PDA

View Full Version : infected with Virtumonde, please help!!



scott38060
2008-02-11, 02:24
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:17:04 PM, on 2/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
c:\PROGRA~1\mcafee.com\vso\OasClnt .exe
c:\program files\mcafee.com\vso\mcvsshld.exe
c:\program files\mcafee.com\vso\mcvsshld .exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched .exe
C:\Program Files\Analog Devices\Core\smax4pnp .exe
C:\Program Files\Dell\Media Experience\DMXLauncher .exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Real\RealPlayer\RealPlay .exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch .exe
C:\PROGRA~1\mcafee.com\agent\mcagent .exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\WINDOWS\System32\DLA\DLACTRLW .EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2 .exe
C:\Program Files\HP\hpcoretech\hpcmpmgr .exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer .exe
c:\program files\common files\installshield\updateservice\isuspm.exe
c:\program files\common files\installshield\updateservice\isuspm .exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
F3 - REG:win.ini: load=C:\WINDOWS\system32\sstts.exe
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [ISUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm .exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\MCUPDA~1.EXE
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [MSKAGENTEXE] c:\PROGRA~1\mcafee\SPAMKI~1\MSKAGE~1.EXE
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [RecoverFromReboot] C:\WINDOWS\Temp\RecoverFromReboot.exe
O4 - HKLM\..\Run: [3cffa7a3] rundll32.exe "C:\WINDOWS\system32\nxfhjcli.dll",b
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [CleanUp] C:\PROGRA~1\McAfee.com\Shared\mcappins.exe /v=3 /cleanup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingD696] cmd /c del "C:\WINDOWS\system32\sstts.dll"
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra 'Tools' menuitem: McAfee Anti-Phishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://static.slide.com/uploader/SlideImageUploader.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1191526068690
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

--
End of file - 8966 bytes
*********************************************
KASPERSKY LOG REPORT:

KASPERSKY ONLINE SCANNER REPORT
Sunday, February 10, 2008 7:11:37 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 10/02/2008
Kaspersky Anti-Virus database records: 556170


Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true

Scan Target My Computer
C:\
D:\
E:\
F:\

Scan Statistics
Total number of scanned objects 65580
Number of viruses found 7
Number of infected objects 1689
Number of suspicious objects 4
Duration of the scan process 01:05:52

********************************************
Thank you in advance!!
Scott

ken545
2008-02-11, 18:42
Hello Scott

Welcome to Safer Networking.

Please read Before YouPost (http://forums.spybot.info/showthread.php?t=288)
That said, All advice given by anyone volunteering here, is taken at own risk.
While best efforts are made to assist in removing infections safely, unexpected stuff can happen.

You never posted the entire Kaspersky log, I would like it see it please.



Please download SuperAntiSpyware (http://www.superantispyware.com/downloadfi...ANTISPYWAREFREE)
Install the program

Run SuperAntiSpyware and click: Check for updates
Once the update is finished, on the main screen, click: Scan your computer
Check: Perform Complete Scan
Click Next to start the scan.

Superantispyware scans the computer, and when finished, lists all the infections found.
Make sure everything found has a check next to it, and press: Next
Then, click Finish

It is possible that the program asks to reboot in order to delete some files.

Obtain the SuperAntiSpyware log as follows:
Click: Preferences
Click the Statistics/Logs tab
Under Scanner Logs, double-click SuperAntiSpyware Scan Log
It opens in your default text editor (such as Notepad)

Please provide the SuperAntiSpyware log in your reply, as well as a new HijackThis log.





Download ComboFix from Here (http://download.bleepingcomputer.com/sUBs/ComboFix.exe) to your Desktop.

**Note: In the event you already have Combofix, please delete it from your desktop and download this new version . It is important that it is saved directly to your desktop**


Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
WARNING: IF you have not already done so Combofix will disconnect your machine from the Internet when it starts
Please do not re-connect your machine back to the Internet until Combofix has completely finished.

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review

1. Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze
2. If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

I need to see the SAS log , the Combofix log and a New HJT log please

scott38060
2008-02-12, 00:07
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 02/11/2008 at 03:46 PM

Application Version : 3.9.1008

Core Rules Database Version : 3399
Trace Rules Database Version: 1391

Scan type : Complete Scan
Total Scan Time : 00:52:34

Memory items scanned : 449
Memory threats detected : 15
Registry items scanned : 5336
Registry threats detected : 46
File items scanned : 38562
File threats detected : 1768

Adware.Vundo Variant
C:\WINDOWS\SYSTEM32\SSTTS.DLL
C:\WINDOWS\SYSTEM32\SSTTS.DLL
C:\WINDOWS\SYSTEM32\JKKIHGE.DLL
C:\WINDOWS\SYSTEM32\JKKIHGE.DLL
HKLM\Software\Classes\CLSID\{93C39651-962C-41B8-9961-D8591E534ABA}
HKCR\CLSID\{93C39651-962C-41B8-9961-D8591E534ABA}
HKCR\CLSID\{93C39651-962C-41B8-9961-D8591E534ABA}\InprocServer32
HKCR\CLSID\{93C39651-962C-41B8-9961-D8591E534ABA}\InprocServer32#ThreadingModel
HKLM\Software\Classes\CLSID\{CA4F0D8D-5F2B-4F16-838A-8D52249EAB21}
HKCR\CLSID\{CA4F0D8D-5F2B-4F16-838A-8D52249EAB21}
HKCR\CLSID\{CA4F0D8D-5F2B-4F16-838A-8D52249EAB21}\InprocServer32
HKCR\CLSID\{CA4F0D8D-5F2B-4F16-838A-8D52249EAB21}\InprocServer32#ThreadingModel
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{93C39651-962C-41B8-9961-D8591E534ABA}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA4F0D8D-5F2B-4F16-838A-8D52249EAB21}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks#{CA4F0D8D-5F2B-4F16-838A-8D52249EAB21}
HKCR\CLSID\{CA4F0D8D-5F2B-4F16-838A-8D52249EAB21}
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP144\A0021967.DLL
C:\VUNDOFIX BACKUPS\JKKIHGE.DLL.BAD

Adware.Vundo-Variant/Small-A
C:\WINDOWS\SYSTEM32\ABNMTCPH.DLL
C:\WINDOWS\SYSTEM32\ABNMTCPH.DLL
HKLM\Software\Classes\CLSID\{444c6f71-c6bc-46b8-8da4-ae9499d84b39}
HKCR\CLSID\{444C6F71-C6BC-46B8-8DA4-AE9499D84B39}
HKCR\CLSID\{444C6F71-C6BC-46B8-8DA4-AE9499D84B39}\InprocServer32
HKCR\CLSID\{444C6F71-C6BC-46B8-8DA4-AE9499D84B39}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\UMNECUEI.DLL
HKLM\Software\Classes\CLSID\{fa32be34-cab4-416a-8960-595cd6f2f276}
HKCR\CLSID\{FA32BE34-CAB4-416A-8960-595CD6F2F276}
HKCR\CLSID\{FA32BE34-CAB4-416A-8960-595CD6F2F276}\InprocServer32
HKCR\CLSID\{FA32BE34-CAB4-416A-8960-595CD6F2F276}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\TOINMWTP.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{444c6f71-c6bc-46b8-8da4-ae9499d84b39}
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\JXVHFTRV.DLL
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\NGNUUPHK.DLL
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\WNQUTBPR.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP137\A0019530.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP137\A0019531.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP137\A0019532.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP138\A0019625.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP138\A0019648.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP138\A0019684.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP138\A0019689.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP138\A0019722.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP138\A0019724.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP138\A0019803.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP138\A0019805.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP138\A0019806.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP138\A0019808.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP138\A0019810.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP138\A0019811.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP138\A0019812.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP144\A0021773.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP144\A0021774.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP144\A0021776.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP144\A0021777.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP144\A0021812.DLL
C:\WINDOWS\SYSTEM32\JXVJYFET.DLL
C:\WINDOWS\SYSTEM32\RTBNTLKI.DLL

Trojan.Vundo/Variant-Installer/A
C:\PROGRAM FILES\ANALOG DEVICES\CORE\SMAX4PNP.EXE
C:\PROGRAM FILES\ANALOG DEVICES\CORE\SMAX4PNP.EXE
C:\PROGRAM FILES\REAL\REALPLAYER\REALPLAY.EXE
C:\PROGRAM FILES\REAL\REALPLAYER\REALPLAY.EXE
C:\PROGRAM FILES\COMMON FILES\INSTALLSHIELD\UPDATESERVICE\ISSCH.EXE
C:\PROGRAM FILES\COMMON FILES\INSTALLSHIELD\UPDATESERVICE\ISSCH.EXE
C:\PROGRAM FILES\MCAFEE.COM\VSO\OASCLNT.EXE
C:\PROGRAM FILES\MCAFEE.COM\VSO\OASCLNT.EXE
C:\WINDOWS\SYSTEM32\DLA\DLACTRLW.EXE
C:\WINDOWS\SYSTEM32\DLA\DLACTRLW.EXE
C:\PROGRA~1\MCAFEE.COM\VSO\MCVSSHLD.EXE
C:\PROGRA~1\MCAFEE.COM\VSO\MCVSSHLD.EXE
C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFTRAY.EXE
C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFTRAY.EXE
C:\PROGRAM FILES\HP\HP SOFTWARE UPDATE\HPWUSCHD2.EXE
C:\PROGRAM FILES\HP\HP SOFTWARE UPDATE\HPWUSCHD2.EXE
C:\PROGRAM FILES\HP\HPCORETECH\HPCMPMGR.EXE
C:\PROGRAM FILES\HP\HPCORETECH\HPCMPMGR.EXE
C:\PROGRAM FILES\SPYBOT - SEARCH & DESTROY\TEATIMER.EXE
C:\PROGRAM FILES\SPYBOT - SEARCH & DESTROY\TEATIMER.EXE
[SoundMAXPnP] C:\PROGRAM FILES\ANALOG DEVICES\CORE\SMAX4PNP.EXE
[RealTray] C:\PROGRAM FILES\REAL\REALPLAYER\REALPLAY.EXE
[QuickTime Task] C:\PROGRAM FILES\QUICKTIME\QTTASK .EXE
C:\PROGRAM FILES\QUICKTIME\QTTASK .EXE
[ISUSPM Startup] C:\PROGRAM FILES\COMMON FILES\INSTALLSHIELD\UPDATESERVICE\ISUSPM .EXE
C:\PROGRAM FILES\COMMON FILES\INSTALLSHIELD\UPDATESERVICE\ISUSPM .EXE
[ISUSScheduler] C:\PROGRAM FILES\COMMON FILES\INSTALLSHIELD\UPDATESERVICE\ISSCH.EXE
[VSOCheckTask] C:\PROGRA~1\MCAFEE.COM\VSO\MCMNHDLR.EXE
C:\PROGRA~1\MCAFEE.COM\VSO\MCMNHDLR.EXE
[OASClnt] C:\PROGRAM FILES\MCAFEE.COM\VSO\OASCLNT.EXE
[MCAgentExe] C:\PROGRA~1\MCAFEE.COM\AGENT\MCAGENT.EXE
C:\PROGRA~1\MCAFEE.COM\AGENT\MCAGENT.EXE
[MCUpdateExe] C:\PROGRA~1\MCAFEE.COM\AGENT\MCUPDATE.EXE
C:\PROGRA~1\MCAFEE.COM\AGENT\MCUPDATE.EXE
[MSKDetectorExe] C:\PROGRA~1\MCAFEE\SPAMKI~1\MSKDETCT.EXE
C:\PROGRA~1\MCAFEE\SPAMKI~1\MSKDETCT.EXE
[DLA] C:\WINDOWS\SYSTEM32\DLA\DLACTRLW.EXE
[VirusScan Online] C:\PROGRA~1\MCAFEE.COM\VSO\MCVSSHLD.EXE
[MPFExe] C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFTRAY.EXE
[HP Software Update] C:\PROGRAM FILES\HP\HP SOFTWARE UPDATE\HPWUSCHD2.EXE
[HP Component Manager] C:\PROGRAM FILES\HP\HPCORETECH\HPCMPMGR.EXE
[SpybotSD TeaTimer] C:\PROGRAM FILES\SPYBOT - SEARCH & DESTROY\TEATIMER.EXE
HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\RealPlay.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\RealPlay.exe#Path
HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\smax4pnp.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\smax4pnp.exe#Path
C:\PROGRAM FILES\MCAFEE.COM\AGENT\MCAGENT.EXE
C:\DOCUMENTS AND SETTINGS\ALL USERS\DESKTOP\MCAFEE SECURITYCENTER.LNK
C:\DOCUMENTS AND SETTINGS\ALL USERS\START MENU\PROGRAMS\MCAFEE\MCAFEE SECURITYCENTER.LNK
C:\PROGRAM FILES\MCAFEE.COM\VSO\MCMNHDLR.EXE
C:\DOCUMENTS AND SETTINGS\ALL USERS\START MENU\PROGRAMS\MCAFEE\MCAFEE VIRUSSCAN\ACTIVESHIELD.LNK
C:\DOCUMENTS AND SETTINGS\ALL USERS\START MENU\PROGRAMS\MCAFEE\MCAFEE VIRUSSCAN\MANAGE QUARANTINED FILES.LNK
C:\DOCUMENTS AND SETTINGS\ALL USERS\START MENU\PROGRAMS\MCAFEE\MCAFEE VIRUSSCAN\SCAN FOR VIRUSES.LNK
C:\DOCUMENTS AND SETTINGS\ALL USERS\START MENU\PROGRAMS\REAL\REALPLAYER\REALPLAYER.LNK
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX108.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX111.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX117.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX11A.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX123.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX129.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX12D.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX130.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX133.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX22.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX2E4.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX2E7.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX2F0.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX2F9.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX2FF.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX30B.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX311.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX314.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX317.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX31A.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX32DA.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX32DD.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX32E6.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX32EF.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX32F2.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX32F5.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX32F8.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX3301.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX3307.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX330A.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX330D.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX3310.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX338E.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX3391.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX339A.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX33A3.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX33A9.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX33AC.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX33B5.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX33BB.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX33C1.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX33C4.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX34EB.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX35.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX5F.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX62.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX6B.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX74.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX7A.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX7D.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX86.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX8C.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX8F.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX92.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCX95.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCXA3.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCXA7.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCXB0.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCXB9.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCXBF.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCXC2.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCXCB.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCXD1.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCXD4.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCXD7.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCXDA.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCXFC.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\RCXFF.TMP
C:\DOCUMENTS AND SETTINGS\SCOTT\LOCAL SETTINGS\TEMP\TMP3460.TMP
C:\PROGRAM FILES\COMMON FILES\INSTALLSHIELD\UPDATESERVICE\ISUSPM .EXE
C:\PROGRAM FILES\COMMON FILES\INSTALLSHIELD\UPDATESERVICE\ISUSPM .EXE
C:\PROGRAM FILES\COMMON FILES\INSTALLSHIELD\UPDATESERVICE\ISUSPM .EXE
C:\PROGRAM FILES\COMMON FILES\INSTALLSHIELD\UPDATESERVICE\ISUSPM.EXE
C:\PROGRAM FILES\MCAFEE\SPAMKILLER\MSKAGENT .EXE
C:\PROGRAM FILES\MCAFEE\SPAMKILLER\MSKAGENT .EXE
C:\PROGRAM FILES\MCAFEE\SPAMKILLER\MSKDETCT.EXE
C:\PROGRAM FILES\MCAFEE.COM\AGENT\MCUPDATE .EXE
C:\PROGRAM FILES\MCAFEE.COM\AGENT\MCUPDATE.EXE
C:\PROGRAM FILES\MCAFEE.COM\PERSONAL FIREWALL\MPFTRAY.EXE
C:\PROGRAM FILES\MCAFEE.COM\SHARED\MCAPPINS.EXE
C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSSHLD.EXE
C:\PROGRAM FILES\QUICKTIME\QTTASK .EXE
C:\PROGRAM FILES\QUICKTIME\QTTASK .EXE
C:\PROGRAM FILES\QUICKTIME\QTTASK .EXE
C:\PROGRAM FILES\QUICKTIME\QTTASK .EXE
C:\PROGRAM FILES\QUICKTIME\QTTASK .EXE
C:\PROGRAM FILES\QUICKTIME\QTTASK.EXE

scott38060
2008-02-12, 00:09
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp100\a0015200.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp100\a0015201.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp100\a0015204.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp100\a0015205.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp100\a0015206.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp100\a0015207.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp100\a0015208.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp100\a0015209.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp100\a0015210.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp100\a0015211.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp100\a0015212.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp100\a0015213.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp100\a0015214.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp100\a0015215.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp100\a0015217.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp100\a0015218.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp100\a0015219.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp100\a0015220.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp100\a0015221.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp100\a0015222.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp100\a0015223.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp100\a0015224.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp100\a0015225.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp100\a0015226.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp102\a0015241.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp102\a0015242.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp102\a0015245.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp102\a0015246.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp102\a0015247.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp102\a0015248.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp102\a0015249.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp102\a0015250.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp102\a0015251.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp102\a0015252.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp102\a0015253.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp102\a0015254.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp102\a0015256.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp102\a0015257.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp102\a0015259.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp102\a0015260.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp102\a0015261.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp102\a0015262.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp102\a0015263.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp102\a0015264.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp102\a0015265.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp102\a0015266.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp102\a0015267.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp102\a0015268.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp102\a0015271.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp103\a0015275.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp103\a0015294.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp103\a0015295.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp103\a0015298.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp103\a0015299.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp103\a0015300.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp103\a0015301.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp103\a0015302.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp103\a0015303.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp103\a0015304.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp103\a0015305.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp103\a0015306.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp103\a0015307.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp103\a0015308.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp103\a0015309.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp103\a0015311.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp103\a0015312.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp103\a0015313.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp103\a0015314.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp103\a0015315.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp103\a0015316.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp103\a0015317.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp103\a0015318.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp103\a0015319.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp103\a0015320.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp104\a0015327.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp104\a0015328.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp104\a0015331.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp104\a0015332.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp104\a0015333.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp104\a0015334.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp104\a0015335.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp104\a0015336.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp104\a0015337.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp104\a0015338.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp104\a0015339.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp104\a0015340.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp104\a0015341.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp104\a0015342.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp104\a0015344.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp104\a0015345.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp104\a0015346.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp104\a0015347.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp104\a0015348.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp104\a0015349.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp104\a0015350.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp104\a0015351.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp104\a0015352.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp104\a0015353.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp105\a0015359.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp105\a0015360.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp105\a0015363.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp105\a0015364.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp105\a0015365.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp105\a0015366.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp105\a0015367.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp105\a0015368.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp105\a0015369.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp105\a0015370.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp105\a0015371.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp105\a0015372.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp105\a0015373.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp105\a0015374.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp105\a0015376.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp105\a0015377.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp105\a0015378.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp105\a0015379.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp105\a0015380.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp105\a0015381.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp105\a0015382.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp105\a0015383.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp105\a0015384.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp105\a0015385.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp106\a0015406.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp106\a0015407.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp106\a0015410.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp106\a0015411.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp106\a0015412.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp106\a0015413.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp106\a0015414.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp106\a0015415.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp106\a0015416.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp106\a0015417.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp106\a0015418.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp106\a0015419.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp106\a0015422.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp106\a0015424.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp106\a0015426.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp106\a0015427.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp106\a0015428.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp106\a0015429.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp106\a0015430.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp106\a0015431.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp106\a0015432.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp106\a0015433.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp106\a0015434.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp106\a0015435.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp107\a0015527.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp107\a0015562.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp107\a0015563.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp107\a0015566.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp107\a0015569.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp107\a0015574.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp107\a0015575.exe

scott38060
2008-02-12, 00:11
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp107\a0015578.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp107\a0015582.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp107\a0015583.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp107\a0015584.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp107\a0015586.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp107\a0015588.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp107\a0015592.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp107\a0015593.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp107\a0015594.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp107\a0015597.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp107\a0015598.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp107\a0015599.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp107\a0015601.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp107\a0015602.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp107\a0015603.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp108\a0015625.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015634.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015635.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015636.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015637.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015640.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015642.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015643.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015644.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015645.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015646.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015647.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015648.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015649.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015650.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015652.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015653.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015654.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015655.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015656.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015657.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015658.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015659.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015660.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015667.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015668.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015669.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015670.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015673.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015706.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015707.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015708.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015709.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015713.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015714.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015715.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015716.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015717.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015718.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015719.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015720.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015721.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015722.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015723.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015724.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015725.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015726.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015727.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015728.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015729.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015730.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015731.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015732.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015733.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015751.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015753.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015754.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015755.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015758.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015763.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015766.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015767.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015768.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015769.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015773.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015775.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015776.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015779.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015781.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015782.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015783.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015784.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015785.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015786.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015787.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015788.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015789.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015792.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015793.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015795.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015797.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015800.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015827.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015828.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015830.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015833.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015835.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015836.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015838.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015839.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015840.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015841.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015843.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015844.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015846.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015847.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015848.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015850.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015851.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015852.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015853.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015854.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015855.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015890.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015909.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015910.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015911.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015914.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015915.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015916.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015917.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015918.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015919.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015920.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015921.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015922.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015923.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015924.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015925.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015926.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015927.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015928.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015929.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015930.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015931.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015932.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015933.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015934.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015936.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015940.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0015954.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0015955.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0015956.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0015959.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0015961.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0015962.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0015963.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0015964.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0015965.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0015966.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0015967.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0015968.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0015969.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0015970.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0015971.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0015972.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0015973.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0015974.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0015975.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0015976.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0015977.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0015978.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0015979.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016832.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016834.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016836.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016837.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016844.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016845.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016846.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016847.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016848.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016849.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016851.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016852.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016853.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016855.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016856.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016858.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016859.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016861.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016862.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016863.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016865.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016866.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016867.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016870.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016871.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016872.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp115\a0016898.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp115\a0016899.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp115\a0016900.exe

scott38060
2008-02-12, 00:11
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp107\a0015578.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp107\a0015582.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp107\a0015583.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp107\a0015584.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp107\a0015586.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp107\a0015588.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp107\a0015592.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp107\a0015593.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp107\a0015594.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp107\a0015597.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp107\a0015598.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp107\a0015599.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp107\a0015601.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp107\a0015602.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp107\a0015603.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp108\a0015625.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015634.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015635.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015636.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015637.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015640.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015642.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015643.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015644.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015645.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015646.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015647.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015648.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015649.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015650.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015652.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015653.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015654.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015655.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015656.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015657.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015658.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015659.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015660.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015667.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015668.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015669.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp109\a0015670.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015673.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015706.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015707.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015708.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015709.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015713.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015714.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015715.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015716.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015717.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015718.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015719.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015720.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015721.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015722.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015723.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015724.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015725.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015726.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015727.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015728.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015729.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015730.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015731.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015732.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp110\a0015733.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015751.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015753.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015754.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015755.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015758.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015763.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015766.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015767.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015768.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015769.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015773.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015775.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015776.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015779.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015781.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015782.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015783.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015784.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015785.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015786.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015787.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015788.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015789.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015792.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015793.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015795.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015797.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015800.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015827.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015828.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015830.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015833.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015835.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015836.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015838.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015839.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015840.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015841.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015843.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015844.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015846.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015847.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015848.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015850.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015851.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015852.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015853.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015854.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015855.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp112\a0015890.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015909.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015910.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015911.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015914.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015915.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015916.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015917.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015918.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015919.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015920.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015921.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015922.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015923.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015924.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015925.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015926.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015927.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015928.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015929.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015930.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015931.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015932.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015933.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015934.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015936.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp113\a0015940.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0015954.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0015955.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0015956.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0015959.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0015961.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0015962.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0015963.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0015964.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0015965.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0015966.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0015967.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0015968.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0015969.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0015970.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0015971.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0015972.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0015973.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0015974.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0015975.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0015976.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0015977.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0015978.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0015979.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016832.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016834.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016836.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016837.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016844.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016845.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016846.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016847.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016848.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016849.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016851.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016852.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016853.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016855.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016856.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016858.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016859.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016861.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016862.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016863.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016865.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016866.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016867.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016870.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016871.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp114\a0016872.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp115\a0016898.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp115\a0016899.exe
C:\system Volume Information\_restore{202550a8-7a33-4bca-9586-051d24ddbf8f}\rp115\a0016900.exe

scott38060
2008-02-12, 01:11
This log is quite large.....IE keeps freezing up when I try to post, and then I come back and see that I double posted.....Is there a trick to posting 175000 characters, versus using 8 or 9 posts?

ComboFix 08-02-12.1 - Scott 2008-02-11 16:11:06.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.214 [GMT -6:00]
Running from: C:\Documents and Settings\Scott\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\sttss.ini
C:\WINDOWS\system32\sttss.ini2

----- BITS: Possible infected sites -----

hxxp://www.download.windowsupdate.com
.
((((((((((((((((((((((((( Files Created from 2008-01-12 to 2008-02-12 )))))))))))))))))))))))))))))))
.

2008-02-11 14:51 . 2008-02-11 16:06 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-02-11 14:51 . 2008-02-11 14:51 <DIR> d-------- C:\Documents and Settings\Scott\Application Data\SUPERAntiSpyware.com
2008-02-11 14:51 . 2008-02-11 14:51 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-02-10 23:27 . 2008-02-11 14:48 414 ---hs---- C:\WINDOWS\system32\hpctmnba.ini
2008-02-10 23:24 . 2008-02-10 23:24 294 ---hs---- C:\WINDOWS\system32\ikltnbtr.ini
2008-02-10 19:16 . 2008-02-10 19:16 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-10 16:04 . 2008-02-10 16:04 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-02-10 16:04 . 2008-02-10 16:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-02-10 08:54 . 2008-02-10 08:54 <DIR> d-------- C:\Program Files\Windows Installer Clean Up
2008-02-10 08:54 . 2008-02-10 08:54 <DIR> d-------- C:\Program Files\MSECACHE
2008-02-09 22:45 . 2007-06-05 10:56 44,928 --a------ C:\WINDOWS\system32\drivers\SDTHOOK.SYS
2008-02-09 22:29 . 2008-02-09 22:48 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2008-02-09 22:29 . 2008-02-09 22:29 30,590 --a------ C:\WINDOWS\system32\pavas.ico
2008-02-09 22:29 . 2008-02-09 22:29 2,550 --a------ C:\WINDOWS\system32\Uninstall.ico
2008-02-09 22:29 . 2008-02-09 22:29 1,406 --a------ C:\WINDOWS\system32\Help.ico
2008-02-09 22:13 . 2008-02-09 22:13 336,384 --a------ C:\WINDOWS\system32\sstts.dll_old
2008-02-09 21:22 . 2008-02-09 22:11 <DIR> d-------- C:\VundoFix Backups
2008-02-09 07:50 . 2008-02-09 23:13 68 --ah----- C:\aaw7boot.cmd
2008-02-09 01:06 . 2008-02-11 14:49 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-08 20:09 . 2008-02-09 16:16 114,688 --a------ C:\WINDOWS\system32\igfxpers .exe
2008-02-08 20:09 . 2008-02-09 16:16 94,208 --a------ C:\WINDOWS\system32\igfxtray .exe
2008-02-08 20:09 . 2008-02-09 16:16 77,824 --a------ C:\WINDOWS\system32\hkcmd .exe
2008-02-08 19:50 . 2008-02-09 11:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-02-08 19:28 . 2008-02-08 23:00 <DIR> d-------- C:\Program Files\Yahoo!
2008-02-08 19:27 . 2008-02-08 23:01 <DIR> d-------- C:\Program Files\CCleaner
2008-02-06 20:31 . 2008-02-11 16:03 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-02-06 20:31 . 2008-02-08 23:37 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-06 20:22 . 2008-02-06 20:22 <DIR> d-------- C:\Program Files\Lavasoft
2008-02-06 20:22 . 2008-02-06 20:23 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-11 20:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee.com Personal Firewall
2008-02-11 20:47 --------- d-----w C:\Program Files\QuickTime
2008-02-10 22:12 --------- d-----w C:\Documents and Settings\Scott\Application Data\McAfee.com Personal Firewall
2008-02-10 21:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\pdf995
2008-02-10 04:44 --------- d-----w C:\Program Files\Digital Line Detect
2008-02-10 04:43 --------- d-----w C:\Program Files\Google
2008-02-10 04:43 --------- d-----w C:\Program Files\BAE
2008-02-09 17:00 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-02-09 15:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-02-09 15:33 --------- d-----w C:\Program Files\MUSICMATCH
2008-02-09 15:30 --------- d-----w C:\Program Files\Common Files\Corel
2008-02-09 05:06 --------- d-----w C:\Program Files\Corel
2008-01-27 21:41 --------- d-----w C:\Documents and Settings\Scott\Application Data\AdobeUM
.

<pre>
----a-w 1,404,928 2008-02-11 20:47:13 C:\Program Files\Analog Devices\Core\smax4pnp .exe
----a-w 81,920 2008-02-11 20:47:08 C:\Program Files\Common Files\InstallShield\UpdateService\issch .exe
----a-w 249,856 2008-02-11 20:47:10 C:\Program Files\Common Files\InstallShield\UpdateService\isuspm .exe
----a-w 58,992 2008-02-09 15:15:00 C:\Program Files\Common Files\Symantec Shared\ccApp .exe
----a-w 106,496 2008-02-09 15:16:05 C:\Program Files\Corel\Corel Photo Album 6\MediaDetect .exe
----a-w 94,208 2008-02-11 20:46:59 C:\Program Files\Dell\Media Experience\DMXLauncher .exe
----a-w 49,152 2008-02-11 20:47:21 C:\Program Files\HP\HP Software Update\HPWuSchd2 .exe
----a-w 241,664 2008-02-11 20:47:28 C:\Program Files\HP\hpcoretech\hpcmpmgr .exe
----a-w 32,881 2008-02-11 20:46:58 C:\Program Files\Java\j2re1.4.2_03\bin\jusched .exe
----a-w 110,592 2008-02-11 20:47:23 C:\Program Files\McAfee\SpamKiller\MSKAGE~1 .EXE
----a-w 1,121,280 2008-02-11 20:47:23 C:\Program Files\McAfee\SpamKiller\MSKDetct .exe
----a-w 303,104 2008-02-11 20:47:10 C:\Program Files\McAfee.com\Agent\mcagent .exe
----a-w 212,992 2008-02-11 20:47:14 C:\Program Files\McAfee.com\Agent\MCUPDA~1 .EXE
----a-w 1,005,096 2008-02-11 20:47:25 C:\Program Files\McAfee.com\Personal Firewall\MpfTray .exe
----a-w 131,072 2008-02-11 20:47:27 C:\Program Files\McAfee.com\Shared\mcappins .exe
----a-w 151,552 2008-02-11 20:47:09 C:\Program Files\McAfee.com\VSO\mcmnhdlr .exe
----a-w 163,840 2008-02-11 20:47:18 C:\Program Files\McAfee.com\VSO\mcvsshld .exe
----a-w 53,248 2008-02-11 20:47:06 C:\Program Files\McAfee.com\VSO\oasclnt .exe
----a-w 1,694,208 2008-02-10 21:26:05 C:\Program Files\Messenger\msmsgs .exe
----a-w 8,192 2008-02-09 15:15:36 C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mimboot .exe
----a-w 110,592 2008-02-09 15:15:05 C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray .exe
----a-w 98,304 2008-02-11 20:47:02 C:\Program Files\QuickTime\qttask .exe
----a-w 26,112 2008-02-11 20:47:07 C:\Program Files\Real\RealPlayer\RealPlay .exe
----a-w 2,097,488 2008-02-11 20:47:37 C:\Program Files\Spybot - Search & Destroy\TeaTimer .exe
----a-w 77,824 2008-02-09 22:16:16 C:\WINDOWS\system32\hkcmd .exe
----a-w 114,688 2008-02-09 22:16:18 C:\WINDOWS\system32\igfxpers .exe
----a-w 94,208 2008-02-09 22:16:08 C:\WINDOWS\system32\igfxtray .exe
----a-w 122,940 2008-02-11 20:47:16 C:\WINDOWS\system32\DLA\DLACTRLW .EXE
</pre>


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1CD334CD-4DDC-4117-A784-63527969B21C}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{62613FC0-2577-4E69-975E-A84CB3EDE837}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8E511AE3-F828-4AA8-8E47-2EE0B6B4E184}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d498ea4a-e4ed-450a-8d49-3908498e29ab}]
C:\WINDOWS\system32\sprcxdry.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [ ]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06 1318912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSKAGENTEXE"="C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe" [2005-09-26 10:26 110592]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [ ]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [ ]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [ ]
"3cffa7a3"="C:\WINDOWS\system32\abnmtcph.dll" [ ]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-03-22 22:07:02 24576]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-05-28 21:31:38 241664]
HP Image Zone Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2004-05-28 22:06:36 53248]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll


.
Contents of the 'Scheduled Tasks' folder
"2008-02-11 20:47:43 C:\WINDOWS\Tasks\McAfee.com Scan for Viruses - My Computer (DGCLWP91-Scott).job"
- c:\program files\mcafee.com\vso\mcmnhdlr.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-12 16:20:08
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\WINDOWS\system32\wdfmgr.exe
.
**************************************************************************
.
Completion time: 2008-02-12 16:22:38 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-12 22:22:34
.
2008-02-09 21:59:03 --- E O F ---

scott38060
2008-02-12, 01:12
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:12:16 PM, on 2/12/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1CD334CD-4DDC-4117-A784-63527969B21C} - (no file)
O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: (no name) - {62613FC0-2577-4E69-975E-A84CB3EDE837} - (no file)
O2 - BHO: (no name) - {8E511AE3-F828-4AA8-8E47-2EE0B6B4E184} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\BAE\BAE.dll
O2 - BHO: (no name) - {d498ea4a-e4ed-450a-8d49-3908498e29ab} - C:\WINDOWS\system32\sprcxdry.dll (file missing)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [3cffa7a3] rundll32.exe "C:\WINDOWS\system32\abnmtcph.dll",b
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://static.slide.com/uploader/SlideImageUploader.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1191526068690
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

--
End of file - 7525 bytes

ken545
2008-02-12, 03:33
Scott,

The Vundo trojan your infected with is the latest version that includes a FILE INFECTOR :red: If you look in your Combofix log , all those programs in the Blue Code Box are infected by this trojan. I can't guarantee that those programs will work properly after your clean, lets see.

Open Notepad and copy all the text inside the Codebox by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above RenV::



RenV::
----a-w 1,404,928 2008-02-11 20:47:13 C:\Program Files\Analog Devices\Core\smax4pnp .exe
----a-w 81,920 2008-02-11 20:47:08 C:\Program Files\Common Files\InstallShield\UpdateService\issch .exe
----a-w 249,856 2008-02-11 20:47:10 C:\Program Files\Common Files\InstallShield\UpdateService\isuspm .exe
----a-w 58,992 2008-02-09 15:15:00 C:\Program Files\Common Files\Symantec Shared\ccApp .exe
----a-w 106,496 2008-02-09 15:16:05 C:\Program Files\Corel\Corel Photo Album 6\MediaDetect .exe
----a-w 94,208 2008-02-11 20:46:59 C:\Program Files\Dell\Media Experience\DMXLauncher .exe
----a-w 49,152 2008-02-11 20:47:21 C:\Program Files\HP\HP Software Update\HPWuSchd2 .exe
----a-w 241,664 2008-02-11 20:47:28 C:\Program Files\HP\hpcoretech\hpcmpmgr .exe
----a-w 32,881 2008-02-11 20:46:58 C:\Program Files\Java\j2re1.4.2_03\bin\jusched .exe
----a-w 110,592 2008-02-11 20:47:23 C:\Program Files\McAfee\SpamKiller\MSKAGE~1 .EXE
----a-w 1,121,280 2008-02-11 20:47:23 C:\Program Files\McAfee\SpamKiller\MSKDetct .exe
----a-w 303,104 2008-02-11 20:47:10 C:\Program Files\McAfee.com\Agent\mcagent .exe
----a-w 212,992 2008-02-11 20:47:14 C:\Program Files\McAfee.com\Agent\MCUPDA~1 .EXE
----a-w 1,005,096 2008-02-11 20:47:25 C:\Program Files\McAfee.com\Personal Firewall\MpfTray .exe
----a-w 131,072 2008-02-11 20:47:27 C:\Program Files\McAfee.com\Shared\mcappins .exe
----a-w 151,552 2008-02-11 20:47:09 C:\Program Files\McAfee.com\VSO\mcmnhdlr .exe
----a-w 163,840 2008-02-11 20:47:18 C:\Program Files\McAfee.com\VSO\mcvsshld .exe
----a-w 53,248 2008-02-11 20:47:06 C:\Program Files\McAfee.com\VSO\oasclnt .exe
----a-w 1,694,208 2008-02-10 21:26:05 C:\Program Files\Messenger\msmsgs .exe
----a-w 8,192 2008-02-09 15:15:36 C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mimboot .exe
----a-w 110,592 2008-02-09 15:15:05 C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray .exe
----a-w 98,304 2008-02-11 20:47:02 C:\Program Files\QuickTime\qttask .exe
----a-w 26,112 2008-02-11 20:47:07 C:\Program Files\Real\RealPlayer\RealPlay .exe
----a-w 2,097,488 2008-02-11 20:47:37 C:\Program Files\Spybot - Search & Destroy\TeaTimer .exe
----a-w 77,824 2008-02-09 22:16:16 C:\WINDOWS\system32\hkcmd .exe
----a-w 114,688 2008-02-09 22:16:18 C:\WINDOWS\system32\igfxpers .exe
----a-w 94,208 2008-02-09 22:16:08 C:\WINDOWS\system32\igfxtray .exe
----a-w 122,940 2008-02-11 20:47:16 C:\WINDOWS\system32\DLA\DLACTRLW .EXE

File::
C:\WINDOWS\system32\hpctmnba.ini
C:\WINDOWS\system32\ikltnbtr.ini
C:\WINDOWS\system32\sstts.dll_old
C:\WINDOWS\system32\sprcxdry.dll

Folder::
C:\VundoFix Backups

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1CD334CD-4DDC-4117-A784-63527969B21C}]

[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{62613FC0-2577-4E69-975E-A84CB3EDE837}]

[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8E511AE3-F828-4AA8-8E47-2EE0B6B4E184}]

[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d498ea4a-e4ed-450a-8d49-3908498e29ab}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"3cffa7a3"=-



Save this as CFScript to your desktop.

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

http://i24.photobucket.com/albums/c30/ken545/CFScript.gif


This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.

scott38060
2008-02-12, 03:44
Thank you so much for your help, ken545. I know you guys are busy, and I sincerely appreciate your willingness to help!
I am performing these tasks now and will post the new logs soon.
~Scott

scott38060
2008-02-12, 03:51
ComboFix 08-02-12.1 - Scott 2008-02-12 20:46:31.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.180 [GMT -6:00]
Running from: C:\Documents and Settings\Scott\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Scott\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE
C:\WINDOWS\system32\hpctmnba.ini
C:\WINDOWS\system32\ikltnbtr.ini
C:\WINDOWS\system32\sprcxdry.dll
C:\WINDOWS\system32\sstts.dll_old
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\VundoFix Backups
C:\VundoFix Backups\adrifwwy.dll.bad
C:\VundoFix Backups\ajtxnold.dll.bad
C:\VundoFix Backups\dajfmejf.dll.bad
C:\VundoFix Backups\dlonxtja.ini.bad
C:\VundoFix Backups\ebjvnqkw.dll.bad
C:\VundoFix Backups\fjemfjad.ini.bad
C:\VundoFix Backups\ilcjhfxn.ini.bad
C:\VundoFix Backups\mfmtupcb.dll.bad
C:\VundoFix Backups\nxfhjcli.dll.bad
C:\VundoFix Backups\sprcxdry.dll.bad
C:\VundoFix Backups\sstts.dll.bad
C:\VundoFix Backups\sttss.ini.bad
C:\VundoFix Backups\sttss.ini2.bad
C:\VundoFix Backups\ytlvcjvn.dll.bad
C:\VundoFix Backups\ywwfirda.ini.bad
C:\WINDOWS\system32\hpctmnba.ini
C:\WINDOWS\system32\ikltnbtr.ini
C:\WINDOWS\system32\sstts.dll_old

.
((((((((((((((((((((((((( Files Created from 2008-01-13 to 2008-02-13 )))))))))))))))))))))))))))))))
.

2008-02-11 14:51 . 2008-02-12 17:16 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-02-11 14:51 . 2008-02-11 14:51 <DIR> d-------- C:\Documents and Settings\Scott\Application Data\SUPERAntiSpyware.com
2008-02-11 14:51 . 2008-02-11 14:51 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-02-10 19:16 . 2008-02-10 19:16 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-10 16:04 . 2008-02-10 16:04 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-02-10 16:04 . 2008-02-10 16:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-02-10 08:54 . 2008-02-10 08:54 <DIR> d-------- C:\Program Files\Windows Installer Clean Up
2008-02-10 08:54 . 2008-02-10 08:54 <DIR> d-------- C:\Program Files\MSECACHE
2008-02-09 22:45 . 2007-06-05 10:56 44,928 --a------ C:\WINDOWS\system32\drivers\SDTHOOK.SYS
2008-02-09 22:29 . 2008-02-09 22:48 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2008-02-09 22:29 . 2008-02-09 22:29 30,590 --a------ C:\WINDOWS\system32\pavas.ico
2008-02-09 22:29 . 2008-02-09 22:29 2,550 --a------ C:\WINDOWS\system32\Uninstall.ico
2008-02-09 22:29 . 2008-02-09 22:29 1,406 --a------ C:\WINDOWS\system32\Help.ico
2008-02-09 07:50 . 2008-02-09 23:13 68 --ah----- C:\aaw7boot.cmd
2008-02-09 01:06 . 2008-02-11 14:49 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-08 20:09 . 2008-02-09 16:16 114,688 --a------ C:\WINDOWS\system32\igfxpers.exe
2008-02-08 20:09 . 2008-02-09 16:16 94,208 --a------ C:\WINDOWS\system32\igfxtray.exe
2008-02-08 20:09 . 2008-02-09 16:16 77,824 --a------ C:\WINDOWS\system32\hkcmd.exe
2008-02-08 19:50 . 2008-02-09 11:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-02-08 19:28 . 2008-02-08 23:00 <DIR> d-------- C:\Program Files\Yahoo!
2008-02-08 19:27 . 2008-02-08 23:01 <DIR> d-------- C:\Program Files\CCleaner
2008-02-06 20:31 . 2008-02-12 20:46 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-02-06 20:31 . 2008-02-08 23:37 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-06 20:22 . 2008-02-06 20:22 <DIR> d-------- C:\Program Files\Lavasoft
2008-02-06 20:22 . 2008-02-06 20:23 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-13 02:46 --------- d-----w C:\Program Files\QuickTime
2008-02-13 02:46 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-02-11 20:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee.com Personal Firewall
2008-02-10 22:12 --------- d-----w C:\Documents and Settings\Scott\Application Data\McAfee.com Personal Firewall
2008-02-10 21:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\pdf995
2008-02-10 04:44 --------- d-----w C:\Program Files\Digital Line Detect
2008-02-10 04:43 --------- d-----w C:\Program Files\Google
2008-02-10 04:43 --------- d-----w C:\Program Files\BAE
2008-02-09 15:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-02-09 15:33 --------- d-----w C:\Program Files\MUSICMATCH
2008-02-09 15:30 --------- d-----w C:\Program Files\Common Files\Corel
2008-02-09 05:06 --------- d-----w C:\Program Files\Corel
2008-01-27 21:41 --------- d-----w C:\Documents and Settings\Scott\Application Data\AdobeUM
2007-12-18 12:02 3,350 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2007-12-14 17:32 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2007-11-14 07:26 450,560 ------w C:\WINDOWS\system32\dllcache\jscript.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-02-10 15:26 1694208]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06 1318912]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSKAGENTEXE"="C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe" [2005-09-26 10:26 110592]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2008-02-09 16:16 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2008-02-09 16:16 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2008-02-09 16:16 114688]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-03-22 22:07:02 24576]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-05-28 21:31:38 241664]
HP Image Zone Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2004-05-28 22:06:36 53248]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll


.
Contents of the 'Scheduled Tasks' folder
"2008-02-11 20:47:43 C:\WINDOWS\Tasks\McAfee.com Scan for Viruses - My Computer (DGCLWP91-Scott).job"
- c:\program files\mcafee.com\vso\mcmnhdlr.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-12 20:48:28
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-12 20:49:05
ComboFix-quarantined-files.txt 2008-02-13 02:48:51
ComboFix2.txt 2008-02-12 22:22:38
.
2008-02-09 21:59:03 --- E O F ---

scott38060
2008-02-12, 03:52
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:50:25 PM, on 2/12/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\BAE\BAE.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://static.slide.com/uploader/SlideImageUploader.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1191526068690
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

--
End of file - 7065 bytes

ken545
2008-02-12, 04:10
Scott,

Good job, it looks like you got it :bigthumb:


Download CCleaner from here (http://www.ccleaner.com/) to clean temp files from your computer.

Double click on the file to start the installation of the program.
Select your language and click OK, then next.
Read the license agreement and click I Agree.
Click next to use the default install location. Click Install then finish to complete installation.
Double click the CCleaner shortcut on the desktop to start the program.
On the "Windows" tab, under "Internet Explorer," uncheck "Cookies" if you do not want them deleted. (If deleted, you will likely need to reenter your passwords at all sites where a cookie is used to recognize you when you visit).
If you use either the Firefox or Mozilla browsers, the box to uncheck for "Cookies" is on the Applications tab, under Firefox/Mozilla.
Click on the "Options" icon at the left side of the window, then click on "Advanced."
deselect "Only delete files in Windows Temp folders older than 48 hours."
Click on the "Cleaner" icon on the left side of the window, then click Run Cleaner to run the program.
Caution: It is not recommended that you use the "Issues" feature unless you are very familiar with the registry as it has been known to find legitimate items.
After CCleaner has completed its process, click Exit.


*NOTE* CCleaner deletes EVERYTHING out of temp/temporary folders. If you have anything in a temp folder, back it up or move it to a permanent folder prior to running CCleaner!


How are things running now?? Take your time, been a loooooooooog day and a bad cold to boot, be back in the AM

Ken

ken545
2008-02-12, 04:10
Scott,

Good job, it looks like you got it :bigthumb: You HJT log looks fine and Combofix cleaned the infected programs.


Download CCleaner from here (http://www.ccleaner.com/) to clean temp files from your computer.

Double click on the file to start the installation of the program.
Select your language and click OK, then next.
Read the license agreement and click I Agree.
Click next to use the default install location. Click Install then finish to complete installation.
Double click the CCleaner shortcut on the desktop to start the program.
On the "Windows" tab, under "Internet Explorer," uncheck "Cookies" if you do not want them deleted. (If deleted, you will likely need to reenter your passwords at all sites where a cookie is used to recognize you when you visit).
If you use either the Firefox or Mozilla browsers, the box to uncheck for "Cookies" is on the Applications tab, under Firefox/Mozilla.
Click on the "Options" icon at the left side of the window, then click on "Advanced."
deselect "Only delete files in Windows Temp folders older than 48 hours."
Click on the "Cleaner" icon on the left side of the window, then click Run Cleaner to run the program.
Caution: It is not recommended that you use the "Issues" feature unless you are very familiar with the registry as it has been known to find legitimate items.
After CCleaner has completed its process, click Exit.


*NOTE* CCleaner deletes EVERYTHING out of temp/temporary folders. If you have anything in a temp folder, back it up or move it to a permanent folder prior to running CCleaner!


How are things running now?? Take your time, been a loooooooooog day and a bad cold to boot, be back in the AM

Ken

scott38060
2008-02-12, 04:32
Thanks again for your help, Ken. The computer has run 10 times better ever since running SuperAntiSpyware the first time. I ran CC cleaner (I had previously installed it, but the version I have still is current according to their website) and will follow up with an update in the next day or so. Any recommendations at this point? (ie: should run Spybot S&D, AdAware, SAS, etc?)

Hope your cold gets better!! NyQuil does the trick for me!!

With sincere appreciation,
Scott

ken545
2008-02-12, 10:58
Morning Scott,

Glad things are better :bigthumb: I am posting some housecleaning and links to free software to help keep you more secure. Post back in a few days and let me know if things are still ok.


Click START then RUN
Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.


http://i189.photobucket.com/albums/z176/EPL47/CF_Cleanup.png


When shown the disclaimer, Select "2"

The above procedure will:

Delete the following:
ComboFix and its associated files and folders.
VundoFix backups, if present
The C:\Deckard folder, if present
The C:_OtMoveIt folder, if present

Reset the clock settings.
Hide file extensions, if required.
Hide System/Hidden files, if required.
Reset System Restore.





Malware Complaints (http://malwarecomplaints.info/index.php)
Are you mad ? I mean really mad, seething mad, so mad your ready to spit, mad that you have taken your hard earned dollars to buy a computer only to have some Miscredents, Dirt Bags and Cyber Criminals install a malicious program on your computer without your knowledge or consent. You can post your complaint at the above site. If you live in the U.S.A. you can also report your grievance to your State Attorney Generals Office and the Federal Trade Commission's Bureau of Consumer Protection.


How did I get infected in the first place ? Read these links and find out how to prevent getting infected again.
Tutorial for System Restore (http://www.bleepingcomputer.com/tutorials/tutorial56.html) <-- Do this first to prevent yourself from being reinfected.
WhattheTech (http://forums.whatthetech.com/So_how_did_I_get_infected_in_the_first_place_t57817.html)
TonyKlein CastleCops (http://www.castlecops.com/postlite7736-.html)
Grinler BleepingComputer (http://www.bleepingcomputer.com/forums/topic2520.html)
GeeksTo Go (http://www.geekstogo.com/forum/index.php?autocom=custom&page=How_did_I)
Dslreports (http://www.dslreports.com/faq/10002)



Keep in mind if you install some of these programs. Only ONE Anti Virus and only ONE Firewall is recommended, more is overkill and can cause you problems. You can install all the Spyware programs I have listed without any problems. If you install Spyware Blaster, you can still install Spybot Search and Destroy but do not enable the TeaTimer in Spybot.

Here are some free programs to install, all free and highly regarded by the fine people in the Malware Removal Community

Spybot Search and Destroy 1.5 (http://www.safer-networking.org/en/download/)
Check for Updates/ Immunize and run a Full System Scan on a regular basis. If you install Spyware Blaster ( Recommended ) then do not enable the TeaTimer in Spybot Search and Destroy.

Spyware Blaster (http://www.javacoolsoftware.com/spywareblaster.html) It will prevent most spyware from ever being installed. No scan to run, just update about once a week and enable all protection.

Spyware Guard (http://www.javacoolsoftware.com/spywareguard.html) It offers realtime protection from spyware installation attempts, again, no scan to run, just install it and let it do its thing.

IE-Spyad (http://www.pcworld.com/downloads/file/fid,23332-order,1-page,1-c,antispywaretools/description.html)
IE-Spyad places over 6000 web sites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (cookies etc) from the sites listed, although you will still be able to connect to the sites.

Firefox 2.0.0.6 (http://www.mozilla.org/products/firefox/) It has more features and is a lot more secure than IE. It is a very easy and painless download and install, it will no way interfere with IE, you can use them both.


Glad we could help

Safe Surfn
Ken

scott38060
2008-02-15, 03:19
Ken,
Just wanted to follow up with you and let you know that my computer is continuing to run flawlessly.....with one exception. I am trying to remove all traces of McAfee products from my machine. You stated (a few post up) that "those programs in the Blue Code Box are infected by this trojan. I can't guarantee that those programs will work properly after your clean, lets see." I think this step may have annihilated my virusscan (which is cool by me!), but I still need to get rid of spamkiller and the mcafee firewall. Once I can remove those, I am going to install the AVG virus scan, and a ZoneAlarm or similar firewall. Any suggestions as to how I can remove this McAfee stuff? Thanks!!!!!!!!!!!

~Scott

ken545
2008-02-15, 10:11
Hello Scott,

Thanks for taking the time to let me know how your doing, glad your doing well.

Mcafee has a removal tool that will remove all Mcafee products from your system.
http://service.mcafee.com/FAQDocument.aspx?id=107083&lc=1033


After you run it, reboot and post a HJT log and we can see if its all gone

scott38060
2008-02-21, 01:14
Thank you, Ken. I did what you suggested and got a "Clean Up Successful" Message from the clean up tool. Heres the HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:11:55 PM, on 2/21/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\BAE\BAE.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://static.slide.com/uploader/SlideImageUploader.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1191526068690
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

--
End of file - 6076 bytes

ken545
2008-02-21, 04:48
Scott,

Mcafee is gone and your HJT log looks fine :bigthumb:


Take Care,

Ken:p:

scott38060
2008-02-22, 00:46
Thanks a million, Ken. I installed AVG anti-virus and continue to run Spybot S&D. Everything seems tip-top.

You rock, man!!

~Scott

ken545
2008-02-22, 01:25
Your very welcome Scott :bigthumb:

Ken