very slow, popups, winantivirus pro, malware alarm, vundo

fiveskiers

New member
I think I did all that was asked first, so here goes. Sometimes McAfee says trojan removed - vundo.dll. There have been massive-sometimes 4 per minute-popups. The main popup used to be malwarealarm, ran spybot and deleted some files on my own, haven't seen that one in a while. Now the popups are mostly antivirus-winantivirus Pro and others-but sometimes movies and other stuff.
Heres the two logs. Had trouble getting the online scanner log in here. Hope this works.
Thanks in advance.

Scan Results: 67434 files scanned. 2 viruses were detected.

File Infection Status Path

byxyxur.dll Win32/Chisyne!generic
cannot cure C:\WINDOWS\system32\

urqrsst.dll Win32/Chisyne!generic
cannot cure C:\WINDOWS\system32\




Logfile of HijackThis v1.99.1
Scan saved at 1:22:47 AM, on 5/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Apoint\Apntex.exe
C:\PROGRA~1\MUSICM~1\MUSICM~2\mm_tray.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\AOL\1137190957\ee\AOLSoftware.exe
C:\WINDOWS\system32\bcmntray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Corel\Corel Snapfire\Corel Photo Downloader.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\McAfee\MSK\MskAgent.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\CASIO\Photo Loader\Plauto.exe
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
C:\Program Files\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.adelphia.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [MMTray] C:\PROGRA~1\MUSICM~1\MUSICM~2\mm_tray.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1137190957\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\bcmntray
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Snapfire\Corel Photo Downloader.exe
O4 - HKLM\..\Run: [MskAgentexe] C:\Program Files\McAfee\MSK\MskAgent.exe
O4 - HKLM\..\Run: [WindowsService] rundll32.exe "C:\WINDOWS\system32\yosnvvnb.dll",realset
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Photo Loader supervisory.lnk = C:\Program Files\CASIO\Photo Loader\Plauto.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.sxload.net (HKLM)
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www.ca.com/us/securityadvisor/virusinfo/webscan.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
 
Hi fiveskiers

Rename HijackThis.exe to scanner.exe and post back a fresh HijackThis log, please :)
 
Thanks for the fast reply. Sorry, I'm not sure I know what you mean. I'm a little slow so whatever details you could include would be appreciated.
Thanks.
 
Hi

Rename C:\Program Files\HijackThis.exe <--- this file to C:\Program Files\scanner.exe <-- this :)
 
Thanks. That's what I was thinking, but it seemed to simple so I thought you wanted something else. I'll do it tonight when I get home.

I'm not questioning your expertise, just curious for the future, how does that affect the results of the scan?
 
Hi

Renaming will reveal more entries in HijackThis log. Vundo hides 02 and 020 lines if process named HijackThis.exe is running; that's why it needs to be renamed.
 
Sweet. Thats why you're the expert and I'm not:bigthumb:
I'll post later this evening. Some posts have asked users to stay off the net, is that important in this case?
 
I changed the name, but when the program runs its still called HijackThis-is that OK, or did I miss something.
FYI-I'm also getting Yahabags redirects recently.
Thanks.


Logfile of HijackThis v1.99.1
Scan saved at 6:07:53 AM, on 5/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\PROGRA~1\MUSICM~1\MUSICM~2\mm_tray.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\Program Files\Common Files\AOL\1137190957\ee\AOLSoftware.exe
C:\WINDOWS\system32\bcmntray.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
C:\Program Files\iTunes\iTunesHelper.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\Corel\Corel Snapfire\Corel Photo Downloader.exe
C:\Program Files\McAfee\MSK\MskAgent.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Apoint\Apntex.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\CASIO\Photo Loader\Plauto.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\fxssvc.exe
c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\scanner.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.adelphia.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PsapiAnalyzer Object - {0A99A153-E4A0-4124-9DBE-AFADC0C902B6} - c:\windows\security\wmsip.dll
O2 - BHO: (no name) - {2B4EA2D9-A10C-40AA-A98A-CBBE42C9E5Be} - C:\WINDOWS\system32\khleadba.dll
O2 - BHO: (no name) - {3A0B7095-62CB-45A2-A865-A65FD33F3124} - C:\WINDOWS\system32\omdkdldn.dll
O2 - BHO: (no name) - {3F9D0C61-737D-44D1-BD80-91AF857061CC} - C:\WINDOWS\system32\urqrsst.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {714FAF2E-0510-4000-AACE-A2C314DE1FE0} - C:\WINDOWS\system32\pmnnm.dll (file missing)
O2 - BHO: (no name) - {753E6D0B-F4E6-45C4-B0E8-EAE23E28FDFB} - (no file)
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: (no name) - {926AA8EE-6D21-4DAB-9C86-7985B6345E4f} - C:\WINDOWS\system32\omdkdldn.dll
O2 - BHO: (no name) - {A89EE8FC-7762-4238-877A-ACB1DAA476F2} - C:\WINDOWS\system32\gebca.dll
O2 - BHO: (no name) - {B9AEAF5A-4694-411B-A6E6-BD736854B9D3} - C:\WINDOWS\system32\khleadba.dll
O2 - BHO: (no name) - {CD4792DF-FBF8-4CD7-9FD6-116FD53EF2C1} - C:\WINDOWS\system32\omdkdldn.dll
O2 - BHO: (no name) - {D651AFF4-9590-424d-BD1E-8E33E090DFB3} - C:\WINDOWS\system32\pifvrojc.dll
O2 - BHO: (no name) - {E34B5FDC-0C6C-47C2-8B00-45777AB73F40} - C:\WINDOWS\system32\omdkdldn.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [MMTray] C:\PROGRA~1\MUSICM~1\MUSICM~2\mm_tray.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1137190957\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\bcmntray
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Snapfire\Corel Photo Downloader.exe
O4 - HKLM\..\Run: [MskAgentexe] C:\Program Files\McAfee\MSK\MskAgent.exe
O4 - HKLM\..\Run: [WindowsUpdate] rundll32.exe "C:\WINDOWS\system32\flceohcm.dll",realset
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Photo Loader supervisory.lnk = C:\Program Files\CASIO\Photo Loader\Plauto.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.sxload.net (HKLM)
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www.ca.com/us/securityadvisor/virusinfo/webscan.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: gebca - C:\WINDOWS\system32\gebca.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: ssqrs - C:\WINDOWS\system32\ssqrs.dll
O20 - Winlogon Notify: urqrsst - C:\WINDOWS\SYSTEM32\urqrsst.dll
O20 - Winlogon Notify: wmsip - c:\windows\security\wmsip.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
 
Hi

No worries, it's just fine now :)

Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log in a reply to this thread.
Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button" when VundoFix appears upon rebooting.
 
The Vundo list the 1st and 2nd scans werent the same. I assume thats because if fixed some the 1st time. When it was trying to fix the 1st time and closing down, it said something like system error 75 unable to access...path or something similar, I don't remember exactly. But on the 2nd scan it was ok. I assume it was taken care of on the 2nd scan, but just wanted you to know in case it was an issue. Heres the 2nd vundo log and the subsequent HijackThis log. Thanks Again.

VundoFix V6.3.21

Checking Java version...

Java version is 1.4.2.3
Old versions of java are exploitable and should be removed.

Scan started at 6:50:26 AM 5/11/2007

Listing files found while scanning....

c:\windows\security\wmsip.dll
C:\WINDOWS\system32\acbeg.bak1
C:\WINDOWS\system32\acbeg.bak2
C:\WINDOWS\system32\acbeg.ini
C:\WINDOWS\system32\byxyxur.dll
C:\WINDOWS\system32\gebca.dll
C:\WINDOWS\system32\pifvrojc.dll
C:\WINDOWS\system32\urqrsst.dll

Beginning removal...

Attempting to delete c:\windows\security\wmsip.dll
c:\windows\security\wmsip.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\acbeg.bak1
C:\WINDOWS\system32\acbeg.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\acbeg.bak2
C:\WINDOWS\system32\acbeg.bak2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\acbeg.ini
C:\WINDOWS\system32\acbeg.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\byxyxur.dll
C:\WINDOWS\system32\byxyxur.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\gebca.dll
C:\WINDOWS\system32\gebca.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\pifvrojc.dll
C:\WINDOWS\system32\pifvrojc.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\urqrsst.dll
C:\WINDOWS\system32\urqrsst.dll Could not be deleted.

Performing Repairs to the registry.
Done!

VundoFix V6.3.21

Checking Java version...

Java version is 1.4.2.3
Old versions of java are exploitable and should be removed.

Scan started at 7:08:13 AM 5/11/2007

Listing files found while scanning....

C:\WINDOWS\system32\srqss.bak1
C:\WINDOWS\system32\srqss.bak2
C:\WINDOWS\system32\srqss.ini
C:\WINDOWS\system32\ssqrs.dll
C:\WINDOWS\system32\urqrsst.dll

Beginning removal...

Attempting to delete C:\WINDOWS\system32\srqss.bak1
C:\WINDOWS\system32\srqss.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\srqss.bak2
C:\WINDOWS\system32\srqss.bak2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\srqss.ini
C:\WINDOWS\system32\srqss.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\ssqrs.dll
C:\WINDOWS\system32\ssqrs.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\urqrsst.dll
C:\WINDOWS\system32\urqrsst.dll Has been deleted!

Performing Repairs to the registry.
Done!


Logfile of HijackThis v1.99.1
Scan saved at 11:32:14 AM, on 5/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\PROGRA~1\MUSICM~1\MUSICM~2\mm_tray.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\AOL\1137190957\ee\AOLSoftware.exe
C:\WINDOWS\system32\bcmntray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Corel\Corel Snapfire\Corel Photo Downloader.exe
C:\Program Files\McAfee\MSK\MskAgent.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\CASIO\Photo Loader\Plauto.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\scanner.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.adelphia.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PsapiAnalyzer Object - {0A99A153-E4A0-4124-9DBE-AFADC0C902B6} - c:\windows\security\wmsip.dll (file missing)
O2 - BHO: (no name) - {0D72B29A-E169-4005-93EA-0067B93B7720} - C:\WINDOWS\system32\ssqrs.dll (file missing)
O2 - BHO: (no name) - {2B4EA2D9-A10C-40AA-A98A-CBBE42C9E5Be} - C:\WINDOWS\system32\khleadba.dll
O2 - BHO: (no name) - {3A0B7095-62CB-45A2-A865-A65FD33F3124} - C:\WINDOWS\system32\omdkdldn.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {714FAF2E-0510-4000-AACE-A2C314DE1FE0} - C:\WINDOWS\system32\pmnnm.dll (file missing)
O2 - BHO: (no name) - {753E6D0B-F4E6-45C4-B0E8-EAE23E28FDFB} - (no file)
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: (no name) - {926AA8EE-6D21-4DAB-9C86-7985B6345E4f} - C:\WINDOWS\system32\omdkdldn.dll
O2 - BHO: (no name) - {A89EE8FC-7762-4238-877A-ACB1DAA476F2} - C:\WINDOWS\system32\gebca.dll (file missing)
O2 - BHO: (no name) - {B9AEAF5A-4694-411B-A6E6-BD736854B9D3} - C:\WINDOWS\system32\khleadba.dll
O2 - BHO: (no name) - {CD4792DF-FBF8-4CD7-9FD6-116FD53EF2C1} - C:\WINDOWS\system32\omdkdldn.dll
O2 - BHO: (no name) - {E34B5FDC-0C6C-47C2-8B00-45777AB73F40} - C:\WINDOWS\system32\omdkdldn.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [MMTray] C:\PROGRA~1\MUSICM~1\MUSICM~2\mm_tray.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1137190957\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\bcmntray
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Snapfire\Corel Photo Downloader.exe
O4 - HKLM\..\Run: [MskAgentexe] C:\Program Files\McAfee\MSK\MskAgent.exe
O4 - HKLM\..\Run: [WindowsUpdate] rundll32.exe "C:\WINDOWS\system32\flceohcm.dll",realset
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Photo Loader supervisory.lnk = C:\Program Files\CASIO\Photo Loader\Plauto.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.sxload.net (HKLM)
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www.ca.com/us/securityadvisor/virusinfo/webscan.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
 
Hi

Open HijackThis, click do a system scan only and checkmark these:


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway <--- optional (if don't want that to be your home page)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cust...search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/cust.../www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway <--- see above
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway <--- see above
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/cust.../www.yahoo.com
O2 - BHO: PsapiAnalyzer Object - {0A99A153-E4A0-4124-9DBE-AFADC0C902B6} - c:\windows\security\wmsip.dll (file missing)
O2 - BHO: (no name) - {0D72B29A-E169-4005-93EA-0067B93B7720} - C:\WINDOWS\system32\ssqrs.dll (file missing)
O2 - BHO: (no name) - {2B4EA2D9-A10C-40AA-A98A-CBBE42C9E5Be} - C:\WINDOWS\system32\khleadba.dll
O2 - BHO: (no name) - {3A0B7095-62CB-45A2-A865-A65FD33F3124} - C:\WINDOWS\system32\omdkdldn.dll
O2 - BHO: (no name) - {714FAF2E-0510-4000-AACE-A2C314DE1FE0} - C:\WINDOWS\system32\pmnnm.dll (file missing)
O2 - BHO: (no name) - {753E6D0B-F4E6-45C4-B0E8-EAE23E28FDFB} - (no file)
O2 - BHO: (no name) - {926AA8EE-6D21-4DAB-9C86-7985B6345E4f} - C:\WINDOWS\system32\omdkdldn.dll
O2 - BHO: (no name) - {A89EE8FC-7762-4238-877A-ACB1DAA476F2} - C:\WINDOWS\system32\gebca.dll (file missing)
O2 - BHO: (no name) - {B9AEAF5A-4694-411B-A6E6-BD736854B9D3} - C:\WINDOWS\system32\khleadba.dll
O2 - BHO: (no name) - {CD4792DF-FBF8-4CD7-9FD6-116FD53EF2C1} - C:\WINDOWS\system32\omdkdldn.dll
O2 - BHO: (no name) - {E34B5FDC-0C6C-47C2-8B00-45777AB73F40} - C:\WINDOWS\system32\omdkdldn.dll
O4 - HKLM\..\Run: [WindowsUpdate] rundll32.exe "C:\WINDOWS\system32\flceohcm.dll",realset
O15 - Trusted Zone: *.sxload.net (HKLM)


Close all windows including browser and press fix checked.

Reboot

Delete if present:

C:\WINDOWS\system32\khleadba.dll
C:\WINDOWS\system32\omdkdldn.dll
C:\WINDOWS\system32\flceohcm.dll

Empty Recycle Bin

Post a fresh HijackThis log.
 
Hello,
After I pressed "fix checked" a window asks if I want to permanently delete and/or repair these 19 items. Is this a YES? Then reboot? - is this the same as restart?

Then you say...
Delete if present:

C:\WINDOWS\system32\khleadba.dll
C:\WINDOWS\system32\omdkdldn.dll
C:\WINDOWS\system32\flceohcm.dll

Will a program be running automatically or do I need to run one to see if these 3 appear? Thanks
 
Hi

"Is this a YES?"

Yes :)

"Then reboot? - is this the same as restart?"

Yes.

Delete those files via Windows Explorer or My Computer :)
 
Hello,
All 3 were present and deleted. Heres the new HJT

Logfile of HijackThis v1.99.1
Scan saved at 2:12:31 PM, on 5/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\PROGRA~1\MUSICM~1\MUSICM~2\mm_tray.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\AOL\1137190957\ee\AOLSoftware.exe
C:\WINDOWS\system32\bcmntray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Corel\Corel Snapfire\Corel Photo Downloader.exe
C:\Program Files\McAfee\MSK\MskAgent.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\CASIO\Photo Loader\Plauto.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.adelphia.net/
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [MMTray] C:\PROGRA~1\MUSICM~1\MUSICM~2\mm_tray.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1137190957\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\bcmntray
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Snapfire\Corel Photo Downloader.exe
O4 - HKLM\..\Run: [MskAgentexe] C:\Program Files\McAfee\MSK\MskAgent.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Photo Loader supervisory.lnk = C:\Program Files\CASIO\Photo Loader\Plauto.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www.ca.com/us/securityadvisor/virusinfo/webscan.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
 
Hi

Please do an online scan with Kaspersky Online Scanner. You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings
  • In the scan settings make sure that the following are selected:

    o Scan using the following Anti-Virus database:

    + Extended (If available otherwise Standard)

    o Scan Options:

    + Scan Archives
    + Scan Mail Bases
  • Click OK
  • Now under select a target to scan select My Computer
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button
  • Save the file to your desktop.
  • Copy and paste that information in your next post.

Post:

- a fresh HijackThis log
- kaspersky report
 
Hi
I tried posting the whole Kaspersky file, but thak made the post 120k and it can only be 20k. Should I just post it in 6 or 7 parts? (I think I chose expanded report. I have closed that window now, but maybe I should scan again and not choose this option to make a shorter report, or do you want the whole thing?) Let me know. Thanks

Logfile of HijackThis v1.99.1
Scan saved at 7:04:56 AM, on 5/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\PROGRA~1\MUSICM~1\MUSICM~2\mm_tray.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\AOL\1137190957\ee\AOLSoftware.exe
C:\WINDOWS\system32\bcmntray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Corel\Corel Snapfire\Corel Photo Downloader.exe
C:\Program Files\McAfee\MSK\MskAgent.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\CASIO\Photo Loader\Plauto.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.adelphia.net/
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [MMTray] C:\PROGRA~1\MUSICM~1\MUSICM~2\mm_tray.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1137190957\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\bcmntray
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Snapfire\Corel Photo Downloader.exe
O4 - HKLM\..\Run: [MskAgentexe] C:\Program Files\McAfee\MSK\MskAgent.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Photo Loader supervisory.lnk = C:\Program Files\CASIO\Photo Loader\Plauto.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www.ca.com/us/securityadvisor/virusinfo/webscan.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: McAfee Application Installer Cleanup (0165201179022367) (0165201179022367mcinstcleanup) - McAfee, Inc. - C:\WINDOWS\TEMP\016520~1.EXE
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Sunday, May 13, 2007 7:03:47 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.0
Kaspersky Anti-Virus database last update: 12/05/2007
Kaspersky Anti-Virus database records: 318204
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\

Scan Statistics:
Total number of scanned objects: 81310
Number of viruses found: 5
Number of infected objects: 23
Number of suspicious objects: 0
Duration of the scan process: 02:38:21

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\McAfee\MNA\NAData Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MPF\data\log.edb Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\Events.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\{ED596B73-E626-493E-A5FB-83459FA0EE4E}.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSC\McUsers.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSK\MSKWMDB.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSK\RBLDB.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\MSK\settingsdb.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Data\TFR10.tmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Logs\OAS.Log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3ad391678a806ec4d691e83aaa393b6f_50e417e0-e461-474b-96e2-077b80325612 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\48d27dc494cad9658253efdb27aafb63_50e417e0-e461-474b-96e2-077b80325612 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\61e46483be75394315b1e539a2c5654d_50e417e0-e461-474b-96e2-077b80325612 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7cb58466dec14406bec2257bc34d9cf6_50e417e0-e461-474b-96e2-077b80325612 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\0\0201D20472 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\0\0201D206E1 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\0\0201D25465 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\0\0201D26F35 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\0\0201D29550 Object is locked
 
skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\0\0201D29B40 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\0\0201D29B42 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\0\0201E060AF Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\0\0201E068C0 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\0\0201E08641 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\0\2B000003CA Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\0\2B00001924 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\0\2B000019A1 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\0\2B000019A8 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\0\2B00001F36 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\0\2B00001FB3 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\0\2B00001FB4 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\0\2B00002089 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\0\2B000020BF Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\0\2B000020ED Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\006EF91B424F8FA4BB4BF6C78B7D28D2 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\0201D20472 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\0201D205A1 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\0201D20E56 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\0201D22E99 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\0201D233DE Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\0201D24A65 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\0201D25465 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\0201D2673B Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\0201D271AC Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\0201D29550 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\0201D29B40 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\0201D29B42 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\0201D2A16C Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\0201E060AF Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\0201E068C0 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\0201E08641 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\0201E08DF3 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\083389394F65FDA15164017310345141 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\10A40F9A598C82A9A4FA1349459A5939 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\20A1E2A1D447AD4970EF04BE465D9FEE Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\2159E1971ED0878F92C9D61E64D3CA16 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\2B0000009D Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\2B000003CA Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\2B0000092C Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\2B00000A6C Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\2B000010A7 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\2B00001924 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\2B000019A1 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\2B000019A8 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\2B00001F36 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\2B00001FB4 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\2B000020BF Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\2B000020ED Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\2B0000290F Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\2C61705F69636F6E Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\2F47DE2FA13757C13805A281EC80E0F2 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\3D980A586036BB2A8E1BA982A08FB9C3 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\450DFB7A37C0C783A9241A1433D47C55 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\45B616924B29F6E0EDD0FF112AA27D91 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\585790A1BCCE15B4E5D183E187265C37 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\68CFAA06282795074DAF27DCA59C0382 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\75F448642575E007369ECA2126190B6B Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\820FC355FC98630EF6577A5F8C91CC04 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\983CF93A2ED182645359A96C33662CE0 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\AB5C5AA1A15FEEC4A311369999DCD36A Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\AE75E0CE8675950C1E9D469238F12DC6 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\B59094ADF4223C472AE65412677F8E33 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\BB7AFFF3C0A166E9ECB8052194BD0646 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\BB8856ED76452E00422146E8E329BCA8 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\BF19B814634F519C09532E2137545AAB Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\C6C985E676D5E27F262FA9F9DDB45036 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\D03E65820F3C87501D25948B7B1065FB Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\D25B943EF3EAB8DC7C446059E78B413F Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\D6E8DB1604827997A06564F6B7084388 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\DC1FA6D8C88F5E471CEEC9701AFF292A Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\DD4038E4882CACF2482F2B9DC223AC9A Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1\ED49A39943E8BF03CB35CE9803144491 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1024\0201D201A5 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1024\0201D243EE Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1024\0201D243EF Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1024\0201D243F2 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1024\0201D243F3 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1024\0201D2956B Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1024\0201E03087 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1024\0201E0309C Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1024\0201E05FA4 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1024\0201E05FCB Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1024\0201E05FD0 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1024\2B000001B7 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1024\2B000001E2 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1024\2B000001E4 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1024\2B0000020B Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1024\2B0000023C Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\1024\2B00002AF1 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\129\0201D20F48 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\129\0201D210D1 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\129\0201D215F1 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\129\0201D232AF Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\129\0201D252B9 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\129\0201D283DD Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\129\0201D2B0AE Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\129\0201E075CE Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\129\0202564B15 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\129\2B0000128A Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\129\2B0000144F Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\129\2B00001608 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\129\2B00001862 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\129\2B00001A6C Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\129\2B00001AEC Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\129\2B00001B53 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\129\2B00001B87 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\129\2B00001EC9 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\131\0201D25DB8 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\131\0201D29E6E Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\131\2B00001057 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\3\0201D23F04 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\3\0201D25DB8 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\3\0201D29439 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\3\0201D29E6E Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\3\0201D29E7B Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\3\0201E0112A Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\3\2B000007FB Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\3\2B00000C2B Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\3\2B00001057 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\bart\3\2B00001081 Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\users\bordergirl628\buddyicon Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\users\bordergirl628\feedbag Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\users\ebordergirl628\buddyicon Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\users\grebordergirl628\buddyicon Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\users\ilbordergirl628\buddyicon Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\acccore\caches\users\w.gbordergirl628\buddyicon Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Adobe\Acrobat\6.0\AcroForm\MRUFormsList Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Adobe\Acrobat\6.0\AdobeComFnt06.lst Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Adobe\Acrobat\6.0\Collab\OfflineDocs Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Adobe\Acrobat\6.0\Collab\Reviews Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Adobe\Acrobat\6.0\JSADM.exv Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Adobe\Acrobat\6.0\Preferences\AutoFillDefaults.dat Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Adobe\Acrobat\6.0\Preferences\defaultHeuristics.dat Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Adobe\Acrobat\6.0\TMGrpPrm.sav Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Adobe\Acrobat\6.0\Updater\udstore.js Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Adobe\Acrobat\7.0\AdobeCMapFnt07.lst Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Adobe\Acrobat\7.0\AdobeSysFnt07.lst Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Adobe\Acrobat\7.0\Collab\RSS Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Adobe\Acrobat\7.0\JavaScripts\glob.settings.js Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Adobe\Acrobat\7.0\JSADM.exv Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Adobe\Acrobat\7.0\Messages\ENU\read0700win_ENUadbe0700.pdf Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Adobe\Acrobat\7.0\Preferences\AutoFillDefaults.dat Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Adobe\Acrobat\7.0\Preferences\defaultHeuristics.dat Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Adobe\Acrobat\7.0\Updater\AdbeRdr709_en_US.exe Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Adobe\Acrobat\7.0\Updater\rvRestart.txt Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Adobe\Acrobat\7.0\Updater\udlog.txt Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Adobe\Acrobat\7.0\Updater\udstore.js Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Adobe\Acrobat\7.0\UserCache.bin Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\AdobeUM\AcRdB7_0_0.ini Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\AdobeUM\AcRdB7_0_0.sta Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\AdobeUM\AcRdB7_0_5.ini Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\AdobeUM\AcRdB7_0_5.sta Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\AdobeUM\AcRdB7_0_7.sta Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\AdobeUM\AcRdB7_0_9.sta Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Apple Computer\iTunes\CD Info.cidb Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Apple Computer\iTunes\iTunes.pref Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\ImageDB.db Object is locked skipped
 
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\LastDBFilter.PspCache Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\LastDBTreeSel.PspCache Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1145399566074\body.htm Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1145399566074\snippet-Snapfire-SP-ALL,22.gif Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1145399569882\15-Snapfire-NW-ALL-2-snippet-right.gif Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1145399569882\body.htm Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1145399569882\detail.htm Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1145399569882\masthead_psppXI,11.jpg Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1145399569882\masthead_psppXI,6.jpg Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1146003518408\18-Snapfire-TU-ALL-1-snippet-top,0.gif Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1146003518408\18-Snapfire-TU-ALL-1-snippet-top.gif Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1146003518408\body.htm Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1146003518958\body.htm Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1146003518958\detail-Snapfire-QT-ENHANCE-1.gif Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1146003518958\detail.htm Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1146003518958\snippet-Snapfire-QT-ENHANCE-1,2.gif Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1146003518958\snippet-Snapfire-QT-ENHANCE-1.gif Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1146003519055\6-Snapfire-QT-ENHANCE-2-snippet-right,0.gif Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1146003519055\6-Snapfire-QT-ENHANCE-2-snippet-right.gif Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1146003519055\body.htm Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1146003519055\detail-Snapfire-QT-ENHANCE-2,0.gif Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1146003519055\detail-Snapfire-QT-ENHANCE-2.gif Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1146003519055\detail.htm Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1146003519151\7-Snapfire-QT-ENHANCE-3-snippet-top,0.gif Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1146003519151\7-Snapfire-QT-ENHANCE-3-snippet-top.gif Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1146003519151\body.htm Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1146003519151\detail-Snapfire-QT-ENHANCE-3,0.gif Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1146003519151\detail-Snapfire-QT-ENHANCE-3.gif Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1146003519151\detail.htm Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1146003519174\8-Snapfire-QT-CREATE-1-snippet-top,2.gif Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1146003519174\8-Snapfire-QT-CREATE-1-snippet-top.gif Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1146003519174\body.htm Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1146003519174\detail-Snapfire-QT-CREATE-1,2.gif Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1146003519174\detail-Snapfire-QT-CREATE-1.gif Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1146003519174\detail.htm Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1146003519204\9-Snapfire-QT-CREATE-2-snippet-right,2.gif Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1146003519204\9-Snapfire-QT-CREATE-2-snippet-right.gif Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1146003519204\body.htm Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1146003519204\detail-Snapfire-QT-CREATE-2,2.gif Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1146003519204\detail-Snapfire-QT-CREATE-2.gif Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1146003519204\detail.htm Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1146003519234\body.htm Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1146003519234\detail-Snapfire-QT-ALL-2.gif Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1146003519234\detail.htm Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1146003519234\snippet-Snapfire-QT-ALL-2.gif Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1146003519249\14-Snapfire-NW-ALL-1-snippet-top.gif Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1146003519249\body.htm Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1146003519266\12-Snapfire-NWRR-ALL-1-snippet-top,2.gif Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1146003519266\12-Snapfire-NWRR-ALL-1-snippet-top.gif Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1146003519266\body.htm Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1146003519283\body.htm Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1146003519283\detail-Snapfire-NWINTRO-ALL-1-rev,0.gif Object is locked skipped
C:\Documents and Settings\Amanda Hochkammer\Application Data\Corel\Messages\540223438_607216\EN\MessageCache1\1146003519283\detail-Snapfire-NWINTRO-ALL-1-rev,5.gif Object is locked skipped
 
Back
Top