Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

WinFixer...Please help! [RESOLVED]


  • This topic is locked This topic is locked

#31
Amateur Geek

Amateur Geek

    Member

  • Topic Starter
  • Member
  • PipPip
  • 24 posts
Six hours later the scan is complete however it will not let me copy the virus log; it did at least allow me to copy the complete log so here are items I thought would be of interest...otherwise, how should I get the information to you?

Thanks!


Sat Aug 13 20:20:54 2005 => File C:\WINDOWS\SYSTEM32\nowrszht.dll tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.
Sat Aug 13 18:27:35 2005 => File C:\l2mfix.exe tagged as not-a-virus:RiskTool.Win32.Processor.20. No Action Taken.
Sat Aug 13 17:46:17 2005 => Object "AltNet Spyware/Adware" found in File System! Action Taken: No Action Taken.
SSat Aug 13 17:46:33 2005 => System found infected with iSearch Spyware/Adware (patch.exe)! Action taken: No Action Taken.

nning File C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20050810.004\NAVENG.SYS
Sat Aug 13 17:46:02 2005 => Scanning File C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20050810.00

at Aug 13 17:46:33 2005 => System found infected with iSearch Spyware/Adware (patch.exe)! Action taken: No Action Taken.

Sat Aug 13 19:15:01 2005 => File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\053226BB infected by "Trojan-Dropper.Win32.Agent.hh" Virus! Action Taken: No Action Taken.

Sat Aug 13 17:46:02 2005 => Scanning File C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20050810.004\NAVENG.SYS

Sat Aug 13 17:48:57 2005 => File C:\WINDOWS\system32\fp0m03d1e.dll tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.
Sat Aug 13 17:49:30 2005 => File C:\WINDOWS\system32\jt6807jue.dll tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.
Sat Aug 13 17:49:30 2005 => File C:\WINDOWS\system32\k6800glme6qa0.dll tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.
Sat Aug 13 17:49:45 2005 => File C:\WINDOWS\system32\mbratelc.dll tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.
Sat Aug 13 17:49:47 2005 => File C:\WINDOWS\system32\MEIMRT32.DLL tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.
Sat Aug 13 17:49:52 2005 => File C:\WINDOWS\system32\mistkprp.dll tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.

Sat Aug 13 17:52:37 2005 => Scanning File C:\DOCUME~1\Owner\LOCALS~1\Temp\virus.avi



Sat Aug 13 17:52:37 2005 => Scanning File C:\DOCUME~1\Owner\LOCALS~1\Temp\virus001.avc
Sat Aug 13 17:52:37 2005 => Scanning File C:\DOCUME~1\Owner\LOCALS~1\Temp\virus002.avc
Sat Aug 13 17:52:37 2005 => Scanning File C:\DOCUME~1\Owner\LOCALS~1\Temp\virus003.avc
Sat Aug 13 17:52:37 2005 => Scanning File C:\DOCUME~1\Owner\LOCALS~1\Temp\virus004.avc
Sat Aug 13 17:52:37 2005 => Scanning File C:\DOCUME~1\Owner\LOCALS~1\Temp\virus005.avc
Sat Aug 13 17:52:37 2005 => Scanning File C:\DOCUME~1\Owner\LOCALS~1\Temp\virus006.avc
Sat Aug 13 17:52:38 2005 => Scanning File C:\DOCUME~1\Owner\LOCALS~1\Temp\virus007.avc
Sat Aug 13 17:52:38 2005 => Scanning File C:\DOCUME~1\Owner\LOCALS~1\Temp\virus008.avc
Sat Aug 13 17:52:38 2005 => Scanning File C:\DOCUME~1\Owner\LOCALS~1\Temp\virus009.avc
Sat Aug 13 17:52:38 2005 => Scanning File C:\DOCUME~1\Owner\LOCALS~1\Temp\virus010.avc
Sat Aug 13 17:52:38 2005 => Scanning File C:\DOCUME~1\Owner\LOCALS~1\Temp\virus011.avc
Sat Aug 13 17:52:38 2005 => Scanning File C:\DOCUME~1\Owner\LOCALS~1\Temp\virus012.avc
Sat Aug 13 17:52:38 2005 => Scanning File C:\DOCUME~1\Owner\LOCALS~1\Temp\virus013.avc
Sat Aug 13 17:52:38 2005 => Scanning File C:\DOCUME~1\Owner\LOCALS~1\Temp\virus014.avc
Sat Aug 13 17:52:38 2005 => Scanning File C:\DOCUME~1\Owner\LOCALS~1\Temp\virus015.avc
Sat Aug 13 17:52:38 2005 => Scanning File C:\DOCUME~1\Owner\LOCALS~1\Temp\virus016.avc
Sat Aug 13 17:52:38 2005 => Scanning File C:\DOCUME~1\Owner\LOCALS~1\Temp\virus017.avc
Sat Aug 13 17:52:38 2005 => Scanning File C:\DOCUME~1\Owner\LOCALS~1\Temp\virus018.avc
Sat Aug 13 17:52:38 2005 => Scanning File C:\DOCUME~1\Owner\LOCALS~1\Temp\virus019.avc
Sat Aug 13 17:52:38 2005 => Scanning File C:\DOCUME~1\Owner\LOCALS~1\Temp\virus020.avc
Sat Aug 13 17:52:38 2005 => Scanning File C:\DOCUME~1\Owner\LOCALS~1\Temp\WIN.PRO
Sat Aug 13 17:52:38 2005 => Scanning File C:\DOCUME~1\Owner\LOCALS~1\Temp\worm001.avc
Sat Aug 13 17:52:38 2005 => Scanning File C:\DOCUME~1\Owner\LOCALS~1\Temp\worm002.avc
Sat Aug 13 17:52:38 2005 => Scanning File C:\DOCUME~1\Owner\LOCALS~1\Temp\worm003.avc
Sat Aug 13 17:52:38 2005 => Scanning File C:\DOCUME~1\Owner\LOCALS~1\Temp\worm004.avc
Sat Aug 13 17:52:39 2005 => Scanning File C:\DOCUME~1\Owner\LOCALS~1\Temp\worm005.avc
Sat Aug 13 17:52:39 2005 => Scanning File C:\DOCUME~1\Owner\LOCALS~1\Temp\worm006.avc
Sat Aug 13 17:52:39 2005 => Scanning File C:\DOCUME~1\Owner\LOCALS~1\Temp\worm999.avc
Sat Aug 13 17:52:39 2005 => Scanning File C:\DOCUME~1\Owner\LOCALS~1\Temp\x-files.avc

uments and Settings\Owner\Local Settings\Temp\virus.avi
Sat Aug 13 18:04:17 2005 => Scanning File C:\Documents and Settings\Owner\Local Settings\Temp\virus001.avc
Sat Aug 13 18:04:17 2005 => Scanning File C:\Documents and Settings\Owner\Local Settings\Temp\virus002.avc
Sat Aug 13 18:04:17 2005 => Scanning File C:\Documents and Settings\Owner\Local Settings\Temp\virus003.avc
Sat Aug 13 18:04:17 2005 => Scanning File C:\Documents and Settings\Owner\Local Settings\Temp\virus004.avc
Sat Aug 13 18:04:17 2005 => Scanning File C:\Documents and Settings\Owner\Local Settings\Temp\virus005.avc
Sat Aug 13 18:04:17 2005 => Scanning File C:\Documents and Settings\Owner\Local Settings\Temp\virus006.avc
Sat Aug 13 18:04:18 2005 => Scanning File C:\Documents and Settings\Owner\Local Settings\Temp\virus007.avc
Sat Aug 13 18:04:18 2005 => Scanning File C:\Documents and Settings\Owner\Local Settings\Temp\virus008.avc
Sat Aug 13 18:04:18 2005 => Scanning File C:\Documents and Settings\Owner\Local Settings\Temp\virus009.avc
Sat Aug 13 18:04:18 2005 => Scanning File C:\Documents and Settings\Owner\Local Settings\Temp\virus010.avc
Sat Aug 13 18:04:18 2005 => Scanning File C:\Documents and Settings\Owner\Local Settings\Temp\virus011.avc
Sat Aug 13 18:04:18 2005 => Scanning File C:\Documents and Settings\Owner\Local Settings\Temp\virus012.avc
Sat Aug 13 18:04:18 2005 => Scanning File C:\Documents and Settings\Owner\Local Settings\Temp\virus013.avc
Sat Aug 13 18:04:18 2005 => Scanning File C:\Documents and Settings\Owner\Local Settings\Temp\virus014.avc
Sat Aug 13 18:04:18 2005 => Scanning File C:\Documents and Settings\Owner\Local Settings\Temp\virus015.avc
Sat Aug 13 18:04:18 2005 => Scanning File C:\Documents and Settings\Owner\Local Settings\Temp\virus016.avc
Sat Aug 13 18:04:18 2005 => Scanning File C:\Documents and Settings\Owner\Local Settings\Temp\virus017.avc
Sat Aug 13 18:04:18 2005 => Scanning File C:\Documents and Settings\Owner\Local Settings\Temp\virus018.avc
Sat Aug 13 18:04:18 2005 => Scanning File C:\Documents and Settings\Owner\Local Settings\Temp\virus019.avc
Sat Aug 13 18:04:18 2005 => Scanning File C:\Documents and Settings\Owner\Local Settings\Temp\virus020.avc
Sat Aug 13 18:04:18 2005 => Scanning File C:\Documents and Settings\Owner\Local Settings\Temp\WIN.PRO
Sat Aug 13 18:04:18 2005 => Scanning File C:\Documents and Settings\Owner\Local Settings\Temp\worm001.avc
Sat Aug 13 18:04:18 2005 => Scanning File C:\Documents and Settings\Owner\Local Settings\Temp\worm002.avc
Sat Aug 13 18:04:18 2005 => Scanning File C:\Documents and Settings\Owner\Local Settings\Temp\worm003.avc
Sat Aug 13 18:04:18 2005 => Scanning File C:\Documents and Settings\Owner\Local Settings\Temp\worm004.avc
Sat Aug 13 18:04:18 2005 => Scanning File C:\Documents and Settings\Owner\Local Settings\Temp\worm005.avc
Sat Aug 13 18:04:18 2005 => Scanning File C:\Documents and Settings\Owner\Local Settings\Temp\worm006.avc
Sat Aug 13 18:04:19 2005 => Scanning File C:\Documents and Settings\Owner\Local Settings\Temp\worm999.avc
Sat Aug 13 18:04:19 2005 => Scanning File C:\Documents and Settings\Owner\Local Settings\Temp\x-files.avc

Sat Aug 13 18:05:24 2005 => Scanning File C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\KUKDQMZD\frs_virusinfo[1].gif

Sat Aug 13 18:40:43 2005 => Scanning Folder: C:\Program Files\Common Files\Symantec Shared\VirusDefs\*.*
Sat Aug 13 18:40:43 2005 => Scanning Folder: C:\Program Files\Common Files\Symantec Shared\VirusDefs\20031216.007\*.*
Sat Aug 13 18:40:43 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20031216.007\CATALOG.DAT
Sat Aug 13 18:40:43 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20031216.007\ECBOOTIL.VXD
Sat Aug 13 18:40:43 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20031216.007\ECMSVR32.DLL
Sat Aug 13 18:40:43 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20031216.007\HH
Sat Aug 13 18:40:43 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20031216.007\NAVENG.EXP
Sat Aug 13 18:40:43 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20031216.007\NAVENG.SYS
Sat Aug 13 18:40:43 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20031216.007\NAVENG.VXD
Sat Aug 13 18:40:43 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20031216.007\NAVENG32.DLL
Sat Aug 13 18:40:44 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20031216.007\NAVEX15.EXP
Sat Aug 13 18:40:44 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20031216.007\NAVEX15.SYS
Sat Aug 13 18:40:44 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20031216.007\NAVEX15.VXD
Sat Aug 13 18:40:45 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20031216.007\NAVEX32A.DLL
Sat Aug 13 18:40:45 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20031216.007\NCSACERT.TXT
Sat Aug 13 18:40:45 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20031216.007\SCRAUTH.DAT
Sat Aug 13 18:40:45 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20031216.007\SYMAVENG.CAT
Sat Aug 13 18:40:45 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20031216.007\SYMAVENG.INF
Sat Aug 13 18:40:45 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20031216.007\TCDEFS.DAT
Sat Aug 13 18:40:45 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20031216.007\TCSCAN7.DAT
Sat Aug 13 18:40:45 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20031216.007\TCSCAN8.DAT
Sat Aug 13 18:40:45 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20031216.007\TCSCAN9.DAT
Sat Aug 13 18:40:45 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20031216.007\TECHNOTE.TXT
Sat Aug 13 18:40:45 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20031216.007\TINF.DAT
Sat Aug 13 18:40:45 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20031216.007\TINFIDX.DAT
Sat Aug 13 18:40:46 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20031216.007\TINFL.DAT
Sat Aug 13 18:40:46 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20031216.007\TSCAN1.DAT
Sat Aug 13 18:40:46 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20031216.007\TSCAN1HD.DAT
Sat Aug 13 18:40:46 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20031216.007\V.GRD
Sat Aug 13 18:40:46 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20031216.007\V.SIG
Sat Aug 13 18:40:46 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20031216.007\VIRSCAN.INF
Sat Aug 13 18:40:46 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20031216.007\VIRSCAN1.DAT
Sat Aug 13 18:40:46 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20031216.007\VIRSCAN2.DAT
Sat Aug 13 18:40:46 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20031216.007\VIRSCAN3.DAT
Sat Aug 13 18:40:46 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20031216.007\VIRSCAN4.DAT
Sat Aug 13 18:40:46 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20031216.007\VIRSCAN5.DAT
Sat Aug 13 18:40:46 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20031216.007\VIRSCAN6.DAT
Sat Aug 13 18:40:46 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20031216.007\VIRSCAN7.DAT
Sat Aug 13 18:40:46 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20031216.007\VIRSCAN8.DAT
Sat Aug 13 18:40:47 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20031216.007\VIRSCAN9.DAT
Sat Aug 13 18:40:47 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20031216.007\VIRSCANT.DAT
Sat Aug 13 18:40:47 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20031216.007\WHATSNEW.TXT
Sat Aug 13 18:40:47 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20031216.007\ZDONE.DAT
Sat Aug 13 18:40:47 2005 => Scanning Folder: C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050809.007\*.*
Sat Aug 13 18:40:47 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050809.007\CATALOG.DAT
Sat Aug 13 18:40:47 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050809.007\CCERASER.DLL
Sat Aug 13 18:40:48 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050809.007\ECBOOTIL.VXD
Sat Aug 13 18:40:48 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050809.007\ECMSVR32.DLL
Sat Aug 13 18:40:49 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050809.007\ESRDEF.XML
Sat Aug 13 18:40:49 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050809.007\HH
Sat Aug 13 18:40:49 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050809.007\NAVENG.EXP
Sat Aug 13 18:40:49 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050809.007\NAVENG.SYS
Sat Aug 13 18:40:49 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050809.007\NAVENG.VXD
Sat Aug 13 18:40:49 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050809.007\NAVENG32.DLL
Sat Aug 13 18:40:49 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050809.007\NAVEX15.EXP
Sat Aug 13 18:40:49 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050809.007\NAVEX15.SYS
Sat Aug 13 18:40:50 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050809.007\NAVEX15.VXD
Sat Aug 13 18:40:50 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050809.007\NAVEX32A.DLL
Sat Aug 13 18:40:50 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050809.007\NCSACERT.TXT
Sat Aug 13 18:40:50 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050809.007\SCRAUTH.DAT
Sat Aug 13 18:40:50 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050809.007\SYMAVENG.CAT
Sat Aug 13 18:40:50 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050809.007\SYMAVENG.INF
Sat Aug 13 18:40:50 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050809.007\TCDEFS.DAT
Sat Aug 13 18:40:50 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050809.007\TCSCAN7.DAT
Sat Aug 13 18:40:51 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050809.007\TCSCAN8.DAT
Sat Aug 13 18:40:51 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050809.007\TCSCAN9.DAT
Sat Aug 13 18:40:51 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050809.007\TECHNOTE.TXT
Sat Aug 13 18:40:51 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050809.007\TINF.DAT
Sat Aug 13 18:40:51 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050809.007\TINFIDX.DAT
Sat Aug 13 18:40:51 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050809.007\TINFL.DAT
Sat Aug 13 18:40:51 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050809.007\TSCAN1.DAT
Sat Aug 13 18:40:51 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050809.007\TSCAN1HD.DAT
Sat Aug 13 18:40:51 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050809.007\UPDATE.TXT
Sat Aug 13 18:40:51 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050809.007\V.GRD
Sat Aug 13 18:40:51 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050809.007\V.SIG
Sat Aug 13 18:40:51 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050809.007\VIRSCAN.INF
Sat Aug 13 18:40:52 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050809.007\VIRSCAN1.DAT
Sat Aug 13 18:40:52 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050809.007\VIRSCAN2.DAT
Sat Aug 13 18:40:52 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050809.007\VIRSCAN3.DAT
Sat Aug 13 18:40:52 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050809.007\VIRSCAN4.DAT
Sat Aug 13 18:40:52 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050809.007\VIRSCAN5.DAT
Sat Aug 13 18:40:52 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050809.007\VIRSCAN6.DAT
Sat Aug 13 18:40:52 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050809.007\VIRSCAN7.DAT
Sat Aug 13 18:40:52 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050809.007\VIRSCAN8.DAT
Sat Aug 13 18:40:52 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050809.007\VIRSCAN9.DAT
Sat Aug 13 18:40:52 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050809.007\VIRSCANT.DAT
Sat Aug 13 18:40:53 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050809.007\vscanmsx.dat
Sat Aug 13 18:40:53 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050809.007\WHATSNEW.TXT
Sat Aug 13 18:40:53 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050809.007\ZDONE.DAT
Sat Aug 13 18:40:53 2005 => Scanning Folder: C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050810.004\*.*
Sat Aug 13 18:40:53 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050810.004\CATALOG.DAT
Sat Aug 13 18:40:53 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050810.004\CCERASER.DLL
Sat Aug 13 18:40:53 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050810.004\ECBOOTIL.VXD
Sat Aug 13 18:40:53 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050810.004\ECMSVR32.DLL
Sat Aug 13 18:40:53 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050810.004\ESRDEF.XML
Sat Aug 13 18:40:54 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050810.004\HH
Sat Aug 13 18:40:54 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050810.004\NAVENG.EXP
Sat Aug 13 18:40:54 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050810.004\NAVENG.SYS
Sat Aug 13 18:40:54 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050810.004\NAVENG.VXD
Sat Aug 13 18:40:54 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050810.004\NAVENG32.DLL
Sat Aug 13 18:40:54 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050810.004\NAVEX15.EXP
Sat Aug 13 18:40:54 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050810.004\NAVEX15.SYS
Sat Aug 13 18:40:54 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050810.004\NAVEX15.VXD
Sat Aug 13 18:40:54 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050810.004\NAVEX32A.DLL
Sat Aug 13 18:40:54 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050810.004\NCSACERT.TXT
Sat Aug 13 18:40:54 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050810.004\SCRAUTH.DAT
Sat Aug 13 18:40:54 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050810.004\SYMAVENG.CAT
Sat Aug 13 18:40:54 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050810.004\SYMAVENG.INF
Sat Aug 13 18:40:55 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050810.004\TCDEFS.DAT
Sat Aug 13 18:40:55 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050810.004\TCSCAN7.DAT
Sat Aug 13 18:40:55 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050810.004\TCSCAN8.DAT
Sat Aug 13 18:40:55 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050810.004\TCSCAN9.DAT
Sat Aug 13 18:40:55 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050810.004\TECHNOTE.TXT
Sat Aug 13 18:40:55 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050810.004\TINF.DAT
Sat Aug 13 18:40:55 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050810.004\TINFIDX.DAT
Sat Aug 13 18:40:55 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050810.004\TINFL.DAT
Sat Aug 13 18:40:55 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050810.004\TSCAN1.DAT
Sat Aug 13 18:40:55 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050810.004\TSCAN1HD.DAT
Sat Aug 13 18:40:55 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050810.004\UPDATE.TXT
Sat Aug 13 18:40:55 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050810.004\V.GRD
Sat Aug 13 18:40:55 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050810.004\V.SIG
Sat Aug 13 18:40:55 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050810.004\VIRSCAN.INF
Sat Aug 13 18:40:55 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050810.004\VIRSCAN1.DAT
Sat Aug 13 18:40:55 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050810.004\VIRSCAN2.DAT
Sat Aug 13 18:40:56 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050810.004\VIRSCAN3.DAT
Sat Aug 13 18:40:56 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050810.004\VIRSCAN4.DAT
Sat Aug 13 18:40:56 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050810.004\VIRSCAN5.DAT
Sat Aug 13 18:40:56 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050810.004\VIRSCAN6.DAT
Sat Aug 13 18:40:56 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050810.004\VIRSCAN7.DAT
Sat Aug 13 18:40:56 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050810.004\VIRSCAN8.DAT
Sat Aug 13 18:40:56 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050810.004\VIRSCAN9.DAT
Sat Aug 13 18:40:56 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050810.004\VIRSCANT.DAT
Sat Aug 13 18:40:56 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050810.004\vscanmsx.dat
Sat Aug 13 18:40:56 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050810.004\WHATSNEW.TXT
Sat Aug 13 18:40:56 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050810.004\ZDONE.DAT
Sat Aug 13 18:40:56 2005 => Scanning Folder: C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\*.*
Sat Aug 13 18:40:56 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\catalog.dat
Sat Aug 13 18:40:56 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\ecbootil.vxd
Sat Aug 13 18:40:57 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\ecmsvr32.dll
Sat Aug 13 18:40:58 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\hh
Sat Aug 13 18:40:58 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\naveng.exp
Sat Aug 13 18:40:58 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\naveng.sys
Sat Aug 13 18:40:58 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\naveng.vxd
Sat Aug 13 18:40:58 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\naveng32.dll
Sat Aug 13 18:40:58 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\navex15.exp
Sat Aug 13 18:40:58 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\navex15.sys
Sat Aug 13 18:40:59 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\navex15.vxd
Sat Aug 13 18:40:59 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\navex32a.dll
Sat Aug 13 18:40:59 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\ncsacert.txt
Sat Aug 13 18:41:00 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\scrauth.dat
Sat Aug 13 18:41:00 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\symaveng.cat
Sat Aug 13 18:41:00 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\symaveng.inf
Sat Aug 13 18:41:00 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\tcdefs.dat
Sat Aug 13 18:41:00 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\tcscan7.dat
Sat Aug 13 18:41:00 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\tcscan8.dat
Sat Aug 13 18:41:00 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\tcscan9.dat
Sat Aug 13 18:41:00 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\technote.txt
Sat Aug 13 18:41:00 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\tinf.dat
Sat Aug 13 18:41:00 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\tinfidx.dat
Sat Aug 13 18:41:00 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\tinfl.dat
Sat Aug 13 18:41:00 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\tscan1.dat
Sat Aug 13 18:41:01 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\tscan1hd.dat
Sat Aug 13 18:41:01 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\v.grd
Sat Aug 13 18:41:01 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\v.sig
Sat Aug 13 18:41:01 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\virscan.inf
Sat Aug 13 18:41:01 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\virscan1.dat
Sat Aug 13 18:41:01 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\virscan2.dat
Sat Aug 13 18:41:01 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\virscan3.dat
Sat Aug 13 18:41:01 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\virscan4.dat
Sat Aug 13 18:41:01 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\virscan5.dat
Sat Aug 13 18:41:02 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\virscan6.dat
Sat Aug 13 18:41:02 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\virscan7.dat
Sat Aug 13 18:41:02 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\virscan8.dat
Sat Aug 13 18:41:02 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\virscan9.dat
Sat Aug 13 18:41:02 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\VIRSCANT.DAT
Sat Aug 13 18:41:02 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\whatsnew.txt
Sat Aug 13 18:41:02 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub\zdone.dat
Sat Aug 13 18:41:02 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\definfo.dat
Sat Aug 13 18:41:02 2005 => Scanning Folder: C:\Program Files\Common Files\Symantec Shared\VirusDefs\incoming\*.*
Sat Aug 13 18:41:02 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\MyAuth.dat [**]
Sat Aug 13 18:41:02 2005 => Scanning Folder: C:\Program Files\Common Files\Symantec Shared\VirusDefs\Savrt\*.*
Sat Aug 13 18:41:02 2005 => Scanning Folder: C:\Program Files\Common Files\Symantec Shared\VirusDefs\TextHub\*.*
Sat Aug 13 18:41:02 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\TextHub\virscant.dat
Sat Aug 13 18:41:02 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\VirusDefs\usage.dat
Sat Aug 13 18:41:02 2005 => Scanning File C:\Program Files\Common Files\Symantec Shared\WDScnrLK.dll

Sat Aug 13 19:01:31 2005 => Scanning File C:\Program Files\MailScan\LOG\25-11-2002\VirusByMailsRecvd.txt

Sat Aug 13 19:01:32 2005 => Scanning File C:\Program Files\MailScan\LOG\26-11-2002\VirusByMailsRecvd.txt

Sat Aug 13 19:15:01 2005 => File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\053226BB infected by "Trojan-Dropper.Win32.Agent.hh" Virus! Action Taken: No Action Taken.
Sat Aug 13 19:15:01 2005 => File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\053226BB infected by "Trojan-Dropper.Win32.Agent.hh" Virus! Action Taken: No Action Taken.

Sat Aug 13 19:15:01 2005 => Scanning File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\053550B7
Sat Aug 13 19:15:02 2005 => File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\053550B7 tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.

Sat Aug 13 19:15:02 2005 => Scanning File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\053C24B0
Sat Aug 13 19:15:02 2005 => File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\053C24B0 tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.

Sat Aug 13 19:15:02 2005 => Scanning File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\053F4EAC
Sat Aug 13 19:15:02 2005 => File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\053F4EAC tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.

Sat Aug 13 19:15:02 2005 => Scanning File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\054278A9
Sat Aug 13 19:15:02 2005 => Scanning File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\054622A5
Sat Aug 13 19:15:02 2005 => File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\054622A5 tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.

Sat Aug 13 19:15:02 2005 => Scanning File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\0B1768AF
Sat Aug 13 19:15:03 2005 => File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\0B1768AF infected by "Trojan.Win32.StartPage.nk" Virus! Action Taken: No Action Taken.

Sat Aug 13 19:15:03 2005 => Scanning File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\122B1ABF
Sat Aug 13 19:15:03 2005 => File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\122B1ABF tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.

Sat Aug 13 19:15:03 2005 => Scanning File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1545242D
Sat Aug 13 19:15:03 2005 => File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1545242D tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.

Sat Aug 13 19:15:03 2005 => Scanning File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\16A724AE
Sat Aug 13 19:15:03 2005 => File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\16A724AE tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.

Sat Aug 13 19:15:03 2005 => Scanning File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1C891864
Sat Aug 13 19:15:03 2005 => File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1C891864 tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.

Sat Aug 13 19:15:03 2005 => Scanning File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1C8C4260
Sat Aug 13 19:15:04 2005 => File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\1C8C4260 tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.

Sat Aug 13 19:15:04 2005 => Scanning File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\36E35672
Sat Aug 13 19:15:04 2005 => File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\36E35672 tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.

Sat Aug 13 19:15:04 2005 => Scanning File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\36E7006F
Sat Aug 13 19:15:04 2005 => File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\36E7006F tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.

Sat Aug 13 19:15:04 2005 => Scanning File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\39BF4EB1
Sat Aug 13 19:15:04 2005 => File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\39BF4EB1 tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.

Sat Aug 13 19:15:04 2005 => Scanning File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\3A660470
Sat Aug 13 19:15:05 2005 => File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\3A660470 tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.

Sat Aug 13 19:15:05 2005 => Scanning File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\3E3E17F4
Sat Aug 13 19:15:05 2005 => File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\3E3E17F4 tagged as "not-a-virus:AdWare.PurityScan.w". Action Taken: No Action Taken.

Sat Aug 13 19:15:05 2005 => Scanning File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\454F0AB0
Sat Aug 13 19:15:05 2005 => File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\454F0AB0 infected by "Trojan.Win32.StartPage.nk" Virus! Action Taken: No Action Taken.

Sat Aug 13 19:15:05 2005 => Scanning File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\47AE7D6A
Sat Aug 13 19:15:05 2005 => File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\47AE7D6A tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.

Sat Aug 13 19:15:05 2005 => Scanning File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\50DF46AE
Sat Aug 13 19:15:05 2005 => Scanning File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\57F378BE
Sat Aug 13 19:15:06 2005 => File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\57F378BE tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.

Sat Aug 13 19:15:06 2005 => Scanning File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\5A440A8A
Sat Aug 13 19:15:06 2005 => File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\5A440A8A tagged as "not-a-virus:AdWare.ToolBar.EliteBar.af". Action Taken: No Action Taken.

Sat Aug 13 19:15:06 2005 => Scanning File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\5A473487
Sat Aug 13 19:15:06 2005 => Scanning File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\618C2ED2
Sat Aug 13 19:15:07 2005 => File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\618C2ED2 tagged as "not-a-virus:AdWare.Pacer.j". Action Taken: No Action Taken.

Sat Aug 13 19:15:07 2005 => Scanning File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\66703D65
Sat Aug 13 19:15:07 2005 => File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\66703D65 tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.

Sat Aug 13 19:15:07 2005 => Scanning File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\6CFA14D6
Sat Aug 13 19:15:07 2005 => File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\6CFA14D6 tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.



Sat Aug 13 20:18:12 2005 => File C:\WINDOWS\SYSTEM32\eyentlog.dll tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.


Sat Aug 13 20:18:12 2005 => Scanning File C:\WINDOWS\SYSTEM32\f20olcd31f0.dll
Sat Aug 13 20:18:12 2005 => File C:\WINDOWS\SYSTEM32\f20olcd31f0.dll tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.


Sat Aug 13 20:18:49 2005 => File C:\WINDOWS\SYSTEM32\jt6807jue.dll tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.

Sat Aug 13 18:06:30 2005 => Scanning File C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\STQF0TAJ\Trojan_Hunter[1].png

Sat Aug 13 20:18:49 2005 => Scanning File C:\WINDOWS\SYSTEM32\jupdate-1.5.0_01-b08.log
Sat Aug 13 20:18:50 2005 => Scanning File C:\WINDOWS\SYSTEM32\jupdate-1.5.0_02-b09.log
Sat Aug 13 20:18:50 2005 => Scanning File C:\WINDOWS\SYSTEM32\jview.exe
Sat Aug 13 20:18:50 2005 => Scanning File C:\WINDOWS\SYSTEM32\k6800glme6qa0.dll
Sat Aug 13 20:18:50 2005 => File C:\WINDOWS\SYSTEM32\k6800glme6qa0.dll tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.

Sat Aug 13 20:20:05 2005 => File C:\WINDOWS\SYSTEM32\mistkprp.dll tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.

Sat Aug 13 20:20:10 2005 => File C:\WINDOWS\SYSTEM32\mqdtctm.dll tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.

Sat Aug 13 19:15:05 2005 => File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\454F0AB0 infected by "Trojan.Win32.StartPage.nk" Virus! Action Taken: No Action Taken.


Sat Aug 13 18:01:05 2005 => File C:\Documents and Settings\LocalService\Desktop\santafree.exe tagged as "not-a-virus:AdWare.SaveNow.z". Action Taken: No Action Taken.






Sat Aug 13 19:15:02 2005 => Scanning File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\0B1768AF
Sat Aug 13 19:15:03 2005 => File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\0B1768AF infected by "Trojan.Win32.StartPage.nk" Virus! Action Taken: No Action Taken.

Sat Aug 13 19:15:05 2005 => Scanning File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\454F0AB0
Sat Aug 13 19:15:05 2005 => File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\454F0AB0 infected by "Trojan.Win32.StartPage.nk" Virus! Action Taken: No Action Taken.

Sat Aug 13 17:46:02 2005 => Scanning File C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20050810.004\NAVEX15.SYS


Sat Aug 13 20:25:02 2005 => ***** Scanning complete. *****

Sat Aug 13 20:25:02 2005 => Total Objects Scanned: 84307
Sat Aug 13 20:25:02 2005 => Total Virus(es) Found: 61
Sat Aug 13 20:25:02 2005 => Total Disinfected Files: 0

Edited by Amateur Geek, 13 August 2005 - 10:43 PM.

  • 0

Advertisements


#32
Excal

Excal

    Malware Slayer Extraordinaire!

  • Retired Staff
  • 12,739 posts
We got to get Ltmfix to work, it didn't work the first time around, now I can see the evidence of that.

Run CleanUp! again


Please try this again: (tell me what exactly happens, make sure you let it do everything it needs to)

Close any programs you have open since this step requires a reboot.
  • From the l2mfix folder on your desktop, double click l2mfix.bat and select option #2 for Run Fix by typing 2 and then pressing enter
  • Press any key to reboot your computer.
  • After a reboot, your desktop and icons will appear, then disappear (this is normal). L2mfix will continue to scan your computer and when it's finished, notepad will open with a log.
  • Copy the contents of log and paste it back into this thread, along with a new hijackthis log, and we'll clean up what's left. :tazz:
IMPORTANT: Do NOT run any other files in the l2mfix folder unless you are asked to do so!
  • 0

#33
Amateur Geek

Amateur Geek

    Member

  • Topic Starter
  • Member
  • PipPip
  • 24 posts
Hello Excal,
I downloaded cleanup to my desktop; ran ; it said it cleaned up a whole list of file; a few minutes went by and is said clean up! done. I clicked something? like finish and it said that it will reboot and suggested a second clean up for what was running during clean up so I restarted and ran clean up again; it still had a list of 40 or so items; I restarted again. I double clicked a folder on y desktop l2mfix; within it there were several icons...one was l2mfix (batch) so I clicked that. Then a black like box came up with a header that said C:WINDOWS\System32\cmd.exe and then it said "a sub directory file back regs already exists...blah blah" press any key to continue so I did
Then L2MFIX Tool by Shadowwar camp up and I chose option 2 and it said something like regs permiss set will reboot now and it did.
What it did not do upon the reboot its what you said about icons disappearing--icons simply appeared as always but did not then disappear. A notepad did not pop up with a log so after a while I went into the l2mfix folder with all the icons and choose one that said report that was modified at the date and time I rran this so hopefully this is what you want...along with a hjt log. Sorry to be so wordy but I want to give you the full picture.
Thanks
A.G.
L2Mfix 1.03a

Running From:
C:\Documents and Settings\Owner\Desktop\l2mfix



RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(CI) DENY --C------- BUILTIN\Administrators
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER



Setting registry permissions:


RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!


Denying C(CI) access for predefined group "Administrators"
- adding new ACCESS DENY entry
- removing existing ACCESS DENY entry


Registry Permissions set too:

RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(CI) DENY --C------- BUILTIN\Administrators
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER



Setting up for Reboot


Starting Reboot!
Logfile of HijackThis v1.99.1
Scan saved at 10:19:29 PM, on 08/13/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\windows\system\hpsysdrv.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
C:\WINDOWS\System32\snmp.exe
C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.c.../search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.c...//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.c...//www.yahoo.com
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [AcctMgr] C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe /startup
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [second] C:\Documents and Settings\Owner\Desktop\l2mfix\second.bat
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1123635268359
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft...free/asinst.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) - http://www.windowsec...scan/axscan.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
  • 0

#34
Amateur Geek

Amateur Geek

    Member

  • Topic Starter
  • Member
  • PipPip
  • 24 posts
One more thing (I am telling you this from reading other logs) my HiJack This is on my desktop and has been for each run...is that okay?
  • 0

#35
Excal

Excal

    Malware Slayer Extraordinaire!

  • Retired Staff
  • 12,739 posts
Desktop is fine ;), although you should have it in its own folder.

run option 2 again on LTM. when it reboots and does nothing. Open the LTM folder and double click on second.bat. let it do its buisness and let me know if that produces a log.


Thanks,

:tazz:

Excal
  • 0

#36
Amateur Geek

Amateur Geek

    Member

  • Topic Starter
  • Member
  • PipPip
  • 24 posts
Hi Excal,
I've been on the internet today and I have not had a single pop up!!!! I have not done the last step you recommended...should I still do it?
Thanks!
AG
  • 0

#37
Excal

Excal

    Malware Slayer Extraordinaire!

  • Retired Staff
  • 12,739 posts
Yes please


Thanks,

:tazz:

Excal
  • 0

#38
Amateur Geek

Amateur Geek

    Member

  • Topic Starter
  • Member
  • PipPip
  • 24 posts
alas a log!!!
would you like another hijack this log too?

L2Mfix 1.03a

Running From:
C:\Documents and Settings\Owner\Desktop\l2mfix



RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(CI) DENY --C------- BUILTIN\Administrators
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER



Setting registry permissions:


RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!


Denying C(CI) access for predefined group "Administrators"
- adding new ACCESS DENY entry
- removing existing ACCESS DENY entry


Registry Permissions set too:

RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(CI) DENY --C------- BUILTIN\Administrators
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER



Setting up for Reboot


Starting Reboot!

Setting Directory
C:\Documents and Settings\Owner\Desktop\l2mfix
C:\Documents and Settings\Owner\Desktop\l2mfix
System Rebooted!

Running From:
C:\Documents and Settings\Owner\Desktop\l2mfix

killing explorer and rundll32.exe

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 [email protected]
Killing PID 1484 'explorer.exe'

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 [email protected]
Error, Cannot find a process with an image name of rundll32.exe

Scanning First Pass. Please Wait!

First Pass Completed

Second Pass Scanning

Second pass Completed!
Backing Up: C:\WINDOWS\system32\eyentlog.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\f20olcd31f0.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\fp0m03d1e.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\jt6807jue.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\k6800glme6qa0.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\mbratelc.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\MEIMRT32.DLL
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\mistkprp.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\mqdtctm.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\mwvideo.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\newrsit.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\nowrszht.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\ozcache.dll
1 file(s) copied.
Backing Up: C:\WINDOWS\system32\rncss.dll
1 file(s) copied.
deleting: C:\WINDOWS\system32\eyentlog.dll
Successfully Deleted: C:\WINDOWS\system32\eyentlog.dll
deleting: C:\WINDOWS\system32\f20olcd31f0.dll
Successfully Deleted: C:\WINDOWS\system32\f20olcd31f0.dll
deleting: C:\WINDOWS\system32\fp0m03d1e.dll
Successfully Deleted: C:\WINDOWS\system32\fp0m03d1e.dll
deleting: C:\WINDOWS\system32\jt6807jue.dll
Successfully Deleted: C:\WINDOWS\system32\jt6807jue.dll
deleting: C:\WINDOWS\system32\k6800glme6qa0.dll
Successfully Deleted: C:\WINDOWS\system32\k6800glme6qa0.dll
deleting: C:\WINDOWS\system32\mbratelc.dll
Successfully Deleted: C:\WINDOWS\system32\mbratelc.dll
deleting: C:\WINDOWS\system32\MEIMRT32.DLL
Successfully Deleted: C:\WINDOWS\system32\MEIMRT32.DLL
deleting: C:\WINDOWS\system32\mistkprp.dll
Successfully Deleted: C:\WINDOWS\system32\mistkprp.dll
deleting: C:\WINDOWS\system32\mqdtctm.dll
Successfully Deleted: C:\WINDOWS\system32\mqdtctm.dll
deleting: C:\WINDOWS\system32\mwvideo.dll
Successfully Deleted: C:\WINDOWS\system32\mwvideo.dll
deleting: C:\WINDOWS\system32\newrsit.dll
Successfully Deleted: C:\WINDOWS\system32\newrsit.dll
deleting: C:\WINDOWS\system32\nowrszht.dll
Successfully Deleted: C:\WINDOWS\system32\nowrszht.dll
deleting: C:\WINDOWS\system32\ozcache.dll
Successfully Deleted: C:\WINDOWS\system32\ozcache.dll
deleting: C:\WINDOWS\system32\rncss.dll
Successfully Deleted: C:\WINDOWS\system32\rncss.dll


Zipping up files for submission:
adding: eyentlog.dll (188 bytes security) (deflated 4%)
adding: f20olcd31f0.dll (188 bytes security) (deflated 4%)
adding: fp0m03d1e.dll (188 bytes security) (deflated 4%)
adding: jt6807jue.dll (188 bytes security) (deflated 4%)
adding: k6800glme6qa0.dll (188 bytes security) (deflated 5%)
adding: mbratelc.dll (188 bytes security) (deflated 4%)
adding: MEIMRT32.DLL (188 bytes security) (deflated 4%)
adding: mistkprp.dll (188 bytes security) (deflated 4%)
adding: mqdtctm.dll (188 bytes security) (deflated 4%)
adding: mwvideo.dll (188 bytes security) (deflated 4%)
adding: newrsit.dll (188 bytes security) (deflated 4%)
adding: nowrszht.dll (188 bytes security) (deflated 5%)
adding: ozcache.dll (188 bytes security) (deflated 4%)
adding: rncss.dll (188 bytes security) (deflated 4%)
adding: clear.reg (188 bytes security) (deflated 22%)
adding: echo.reg (188 bytes security) (deflated 9%)
adding: direct.txt (188 bytes security) (stored 0%)
adding: lo2.txt (188 bytes security) (deflated 80%)
adding: readme.txt (188 bytes security) (deflated 49%)
adding: report.txt (188 bytes security) (deflated 65%)
adding: test.txt (188 bytes security) (deflated 74%)
adding: test2.txt (188 bytes security) (stored 0%)
adding: test3.txt (188 bytes security) (stored 0%)
adding: test5.txt (188 bytes security) (stored 0%)
adding: xfind.txt (188 bytes security) (deflated 67%)
adding: backregs/BCF122A4-FACD-453D-95E7-F84848565C8A.reg (188 bytes security) (deflated 70%)
adding: backregs/notibac.reg (188 bytes security) (deflated 87%)
adding: backregs/shell.reg (188 bytes security) (deflated 73%)

Restoring Registry Permissions:


RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!


Revoking access for predefined group "Administrators"
Inherited ACE can not be revoked here!
Inherited ACE can not be revoked here!


Registry permissions set too:

RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER


Restoring Sedebugprivilege:

Granting SeDebugPrivilege to Administrators ... successful

deleting local copy: eyentlog.dll
deleting local copy: f20olcd31f0.dll
deleting local copy: fp0m03d1e.dll
deleting local copy: jt6807jue.dll
deleting local copy: k6800glme6qa0.dll
deleting local copy: mbratelc.dll
deleting local copy: MEIMRT32.DLL
deleting local copy: mistkprp.dll
deleting local copy: mqdtctm.dll
deleting local copy: mwvideo.dll
deleting local copy: newrsit.dll
deleting local copy: nowrszht.dll
deleting local copy: ozcache.dll
deleting local copy: rncss.dll

The following Is the Current Export of the Winlogon notify key:
****************************************************************************
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001


The following are the files found:
****************************************************************************
C:\WINDOWS\system32\eyentlog.dll
C:\WINDOWS\system32\f20olcd31f0.dll
C:\WINDOWS\system32\fp0m03d1e.dll
C:\WINDOWS\system32\jt6807jue.dll
C:\WINDOWS\system32\k6800glme6qa0.dll
C:\WINDOWS\system32\mbratelc.dll
C:\WINDOWS\system32\MEIMRT32.DLL
C:\WINDOWS\system32\mistkprp.dll
C:\WINDOWS\system32\mqdtctm.dll
C:\WINDOWS\system32\mwvideo.dll
C:\WINDOWS\system32\newrsit.dll
C:\WINDOWS\system32\nowrszht.dll
C:\WINDOWS\system32\ozcache.dll
C:\WINDOWS\system32\rncss.dll

Registry Entries that were Deleted:
Please verify that the listing looks ok.
If there was something deleted wrongly there are backups in the backreg folder.
****************************************************************************
REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{BCF122A4-FACD-453D-95E7-F84848565C8A}"=-
[-HKEY_CLASSES_ROOT\CLSID\{BCF122A4-FACD-453D-95E7-F84848565C8A}]
REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"SV1"=""
****************************************************************************
Desktop.ini Contents:
****************************************************************************
****************************************************************************

  • 0

#39
Excal

Excal

    Malware Slayer Extraordinaire!

  • Retired Staff
  • 12,739 posts
yes!!!!! Much better....woot!


Yes please :tazz:



Excal
  • 0

#40
Amateur Geek

Amateur Geek

    Member

  • Topic Starter
  • Member
  • PipPip
  • 24 posts
What do you think?
AG

Logfile of HijackThis v1.99.1
Scan saved at 12:52:09 PM, on 08/14/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
C:\WINDOWS\System32\snmp.exe
C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\windows\system\hpsysdrv.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZSTC06.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZENG06.EXE
C:\hijackthis\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.c.../search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.c...//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.c...//www.yahoo.com
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [AcctMgr] C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe /startup
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1123635268359
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft...free/asinst.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) - http://www.windowsec...scan/axscan.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
  • 0

Advertisements


#41
Excal

Excal

    Malware Slayer Extraordinaire!

  • Retired Staff
  • 12,739 posts
Great job, it appears your computer is clean :tazz:

Ensure you rehide your “hidden files and folders” back to the way they were.

Now that your system is Malware Free, it is important to reset your system Restore. Click Here to learn how to.

Might I suggest the following Free Spyware programs, if you don't already have them, for added security, you can download them at the following links. These programs work great for detection:

Ad-aware SE
Spybot S&D
Microsoft Anti-Spyware


If you are unhappy with your current antivirus and want to replace it or if you dont already have one, I suggest one of these free programs:
*Note - do not use more than one anti-virus program as it will more than likely cause conflict.

AVG
Avast
AntiVir


The following free programs are great for prevention:

SpywareBlaster 3.4
Spywareguard
IE/Spyad

A Firewall is a must! Here are 3 good free versions:
(do not have more than one firewall running on your system)

Sygate
Kerio
ZoneLabs

There are other options other than Internet Explorer for a browser, which some say have better security. Two of them are:

Firefox
Opera

If you decide to keep Internet Explorer, This site is a great source for tightening up security on It's settings.

Make sure that you keep your Operating System and IE updated with the latest Critical Security Updates from Microsoft...they usually come out once a month, on the 2nd Tuesday of each month.

Be sure and give the Temp folders a cleaning out now and then as well, Make sure after you clean your Temp files to empty out your Recycle bin as well.
For ease use the following program:

Cleanup
Run "Cleanup" and when it has finished, Reboot

To help prevent future spyware installations/infections, please read the Anti-Spyware Tutorial and use the tools provided. Also read How I got Infected
  • 0

#42
Amateur Geek

Amateur Geek

    Member

  • Topic Starter
  • Member
  • PipPip
  • 24 posts
Excal...you are the best!!!!!
  • 0

#43
Excal

Excal

    Malware Slayer Extraordinaire!

  • Retired Staff
  • 12,739 posts
Thanks ;)


Good luck and safe surfing :)

:tazz:

Excal
  • 0

#44
Amateur Geek

Amateur Geek

    Member

  • Topic Starter
  • Member
  • PipPip
  • 24 posts
Hi Excal,
1. I am embarrassed at some of my questions but...when you say to ensure I rehide "hidden files and folders" I can't remember that far back...what exactly am I looking for and what do I want to hide (and why?)...and how?

2. In regards to system restore, should I run clean up first? When I went to system restore it was "off" already so are you saying to turn it back on (did we turn it off in this process?). When I saw that it was off I went ahead and rebooted and then I turned it on. Is that the goal? Everytime I run clean up should I have it off and then reboot and turn it back on?

3. Should I keep edwido with Norton --do they do different things?

4. I noticed when we were finally through with WINFIXER my mozilla/firefox icon on my desktop was gone...I also noticed that the problems were more severe (with Winfixer) when I used that browser and the problems began around the time my husband put that browser on my desktop...do you think it came from that download?

5. I think you are awesome to give your time this way :tazz: Thank you a million times!
  • 0

#45
Excal

Excal

    Malware Slayer Extraordinaire!

  • Retired Staff
  • 12,739 posts

1.  I am embarrassed at some of my questions but...when you say to ensure I rehide "hidden files and folders" I can't remember that far back...what exactly am I looking for and what do I want to hide (and why?)...and how?


Go to My Computer >Tools >Folder Options >View tab and make
sure that Do not show hidden files and folders is checked. Check the
Hide extensions for known file types and Hide protected
operating system files option.


2.  In regards to system restore, should I run clean up first? When I went to system restore it was "off" already so are you saying to turn it back on (did we turn it off in this process?).  When I saw that it was off I went ahead and rebooted and then I turned it on.  Is that the goal?  Everytime I run clean up should I have it off and then reboot and turn it back on?


What system restore does is save a point where your computer was running with no problems. Then if you ever run into problems and can't fix them, you can go to the sytem restore program and go back to that date where your saved.
Here are the direction for setting a restore point:

Turn off System Restore by Clicking Start > right-click My Computer and then click Properties. Click the System Restore tab > Check "Turn off System Restore" or "Turn off System Restore on all drives". Click Apply. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this. Click OK.

Reboot your System.

To turn on System Restore by Clicking Start. Right-click My Computer, and then click Properties. Click the System Restore tab. Uncheck "Turn off System Restore" or "Turn off System Restore on all drives." Click Apply, and then OK.

3.  Should I keep ewido with Norton --do they do different things?

Ewido and Norton are each a scanner. But Norton is realtime protection and a preventor and does more things(although Ewido can be set to do real time protection not nearly has good an the Norton Package) Ewdio is only a trial ;)

4.  I noticed when we were finally through with WINFIXER my mozilla/firefox icon on my desktop was gone...I also noticed that the problems were more severe (with Winfixer) when I used that browser and the problems began around the time my husband put that browser on my desktop...do you think it came from that download?


Do get the Icon back on your desktop. Go to start>all programs and go to Modzilla Firefox. when you highlight that you will see the option for Firefox. Put ur mouse over it and right click, select copy. Then paste it on your desktop. Firefox is a safer browser than IE, i would suggest using only IE for windows updates.

Thank you a million times!


Your welcome a trillion times :)


Hope that helps.

:tazz:

Excal
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP