Here are the logs.
The computer is running without issues, I just have to copy/paste links from google instead of just clicking them.
I am also not logging in to any website with username/password except this site to post.
Looks like Kaspersky found the culprit, what do recommend at this point.
Thanks
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0 REPORT
Monday, April 13, 2009
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Monday, April 13, 2009 18:45:03
Records in database: 2041111
--------------------------------------------------------------------------------
Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes
Scan area - My Computer:
C:\
D:\
Scan statistics:
Files scanned: 41673
Threat name: 1
Infected objects: 1
Suspicious objects: 0
Duration of the scan: 01:47:09
File name / Threat name / Threats count
globalroot\systemroot\system32\gxvxchnwwcvyeanmneesxuknuiyuaqhlxtdok.dll/globalroot\systemroot\system32\gxvxchnwwcvyeanmneesxuknuiyuaqhlxtdok.dll Infected: Trojan.Win32.Agent2.hoq 1
The selected area was scanned.
===================================================
+++++++++++++++++++++++++++++++++++++++++++++++++++
DDS (Ver_09-03-16.01) - NTFSx86
Run by Steve at 12:34:59.53 on Mon 04/13/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.135 [GMT -5:00]
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated)
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\ActivCard\ActivCard Gold\agquickp.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\ActivCard\acautoreg.exe
C:\Program Files\Common Files\ActivCard\accoca.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\Steve\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*
http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*
http://www.yahoo.com
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [AGRSMMSG] AGRSMMSG.exe
mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [LogitechCommunicationsManager] "c:\program files\common files\logishrd\lcommgr\Communications_Helper.exe"
mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\quickcam\Quickcam.exe" /hide
mRun: [QuickPassword] c:\program files\activcard\activcard gold\agquickp.exe
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
StartupFolder: c:\docume~1\steve\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\quickcam\eReg.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - c:\program files\pokerstars\PokerStarsUpdate.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {5721FA68-5ABD-40A8-81F1-4136691194BF} - hxxps://www.play.net/components/activex/AXSAL.ocx
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1226867330666
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: AtiExtEvent - Ati2evxx.dll
Notify: NavLogon - c:\windows\system32\NavLogon.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-4-9 64160]
R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2005-2-4 324232]
R1 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2005-2-4 53896]
R2 acautoreg;ActivCard Gold Autoregister;c:\program files\common files\activcard\acautoreg.exe [2002-9-12 53248]
R2 Accoca;ActivCard Gold service;c:\program files\common files\activcard\accoca.exe [2004-8-11 143360]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2005-4-8 185968]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2005-4-8 161392]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-11-27 24652]
R3 Actrpcsc;Actrpcsc;c:\windows\system32\drivers\actrpcsc.sys [2003-9-16 14784]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20090409.004\naveng.sys [2009-4-9 89104]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20090409.004\navex15.sys [2009-4-9 876144]
S2 ACTR;Smart Card Reader;c:\windows\system32\drivers\ACTR.SYS [2003-2-6 16408]
S3 ccPwdSvc;Symantec Password Validation;c:\program files\common files\symantec shared\ccPwdSvc.exe [2005-4-8 83568]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-3-9 951632]
S3 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2005-4-17 124608]
S3 SCRx31 USB Reader;SCRx31 USB Reader;c:\windows\system32\drivers\stc2.sys [2002-8-22 57088]
S3 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2005-4-17 1706176]
S3 WLAN_400_500_SERVICE;HP WLAN W400/W500 Wireless Network Adapter Service;c:\windows\system32\drivers\ar5211.sys [2003-2-25 468768]
=============== Created Last 30 ================
2009-04-13 11:58 <DIR> --d----- C:\ComboFix
2009-04-12 22:03 <DIR> a-dshr-- C:\cmdcons
2009-04-12 21:55 161,792 a------- c:\windows\SWREG.exe
2009-04-12 21:55 98,816 a------- c:\windows\sed.exe
2009-04-09 17:06 15,504 a------- c:\windows\system32\drivers\mbam.sys
2009-04-09 17:06 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-09 17:06 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-04-09 17:06 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-04-09 15:59 15,688 a------- c:\windows\system32\lsdelete.exe
2009-04-09 15:27 64,160 a------- c:\windows\system32\drivers\Lbd.sys
2009-04-09 15:26 <DIR> -cd-h--- c:\docume~1\alluse~1\applic~1\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-04-09 15:25 <DIR> --d----- c:\program files\Lavasoft
==================== Find3M ====================
2009-03-12 18:31 0 a------- c:\windows\system32\drivers\lvuvc.hs
2009-03-12 18:31 0 a------- c:\windows\system32\drivers\logiflt.iad
2009-03-09 05:19 410,984 a------- c:\windows\system32\deploytk.dll
2009-02-09 06:13 1,846,784 a------- c:\windows\system32\win32k.sys
2009-01-28 15:29 110,415 a------- c:\windows\hpoins11.dat
2008-11-17 00:24 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008111020081117\index.dat
2008-11-17 00:24 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008111720081118\index.dat
============= FINISH: 12:35:22.48 ===============
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++
ComboFix 09-04-13.07 - Steve 2009-04-13 12:06.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.265 [GMT -5:00]
Running from: c:\documents and settings\Steve\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Steve\Desktop\CFScript.txt
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated)
FILE ::
c:\windows\system32\drivers\gxvxcxwtrjlwlrykjsvidwqkhcamtxbtkkuty.sys
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Steve\Application Data\Azureus
c:\documents and settings\Steve\Application Data\Azureus\.certs
c:\documents and settings\Steve\Application Data\Azureus\.keystore
c:\documents and settings\Steve\Application Data\Azureus\.lock
c:\documents and settings\Steve\Application Data\Azureus\active\
02DB69B98233AFAA505903C673E0000CA4140C5F.dat
c:\documents and settings\Steve\Application Data\Azureus\active\
02DB69B98233AFAA505903C673E0000CA4140C5F.dat.bak
c:\documents and settings\Steve\Application Data\Azureus\active\
0A89E45F5782717ACE7B80D0B23191007DDAFEBD.dat
c:\documents and settings\Steve\Application Data\Azureus\active\
0A89E45F5782717ACE7B80D0B23191007DDAFEBD.dat.bak
c:\documents and settings\Steve\Application Data\Azureus\active\
0EB90E11A96BF478692C14398D31BBFAA93BF951.dat
c:\documents and settings\Steve\Application Data\Azureus\active\
0EB90E11A96BF478692C14398D31BBFAA93BF951.dat.bak
c:\documents and settings\Steve\Application Data\Azureus\active\1DA9A4E2FAA712E6694C8EB8CEB4D69E7F316CA3.dat
c:\documents and settings\Steve\Application Data\Azureus\active\1DA9A4E2FAA712E6694C8EB8CEB4D69E7F316CA3.dat.bak
c:\documents and settings\Steve\Application Data\Azureus\active\5172CFB72D0E94A72785C38762C8366D5FFE8266.dat
c:\documents and settings\Steve\Application Data\Azureus\active\5172CFB72D0E94A72785C38762C8366D5FFE8266.dat.bak
c:\documents and settings\Steve\Application Data\Azureus\active\55F77AD57FA21C37B8EA7FB3956EC3161CFEE44C.dat
c:\documents and settings\Steve\Application Data\Azureus\active\55F77AD57FA21C37B8EA7FB3956EC3161CFEE44C.dat.bak
c:\documents and settings\Steve\Application Data\Azureus\active\57351AF664B5E8AF952DB0C0381704D3A0C7C31C.dat
c:\documents and settings\Steve\Application Data\Azureus\active\57351AF664B5E8AF952DB0C0381704D3A0C7C31C.dat.bak
c:\documents and settings\Steve\Application Data\Azureus\active\B064332D2719D81E98774AC8842C9B8854A233FA.dat
c:\documents and settings\Steve\Application Data\Azureus\active\B064332D2719D81E98774AC8842C9B8854A233FA.dat.bak
c:\documents and settings\Steve\Application Data\Azureus\active\B386F04DB14DA85560638A4A20CF64DDDD86C95E.dat
c:\documents and settings\Steve\Application Data\Azureus\active\B386F04DB14DA85560638A4A20CF64DDDD86C95E.dat.bak
c:\documents and settings\Steve\Application Data\Azureus\active\C373842353B786346C49D385CA5A12AE288CCC0D.dat
c:\documents and settings\Steve\Application Data\Azureus\active\C373842353B786346C49D385CA5A12AE288CCC0D.dat.bak
c:\documents and settings\Steve\Application Data\Azureus\active\cache.dat
c:\documents and settings\Steve\Application Data\Azureus\azureus.config
c:\documents and settings\Steve\Application Data\Azureus\azureus.config.bak
c:\documents and settings\Steve\Application Data\Azureus\azureus.statistics
c:\documents and settings\Steve\Application Data\Azureus\azureus.statistics.bak
c:\documents and settings\Steve\Application Data\Azureus\banips.config
c:\documents and settings\Steve\Application Data\Azureus\banips.config.bak
c:\documents and settings\Steve\Application Data\Azureus\cache\1191085919.ico
c:\documents and settings\Steve\Application Data\Azureus\cnetworks.config
c:\documents and settings\Steve\Application Data\Azureus\devices.config
c:\documents and settings\Steve\Application Data\Azureus\devices.config.bak
c:\documents and settings\Steve\Application Data\Azureus\dht\addresses.dat
c:\documents and settings\Steve\Application Data\Azureus\dht\contacts.dat
c:\documents and settings\Steve\Application Data\Azureus\dht\diverse.dat
c:\documents and settings\Steve\Application Data\Azureus\dht\general.dat
c:\documents and settings\Steve\Application Data\Azureus\dht\version.dat
c:\documents and settings\Steve\Application Data\Azureus\downloads.config
c:\documents and settings\Steve\Application Data\Azureus\downloads.config.bak
c:\documents and settings\Steve\Application Data\Azureus\filters.config
c:\documents and settings\Steve\Application Data\Azureus\friends.config
c:\documents and settings\Steve\Application Data\Azureus\friends.config.bak
c:\documents and settings\Steve\Application Data\Azureus\ipfilter.cache
c:\documents and settings\Steve\Application Data\Azureus\logs\alerts_1.log
c:\documents and settings\Steve\Application Data\Azureus\logs\AutoSpeedSearchHistory_1.log
c:\documents and settings\Steve\Application Data\Azureus\logs\clientid_1.log
c:\documents and settings\Steve\Application Data\Azureus\logs\CNetworks_1.log
c:\documents and settings\Steve\Application Data\Azureus\logs\debug_1.log
c:\documents and settings\Steve\Application Data\Azureus\logs\debug_2.log
c:\documents and settings\Steve\Application Data\Azureus\logs\Devices_1.log
c:\documents and settings\Steve\Application Data\Azureus\logs\Friends_1.log
c:\documents and settings\Steve\Application Data\Azureus\logs\Friends_2.log
c:\documents and settings\Steve\Application Data\Azureus\logs\MetaSearch_1.log
c:\documents and settings\Steve\Application Data\Azureus\logs\MetaSearch_2.log
c:\documents and settings\Steve\Application Data\Azureus\logs\MetaSearch_Engine_3.txt
c:\documents and settings\Steve\Application Data\Azureus\logs\MetaSearch_Engine_4.txt
c:\documents and settings\Steve\Application Data\Azureus\logs\MetaSearch_Engine_5.txt
c:\documents and settings\Steve\Application Data\Azureus\logs\MetaSearch_Engine_9.txt
c:\documents and settings\Steve\Application Data\Azureus\logs\NetStatus_1.log
c:\documents and settings\Steve\Application Data\Azureus\logs\save\1239427890677_alerts_1.log
c:\documents and settings\Steve\Application Data\Azureus\logs\save\1239427890677_AutoSpeedSearchHistory_1.log
c:\documents and settings\Steve\Application Data\Azureus\logs\save\1239427890677_clientid_1.log
c:\documents and settings\Steve\Application Data\Azureus\logs\save\1239427890677_CNetworks_1.log
c:\documents and settings\Steve\Application Data\Azureus\logs\save\1239427890677_debug_1.log
c:\documents and settings\Steve\Application Data\Azureus\logs\save\1239427890677_debug_2.log
c:\documents and settings\Steve\Application Data\Azureus\logs\save\1239427890677_Devices_1.log
c:\documents and settings\Steve\Application Data\Azureus\logs\save\1239427890677_Friends_1.log
c:\documents and settings\Steve\Application Data\Azureus\logs\save\1239427890677_Friends_2.log
c:\documents and settings\Steve\Application Data\Azureus\logs\save\1239427890677_MetaSearch_1.log
c:\documents and settings\Steve\Application Data\Azureus\logs\save\1239427890677_MetaSearch_2.log
c:\documents and settings\Steve\Application Data\Azureus\logs\save\1239427890677_MetaSearch_Engine_3.txt
c:\documents and settings\Steve\Application Data\Azureus\logs\save\1239427890677_MetaSearch_Engine_4.txt
c:\documents and settings\Steve\Application Data\Azureus\logs\save\1239427890677_MetaSearch_Engine_5.txt
c:\documents and settings\Steve\Application Data\Azureus\logs\save\1239427890677_MetaSearch_Engine_9.txt
c:\documents and settings\Steve\Application Data\Azureus\logs\save\1239427890677_NetStatus_1.log
c:\documents and settings\Steve\Application Data\Azureus\logs\save\1239427890677_seltrace_1.log
c:\documents and settings\Steve\Application Data\Azureus\logs\save\1239427890677_seltrace_2.log
c:\documents and settings\Steve\Application Data\Azureus\logs\save\1239427890677_Subscriptions_1.log
c:\documents and settings\Steve\Application Data\Azureus\logs\save\1239427890677_Subscriptions_2.log
c:\documents and settings\Steve\Application Data\Azureus\logs\save\1239427890677_thread_1.log
c:\documents and settings\Steve\Application Data\Azureus\logs\save\1239427890677_thread_2.log
c:\documents and settings\Steve\Application Data\Azureus\logs\save\1239427890677_v3.ads_1.log
c:\documents and settings\Steve\Application Data\Azureus\logs\save\1239427890677_v3.CMsgr_1.log
c:\documents and settings\Steve\Application Data\Azureus\logs\save\1239427890677_v3.CMsgr_2.log
c:\documents and settings\Steve\Application Data\Azureus\logs\save\1239427890677_v3.emp_1.log
c:\documents and settings\Steve\Application Data\Azureus\logs\save\1239427890677_v3.emp_2.log
c:\documents and settings\Steve\Application Data\Azureus\logs\save\1239427890677_v3.Friends_1.log
c:\documents and settings\Steve\Application Data\Azureus\logs\save\1239427890677_v3.Friends_2.log
c:\documents and settings\Steve\Application Data\Azureus\logs\save\1239427890677_v3.MD_1.log
c:\documents and settings\Steve\Application Data\Azureus\logs\save\1239427890677_v3.PMsgr_1.log
c:\documents and settings\Steve\Application Data\Azureus\logs\save\1239427890677_v3.PMsgr_2.log
c:\documents and settings\Steve\Application Data\Azureus\logs\save\1239427890677_v3.Stream_1.log
c:\documents and settings\Steve\Application Data\Azureus\logs\save\1239427890677_WP_xsearch_1.log
c:\documents and settings\Steve\Application Data\Azureus\logs\seltrace_1.log
c:\documents and settings\Steve\Application Data\Azureus\logs\seltrace_2.log
c:\documents and settings\Steve\Application Data\Azureus\logs\Subscriptions_1.log
c:\documents and settings\Steve\Application Data\Azureus\logs\Subscriptions_2.log
c:\documents and settings\Steve\Application Data\Azureus\logs\thread_1.log
c:\documents and settings\Steve\Application Data\Azureus\logs\thread_2.log
c:\documents and settings\Steve\Application Data\Azureus\logs\v3.ads_1.log
c:\documents and settings\Steve\Application Data\Azureus\logs\v3.CMsgr_1.log
c:\documents and settings\Steve\Application Data\Azureus\logs\v3.CMsgr_2.log
c:\documents and settings\Steve\Application Data\Azureus\logs\v3.emp_1.log
c:\documents and settings\Steve\Application Data\Azureus\logs\v3.emp_2.log
c:\documents and settings\Steve\Application Data\Azureus\logs\v3.Friends_1.log
c:\documents and settings\Steve\Application Data\Azureus\logs\v3.Friends_2.log
c:\documents and settings\Steve\Application Data\Azureus\logs\v3.MD_1.log
c:\documents and settings\Steve\Application Data\Azureus\logs\v3.PMsgr_1.log
c:\documents and settings\Steve\Application Data\Azureus\logs\v3.PMsgr_2.log
c:\documents and settings\Steve\Application Data\Azureus\logs\v3.Stream_1.log
c:\documents and settings\Steve\Application Data\Azureus\logs\WP_xsearch_1.log
c:\documents and settings\Steve\Application Data\Azureus\metasearch.config
c:\documents and settings\Steve\Application Data\Azureus\metasearch.config.bak
c:\documents and settings\Steve\Application Data\Azureus\net\pm_11492.dat
c:\documents and settings\Steve\Application Data\Azureus\net\pm_1239.dat
c:\documents and settings\Steve\Application Data\Azureus\net\pm_2386.dat
c:\documents and settings\Steve\Application Data\Azureus\net\pm_7018.dat
c:\documents and settings\Steve\Application Data\Azureus\net\pm_default.dat
c:\documents and settings\Steve\Application Data\Azureus\plugins\azump\azump_1.2.jar
c:\documents and settings\Steve\Application Data\Azureus\plugins\azump\azump_1.2.zip
c:\documents and settings\Steve\Application Data\Azureus\plugins\azump\azump_1.3.jar
c:\documents and settings\Steve\Application Data\Azureus\plugins\azump\azump_1.3.zip
c:\documents and settings\Steve\Application Data\Azureus\plugins\azump\mplayer.exe
c:\documents and settings\Steve\Application Data\Azureus\plugins\azump\mplayer.exe.bak
c:\documents and settings\Steve\Application Data\Azureus\plugins\azump\mplayer\config
c:\documents and settings\Steve\Application Data\Azureus\plugins\azupnpav\cd.dat
c:\documents and settings\Steve\Application Data\Azureus\sidebarauto.config
c:\documents and settings\Steve\Application Data\Azureus\sidebarauto.config.bak
c:\documents and settings\Steve\Application Data\Azureus\subs\
01C36840FB41C06968B6.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\
01FE0E4954FEEB299706.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\
063789928C9534F568E9.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\
0B181B41E75FD32CFE6A.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\
0B4A3FA0934F89D85DE6.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\
0F193C9F601B15C4EFFE.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\
0F9189F2DBEC140C9799.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\1106AD482F64C5DE68E3.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\12533BF9649105ABA27A.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\1283A0BB65355F99EC2D.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\177D97ABD20DFF1C1109.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\18FAFDB1E53AB485AC35.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\19D197C718E86D5B1B15.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\1D3D4E427B4A70B872CF.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\202149C5A1204A8B1B7A.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\20F764C3B06FECC02E10.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\21B6F154E1FA75E4DF0A.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\21EECBF1BB7422952ADD.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\23874448F3148CDD35E7.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\24916A26657351AD0B01.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\249C4C0F3D8C36A37EB7.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\2827D344944ACF9EAA11.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\28B198533648884FE832.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\28CF14B604BFE173EEFF.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\2908A79FE59C831AEE19.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\2A1F83AF90AF9B597A5D.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\2A33AA44AD4BC72CFD62.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\2ABE91BA6A7B663A3B13.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\2BC6CD577EA4C0CC5846.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\2D0EB0C4B2E9C562C314.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\2DBA0193178660401697.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\2DCFAB8F832477D02694.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\2E0AFE66BD1B23EF0656.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\2F87E4DAC027E04A0BBE.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\2F9F5F271D510720D55B.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\311E10B6B4C70297181A.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\327F4762CCB7C9C5102D.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\33CF1BCC1A5689A6F75C.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\35115140556C9F9E29FD.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\3659DB2D7F9C19943CED.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\38C834E1F8ECD42109BB.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\3C1C33756A83CC05D595.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\3C5CB4D19AB0A32B422D.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\3FF44E9451F6ED2E0995.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\402E169FCE43E348FC5C.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\4551D4CD9CB463595565.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\4720D2E2240A57AC7261.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\47D01B51E6FACC969E1D.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\4CA357805318C119D99F.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\4CD6D96573CE7093FB98.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\4D168F2B107DB23156A3.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\4DB89BB311531CDA9163.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\4E14454F3DFF772B9E75.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\4F2AA8C2D919E9835A62.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\4F5D92DCB17E8F9148BB.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\5006C76DD2492CFB2617.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\50E47EE4E57D670E619F.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\52C6D09A02BBB590C252.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\54004C0B7ADCCE4069C9.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\588E74B9329A6F7D9634.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\58C5882E06E1845DCAB5.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\5D160C929BB9B9286D54.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\5F03B593A0F31F389FE4.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\5F5F8F085B177B805385.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\60686712C2F98D5FFEA2.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\6104F1BBDF2C5EEBF4DD.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\6148A7F564ECA3916149.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\61E988FDE0D2F655E170.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\61FEEACD421B1415E859.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\624910A3A637947DE3C8.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\632A20E73961F1C133F2.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\635070C491AF6F85FED5.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\63FFD22447BDF46E72B3.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\65CE3C46ACE1B29F7AF8.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\65D85767A5BC1B1B8F08.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\6633B2F0BA2BDFCA7731.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\6BB6885CAA82104E1C59.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\6CE4CD4B41EB765CCBCF.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\6DFA201131C8501E986F.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\70568375D069D9506E60.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\7121CFED9C398458EF19.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\715F3715796844007AC1.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\7165F796BFFDE326DB41.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\72D2F5BA4A68FA6F677A.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\737553100CB057ACF094.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\751DA2FD325B465C90A6.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\78F276B35A2031E71B9F.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\79E766BACEC15D14BEA9.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\7C5F6FF540DED929A9FB.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\7CC5D8AEF3ED4DD1746D.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\7E65E45EAE9645A6498E.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\7E9001757D9C4324235E.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\7EFA9C86225EF600EF1D.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\7FC10F8EED6A15E5A4B2.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\813864B48EA2A46A1C48.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\829E59C40EFFE22EB406.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\83F9D7CFBA5E7496ACC5.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\8508EF52A222353C12A0.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\889D0F6452BCC243BF95.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\88E0659ED27843F8EA85.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\8A8138032CEB4BAFDDBC.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\8DE6E5753F5ADF094F49.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\8F8F78FEBDEF8A00BDDB.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\92B9575881A124B384EC.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\93B716386602D52C6EB7.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\941DB1C4E853CFC63604.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\9503124110D1B19F2B0F.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\95B34C1A1F40931D0972.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\96996FBFCB54E44E2CA6.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\977B3EA04CF30CDAADA0.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\99BA212B32FA7225A460.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\9AB0B87234BD0B8CB88B.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\9AEFCE7D60200136FF79.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\A2AF023D22B51F804095.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\A57341AB2AA7A98D5F19.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\A6875C9905F5F324D605.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\A8BB63F35E0741DD03D2.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\AD297982B3FC992F1354.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\ADDC82F617E7121152DF.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\AE238A40E189FF666A5E.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\B0E13D560F212A0FA365.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\B1550EF65E0AB929E979.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\B2AC23F45CAD4F30B271.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\B2D506A43DCB97E41B08.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\B310A68BC35A414FDD37.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\B60794CAFDA9D8A75CAC.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\B64DDBD60DB491D52C4B.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\BA25886EE08A002E3019.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\BAD9AC808DA5DC699651.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\BE5A361DA0A625B43206.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\C18CD95CB3E5FFDEEB1D.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\C424F89EF7397303E945.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\C4E84AEEE011030534E2.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\C868FF325124E3D0D58F.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\CABF74F07CD033603D18.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\CD07C77580D7AD36EF19.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\CDA98B2488EEF66B2033.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\CE275B7D9043458D6329.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\D0835F1B02E072A4CEAC.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\D256EAA652739D44E792.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\D3E41485BA02A389EA5A.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\D60DD357097D9BFA0D43.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\D8522EBD6EF543C371A9.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\D9780F2A5372F623EA0C.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\DA88EB6B92575E17AEDC.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\DB8EBA0A8243FAC1DD16.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\DCD20AB6684A16AA1475.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\E2EA3C29770B1D9EB098.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\E3FAFADD4E7B350EBFCD.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\E57D43AF0552E3F07064.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\E61C34CDF3E87D7329ED.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\E6760CB68517A6A361A8.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\E67D8443DF3B6D5C02B4.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\E7D0ED0A919F46B619A2.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\E8139A68B1EC9E7A6DAD.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\EAE2099E32B8E60E2D65.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\EF633ACD2004ED086FD0.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\F0C718FCBD0D60570C18.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\F14DB936646DBBA8A53E.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\F6E0242FA3807E87A3FB.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\F7929FC9708480F2E7B7.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\F861E354CAAB89D29F1F.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\F8DB91EC965669107B9A.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\F9BBFAC20B1890A3BBF2.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\FC3A8DCD49B069BC8D8F.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\FC5CC391DA4BA78C3961.vuze
c:\documents and settings\Steve\Application Data\Azureus\subs\FC77236E936F73E97B66.vuze
c:\documents and settings\Steve\Application Data\Azureus\subscriptions.config
c:\documents and settings\Steve\Application Data\Azureus\subscriptions.config.bak
c:\documents and settings\Steve\Application Data\Azureus\tables.config
c:\documents and settings\Steve\Application Data\Azureus\tables.config.bak
c:\documents and settings\Steve\Application Data\Azureus\timingstats.dat
c:\documents and settings\Steve\Application Data\Azureus\tmp\AZU2479279535710347623.tmp
c:\documents and settings\Steve\Application Data\Azureus\tmp\AZU2577059822676200331.tmp
c:\documents and settings\Steve\Application Data\Azureus\tmp\AZU2669524396862236105.tmp
c:\documents and settings\Steve\Application Data\Azureus\tmp\AZU36644062861997205.tmp
c:\documents and settings\Steve\Application Data\Azureus\tmp\AZU3935554337750055656.tmp
c:\documents and settings\Steve\Application Data\Azureus\tmp\AZU6065099865669106176.tmp
c:\documents and settings\Steve\Application Data\Azureus\tmp\AZU7283821615276727357.tmp
c:\documents and settings\Steve\Application Data\Azureus\tmp\AZU770135844356570249.tmp
c:\documents and settings\Steve\Application Data\Azureus\tmp\AZU8273678992003312429.tmp
c:\documents and settings\Steve\Application Data\Azureus\tmp\AZU885401208990289953.tmp
c:\documents and settings\Steve\Application Data\Azureus\tmp\AZU986475381120276872.tmp
c:\documents and settings\Steve\Application Data\Azureus\torrents\AZU18373.tmp
c:\documents and settings\Steve\Application Data\Azureus\torrents\AZU2993726963546461717.tmp
c:\documents and settings\Steve\Application Data\Azureus\torrents\AZU3036477330421389454.tmp
c:\documents and settings\Steve\Application Data\Azureus\torrents\AZU48191.tmp
c:\documents and settings\Steve\Application Data\Azureus\torrents\AZU60812.tmp
c:\documents and settings\Steve\Application Data\Azureus\torrents\AZU60815.tmp
c:\documents and settings\Steve\Application Data\Azureus\torrents\AZU7008142331779844129.tmp
c:\documents and settings\Steve\Application Data\Azureus\torrents\AZU7168251074302066430.tmp
c:\documents and settings\Steve\Application Data\Azureus\torrents\AZU8987074982427979399.tmp
c:\documents and settings\Steve\Application Data\Azureus\torrents\BSP_Megan.torrent
c:\documents and settings\Steve\Application Data\Azureus\torrents\btis_aletta_ocean.wmv.torrent
c:\documents and settings\Steve\Application Data\Azureus\torrents\deep_penetration-full.wmv.torrent
c:\documents and settings\Steve\Application Data\Azureus\torrents\delta_white_BTAW.wmv.torrent
c:\documents and settings\Steve\Application Data\Azureus\torrents\diamond_foxxx_MLIB.wmv.torrent
c:\documents and settings\Steve\Application Data\Azureus\torrents\jenna_kelly_CSTI.wmv.torrent
c:\documents and settings\Steve\Application Data\Azureus\torrents\MilfsLikeItBig_(Episode_29)_Phoenix_And_Morgan.torrent
c:\documents and settings\Steve\Application Data\Azureus\torrents\R&B_-_Daisy_Duxe.torrent
c:\documents and settings\Steve\Application Data\Azureus\torrents\Riley_-_Big_Sausage_Pizza.avi.torrent
c:\documents and settings\Steve\Application Data\Azureus\torrents\RWS_capri_cavalli.wmv.torrent
c:\documents and settings\Steve\Application Data\Azureus\tracker.config
c:\documents and settings\Steve\Application Data\Azureus\tracker.config.bak
c:\documents and settings\Steve\Application Data\Azureus\unsentdata.config
c:\documents and settings\Steve\Application Data\Azureus\unsentdata.config.bak
c:\documents and settings\Steve\Application Data\Azureus\update.log
c:\documents and settings\Steve\Application Data\Azureus\update.properties
c:\documents and settings\Steve\Application Data\Azureus\v3.Friends.dat
c:\documents and settings\Steve\Application Data\Azureus\v3.Friends.dat.bak
c:\documents and settings\Steve\Application Data\Azureus\VuzeActivities.config
c:\documents and settings\Steve\Application Data\Azureus\VuzeActivities.config.bak
c:\program files\Vuze
c:\program files\Vuze\plugins\azemp\azemp_2.0.32.jar
c:\program files\Vuze\plugins\azemp\azemp_2.0.32.zip
c:\program files\Vuze\plugins\azemp\azemp_2.0.34.jar
c:\program files\Vuze\plugins\azemp\azemp_2.0.34.zip
c:\program files\Vuze\plugins\azemp\azemp_2.1.02.jar
c:\program files\Vuze\plugins\azemp\azemp_2.1.02.zip
c:\program files\Vuze\plugins\azemp\azmplay.exe.bak
c:\program files\Vuze\plugins\azemp\cp1250-a.raw.bak
c:\program files\Vuze\plugins\azemp\cp1250-b.raw.bak
c:\program files\Vuze\plugins\azemp\font.desc.bak
c:\program files\Vuze\plugins\azemp\mplayer\config
c:\program files\Vuze\plugins\azemp\osd-mplayer-a.raw.bak
c:\program files\Vuze\plugins\azemp\osd-mplayer-b.raw.bak
c:\program files\Vuze\plugins\azemp\plugin.properties_2.0.32
c:\program files\Vuze\plugins\azemp\plugin.properties_2.0.34
c:\program files\Vuze\plugins\azemp\plugin.properties_2.1.02
c:\program files\Vuze\plugins\azupnpav\azupnpav_0.2.17.jar
c:\program files\Vuze\plugins\azupnpav\azupnpav_0.2.17.zip
c:\program files\Vuze\plugins\azupnpav\azupnpav_0.2.5.jar
c:\program files\Vuze\plugins\azupnpav\azupnpav_0.2.5.zip
c:\program files\Vuze\plugins\azupnpav\plugin.properties_0.2.17
c:\program files\Vuze\plugins\azupnpav\plugin.properties_0.2.5
.
((((((((((((((((((((((((( Files Created from 2009-03-13 to 2009-04-13 )))))))))))))))))))))))))))))))
.
2009-04-09 22:06 . 2009-04-06 20:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-04-09 22:06 . 2009-04-06 20:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-09 22:06 . 2009-04-09 22:06 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-09 22:06 . 2009-04-09 22:06 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-04-09 20:59 . 2009-03-09 19:06 15688 ----a-w c:\windows\system32\lsdelete.exe
2009-04-09 20:27 . 2009-03-09 19:06 64160 ----a-w c:\windows\system32\drivers\Lbd.sys
2009-04-09 20:26 . 2009-04-09 20:26 -------- dc-h--w c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-04-09 20:25 . 2009-04-09 20:27 -------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
2009-04-09 20:25 . 2009-04-09 20:25 -------- d-----w c:\program files\Lavasoft
2009-03-20 17:06 . 2009-03-20 17:06 -------- d-----w c:\documents and settings\All Users\Application Data\Office Genuine Advantage
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-13 16:58 . 2009-01-28 22:59 -------- d-----w c:\program files\Symantec AntiVirus
2009-04-13 16:52 . 2009-01-14 17:14 -------- d-----w c:\program files\Common Files\Adobe
2009-04-11 05:29 . 2009-04-10 05:03 668 ----a-w C:\aaw7boot.log
2009-04-10 04:24 . 2009-02-25 23:27 -------- d-----w c:\program files\Spybot - Search & Destroy
2009-04-09 22:21 . 2008-11-21 03:40 -------- d-----w c:\program files\Java
2009-04-02 05:02 . 2009-01-14 23:27 -------- d-----w c:\documents and settings\Steve\Application Data\U3
2009-03-26 00:35 . 2009-02-23 00:27 -------- d-----w c:\documents and settings\Steve\Application Data\Skype
2009-03-26 00:35 . 2009-02-23 00:29 -------- d-----w c:\documents and settings\Steve\Application Data\skypePM
2009-03-22 08:11 . 2009-02-01 23:17 -------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-03-13 08:08 . 2009-03-13 08:08 -------- d-----w c:\program files\Microsoft CAPICOM 2.1.0.2
2009-03-12 23:31 . 2009-01-07 20:38 0 ----a-w c:\windows\system32\drivers\lvuvc.hs
2009-03-12 23:31 . 2009-01-07 20:37 0 ----a-w c:\windows\system32\drivers\logiflt.iad
2009-03-09 10:19 . 2008-11-21 03:40 410984 ----a-w c:\windows\system32\deploytk.dll
2009-02-28 03:19 . 2009-02-28 02:56 -------- d-----w c:\documents and settings\Steve\Application Data\DivX
2009-02-28 02:55 . 2009-02-28 02:54 -------- d-----w c:\program files\DivX
2009-02-26 00:00 . 2009-02-25 23:27 -------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-23 00:27 . 2009-02-23 00:27 -------- d-----w c:\program files\Common Files\Skype
2009-02-23 00:27 . 2009-02-23 00:27 -------- d-----r c:\program files\Skype
2009-02-23 00:27 . 2009-02-23 00:26 -------- d-----w c:\documents and settings\All Users\Application Data\Skype
2009-02-09 11:13 . 2002-08-29 17:00 1846784 ----a-w c:\windows\system32\win32k.sys
2009-02-02 06:05 . 2008-11-16 21:49 69232 ----a-w c:\documents and settings\Steve\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-01-28 20:29 . 2009-01-28 20:26 110415 ----a-w c:\windows\hpoins11.dat
2008-11-17 03:20 . 2008-11-17 03:20 64200 ----a-w c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2005-02-02 102492]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-02-02 692316]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-08-14 565008]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-08-14 2407184]
"QuickPassword"="c:\program files\ActivCard\ActivCard Gold\agquickp.exe" [2002-08-30 131072]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2005-04-08 48752]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-03-09 515416]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"AGRSMMSG"="AGRSMMSG.exe" [2005-03-04 c:\windows\AGRSMMSG.exe]
c:\documents and settings\Steve\Start Menu\Programs\Startup\
Logitech . Product Registration.lnk - c:\program files\Logitech\QuickCam\eReg.exe [2008-02-13 493832]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ac3filter"= ac3filter.acm
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R2 ACTR;Smart Card Reader; [x]
R3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-03-09 951632]
R3 SavRoam;SavRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [2005-04-17 124608]
R3 SCRx31 USB Reader;SCRx31 USB Reader;c:\windows\system32\DRIVERS\stc2.sys [2002-08-22 57088]
R3 WLAN_400_500_SERVICE;HP WLAN W400/W500 Wireless Network Adapter Service;c:\windows\system32\DRIVERS\ar5211.sys [2005-09-15 468768]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2009-03-09 64160]
S2 acautoreg;ActivCard Gold Autoregister;c:\program files\Common Files\ActivCard\acautoreg.exe [2002-09-12 53248]
S2 Accoca;ActivCard Gold service;c:\program files\Common Files\ActivCard\accoca.exe [2004-08-11 143360]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
S3 Actrpcsc;Actrpcsc;c:\windows\system32\DRIVERS\actrpcsc.sys [2003-09-16 14784]
--- Other Services/Drivers In Memory ---
*Deregistered* - EraserUtilDrv10910
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b6e932e0-b40b-11dd-989d-c008699f1e5b}]
\Shell\AutoRun\command - e:\wd_windows_tools\WDEULA.exe
.
Contents of the 'Scheduled Tasks' folder
2009-04-09 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 14:06]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*
http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*
http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {5721FA68-5ABD-40A8-81F1-4136691194BF} - hxxps://www.play.net/components/activex/AXSAL.ocx
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-04-13 12:09
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\gxvxcserv.sys]
"imagepath"="\systemroot\system32\drivers\gxvxcxwtrjlwlrykjsvidwqkhcamtxbtkkuty.sys"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(748)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-04-13 12:10
ComboFix-quarantined-files.txt 2009-04-13 17:10
ComboFix2.txt 2009-04-13 03:08
Pre-Run: 10,632,454,144 bytes free
Post-Run: 10,637,430,784 bytes free
510 --- E O F --- 2009-03-22 08:15