ilikepie

    New Member

  • Member
  • Pip
  • 8 posts
Hi. A few days ago, I opened the task manager and found that 3 iexplore.exe's were running even though I had no internet explorer windows open (I hadn't opened it in months). So, i closed them and for a second a process called FOUR PHONE.exe came up on the list and then it disappered and the three iexplore.exe's were back. So, i searched for FOUR PHONE.exe and found it to be in C:/Documents and Settings/All Users/Application Data/antieqroamokay and i deletd it. Yesterday, i noticed that the 3 iexplorer.exe processes were back again so using the same method i fouind a program called bone ante.exe in the SAME folder but this time i can't delete it. My computer seems to be going much slower than normal and i think this might be causing it. I have done all the steps listed in the what to do before posting a HijackThis log but nothing even detects it.

I re-enabled everything on msconfig startup and here is my HijackThis log.

Logfile of HijackThis v1.99.1
Scan saved at 1:27:06 PM, on 8/10/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\WHATPU~1\WHATPU~1.EXE
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\WallpaperToy\Wallpapertoy.Exe
C:\WINDOWS\System32\svchost.exe
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\HJT\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {8F37895A-937C-23E1-A375-2F9C32D52CDA} - C:\DOCUME~1\ilikepie\APPLIC~1\ITCHTE~1\ace iso.exe
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [LXBSCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBStime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [roam okay iso coal] C:\Documents and Settings\All Users\Application Data\antieqroamokay\FOUR PHONE.exe
O4 - HKLM\..\Run: [THGuard] C:\Program Files\TrojanHunter 4.2\THGuard.exe
O4 - HKLM\..\Run: [WT GameChannel] C:\Program Files\WildTangent\Apps\GameChannel.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [QuickFinder Scheduler] "c:\Program Files\WordPerfect Office 11\Programs\QFSCHD110.EXE"
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PORTMA~1.EXE" -Run
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MemoryCardManager] C:\Program Files\Lexmark\Lexmark Precision Photo\MemCard.exe -startup
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [IcoSet] c:\hp\bin\cloaker.exe c:\hp\bin\IcoSet\adjust.bat seticon
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\PROGRA~1\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [ccRegVfy] "c:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKCU\..\Run: [WhatPulse] C:\PROGRA~1\WHATPU~1\WHATPU~1.EXE
O4 - HKCU\..\Run: [for store] C:\DOCUME~1\ilikepie\APPLIC~1\EXITLI~1\Copy Drive Extra.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Konfabulator.lnk = C:\Program Files\Pixoria\Konfabulator\Konfabulator.exe
O4 - Startup: Shortcut to ashDisp.lnk = C:\Program Files\Alwil Software\Avast4\ashDisp.exe
O4 - Startup: Wallpaper Changer.lnk = C:\Program Files\WallpaperToy\Wallpapertoy.Exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0c\aoltray.exe
O4 - Global Startup: CleverKeys.lnk = C:\Program Files\Lexico\CleverKeys\ClvrKeys.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O10 - Broken Internet access because of LSP provider 'connwsp.dll' missing
O16 - DPF: {023A3744-EA13-4C8A-8B23-ABF98974A9F5} - http://www.gunbound.com/joyonpack.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} - http://www.creative....119/CTSUEng.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} - http://www.installen...gine/isetup.cab
O16 - DPF: {D6FCA8ED-4715-43DE-9BD2-2789778A5B09} (NPKCX Control) - http://guard.gunboun...Crypt/npkcx.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abac...abasetup151.cab
O16 - DPF: {F5C90925-ABBF-4475-88F5-8622B452BA9E} - http://wwemail.suppo...ts/SysQuery.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - http://www.creative....12119/CTPID.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.ao.../ampx_en_dl.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: OPXPGina - C:\Program Files\Softex\OmniPass\opxpgina.dll
O20 - Winlogon Notify: WB - C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\fastload.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: AT Host Service (atnthost) - WebEx - C:\WINDOWS\Downlo~1\WebEx\319\atnthost.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTSvcCDA.EXE
O23 - Service: lxbs_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxbscoms.exe
O23 - Service: npkcsvc - INCA Internet Co., Ltd. - C:\WINDOWS\System32\npkcsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Unknown owner - C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindService.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

Thank you for any help!
  • 0

Advertisements


#2
coachwife6

coachwife6

    SuperStar

  • Retired Staff
  • 11,413 posts
ilikepie too! Sorry, couldn't resist. :tazz:

Sorry you got missed on the first go-round. Please run and post another hijack this log and post it in this thread and we'll get after it. ;)
  • 0

#3
ilikepie

ilikepie

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
No problem. I just really want to get rid of this problem!

Logfile of HijackThis v1.99.1
Scan saved at 11:25:13 AM, on 8/15/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\Downlo~1\WebEx\319\atnthost.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Downlo~1\WebEx\319\RAAGTAPP.EXE
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\WHATPU~1\WHATPU~1.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\WallpaperToy\Wallpapertoy.Exe
c:\progra~1\intern~1\iexplore.exe
c:\progra~1\intern~1\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Winamp\winamp.exe
C:\HJT\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {8F37895A-937C-23E1-A375-2F9C32D52CDA} - C:\DOCUME~1\ilikepie\APPLIC~1\ITCHTE~1\CampEach.exe
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [LXBSCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBStime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [roam okay iso coal] C:\Documents and Settings\All Users\Application Data\antieqroamokay\PHONE PART.exe
O4 - HKLM\..\Run: [WT GameChannel] C:\Program Files\WildTangent\Apps\GameChannel.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [QuickFinder Scheduler] "c:\Program Files\WordPerfect Office 11\Programs\QFSCHD110.EXE"
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PORTMA~1.EXE" -Run
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MemoryCardManager] C:\Program Files\Lexmark\Lexmark Precision Photo\MemCard.exe -startup
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [IcoSet] c:\hp\bin\cloaker.exe c:\hp\bin\IcoSet\adjust.bat seticon
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\PROGRA~1\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [ccRegVfy] "c:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [WhatPulse] C:\PROGRA~1\WHATPU~1\WHATPU~1.EXE
O4 - HKCU\..\Run: [for store] C:\DOCUME~1\ilikepie\APPLIC~1\EXITLI~1\Copy Drive Extra.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Konfabulator.lnk = C:\Program Files\Pixoria\Konfabulator\Konfabulator.exe
O4 - Startup: Shortcut to ashDisp.lnk = C:\Program Files\Alwil Software\Avast4\ashDisp.exe
O4 - Startup: Wallpaper Changer.lnk = C:\Program Files\WallpaperToy\Wallpapertoy.Exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0c\aoltray.exe
O4 - Global Startup: CleverKeys.lnk = C:\Program Files\Lexico\CleverKeys\ClvrKeys.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O10 - Broken Internet access because of LSP provider 'connwsp.dll' missing
O16 - DPF: {023A3744-EA13-4C8A-8B23-ABF98974A9F5} - http://www.gunbound.com/joyonpack.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} - http://www.creative....119/CTSUEng.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} - http://www.installen...gine/isetup.cab
O16 - DPF: {D6FCA8ED-4715-43DE-9BD2-2789778A5B09} (NPKCX Control) - http://guard.gunboun...Crypt/npkcx.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abac...abasetup151.cab
O16 - DPF: {F5C90925-ABBF-4475-88F5-8622B452BA9E} - http://wwemail.suppo...ts/SysQuery.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - http://www.creative....12119/CTPID.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.ao.../ampx_en_dl.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: OPXPGina - C:\Program Files\Softex\OmniPass\opxpgina.dll
O20 - Winlogon Notify: WB - C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\fastload.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: AT Host Service (atnthost) - WebEx - C:\WINDOWS\Downlo~1\WebEx\319\atnthost.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTSvcCDA.EXE
O23 - Service: lxbs_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxbscoms.exe
O23 - Service: npkcsvc - INCA Internet Co., Ltd. - C:\WINDOWS\System32\npkcsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Unknown owner - C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindService.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
  • 0

#4
POADB

POADB

    Visiting Staff

  • Member
  • PipPip
  • 46 posts
Create a new Folder and call it LOP
Download and unzip the following to the LOP folder you just created:
http://metallica.gee...com/findlop.zip

Inside the folder find findlop.bat
Doubleclick it and it will create the file C:\findlop.txt
Find that file and copy the content into your next post.


NOTE TO ANALYSTS!!! - Feel Free To Assist..

Edited by POADB, 15 August 2005 - 09:37 AM.

  • 0

#5
ilikepie

ilikepie

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Here it is.

[TRACE] Enumerating jobs and queues
[TRACE] Activating job 'AEC7DE4D91B4596D.job'
[TRACE] Printing all job properties

ApplicationName: 'c:\docume~1\ilikepie\applic~1\exitli~1\meowdentrect.exe'
Parameters: ''
WorkingDirectory: ''
Comment: ''
Creator: 'ilikepie'
Priority: NORMAL
MaxRunTime: 259200000 (3d 0:00:00)
IdleWait: 10
IdleDeadline: 60
MostRecentRun: 08/14/2005 23:00:00
NextRun: 08/15/2005 12:00:00
StartError: S_OK
ExitCode: 0
Status: SCHED_S_TASK_READY
ScheduledWorkItem Flags:
DeleteWhenDone = 0
Suspend = 0
StartOnlyIfIdle = 0
KillOnIdleEnd = 0
RestartOnIdleResume = 0
DontStartIfOnBatteries = 0
KillIfGoingOnBatteries = 0
RunOnlyIfLoggedOn = 1
SystemRequired = 0
Hidden = 1
TaskFlags: 0

1 Trigger

Trigger 0:
Type: Daily
DaysInterval: 1
StartDate: 10/21/1996
EndDate: 00/00/0000
StartTime: 00:00
MinutesDuration: 1440
MinutesInterval: 60
Flags:
HasEndDate = 0
KillAtDuration = 0
Disabled = 0
  • 0

#6
POADB

POADB

    Visiting Staff

  • Member
  • PipPip
  • 46 posts
Sorry for the wait - got caught up chatting :tazz:

Save the next instructions in notepad, because you also have to work in safe mode without networking support, so this page wouldn't be available then. You should not have any browsers on.

If there's anything that you don't understand, ask your question(s) before proceeding with the fixes. You should not have any open browsers when you are carrying out the procedures below.

It is also important you don't miss a step and perform everything in the right order!!. .


= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =

Please download these additional files/programs. Do not run them unless instructed to do so.
Unless otherwise stated, they should be stored in same directory as the HiJackThis program.

Please download Trend Micro™ Anti-Spyware for the Web Utility (by clicking the "Scan and Clean your PC" button).
  • Save it to your desktop.
  • Double-click the new icon on your desktop (tmas-web-scan.exe)
  • It will say "Loading TrendMicro definitions".
  • Once the definitions are loaded, the program will appear to close then re-open.
  • Click "Start Scan"
  • After it's done scanning, click "Scan Results"
  • Make sure all items found have a check next to them, then click "Clean Threats Now".
  • Click Exit.
Reboot your computer. In place of the TrendMicro icon will be a text file called "Antispyware.log", please double-click that log and copy the entire contents and paste them in your next post.

Unplug your computer from the Internet when you have finished downloading


= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =
DISABLE SPYBOT TEATIMER

While TeaTimer is an excellent tool for the prevention of spyware, it can sometimes prevent HijackThis from fixing certain things.
Please disable TeaTimer for now until you are clean. TeaTimer can be re-activated once your HijackThis log is clean.
  • Open Spybot Search & Destroy.
  • In the Mode menu click "Advanced mode" if not already selected.
  • Choose [Yes] at the Warning prompt.
  • Expand the [Tools] menu.
  • Click [Resident].
  • Uncheck the Resident "TeaTimer" (Protection of overall system settings) active. box.
  • In the File menu click [Exit] to exit Spybot Search & Destroy.
= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =

Navigate to Start>Settings > Control Panel > scheduled Tasks
locate & delete this task - AEC7DE4D91B4596D.job

= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =

REBOOT TO SAFE MODE
  • Restart the computer. The computer begins processing a set of instructions known as BIOS.
  • As soon as the BIOS has finished loading, begin tapping the F8 key on your keyboard.
  • Continue to do so until the 'Windows Advanced Options' menu appears.
  • Using the arrow keys on the keyboard, scroll to and select the menu item - Safe Mode.
= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =

Enable the viewing of Hidden files
  • From Windows Explorer, go to Tools>Folder Options>View tab.
  • Enable the option for `Show hidden files and folder´
  • Disable the option for `Hide file extensions for known types´
  • Disable the option for `Hide protected operating system files´
  • Click Yes to confirm & then click OK
= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =

Uninstall the following programs, if present, using Control Panel > Add/Remove Programs :WildTangent
= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =

Run a scan with HiJackThis & select(tick) the following & click [Fix checked] :

O2 - BHO: (no name) - {8F37895A-937C-23E1-A375-2F9C32D52CDA} - C:\DOCUME~1\ilikepie\APPLIC~1\ITCHTE~1\CampEach.exe
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - HKLM\..\Run: [roam okay iso coal] C:\Documents and Settings\All Users\Application Data\antieqroamokay\PHONE PART.exe
O4 - HKLM\..\Run: [WT GameChannel] C:\Program Files\WildTangent\Apps\GameChannel.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [for store] C:\DOCUME~1\ilikepie\APPLIC~1\EXITLI~1\Copy Drive Extra.exe



= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =


Locate and delete the following folder(s), if present:
  • c:\docume~1\ilikepie\applic~1\exitli~1\
    C:\DOCUME~1\ilikepie\APPLIC~1\ITCHTE~1\
    C:\Documents and Settings\All Users\Application Data\antieqroamokay\
    C:\Program Files\WildTangent\


    = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =


    REBOOT TO NORMAL MODE

    Perform an online scan in Internet Explorer with Panda ActiveScan [list=1]
  • Click on the Scan your PC button & a 'pop up' window shall appear. * ensure that your pop up blocker doesn't block it
  • Click On 'Scan Now'
  • Enter your e-mail address & click 'Scan Now' ...begins downloading Panda's ActiveX controls.- 8MB
  • Begin the scan by selecting My Computer
    * You needn't remain online while it's doing the scan but you have to re-connect after it has finished to see the report.
  • If it finds any malware, it will offer you a report. Click on see report
  • Then click Save report
  • Post the contents of the report in your next reply
* Turn off the real time scanner of any existing antivirus program while performing the online scan




= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =

In your next post, please include fresh logs from:
  • HiJackThis
  • Online scan
Please provide details of any problems you encountered whilst performing the above steps & update us on how the computer behaves now

Edited by POADB, 15 August 2005 - 10:24 AM.

  • 0

#7
ilikepie

ilikepie

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Well, I follwed all of the steps and the problem stopped but then I couldn't go on the internet anymore . I called the tech support of my ISP and they said something along the lines that some spyware attached itself to the WinSocket and deleted it when i got rid of the spyware and gave no advice of how to fix it. So, I used System Restore and restored to about a month ago. Now I can use my internet again and i'm pretty sure the infection is gone. I'm going to run ad-aware and spybot to see if I accidentally restored any spyware but here's my hijackthis log and activescan results.

Logfile of HijackThis v1.99.1
Scan saved at 2:00:09 PM, on 8/16/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\Downlo~1\WebEx\319\atnthost.exe
C:\WINDOWS\Downlo~1\WebEx\319\RAAGTAPP.EXE
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\WHATPU~1\WHATPU~1.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Winamp\winamp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\SoftwareDistribution\Download\7fc28d97b1595fa7b9dce8dd43cee6b0\update\update.exe
C:\HJT\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [LXBSCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBStime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [WT GameChannel] C:\Program Files\WildTangent\Apps\GameChannel.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [QuickFinder Scheduler] "c:\Program Files\WordPerfect Office 11\Programs\QFSCHD110.EXE"
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PORTMA~1.EXE" -Run
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MemoryCardManager] C:\Program Files\Lexmark\Lexmark Precision Photo\MemCard.exe -startup
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [IcoSet] c:\hp\bin\cloaker.exe c:\hp\bin\IcoSet\adjust.bat seticon
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\PROGRA~1\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [ccRegVfy] "c:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [WhatPulse] C:\PROGRA~1\WHATPU~1\WHATPU~1.EXE
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0c\aoltray.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O10 - Broken Internet access because of LSP provider 'connwsp.dll' missing
O16 - DPF: {023A3744-EA13-4C8A-8B23-ABF98974A9F5} - http://www.gunbound.com/joyonpack.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} - http://www.creative....119/CTSUEng.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} - http://www.installen...gine/isetup.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft...free/asinst.cab
O16 - DPF: {D6FCA8ED-4715-43DE-9BD2-2789778A5B09} (NPKCX Control) - http://guard.gunboun...Crypt/npkcx.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abac...abasetup151.cab
O16 - DPF: {F5C90925-ABBF-4475-88F5-8622B452BA9E} - http://wwemail.suppo...ts/SysQuery.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - http://www.creative....12119/CTPID.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.ao.../ampx_en_dl.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: OPXPGina - C:\Program Files\Softex\OmniPass\opxpgina.dll
O20 - Winlogon Notify: WB - C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\fastload.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: AT Host Service (atnthost) - WebEx - C:\WINDOWS\Downlo~1\WebEx\319\atnthost.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTSvcCDA.EXE
O23 - Service: npkcsvc - INCA Internet Co., Ltd. - C:\WINDOWS\System32\npkcsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

-

Incident Status Location

Adware:adware/savenow No disinfected Windows Registry
Adware:Adware/WUpd No disinfected C:\Documents and Settings\ilikepie\Application Data\Opera\Opera7\profile\cache4\opr027P9.htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\ilikepie\Application Data\Opera\Opera7\profile\cache4\opr027QL.htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\ilikepie\Application Data\Opera\Opera7\profile\cache4\opr027R8.htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\ilikepie\Application Data\Opera\Opera7\profile\cache4\opr027RN.htm
Adware:Adware/Lop No disinfected C:\Documents and Settings\ilikepie\Local Settings\Temp\301b24ad.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\ilikepie\Local Settings\Temp\325eb0d7.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\ilikepie\Local Settings\Temp\32e3369d.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\ilikepie\Local Settings\Temp\fdf467.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\ilikepie\Local Settings\Temp\mrpmezqs.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\ilikepie\Local Settings\Temp\smzdkohw.exe
Adware:Adware/Lop No disinfected C:\Documents and Settings\ilikepie\Local Settings\Temp\xgmwbbol.exe
  • 0

#8
POADB

POADB

    Visiting Staff

  • Member
  • PipPip
  • 46 posts
Hello again ilikepie.

It's unfortunate that you lost your internet conntection after following my instructions. I can assure you, we didn't touch your WinSock layer.

I'm wondering if Pure Networks is linked to WildTangent. I base my query on the fact that, from evidence in your log, Pure Networks is inbedded in your winsock layer. Pure Networks is included with AOL which automatically configures most in-home Internet gateways improving access and performance for applications such as instant messaging online gaming and streaming music and video. Or so it should.

######################

Download KillBox http://www.greyknigh...spy/KillBox.exe.

Please download CleanUp! (Alternate Link if main link don't work - http://www.greyknigh...spy/CleanUp.exe ) and install it. Do not run it yet!

= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =

While TeaTimer is an excellent tool for the prevention of spyware, it can sometimes prevent HijackThis from fixing certain things.
Please disable TeaTimer for now until you are clean. TeaTimer can be re-activated once your HijackThis log is clean.
  • Open Spybot Search & Destroy.
  • In the Mode menu click "Advanced mode" if not already selected.
  • Choose [Yes] at the Warning prompt.
  • Expand the [Tools] menu.
  • Click [Resident].
  • Uncheck the Resident "TeaTimer" (Protection of overall system settings) active. box.
  • In the File menu click [Exit] to exit Spybot Search & Destroy.
= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =

list][*] C:\Documents and Settings\ilikepie\Application Data\Opera\Opera7\profile\cache4\opr027P9.htm
C:\Documents and Settings\ilikepie\Application Data\Opera\Opera7\profile\cache4\opr027QL.htm
C:\Documents and Settings\ilikepie\Application Data\Opera\Opera7\profile\cache4\opr027R8.htm
C:\Documents and Settings\ilikepie\Application Data\Opera\Opera7\profile\cache4\opr027RN.htm
C:\Documents and Settings\ilikepie\Local Settings\Temp\301b24ad.exe
C:\Documents and Settings\ilikepie\Local Settings\Temp\325eb0d7.exe
C:\Documents and Settings\ilikepie\Local Settings\Temp\32e3369d.exe
C:\Documents and Settings\ilikepie\Local Settings\Temp\fdf467.exe
C:\Documents and Settings\ilikepie\Local Settings\Temp\mrpmezqs.exe
C:\Documents and Settings\ilikepie\Local Settings\Temp\smzdkohw.exe
C:\Documents and Settings\ilikepie\Local Settings\Temp\xgmwbbol.exe
[/list]Select/Highlight all the filename(s) from the above.
Copy to clipboard by pressing [CTRL]+[C] on your keyboard.
Start KillBox.exe
  • Go to the File menu, and choose Paste from Clipboard * this feature does not work on older versons of Killbox
    Click the dropdown-arrow next to the "Full Path of File to Delete" field.
    Verify that the filenames you pasted are found in there.
  • Select/tick the following:
    • Replace on Reboot
    • Use Dummy
    • End Explorer Shell While Killing File
    • Unregister.dll Before Deleting * if it's not grayed out
  • Click the RED X button.
  • Click Yes at the 'Delete on Reboot' prompt.
  • Click Yes at the 'Pending Operations prompt'.
* If you received a message such as: "PendingFileRenameOperations registry data has been removed by external process", you have to manually restart Windows.

* If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run TheKillbox, download and run missingfilesetup.exe Then try Killbox again.



= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =

Uninstall via Add/Remove

WildTangent


Run HJT and fix the following

O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - HKLM\..\Run: [WT GameChannel] C:\Program Files\WildTangent\Apps\GameChannel.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k


Delete the following folder:

C:\Program Files\WildTangent\


Open Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu). Set the program up as follows:
*Click "Options..."
*Move the arrow down to "Custom CleanUp!"
*Put a check next to the following:
  • Empty Recycle Bins
  • Delete Cookies
  • Delete Prefetch files
    [X]Scan local drives for temporary files (Please uncheck this option)
  • Cleanup! All Users
Click OK
Press the CleanUp! button to start the program. Reboot/logoff when prompted.


WARNING - CleanUp! will delete all files and folders contained within Temporary Directories. If you knowingly have items you would like to keep stored in these locations, Move them now!!!


= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =

Please download Trend Micro™ Anti-Spyware for the Web Utility (by clicking the "Scan and Clean your PC" button).
  • Save it to your desktop.
  • Double-click the new icon on your desktop (tmas-web-scan.exe)
  • It will say "Loading TrendMicro definitions".
  • Once the definitions are loaded, the program will appear to close then re-open.
  • Click "Start Scan"
  • After it's done scanning, click "Scan Results"
  • Make sure all items found have a check next to them, then click "Clean Threats Now".
  • Click Exit.
Reboot your computer. In place of the TrendMicro icon will be a text file called "Antispyware.log", please double-click that log and copy the entire contents and paste them in your next post.

Post a new HJT log when you're done.
  • 0

#9
ilikepie

ilikepie

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
All right. I had to stop Cleanup because it started to delete all my folders on the desktop . Was it supposed to do that? Regardless, it deleted all cookies so Ii think it was a semi-sucess. Here are the fresh logs!

Logfile of HijackThis v1.99.1
Scan saved at 8:23:44 PM, on 8/16/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\Downlo~1\WebEx\319\atnthost.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Downlo~1\WebEx\319\RAAGTAPP.EXE
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ps2.exe
C:\WINDOWS\system32\igfxtray.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\D-Tools\daemon.exe
C:\PROGRA~1\WHATPU~1\WHATPU~1.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\HJT\HijackThis.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [LXBSCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBStime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [QuickFinder Scheduler] "c:\Program Files\WordPerfect Office 11\Programs\QFSCHD110.EXE"
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PORTMA~1.EXE" -Run
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MemoryCardManager] C:\Program Files\Lexmark\Lexmark Precision Photo\MemCard.exe -startup
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [IcoSet] c:\hp\bin\cloaker.exe c:\hp\bin\IcoSet\adjust.bat seticon
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\PROGRA~1\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [ccRegVfy] "c:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKCU\..\Run: [WhatPulse] C:\PROGRA~1\WHATPU~1\WHATPU~1.EXE
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0c\aoltray.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O10 - Broken Internet access because of LSP provider 'connwsp.dll' missing
O16 - DPF: {023A3744-EA13-4C8A-8B23-ABF98974A9F5} - http://www.gunbound.com/joyonpack.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} - http://www.creative....119/CTSUEng.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} - http://www.installen...gine/isetup.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft...free/asinst.cab
O16 - DPF: {D6FCA8ED-4715-43DE-9BD2-2789778A5B09} (NPKCX Control) - http://guard.gunboun...Crypt/npkcx.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abac...abasetup151.cab
O16 - DPF: {F5C90925-ABBF-4475-88F5-8622B452BA9E} - http://wwemail.suppo...ts/SysQuery.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - http://www.creative....12119/CTPID.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.ao.../ampx_en_dl.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: OPXPGina - C:\Program Files\Softex\OmniPass\opxpgina.dll
O20 - Winlogon Notify: WB - C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\fastload.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: AT Host Service (atnthost) - WebEx - C:\WINDOWS\Downlo~1\WebEx\319\atnthost.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTSvcCDA.EXE
O23 - Service: npkcsvc - INCA Internet Co., Ltd. - C:\WINDOWS\System32\npkcsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

Started Scanning
Internet Cookies
Programs in Memory
Windows Registry
Found '' in 'SOFTWARE\LimeWire'
Found '' in 'Software\Kazaa'
Found '' in 'Software\Kazaa\ResultsFilter'
Found '' in 'Software\Kazaa\Transfer'
Found '' in 'Software\KaZaA\CloudLoad'
Found '' in 'Software\KaZaA\ConnectionInfo'
Found '' in 'Software\KaZaA\LocalContent'
Found '' in 'Software\Kazaa'
Found '' in 'Software\Kazaa\Advanced'
Found '' in 'Software\Kazaa\InstantMessaging'
Found '' in 'Software\Kazaa\LocalContent'
Found '' in 'Software\Kazaa\Skins'
Found '' in 'Software\Kazaa\UserDetails'
Found '' in 'SOFTWARE\Kazaa\Bandwidth\in'
Found '' in 'SOFTWARE\Kazaa\Bandwidth\LastEstimate'
Found '' in 'SOFTWARE\Kazaa\Bandwidth\out'
Found '' in 'SOFTWARE\Magnet'
Found '' in 'SOFTWARE\Classes\magnet'
Found '' in 'SOFTWARE\Classes\magnet\shell\open\command'
Found 'URL Protocol' in 'SOFTWARE\Classes\magnet'
Found 'LastSearchHash' in 'Software\Kazaa'
Found 'ScanFolder' in 'Software\Kazaa\Advanced'
Found 'IgnoreAll' in 'Software\Kazaa\InstantMessaging'
Found '' in 'Software\Kazaa\Search'
Found 'adult_filter_level' in 'Software\Kazaa\ResultsFilter'
Found 'b' in 'SOFTWARE\Kazaa\Bandwidth\LastEstimate'
Found 'b0' in 'SOFTWARE\Kazaa\Bandwidth\in'
Found 'b0' in 'SOFTWARE\Kazaa\Bandwidth\out'
Found 'b0seconds' in 'SOFTWARE\Kazaa\Bandwidth\in'
Found 'b0seconds' in 'SOFTWARE\Kazaa\Bandwidth\out'
Found 'b1' in 'SOFTWARE\Kazaa\Bandwidth\in'
Found 'b1' in 'SOFTWARE\Kazaa\Bandwidth\out'
Found 'CacheDiscoveryTime' in 'Software\Kazaa\Transfer'
Found 'CacheHost' in 'Software\Kazaa\Transfer'
Found 'CachePort' in 'Software\Kazaa\Transfer'
Found 'CountryCode' in 'Software\Kazaa\UserDetails'
Found 'DatabaseDir' in 'SOFTWARE\Kazaa\LocalContent'
Found 'DlDir0' in 'Software\Kazaa\Transfer'
Found 'DownloadDir' in 'SOFTWARE\Kazaa\LocalContent'
Found 'AutoConnected' in 'Software\Kazaa\UserDetails'
Found 'firewall_filter' in 'Software\Kazaa\ResultsFilter'
Found 'SkinsDir' in 'Software\Kazaa\Skins'
Found 'NoUploadLimitWhenIdle' in 'Software\Kazaa\Transfer'
Found 'UserName' in 'Software\Kazaa\UserDetails'
Found 'FirewallStatus' in 'SOFTWARE\Kazaa'
Found 'ListenPort' in 'SOFTWARE\Kazaa'
Found 'my_ip_address' in 'SOFTWARE\Kazaa'
Found 'network_config' in 'SOFTWARE\Kazaa'
Found 'UDP_probe_successes' in 'SOFTWARE\Kazaa'
Found 'UDP_receive_status' in 'SOFTWARE\Kazaa'
Found 'time' in 'SOFTWARE\Kazaa\Bandwidth\LastEstimate'
Found 'KazaaNet' in 'SOFTWARE\Kazaa\ConnectionInfo'
Found '' in 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\Range1'
Internet URL Shortcuts
Files and Directories
Found 'LimeWire20.dll' in 'C:\Program Files\LimeWire'
Found '' in 'C:\Program Files\Morpheus'
Found 'MorphUltraCache.net' in 'C:\Program Files\Morpheus'
Found 'NeoWebCache.net' in 'C:\Program Files\Morpheus'
Found 'application.xml' in 'C:\Program Files\Morpheus\Schemas'
Found 'application.xsd' in 'C:\Program Files\Morpheus\Schemas'
Found 'document.xml' in 'C:\Program Files\Morpheus\Schemas'
Found 'image.xml' in 'C:\Program Files\Morpheus\Schemas'
Found 'image.xsd' in 'C:\Program Files\Morpheus\Schemas'
Found 'morph.xml' in 'C:\Program Files\Morpheus\Schemas'
Found 'rom.xml' in 'C:\Program Files\Morpheus\Schemas'
Found 'rom.xsd' in 'C:\Program Files\Morpheus\Schemas'
Found 'video.xml' in 'C:\Program Files\Morpheus\Schemas'
Finished Scanning
Started Backup
Finished Backup
Started Cleaning
Checking for 'C:\Program Files\LimeWire\LimeWire20.dll' in shortcut areas.
Checking for 'C:\Program Files\LimeWire\LimeWire20.dll' in startup areas.
Cleaning 'C:\Program Files\LimeWire\LimeWire20.dll'
Checking for 'C:\Program Files\Morpheus' in shortcut areas.
Checking for 'C:\Program Files\Morpheus' in startup areas.
Cleaning 'C:\Program Files\Morpheus'
Checking for 'C:\Program Files\Morpheus\bitTorrent_LICENSE.txt' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\bitTorrent_LICENSE.txt' in startup areas.
Cleaning 'C:\Program Files\Morpheus\bitTorrent_LICENSE.txt'
Checking for 'C:\Program Files\Morpheus\MorphCache.net' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\MorphCache.net' in startup areas.
Cleaning 'C:\Program Files\Morpheus\MorphCache.net'
Checking for 'C:\Program Files\Morpheus\MorphUltraCache.net' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\MorphUltraCache.net' in startup areas.
Cleaning 'C:\Program Files\Morpheus\MorphUltraCache.net'
Checking for 'C:\Program Files\Morpheus\NeoWebCache.net' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\NeoWebCache.net' in startup areas.
Cleaning 'C:\Program Files\Morpheus\NeoWebCache.net'
Checking for 'C:\Program Files\Morpheus\python23.zip' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\python23.zip' in startup areas.
Cleaning 'C:\Program Files\Morpheus\python23.zip'
Checking for 'C:\Program Files\Morpheus\python_LICENSE.txt' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\python_LICENSE.txt' in startup areas.
Cleaning 'C:\Program Files\Morpheus\python_LICENSE.txt'
Checking for 'C:\Program Files\Morpheus\Schemas\application.xml' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\Schemas\application.xml' in startup areas.
Cleaning 'C:\Program Files\Morpheus\Schemas\application.xml'
Checking for 'C:\Program Files\Morpheus\Schemas\application.xsd' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\Schemas\application.xsd' in startup areas.
Cleaning 'C:\Program Files\Morpheus\Schemas\application.xsd'
Checking for 'C:\Program Files\Morpheus\Schemas\audio.xml' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\Schemas\audio.xml' in startup areas.
Cleaning 'C:\Program Files\Morpheus\Schemas\audio.xml'
Checking for 'C:\Program Files\Morpheus\Schemas\audio.xsd' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\Schemas\audio.xsd' in startup areas.
Cleaning 'C:\Program Files\Morpheus\Schemas\audio.xsd'
Checking for 'C:\Program Files\Morpheus\Schemas\document.xml' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\Schemas\document.xml' in startup areas.
Cleaning 'C:\Program Files\Morpheus\Schemas\document.xml'
Checking for 'C:\Program Files\Morpheus\Schemas\document.xsd' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\Schemas\document.xsd' in startup areas.
Cleaning 'C:\Program Files\Morpheus\Schemas\document.xsd'
Checking for 'C:\Program Files\Morpheus\Schemas\image.xml' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\Schemas\image.xml' in startup areas.
Cleaning 'C:\Program Files\Morpheus\Schemas\image.xml'
Checking for 'C:\Program Files\Morpheus\Schemas\image.xsd' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\Schemas\image.xsd' in startup areas.
Cleaning 'C:\Program Files\Morpheus\Schemas\image.xsd'
Checking for 'C:\Program Files\Morpheus\Schemas\morph.xml' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\Schemas\morph.xml' in startup areas.
Cleaning 'C:\Program Files\Morpheus\Schemas\morph.xml'
Checking for 'C:\Program Files\Morpheus\Schemas\morph.xsd' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\Schemas\morph.xsd' in startup areas.
Cleaning 'C:\Program Files\Morpheus\Schemas\morph.xsd'
Checking for 'C:\Program Files\Morpheus\Schemas\rom.xml' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\Schemas\rom.xml' in startup areas.
Cleaning 'C:\Program Files\Morpheus\Schemas\rom.xml'
Checking for 'C:\Program Files\Morpheus\Schemas\rom.xsd' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\Schemas\rom.xsd' in startup areas.
Cleaning 'C:\Program Files\Morpheus\Schemas\rom.xsd'
Checking for 'C:\Program Files\Morpheus\Schemas\video.xml' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\Schemas\video.xml' in startup areas.
Cleaning 'C:\Program Files\Morpheus\Schemas\video.xml'
Checking for 'C:\Program Files\Morpheus\Schemas\video.xsd' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\Schemas\video.xsd' in startup areas.
Cleaning 'C:\Program Files\Morpheus\Schemas\video.xsd'
Checking for 'C:\Program Files\Morpheus\select.pyd' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\select.pyd' in startup areas.
Cleaning 'C:\Program Files\Morpheus\select.pyd'
Checking for 'C:\Program Files\Morpheus\SkinData\default\About.htm' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\About.htm' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\About.htm'
Checking for 'C:\Program Files\Morpheus\SkinData\default\adnull.html' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\adnull.html' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\adnull.html'
Checking for 'C:\Program Files\Morpheus\SkinData\default\Background.BMP' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\Background.BMP' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\Background.BMP'
Checking for 'C:\Program Files\Morpheus\SkinData\default\bitzi-pattern.gif' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\bitzi-pattern.gif' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\bitzi-pattern.gif'
Checking for 'C:\Program Files\Morpheus\SkinData\default\bitzi-tear.gif' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\bitzi-tear.gif' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\bitzi-tear.gif'
Checking for 'C:\Program Files\Morpheus\SkinData\default\bitzi_perforation.gif' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\bitzi_perforation.gif' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\bitzi_perforation.gif'
Checking for 'C:\Program Files\Morpheus\SkinData\default\bluebar.gif' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\bluebar.gif' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\bluebar.gif'
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-divider.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-divider.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\browser-divider.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-dpr-back.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-dpr-back.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\browser-dpr-back.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-dpr-blank-32x17.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-dpr-blank-32x17.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\browser-dpr-blank-32x17.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-dpr-blank-33x17.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-dpr-blank-33x17.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\browser-dpr-blank-33x17.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-dpr-forward.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-dpr-forward.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\browser-dpr-forward.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-dpr-home.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-dpr-home.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\browser-dpr-home.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-dpr-refresh.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-dpr-refresh.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\browser-dpr-refresh.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-dpr-stop.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-dpr-stop.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\browser-dpr-stop.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-na-back.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-na-back.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\browser-na-back.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-na-blank-32x17.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-na-blank-32x17.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\browser-na-blank-32x17.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-na-blank-33x17.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-na-blank-33x17.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\browser-na-blank-33x17.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-na-forward.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-na-forward.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\browser-na-forward.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-na-home.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-na-home.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\browser-na-home.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-na-refresh.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-na-refresh.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\browser-na-refresh.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-na-stop.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-na-stop.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\browser-na-stop.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-normal-back.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-normal-back.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\browser-normal-back.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-normal-blank-32x17.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-normal-blank-32x17.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\browser-normal-blank-32x17.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-normal-blank-33x17.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-normal-blank-33x17.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\browser-normal-blank-33x17.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-normal-forward.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-normal-forward.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\browser-normal-forward.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-normal-home.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-normal-home.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\browser-normal-home.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-normal-refresh.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-normal-refresh.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\browser-normal-refresh.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-normal-stop.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-normal-stop.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\browser-normal-stop.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-over-back.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-over-back.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\browser-over-back.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-over-forward.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-over-forward.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\browser-over-forward.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-over-home.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-over-home.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\browser-over-home.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-over-refresh.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-over-refresh.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\browser-over-refresh.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-over-stop.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\browser-over-stop.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\browser-over-stop.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\Button-Dark.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\Button-Dark.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\Button-Dark.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\Button.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\Button.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\Button.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\ButtonDown-dark.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\ButtonDown-dark.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\ButtonDown-dark.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\ButtonDown.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\ButtonDown.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\ButtonDown.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\ButtonDownMask.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\ButtonDownMask.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\ButtonDownMask.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\ButtonMask.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\ButtonMask.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\ButtonMask.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\chat.css' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\chat.css' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\chat.css'
Checking for 'C:\Program Files\Morpheus\SkinData\default\chatcombo.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\chatcombo.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\chatcombo.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\chatcombomask.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\chatcombomask.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\chatcombomask.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\ChatHeader.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\ChatHeader.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\ChatHeader.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\ChatSplitter.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\ChatSplitter.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\ChatSplitter.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\checkbox_blank.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\checkbox_blank.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\checkbox_blank.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\checkbox_blank_disabled.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\checkbox_blank_disabled.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\checkbox_blank_disabled.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\checkbox_checked.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\checkbox_checked.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\checkbox_checked.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\checkbox_checked_disabled.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\checkbox_checked_disabled.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\checkbox_checked_disabled.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\Connecting.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\Connecting.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\Connecting.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\Connecting_selected.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\Connecting_selected.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\Connecting_selected.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\CurrentMediaStatic.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\CurrentMediaStatic.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\CurrentMediaStatic.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\Downloads.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\Downloads.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\Downloads.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\DownloadsPressed.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\DownloadsPressed.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\DownloadsPressed.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\DragDropFiles.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\DragDropFiles.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\DragDropFiles.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\eBay.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\eBay.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\eBay.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\file.gif' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\file.gif' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\file.gif'
Checking for 'C:\Program Files\Morpheus\SkinData\default\fileavailability.html' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\fileavailability.html' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\fileavailability.html'
Checking for 'C:\Program Files\Morpheus\SkinData\default\fileavailabilitytorrent.html' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\fileavailabilitytorrent.html' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\fileavailabilitytorrent.html'
Checking for 'C:\Program Files\Morpheus\SkinData\default\filebitzi.html' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\filebitzi.html' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\filebitzi.html'
Checking for 'C:\Program Files\Morpheus\SkinData\default\FileBitziWaiting.html' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\FileBitziWaiting.html' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\FileBitziWaiting.html'
Checking for 'C:\Program Files\Morpheus\SkinData\default\filedetails.html' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\filedetails.html' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\filedetails.html'
Checking for 'C:\Program Files\Morpheus\SkinData\default\filedetails.jpg' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\filedetails.jpg' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\filedetails.jpg'
Checking for 'C:\Program Files\Morpheus\SkinData\default\filetipdetail.html' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\filetipdetail.html' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\filetipdetail.html'
Checking for 'C:\Program Files\Morpheus\SkinData\default\file_info_bg.gif' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\file_info_bg.gif' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\file_info_bg.gif'
Checking for 'C:\Program Files\Morpheus\SkinData\default\flyoutnull.html' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\flyoutnull.html' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\flyoutnull.html'
Checking for 'C:\Program Files\Morpheus\SkinData\default\Header.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\Header.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\Header.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\HeaderBlock.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\HeaderBlock.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\HeaderBlock.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\HeaderBlock.gif' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\HeaderBlock.gif' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\HeaderBlock.gif'
Checking for 'C:\Program Files\Morpheus\SkinData\default\HeaderDowned.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\HeaderDowned.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\HeaderDowned.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\header_chat.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\header_chat.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\header_chat.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\header_chat_dp.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\header_chat_dp.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\header_chat_dp.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\header_close.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\header_close.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\header_close.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\header_close_dp.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\header_close_dp.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\header_close_dp.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\header_help.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\header_help.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\header_help.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\header_help_dp.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\header_help_dp.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\header_help_dp.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\header_maximize.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\header_maximize.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\header_maximize.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\header_maximize_dp.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\header_maximize_dp.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\header_maximize_dp.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\header_minimize.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\header_minimize.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\header_minimize.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\header_minimize_dp.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\header_minimize_dp.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\header_minimize_dp.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\header_morpheusultra.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\header_morpheusultra.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\header_morpheusultra.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\header_morpheusultra_dp.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\header_morpheusultra_dp.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\header_morpheusultra_dp.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\header_preferences.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\header_preferences.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\header_preferences.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\header_preferences_dp.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\header_preferences_dp.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\header_preferences_dp.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\header_restore.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\header_restore.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\header_restore.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\header_restore_dp.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\header_restore_dp.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\header_restore_dp.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\HScrollBar.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\HScrollBar.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\HScrollBar.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\HThumb.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\HThumb.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\HThumb.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\images\arrow.gif' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\images\arrow.gif' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\images\arrow.gif'
Checking for 'C:\Program Files\Morpheus\SkinData\default\images\getmorpheusultra.gif' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\images\getmorpheusultra.gif' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\images\getmorpheusultra.gif'
Checking for 'C:\Program Files\Morpheus\SkinData\default\images\monochrome_morpheus.gif' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\images\monochrome_morpheus.gif' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\images\monochrome_morpheus.gif'
Checking for 'C:\Program Files\Morpheus\SkinData\default\images\monochrome_morpheus.jpg' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\images\monochrome_morpheus.jpg' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\images\monochrome_morpheus.jpg'
Checking for 'C:\Program Files\Morpheus\SkinData\default\images\monochrome_morpheus_ultra.gif' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\images\monochrome_morpheus_ultra.gif' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\images\monochrome_morpheus_ultra.gif'
Checking for 'C:\Program Files\Morpheus\SkinData\default\images\monochrome_morpheus_ultra.jpg' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\images\monochrome_morpheus_ultra.jpg' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\images\monochrome_morpheus_ultra.jpg'
Checking for 'C:\Program Files\Morpheus\SkinData\default\images\welcome.gif' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\images\welcome.gif' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\images\welcome.gif'
Checking for 'C:\Program Files\Morpheus\SkinData\default\Left.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\Left.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\Left.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\LeftDown.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\LeftDown.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\LeftDown.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\lightblue.gif' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\lightblue.gif' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\lightblue.gif'
Checking for 'C:\Program Files\Morpheus\SkinData\default\ListSel.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\ListSel.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\ListSel.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\logo.html' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\logo.html' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\logo.html'
Checking for 'C:\Program Files\Morpheus\SkinData\default\logoUltra.html' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\logoUltra.html' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\logoUltra.html'
Checking for 'C:\Program Files\Morpheus\SkinData\default\MainFrame.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\MainFrame.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\MainFrame.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\MainFrameMask.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\MainFrameMask.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\MainFrameMask.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\MenuHighlight.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\MenuHighlight.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\MenuHighlight.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\MenuNormal.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\MenuNormal.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\MenuNormal.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\Mini.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\Mini.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\Mini.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\MiniDown.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\MiniDown.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\MiniDown.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\MorphDlg.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\MorphDlg.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\MorphDlg.bmp'
Checking for 'C:\Program Files\Morpheus\SkinData\default\MorphDlgMask.bmp' in shortcut areas.
Checking for 'C:\Program Files\Morpheus\SkinData\default\MorphDlgMask.bmp' in startup areas.
Cleaning 'C:\Program Files\Morpheus\SkinData\default\MorphDlgMask.bmp'
  • 0

#10
POADB

POADB

    Visiting Staff

  • Member
  • PipPip
  • 46 posts
No - CleanUp shouldn't have touched folders on your desktop, unless of course they were linked to Temp Directories...

Trend Micro has kindly removed the crap bundled with Kazaa, LimeWire and Morpheus, so I think all that's left now is a virus scan to see if you're clean.

Please run an online virus scan at Panda ActiveScan. Save the results and bring them with you in your next post.
  • 0

#11
ilikepie

ilikepie

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Sorry for the slow reply. I ran the ActiveScan. It didnt give me the option to save the results but it didnt find anything. Thanks for your help!
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP