Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

SpyAxe and others


  • Please log in to reply

#1
irishsig

irishsig

    Member

  • Member
  • PipPip
  • 11 posts
:tazz:

Not sure how it ended up on the system. followed procedures as requested. was unable to run the batch file under smitRem.exe and Cwshredder. all others ran. did run clean4 and allowed temp folders to be hit. Also, unable to get spyaxefix.exe at listed links.

Trojanhunter and adware-se removed a number of items, but still have a hijacked IE and getting the virus warnings. Panda found additional files, malware and adware. Ran programs again, found nothing. Panda found additional files again.

listed are HijackThis before 2nd run and after 2nd run of programs. also listed are ewido scan report, panda active scan report, and cleanup report.

you'll see mcafee items in there - have removed mcafee even through their tech support but files still post althogh shown as missing or deleted.

ready to throw the system out the window.

*******1st Hijack scan report**********

Logfile of HijackThis v1.99.1
Scan saved at 11:07:18 AM, on 12/14/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\system32\mssearchnet.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\DIGStream\digstream.exe
C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Zero Knowledge\Freedom\Freedom.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HijackThis\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
O2 - BHO: HomepageBHO - {1ca480cd-c0e5-4548-874e-b85b17905b3a} - C:\WINDOWS\system32\hp8C6C.tmp
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: SecurityToolbar - {736b5468-bdad-41be-92d0-22ae2ddf7bcb} - C:\Program Files\Security Toolbar\Security Toolbar.dll (file missing)
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Freedom] C:\Program Files\Zero Knowledge\Freedom\Freedom.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [SpyAxe] C:\Program Files\SpyAxe\spyaxe.exe /h
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Event Reminder.lnk = C:\Program Files\PrintMaster 16\pmremind.exe
O4 - Global Startup: Exif Launcher.lnk = ?
O4 - Global Startup: Forget Me Not.lnk = C:\Program Files\Broderbund\AG CreataCard\AGremind.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://bar.mywebsear...?p=zuzeb004YYUS
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell....iler/SysPro.CAB
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.kodakgall..._1/axofupld.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://webchat.dell...t/TLIEFlash.CAB
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee AntiSpyware Real-Time Scanner (McAfeeAntiSpyware) - Unknown owner - c:\progra~1\mcafee\MCAFEE~1\MssSrv.exe (file missing)
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe (file missing)
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Unknown owner - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe (file missing)
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe (file missing)
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe



*************2nd Hijack scan report****************


Logfile of HijackThis v1.99.1
Scan saved at 3:04:47 PM, on 12/14/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\mssearchnet.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\DIGStream\digstream.exe
C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Zero Knowledge\Freedom\Freedom.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msnbc.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Freedom] C:\Program Files\Zero Knowledge\Freedom\Freedom.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Event Reminder.lnk = C:\Program Files\PrintMaster 16\pmremind.exe
O4 - Global Startup: Exif Launcher.lnk = ?
O4 - Global Startup: Forget Me Not.lnk = C:\Program Files\Broderbund\AG CreataCard\AGremind.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://bar.mywebsear...?p=zuzeb004YYUS
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell....iler/SysPro.CAB
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.kodakgall..._1/axofupld.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://webchat.dell...t/TLIEFlash.CAB
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee AntiSpyware Real-Time Scanner (McAfeeAntiSpyware) - Unknown owner - c:\progra~1\mcafee\MCAFEE~1\MssSrv.exe (file missing)
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe (file missing)
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Unknown owner - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe (file missing)
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe (file missing)
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe


****************Clean Up Report************************

CleanUp! started on 12/14/05 13:02:20.
...
C:\WINDOWS\Prefetch\ITUNESHELPER.EXE-0A1B0F2C.pf - deleted
C:\WINDOWS\Prefetch\JAVAW.EXE-2D38EF8E.pf - deleted
C:\WINDOWS\Prefetch\Layout.ini - deleted
C:\WINDOWS\Prefetch\LD61C9.TMP-092B8A6A.pf - deleted
C:\WINDOWS\Prefetch\LD9952.TMP-066AD7F1.pf - deleted
C:\WINDOWS\Prefetch\LDBC38.TMP-33FB2D8F.pf - deleted
C:\WINDOWS\Prefetch\LDCFC5.TMP-1E62C330.pf - deleted
C:\WINDOWS\Prefetch\LDE800.TMP-2415452C.pf - deleted
C:\WINDOWS\Prefetch\LDFE0.TMP-06453680.pf - deleted
C:\WINDOWS\Prefetch\LOGONUI.EXE-312BE1BF.pf - deleted
C:\WINDOWS\Prefetch\MIGRATIONR.EXE-333F41DC.pf - deleted
C:\WINDOWS\Prefetch\MSCONFIG.EXE-1EF1EA0F.pf - deleted
C:\WINDOWS\Prefetch\MSCORNET.EXE-315EF379.pf - deleted
C:\WINDOWS\Prefetch\MSIEXEC.EXE-330626DC.pf - deleted
C:\WINDOWS\Prefetch\MSMSGS.EXE-0620E8B3.pf - deleted
C:\WINDOWS\Prefetch\MSNUNIN.EXE-20B56B94.pf - deleted
C:\WINDOWS\Prefetch\MSSEARCHNET.EXE-36109133.pf - deleted
C:\WINDOWS\Prefetch\MTSAXINSTALLER.EXE-0CA7D990.pf - deleted
C:\WINDOWS\Prefetch\MUN32.EXE-0602431E.pf - deleted
C:\WINDOWS\Prefetch\NOTEPAD.EXE-2F2D61E1.pf - deleted
C:\WINDOWS\Prefetch\NTOSBOOT-B00DFAAD.pf - deleted
C:\WINDOWS\Prefetch\NVCTRL.EXE-325F48B7.pf - deleted
C:\WINDOWS\Prefetch\OSA.EXE-28494AD2.pf - deleted
C:\WINDOWS\Prefetch\OUTLOOK.EXE-013F1C9B.pf - deleted
C:\WINDOWS\Prefetch\PCMSERVICE.EXE-3369AF87.pf - deleted
C:\WINDOWS\Prefetch\PHOTOED.EXE-21D745D3.pf - deleted
C:\WINDOWS\Prefetch\POINT32.EXE-0C2C2E7E.pf - deleted
C:\WINDOWS\Prefetch\PPCLEAN.EXE-1CED121C.pf - deleted
C:\WINDOWS\Prefetch\QUICKDCF.EXE-2244BD53.pf - deleted
C:\WINDOWS\Prefetch\REALSCHED.EXE-0948A6AF.pf - deleted
C:\WINDOWS\Prefetch\REGEDIT.EXE-2AE3423E.pf - deleted
C:\WINDOWS\Prefetch\REGSHAVE.EXE-17FD6DA6.pf - deleted
C:\WINDOWS\Prefetch\REGSVR32.EXE-396DEA2C.pf - deleted
C:\WINDOWS\Prefetch\RUNDLL32.EXE-3C3D2C88.pf - deleted
C:\WINDOWS\Prefetch\RUNDLL32.EXE-3E20222E.pf - deleted
C:\WINDOWS\Prefetch\RUNDLL32.EXE-3F21C0BC.pf - deleted
C:\WINDOWS\Prefetch\RUNDLL32.EXE-3F27BCE3.pf - deleted
C:\WINDOWS\Prefetch\RUNDLL32.EXE-4212F935.pf - deleted
C:\WINDOWS\Prefetch\RUNDLL32.EXE-4D2C1652.pf - deleted
C:\WINDOWS\Prefetch\RUNDLL32.EXE-4DED6A50.pf - deleted
C:\WINDOWS\Prefetch\RUNDLL32.EXE-4FF9832D.pf - deleted
C:\WINDOWS\Prefetch\RUNDLL32.EXE-55E8DFE1.pf - deleted
C:\WINDOWS\Prefetch\RUNDLL32.EXE-5645E36A.pf - deleted
C:\WINDOWS\Prefetch\RUNDLL32.EXE-5E0F7F9E.pf - deleted
C:\WINDOWS\Prefetch\RUNDLL32.EXE-64D5C71E.pf - deleted
C:\WINDOWS\Prefetch\RUNDLL32.EXE-6550F4D5.pf - deleted
C:\WINDOWS\Prefetch\RUNDLL32.EXE-6E0B06E4.pf - deleted
C:\WINDOWS\Prefetch\RUNDLL32.EXE-6E8D4657.pf - deleted
C:\WINDOWS\Prefetch\SA28.EXE-3026C48E.pf - deleted
C:\WINDOWS\Prefetch\SA4E.EXE-2B0D1464.pf - deleted
C:\WINDOWS\Prefetch\SA55.EXE-1F6F9256.pf - deleted
C:\WINDOWS\Prefetch\SA5B.EXE-293D16BB.pf - deleted
C:\WINDOWS\Prefetch\SA65.EXE-078F3071.pf - deleted
C:\WINDOWS\Prefetch\SAPISVR.EXE-33D597B4.pf - deleted
C:\WINDOWS\Prefetch\SECURITYSUITE.EXE-2EFD625D.pf - deleted
C:\WINDOWS\Prefetch\SHMGRATE.EXE-2DD3E4D8.pf - deleted
C:\WINDOWS\Prefetch\SMITREM.EXE-0CCD880E.pf - deleted
C:\WINDOWS\Prefetch\SP1B_UPGRADE.EXE-38A8CC9F.pf - deleted
C:\WINDOWS\Prefetch\SPYAXE.EXE-10E9F12A.pf - deleted
C:\WINDOWS\Prefetch\SSMYPICS.SCR-2B33A3BB.pf - deleted
C:\WINDOWS\Prefetch\SWITCHMONITOR.EXE-1C8343AD.pf - deleted
C:\WINDOWS\Prefetch\SWREG.EXE-3B643347.pf - deleted
C:\WINDOWS\Prefetch\SYSOCMGR.EXE-07A918BD.pf - deleted
C:\WINDOWS\Prefetch\TASKMGR.EXE-06144C13.pf - deleted
C:\WINDOWS\Prefetch\TFSWCTRL.EXE-2D67C816.pf - deleted
C:\WINDOWS\Prefetch\TYPE32.EXE-346CA305.pf - deleted
C:\WINDOWS\Prefetch\UNINSTALL.EXE-09DF0ADA.pf - deleted
C:\WINDOWS\Prefetch\UNINSTALL.EXE-3B585B47.pf - deleted
C:\WINDOWS\Prefetch\UPDREG.EXE-1FDD8DC3.pf - deleted
C:\WINDOWS\Prefetch\USERINIT.EXE-0743FDA9.pf - deleted
C:\WINDOWS\Prefetch\VIEWMGRINSTALLER.EXE-063E8957.pf - deleted
C:\WINDOWS\Prefetch\VMGRREMOK.EXE-278BF469.pf - deleted
C:\WINDOWS\Prefetch\VMPREMOV.EXE-12AFD40B.pf - deleted
C:\WINDOWS\Prefetch\WINLOGON.EXE-0957F9B2.pf - deleted
C:\WINDOWS\Prefetch\WINWORD.EXE-0614BEA2.pf - deleted
C:\WINDOWS\Prefetch\WMIADAP.EXE-32F99497.pf - deleted
C:\WINDOWS\Prefetch\WMIPRVSE.EXE-0D449B4F.pf - deleted
C:\WINDOWS\Prefetch\WMPLAYER.EXE-1ACCF80E.pf - deleted
C:\WINDOWS\Prefetch\WSCNTFY.EXE-0B14C27D.pf - deleted
C:\WINDOWS\Prefetch\WSCRIPT.EXE-0C5C5251.pf - deleted
C:\WINDOWS\Prefetch\WUAUCLT.EXE-1360D60A.pf - deleted
C:\WINDOWS\Prefetch\XOFTSPY.EXE-0035CD67.pf - deleted
C:\WINDOWS\Prefetch\XOFTSPY421_136.EXE-01D0769F.pf - deleted
C:\WINDOWS\Prefetch\ZCLIENTM.EXE-2CFD74E5.pf - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cac10.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cac11.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cac12.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cac13.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cac14.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cac15.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cac16.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cac17.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cac18.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cac19.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cac1A.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cac1B.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cac1C.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cac1D.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cac1E.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cac1F.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cac20.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cac21.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cac22.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cac228.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cac23.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cac25.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cac26.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cac26E.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cac29.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cac2C.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cac2D.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cac2E.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cac2F.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cac32.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cac33.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cac34.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cac35.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cac36.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cac37.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cac38.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cac3A.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cac3B.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cac3C.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cac44.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cac5B.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cac7.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cac8.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cac9.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cacA.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cacB.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cacB5A5.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cacD.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cacE.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\cacF.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac100.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac10E.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac115.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac118.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac13C.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac15F.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac183.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac1AF.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac1D3.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac1E4.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac1F6.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac1F7.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac210.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac246.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac254.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac259.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac25C.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac262.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac263.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac272.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac284.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac289.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac295.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac29F.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac2C7.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac2D8.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac2EB.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac2F5.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac2FC.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac31E.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac32A.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac34A.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac371.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac377.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac387.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac388.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac389.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac38D.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac392.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac39E.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac3A3.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac3C3.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac3FC.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac40C.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac412.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac426.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac438.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac445.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac446.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac447.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac45.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac45C.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac468.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac48D.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac48E.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac4BE.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac4FC.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac504.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac52.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac5AD.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac5B4.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac5D4.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac5D6.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac60.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac61.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac62.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac65.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac82.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac89.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cac8A.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cacAE.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cacAF.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cacBA.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cacBB.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cacCF.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cacD5.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cacE6.tmp - deleted
C:\Documents and Settings\All Users\Application Data\DIGStream\ESPNMotion\cacF0.tmp - deleted
C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch1\lock.tmp - deleted
C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch2\lock.tmp - deleted
C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch3\lock.tmp - deleted
C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch4\lock.tmp - deleted
C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\Cache\McSubDB.Bak - deleted
C:\Documents and Settings\All Users\DRM\DRMv1.bak - deleted
C:\Documents and Settings\All Users\DRM\DRMv1.key.bak - deleted
C:\Documents and Settings\Jeffrey\Application Data\Google\GoogleEarth\myplaces.kml.tmp - deleted
C:\Documents and Settings\Jeffrey\Application Data\Microsoft\Office\fbcD843.tmp - deleted
C:\Documents and Settings\Jeffrey\Application Data\Microsoft\Office\Recent\index.dat - deleted
C:\Documents and Settings\Jeffrey\Application Data\Microsoft\Templates\~$Normal.dot - deleted
C:\Documents and Settings\Jeffrey\UserData\index.dat - deleted
C:\Documents and Settings\Jim\~ - deleted
C:\Documents and Settings\Jim\Application Data\Google\GoogleEarth\myplaces.kml.tmp - deleted
C:\Documents and Settings\Jim\Application Data\Microsoft\Office\fbc64.tmp - deleted
C:\Documents and Settings\Jim\Application Data\Microsoft\Templates\~$Normal.dot - deleted
C:\Documents and Settings\Jim\Cookies\INDEX.DAT currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Jim\Cookies\Jeffrey\Application Data\Microsoft\Office\Recent\index.dat - deleted
C:\Documents and Settings\Jim\Cookies\Jeffrey\Cookies\INDEX.DAT - deleted
C:\Documents and Settings\Jim\Cookies\Jeffrey\Local Settings\History\History.IE5\INDEX.DAT - deleted
C:\Documents and Settings\Jim\Cookies\Jeffrey\Local Settings\History\History.IE5\MSHist012004060520040606\index.dat - deleted
C:\Documents and Settings\Jim\Cookies\Jeffrey\Local Settings\Temp\WER14.tmp - deleted
C:\Documents and Settings\Jim\Cookies\Jeffrey\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT - deleted
C:\Documents and Settings\Jim\Cookies\Jeffrey\UserData\index.dat - deleted
C:\Documents and Settings\Jim\Local Settings\History\History.IE5\INDEX.DAT currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Jim\Local Settings\History\History.IE5\MSHist012005121420051215\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Jim\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Jim\My Documents\Jims Files\~$ming tips 007.doc - deleted
C:\Documents and Settings\Jim\My Documents\Jims Files\Job hunting\~$axo thanks sara reikes.doc - deleted
C:\Documents and Settings\Jim\My Documents\Jims Files\Job hunting\~WRL1264.tmp - deleted
C:\Documents and Settings\Jim\My Documents\My Music\License Backup\drmv1key.bak - deleted
C:\Documents and Settings\Jim\My Documents\My Music\License Backup\drmv1lic.bak - deleted
C:\Documents and Settings\Jim\My Documents\My Music\License Backup\drmv2key.bak - deleted
C:\Documents and Settings\Jim\My Documents\My Music\License Backup\drmv2lic.bak - deleted
C:\Documents and Settings\Jim\UserData\index.dat - deleted
C:\Documents and Settings\LocalService\Cookies\INDEX.DAT currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\INDEX.DAT currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT currently in use. Will be deleted when Windows is restarted.
C:\Documents and Settings\Nancy\~ - deleted
C:\Documents and Settings\Nancy\Application Data\Google\GoogleEarth\myplaces.kml.tmp - deleted
C:\Documents and Settings\Nancy\Application Data\Microsoft\Office\fbc41.tmp - deleted
C:\Documents and Settings\Nancy\Application Data\Microsoft\Templates\~$Normal.dot - deleted
C:\Documents and Settings\Nancy\My Documents\My Music\iTunes\iTunes Music\Jims Songs\My Music\License Backup\drmv1key.bak - deleted
C:\Documents and Settings\Nancy\My Documents\My Music\iTunes\iTunes Music\Jims Songs\My Music\License Backup\drmv1lic.bak - deleted
C:\Documents and Settings\Nancy\My Documents\My Music\iTunes\iTunes Music\Jims Songs\My Music\License Backup\drmv2key.bak - deleted
C:\Documents and Settings\Nancy\My Documents\My Music\iTunes\iTunes Music\Jims Songs\My Music\License Backup\drmv2lic.bak - deleted
C:\Documents and Settings\Nancy\UserData\index.dat - deleted
C:\Program Files\Common Files\McAfee\AntiSpyware\McSpySig.dll.bak - deleted
C:\Program Files\EA SPORTS\Tiger Woods PGA TOUR 2001\Data\Sounds\hitstan.bak - deleted
C:\Program Files\ewido\security suite\Quarantine\fil2E.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\fil2F.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\fil30.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\fil31.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\fil32.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\fil33.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\fil34.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\fil35.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\fil36.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\fil37.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\fil38.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\fil39.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\fil3A.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\fil3B.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\fil3C.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\fil3D.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\fil3E.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\fil3F.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\fil40.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\fil41.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\fil42.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\fil43.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\fil44.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\fil45.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\fil46.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\fil47.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\fil48.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\fil49.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\fil4A.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\fil4B.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\fil4C.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\fil4D.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\fil4E.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\fil4F.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\fil50.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\fil51.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\fil52.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\fil53.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\fil54.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\fil55.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\fil56.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\fil57.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\fil58.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\fil59.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\fil5A.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\fil5B.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\fil5C.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\fil5D.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\reg2B.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\reg2C.tmp - deleted
C:\Program Files\ewido\security suite\Quarantine\reg2D.tmp - deleted
C:\Program Files\Hewlett-Packard\Digital Imaging\Migrate\hpqgends.tmp - deleted
C:\Program Files\Hewlett-Packard\Digital Imaging\{7C8BB31C-E09E-4c7d-BBF1-45E33B467FE1}\Drivers\Scanner\hpqgends.tmp - deleted
C:\Program Files\iPod\bin\TBM25A.tmp - deleted
C:\Program Files\iTunes\iTunes.Resources\TBM254.tmp - deleted
C:\Program Files\iTunes\iTunes.Resources\en.lproj\TBM257.tmp - deleted
C:\Program Files\Kazaa\Db\np.tmp - deleted
C:\Program Files\Kazaa Gold\Kazaa Gold\db\np.tmp - deleted
C:\Program Files\Microsoft Office\Office10\Startup\~$FMaker.dot - deleted
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\FW_35.tmp - deleted
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\FW_36.tmp - deleted
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\FW_37.tmp - deleted
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\FW_38.tmp - deleted
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\FW_39.tmp - deleted
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\FW_3B.tmp - deleted
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\FW_3C.tmp - deleted
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\FW_3D.tmp - deleted
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\FW_3E.tmp - deleted
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\FW_40.tmp - deleted
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\FW_42.tmp - deleted
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\FW_43.tmp - deleted
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\FW_44.tmp - deleted
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\FW_6C.tmp - deleted
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\FW_6D.tmp - deleted
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\FW_6E.tmp - deleted
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\FW_6F.tmp - deleted
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\FW_70.tmp - deleted
C:\Program Files\Real\RealPlayer\DataCache.dcp.bak - deleted
C:\Program Files\Zero Knowledge\Freedom\Resources\zk_en_US\404_home_page_not_activated.html.bak - deleted
C:\RECYCLER\S-1-5-21-1354801008-848158720-2641529481-1007\Dc3.tmp - deleted
C:\WINDOWS\IEPatchUninstall.BAK - deleted
C:\WINDOWS\imsins.BAK - deleted
C:\WINDOWS\{00000002-00000000-00000002-00001102-00000004-10031102}.BAK - deleted
C:\WINDOWS\Help\wmplayer.bak - deleted
C:\WINDOWS\INF\MPLAYER2.BAK - deleted
C:\WINDOWS\PCHealth\HelpCtr\Config\Cache\Personal_32_1033.dat.bak - deleted
C:\WINDOWS\PCHealth\HelpCtr\OfflineCache\index.dat - deleted
C:\WINDOWS\REPAIR\system.bak - deleted
C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.chk - deleted
C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\6752e343d22c025be1f290a6267a146d\BIT28.tmp - deleted
C:\WINDOWS\SYSTEM32\L3CODECA.BAK - deleted
C:\WINDOWS\SYSTEM32\shdocvw.bak - deleted
C:\WINDOWS\SYSTEM32\CONFIG.TMP - deleted
C:\WINDOWS\SYSTEM32\__delete_on_reboot__ld77C0.tmp currently in use. Will be deleted when Windows is restarted.
C:\WINDOWS\SYSTEM32\CatRoot2\edb.chk - deleted
C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Cookies\INDEX.DAT - deleted
C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\INDEX.DAT - deleted
C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\MSHist012004031620040317\index.dat - deleted
C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\MSHist012004041920040420\index.dat - deleted
C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\MSHist012004051220040513\index.dat - deleted
C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\MSHist012004073120040801\index.dat - deleted
C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT - deleted
C:\WINDOWS\SYSTEM32\NtmsData\NTMSDATA.BAK - deleted
C:\WINDOWS\TWAIN_32\hpqgends.tmp - deleted
Emptied Recycle Bin on drive C:
'Run MRU' list - removed from the registry.
Paint Recent File List - removed from the registry.
WordPad Recent File List - removed from the registry.
Telnet's MRU list - removed from the registry.
CleanUp! 4.0 recovered 578.1 MB of disk space from 18500 files.
CleanUp! finished on 12/14/05 13:04:48.



***************Ewido Report*******************

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 12:06:07 PM, 12/14/2005
+ Report-Checksum: EF23EB60

+ Scan result:

HKLM\SOFTWARE\Classes\CLSID\{4401FDC3-7996-4774-8D2B-C1AE9CD6CC25} -> Spyware.E-booksystems : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{120E090D-9136-4b78-8258-F0B44B4BD2AC} -> Spyware.Maxspeed : Cleaned with backup
HKU\S-1-5-21-1354801008-848158720-2641529481-1007\Software\Need2Find -> Spyware.Need2Find : Cleaned with backup
HKU\S-1-5-21-1354801008-848158720-2641529481-1007\Software\Need2Find\bar -> Spyware.Need2Find : Cleaned with backup
[872] C:\WINDOWS\system32\ld77C0.tmp -> Downloader.Zlob.ct : Cleaned with backup
[1984] C:\WINDOWS\system32\ioctrl.dll -> Adware.Spyaxe : Cleaned with backup
C:\Documents and Settings\Jeffrey\Cookies\[email protected][2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Jeffrey\Cookies\[email protected][1].txt -> Spyware.Cookie.Euroclick : Cleaned with backup
C:\Documents and Settings\Jeffrey\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Jeffrey\Cookies\[email protected][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Jeffrey\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Jeffrey\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Jeffrey\Cookies\jeffrey@paypopup[1].txt -> Spyware.Cookie.Paypopup : Cleaned with backup
C:\Documents and Settings\Jeffrey\Cookies\[email protected][2].txt -> Spyw
  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP