Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

My HJT LOG

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

My HJT LOG

Unread postby tanyasm » December 27th, 2006, 4:20 pm

Hi,

Can you please take a look at my log and tell me what needs to be deleted because my computer is running real slow and I have broadband it should be running wayyyyy faster than this.

Here is my HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 2:16:55 PM, on 12/27/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Yahoo!\Antivirus\ISafe.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\support.com\bin\tgcmd.exe
C:\Program Files\Dell Photo AIO Printer 962\dlbxmon.exe
C:\Program Files\CA\eTrust Internet Security Suite\caissdt.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Hewlett-Packard\AiO\hp officejet v series\Bin\hpoant07.exe
C:\Program Files\Common Files\G7PS\Shared Files\Qchex\Qchex.exe
C:\WINDOWS\System32\dlbxcoms.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\cidaemon.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/home.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\support.com\bin\tgcmd.exe" /server
O4 - HKLM\..\Run: [dlbxmon.exe] "C:\Program Files\Dell Photo AIO Printer 962\dlbxmon.exe"
O4 - HKLM\..\Run: [CaISSDT] "C:\Program Files\CA\eTrust Internet Security Suite\caissdt.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HPAiODevice(hp officejet v series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet v series\Bin\hpoant07.exe
O4 - Global Startup: Qchex Tray Icon.lnk = C:\Program Files\Common Files\G7PS\Shared Files\Qchex\Qchex.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} (TTestGenXInstallObject) - http://asp.mathxl.com/wizmodules/testge ... nstall.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/share ... insctl.cab
O16 - DPF: {4FE89055-5300-469E-AFAD-DEB3181EDE76} (PearsonAsstX Control) - http://www.mathxl.com/applets/PearsonInstallAsst.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 3036623678
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 3384494187
O16 - DPF: {8EB3FF4E-86A1-4717-884D-7BA2D38272CB} (F-Secure Online Scanner) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} (Pearson Installation Assistant 2) - http://asp.mathxl.com/books/_Players/Pe ... lAsst2.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan ... asinst.cab
O16 - DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} (InetDownload Class) - https://media.pineconeresearch.com/Acti ... ontrol.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/share ... cgdmgr.cab
O16 - DPF: {C4DD6732-1E82-4AE7-BD94-180331B84082} (DeltaCVX Control) - http://www.mathxl.com/applets/DeltaCVX.cab
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} (Pearson MathXL Player) - http://asp.mathxl.com/books/_Players/MathPlayer.cab
O18 - Protocol: g7ps - {9EACF0FB-4FC7-436E-989B-3197142AD979} - C:\Program Files\Common Files\G7PS\Shared Files\G7PSDLL\G7PS.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AutoComplete Service (Autocomplete) - Acesoft - C:\Program Files\Acesoft\Tracks Eraser Pro\delautocomp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\ISafe.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: dlbx_device - Dell - C:\WINDOWS\System32\dlbxcoms.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\SYSTEM32\YPCSER~1.EXE

Thank you,

Tanya
tanyasm
Regular Member
 
Posts: 52
Joined: November 24th, 2005, 12:37 am
Advertisement
Register to Remove

Unread postby Linkmaster » December 29th, 2006, 12:02 pm

Hi tanyasm, Welcome to MalWare Removal !!
Sorry for the delay in reviewing your post

Your log seems to be OK

Are you having any specific problems ??

I would like to make a suggestion :
You have :
eTrust Internet Suite
Kerio Firewall
Yahoo Antivirus


I think, if im not mistaken, the eTrust suite includes Firewall and Antivirus
I suggest that you use one of each (Kerio for Firewall and Yahoo for Antivirus) or Just the eTrust Internet Suite to run all the time in the background
Having more than one antivirus and/or Firewall running causes a conflict between the programs !! You can use one of the Antivirus programs as a backup to run manually
User avatar
Linkmaster
MRU Honors Grad Emeritus
 
Posts: 822
Joined: October 7th, 2005, 5:57 am
Location: Arkansas, USA

Thanks for responding

Unread postby tanyasm » December 31st, 2006, 4:23 pm

What would you suggest in place of yahoo antivirus because I do not want to use that. I didn't know it was installed on my computer.

Thanks for the quick reply

Tanya
tanyasm
Regular Member
 
Posts: 52
Joined: November 24th, 2005, 12:37 am

I get it

Unread postby tanyasm » December 31st, 2006, 4:25 pm

Sorry...I get it...use either or...so I will use the etrust program but I really like the kerio firewall but I do not care for yahoo antivirus

Thanks again,

Tanya
tanyasm
Regular Member
 
Posts: 52
Joined: November 24th, 2005, 12:37 am

Unread postby Linkmaster » December 31st, 2006, 4:52 pm

If you use and like the eTrust suite, try disabling the firewall and use the kerio Firewall !!

That may work, but then again these things don't like to play nice with others !! :lol:

Did disabling those help ??
How is your system running now ??
User avatar
Linkmaster
MRU Honors Grad Emeritus
 
Posts: 822
Joined: October 7th, 2005, 5:57 am
Location: Arkansas, USA

New HJT log

Unread postby tanyasm » January 7th, 2007, 2:13 pm

Hi again, and no disabling kerio firewall and yahoo antivirus did not work. I even uninstalled those two programs and my computer is still running slow, it's actually running slower and I also cannot open up certain files that I could open before. I now have etrust installed and I do not like that program. Can you please recommend good protection for my computer so I can delete etrust too and Can you please take another look at my log again to make sure everything is fine. I have broadband and my connection is usually real fast now it's real slow.

Thanks again,

Tanya




Logfile of HijackThis v1.99.1
Scan saved at 11:56:21 AM, on 01/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\SanDisk\Sansa Updater\SansaSvr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\support.com\bin\tgcmd.exe
C:\Program Files\Dell Photo AIO Printer 962\dlbxmon.exe
C:\Program Files\CA\eTrust Internet Security Suite\caissdt.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Fisher-Price\FP3 Player\sspnotifier.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Hewlett-Packard\AiO\hp officejet v series\Bin\hpoant07.exe
C:\Program Files\Common Files\G7PS\Shared Files\Qchex\Qchex.exe
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe
C:\WINDOWS\System32\dlbxcoms.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Yahoo!\browser\ybrwicon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\HJT\HijackThis.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/home.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\support.com\bin\tgcmd.exe" /server
O4 - HKLM\..\Run: [dlbxmon.exe] "C:\Program Files\Dell Photo AIO Printer 962\dlbxmon.exe"
O4 - HKLM\..\Run: [CaISSDT] "C:\Program Files\CA\eTrust Internet Security Suite\caissdt.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SSP Notifier] C:\Program Files\Fisher-Price\FP3 Player\sspnotifier.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HPAiODevice(hp officejet v series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet v series\Bin\hpoant07.exe
O4 - Global Startup: Qchex Tray Icon.lnk = C:\Program Files\Common Files\G7PS\Shared Files\Qchex\Qchex.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} (TTestGenXInstallObject) - http://asp.mathxl.com/wizmodules/testge ... nstall.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/share ... insctl.cab
O16 - DPF: {4FE89055-5300-469E-AFAD-DEB3181EDE76} (PearsonAsstX Control) - http://www.mathxl.com/applets/PearsonInstallAsst.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 3036623678
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 3384494187
O16 - DPF: {8EB3FF4E-86A1-4717-884D-7BA2D38272CB} (F-Secure Online Scanner) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} (Pearson Installation Assistant 2) - http://asp.mathxl.com/books/_Players/Pe ... lAsst2.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan ... asinst.cab
O16 - DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} (InetDownload Class) - https://media.pineconeresearch.com/Acti ... ontrol.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/share ... cgdmgr.cab
O16 - DPF: {C4DD6732-1E82-4AE7-BD94-180331B84082} (DeltaCVX Control) - http://www.mathxl.com/applets/DeltaCVX.cab
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} (Pearson MathXL Player) - http://asp.mathxl.com/books/_Players/MathPlayer.cab
O18 - Protocol: g7ps - {9EACF0FB-4FC7-436E-989B-3197142AD979} - C:\Program Files\Common Files\G7PS\Shared Files\G7PSDLL\G7PS.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AutoComplete Service (Autocomplete) - Acesoft - C:\Program Files\Acesoft\Tracks Eraser Pro\delautocomp.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: dlbx_device - Dell - C:\WINDOWS\System32\dlbxcoms.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Sansa Updater Service (SansaService) - Unknown owner - C:\Program Files\SanDisk\Sansa Updater\SansaSvr.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\SYSTEM32\YPCSER~1.EXE
tanyasm
Regular Member
 
Posts: 52
Joined: November 24th, 2005, 12:37 am

Unread postby Linkmaster » January 7th, 2007, 6:56 pm

Hello again, Tanya
Lets see if we first can't find what is slowing you down !! Then I will make some suggestions !

You may wish to print out a copy of these instructions to follow while you complete this procedure

Uninstall Ewido Anti-Spyware from your PC
(I am going to have you install the new version)

I need you to download some programs to aide in our fix :Do Not Run Them Yet

Download ATF (Atribune Temp File) Cleaner© by Atribune

Download and Install AVG Anti-Spyware© by Grisoft

Launch AVG Anti-Spyware, there should be an icon on your desktop double-click it.
The program will now go to the main screen
You will need to update AVG Anti-Spyware to the latest definition files.
On the main screen select the icon Update then select the Update now link
Next select the Start Update button, the update will start and a progress bar will show the updates being installed.
Close AVG Anti-Spyware

Reboot to Safe mode
Restart your computer and begin tapping the F8 key on your keyboard just before Windows starts to load
If done right a Windows Advanced Options menu will appear.
Select the Safe Mode option and press Enter

Run ATF Cleaner
Double-click ATF Cleaner.exe
Under Main choose: Select All
Click the Empty Selected button.
Click Exit on the Main menu to close the program.

Run AVG Anti-Spyware
Click on Scanner at top
Click on Settings
Once in the Settings screen click on Recommended actions and then select Quarantine
Under Reports, Select Automatically generate report after every scan
Un-Select Only if threats were found
Select the Scanner icon at the top and then the Scan tab then click on Complete System Scan
AVG Anti-Spyware will now begin the scanning process, be patient this may take a little time
Once the scan is complete do the following :
If you have any infections you will prompted, then select Apply all actions
Next select the Reports icon at the top.
Select the Save report as button in the lower left hand of the screen and save it to a text file on your system (make sure to remember where you saved that file, this is important).
Close AVG Anti-Spyware

Reboot to Normal Mode

Run Kaspersky WebScanner
Click on Kaspersky Online Scanner
NOTE For Internet Explorer 7 Users : If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%
You will be promted to install an ActiveX component from Kaspersky, Click Yes.
The program will launch and then begin downloading t he latest definition files:
Once the files have been downloaded click on NEXT
Now click on Scan Settings
In the scan settings make that the following are selected:
Scan using the following Anti-Virus database:
Extended (if available otherwise Standard)

Scan Options:
Scan Archives
Scan Mail Bases

Click OK

Now under select a target to scan:
Select My Computer

Then the program will start and scan your system.
The scan will take a while so be patient and let it run.
Once the scan is complete it will display if your system has been infected.
Now click on the Save as Text button:
Save the file to your desktop.

Reboot

Post a fresh HijackThis Log, the AVG Anti-Spyware Log, and the Kaspersky Virus Scan Log here
(You may need to use several replies as the logs may be cut off)

Thank You !
User avatar
Linkmaster
MRU Honors Grad Emeritus
 
Posts: 822
Joined: October 7th, 2005, 5:57 am
Location: Arkansas, USA

New HJT LOG

Unread postby tanyasm » January 8th, 2007, 6:57 pm

Here is a copy of my new HJT Log

I did all the steps you told me to do and once I booted my computer into safe mode the ATF Icon was not on my desktop and when I clicked on all programs to see if it was there it was not there either. I raned the AVG Anti-Spyware in Safe Mode and nothing was found so I do not have a log to submit also when I raned the Kaspersky WebScanner it did not find any thing but I still saved what it did find. Here is the HJT LOG:

Logfile of HijackThis v1.99.1
Scan saved at 4:46:59 PM, on 01/08/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\support.com\bin\tgcmd.exe
C:\Program Files\Dell Photo AIO Printer 962\dlbxmon.exe
C:\Program Files\CA\eTrust Internet Security Suite\caissdt.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Fisher-Price\FP3 Player\sspnotifier.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust PestPatrol Anti-Spyware\PPActiveDetection.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Hewlett-Packard\AiO\hp officejet v series\Bin\hpoant07.exe
C:\Program Files\Common Files\G7PS\Shared Files\Qchex\Qchex.exe
C:\Program Files\SanDisk\Sansa Updater\SansaSvr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\dlbxcoms.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/home.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\support.com\bin\tgcmd.exe" /server
O4 - HKLM\..\Run: [dlbxmon.exe] "C:\Program Files\Dell Photo AIO Printer 962\dlbxmon.exe"
O4 - HKLM\..\Run: [CaISSDT] "C:\Program Files\CA\eTrust Internet Security Suite\caissdt.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SSP Notifier] C:\Program Files\Fisher-Price\FP3 Player\sspnotifier.exe
O4 - HKLM\..\Run: [eTrustPPAP] "C:\Program Files\CA\eTrust Internet Security Suite\eTrust PestPatrol Anti-Spyware\PPActiveDetection.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HPAiODevice(hp officejet v series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet v series\Bin\hpoant07.exe
O4 - Global Startup: Qchex Tray Icon.lnk = C:\Program Files\Common Files\G7PS\Shared Files\Qchex\Qchex.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partne ... nicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} (TTestGenXInstallObject) - http://asp.mathxl.com/wizmodules/testge ... nstall.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/share ... insctl.cab
O16 - DPF: {4FE89055-5300-469E-AFAD-DEB3181EDE76} (PearsonAsstX Control) - http://www.mathxl.com/applets/PearsonInstallAsst.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 3036623678
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 3384494187
O16 - DPF: {8EB3FF4E-86A1-4717-884D-7BA2D38272CB} (F-Secure Online Scanner) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} (Pearson Installation Assistant 2) - http://asp.mathxl.com/books/_Players/Pe ... lAsst2.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan ... asinst.cab
O16 - DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} (InetDownload Class) - https://media.pineconeresearch.com/Acti ... ontrol.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/share ... cgdmgr.cab
O16 - DPF: {C4DD6732-1E82-4AE7-BD94-180331B84082} (DeltaCVX Control) - http://www.mathxl.com/applets/DeltaCVX.cab
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} (Pearson MathXL Player) - http://asp.mathxl.com/books/_Players/MathPlayer.cab
O18 - Protocol: g7ps - {9EACF0FB-4FC7-436E-989B-3197142AD979} - C:\Program Files\Common Files\G7PS\Shared Files\G7PSDLL\G7PS.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AutoComplete Service (Autocomplete) - Acesoft - C:\Program Files\Acesoft\Tracks Eraser Pro\delautocomp.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: dlbx_device - Dell - C:\WINDOWS\System32\dlbxcoms.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Sansa Updater Service (SansaService) - Unknown owner - C:\Program Files\SanDisk\Sansa Updater\SansaSvr.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe

And here is the Kaspersky Online Scanner:

Monday, January 08, 2007 4:45:09 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 8/01/2007
Kaspersky Anti-Virus database records: 256730

Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true

Scan Target My Computer
C:\
D:\
E:\

Scan Statistics
Total number of scanned objects 86135
Number of viruses found 0
Number of infected objects 0 / 0
Number of suspicious objects 0
Duration of the scan process 01:36:57

Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9c32d69899f88b2adeec93156d5c94d0_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b89015467387cb6f0d2f9f1e9534eb7e_1dce0e75-1303-433a-bfc1-6b582bd25551 Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Windows NT\MSFax\ActivityLog\InboxLOG.txt Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Windows NT\MSFax\ActivityLog\OutboxLOG.txt Object is locked skipped

C:\Documents and Settings\LocalService\Cookies\INDEX.DAT Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT Object is locked skipped

C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\Tanya Smith\Application Data\Fisher-Price\FP3 Player\CMNotifyTrace.log Object is locked skipped

C:\Documents and Settings\Tanya Smith\Application Data\Gtek\GTUpdate\AUpdate\DellSupport\DSAgnt.log Object is locked skipped

C:\Documents and Settings\Tanya Smith\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\Tanya Smith\Local Settings\Application Data\ApplicationHistory\sspnotifier.exe.f1a33aab.ini.inuse Object is locked skipped

C:\Documents and Settings\Tanya Smith\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\Tanya Smith\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\Tanya Smith\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Tanya Smith\Local Settings\Temp\Perflib_Perfdata_770.dat Object is locked skipped

C:\Documents and Settings\Tanya Smith\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Tanya Smith\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\Tanya Smith\ntuser.dat.LOG Object is locked skipped

C:\Program Files\Dell\Support\UI\Search\catalog.wci\00000002.ps1 Object is locked skipped

C:\Program Files\Dell\Support\UI\Search\catalog.wci\00000002.ps2 Object is locked skipped

C:\Program Files\Dell\Support\UI\Search\catalog.wci\cicat.fid Object is locked skipped

C:\Program Files\Dell\Support\UI\Search\catalog.wci\cicat.hsh Object is locked skipped

C:\Program Files\Dell\Support\UI\Search\catalog.wci\CiCL0001.000 Object is locked skipped

C:\Program Files\Dell\Support\UI\Search\catalog.wci\CiP10000.000 Object is locked skipped

C:\Program Files\Dell\Support\UI\Search\catalog.wci\CiP20000.000 Object is locked skipped

C:\Program Files\Dell\Support\UI\Search\catalog.wci\CiPT0000.000 Object is locked skipped

C:\Program Files\Dell\Support\UI\Search\catalog.wci\CiSL0001.000 Object is locked skipped

C:\Program Files\Dell\Support\UI\Search\catalog.wci\CiSP0000.000 Object is locked skipped

C:\Program Files\Dell\Support\UI\Search\catalog.wci\CiST0000.000 Object is locked skipped

C:\Program Files\Dell\Support\UI\Search\catalog.wci\CiVP0000.000 Object is locked skipped

C:\Program Files\Dell\Support\UI\Search\catalog.wci\INDEX.000 Object is locked skipped

C:\Program Files\Dell\Support\UI\Search\catalog.wci\propstor.bk1 Object is locked skipped

C:\Program Files\Dell\Support\UI\Search\catalog.wci\propstor.bk2 Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\20050609032811.zip Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\20050609034433.zip Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\20050627215801.zip Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\20050719222501.zip Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq102.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq113.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq115.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq117.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq118.tmp\sais.log Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq118.tmp\saisau.dat Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq118.tmp\sais_kyf.dat Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq11A.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq11C.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq11E.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq120.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq122.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq124.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq126.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq128.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq12A.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq12C.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq12E.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq130.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq132.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq146.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq148.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq14A.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq14C.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq14E.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq150.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq152.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq154.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq156.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq158.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq15A.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq15C.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq15E.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq160.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq162.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq164.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq166.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq168.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq16A.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq16C.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq16E.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq170.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq172.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq174.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq176.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq178.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq17A.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq17C.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq17E.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq180.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq182.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq184.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq186.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq188.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq18A.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq18C.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq18E.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq190.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq196.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq198.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq19A.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq19C.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1A2.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1A4.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1A6.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1A8.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1AA.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1AC.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1AE.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1B0.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1B2.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1B4.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1B6.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1B8.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1BA.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1BC.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1BE.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1C0.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1C2.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1C4.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1C6.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1C8.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1CA.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1CC.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1CE.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1D0.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1D2.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1D4.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1D6.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1D8.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1DA.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1DC.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1DE.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1E0.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1E2.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1E4.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1E6.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1E8.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1EA.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1EC.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1EE.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1F0.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1F2.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1F4.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1F6.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1F8.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1FA.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1FC.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1FE.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq200.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq202.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq204.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq206.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq208.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq20A.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq20C.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq20E.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq210.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq212.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq214.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq216.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq218.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq21A.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq21C.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq21E.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq220.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq222.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq224.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq226.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq228.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq22A.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq22C.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq22E.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq230.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq232.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq234.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq236.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq238.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq23A.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq23C.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq23E.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq240.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq242.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq244.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq246.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq24D.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq24E.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq24F.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq250.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq251.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq252.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq253.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq254.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq255.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq256.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq257.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq258.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq259.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq25A.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq25B.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq25C.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq25D.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq25E.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq25F.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq26.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq260.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq261.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq262.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq263.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq264.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq265.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq266.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq267.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq268.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq269.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq26A.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq26B.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq26C.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq26D.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq26E.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq26F.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq270.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq271.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq272.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq273.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq274.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq275.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq276.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq277.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq278.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq279.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq27A.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq27B.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq27C.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq27D.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq27E.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq27F.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq280.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq281.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq282.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq283.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq284.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq285.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq286.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq287.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq288.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq289.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq28A.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq28B.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq28C.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq28D.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq28E.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq28F.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq290.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq291.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq292.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq293.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq294.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq295.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq296.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq297.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq298.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq299.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq29A.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq29B.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq29C.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq29D.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq29E.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq29F.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2A0.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2A1.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2A2.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2A3.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2A4.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2A5.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2A6.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2A7.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2A8.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2A9.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2AA.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2AB.tmp\Amateur\Young Amateurs.lnk Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2AB.tmp\Anal\Ass Breakers.lnk Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2AB.tmp\Asian\Asian Nudes.lnk Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2AB.tmp\Asian\Asian Teen Tarts.lnk Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2AB.tmp\Bisexual\Bi Sex Tv.lnk Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2AB.tmp\Black\Ebony Café.lnk Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2AB.tmp\Black\Ebony Teen Tart.lnk Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2AB.tmp\Black\Sweet Black.lnk Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2AB.tmp\Cartoon\Acme Porn.lnk Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2AB.tmp\Cumshots\Jizz Catchers.lnk Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2AB.tmp\Cumshots\Jizz Shower.lnk Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2AB.tmp\Fetish\Fetish Abyss.lnk Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2AB.tmp\Fetish\Whips and Women.lnk Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2AB.tmp\Gang Bang\Orgy Frenzy.lnk Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2AB.tmp\Gay\Male Next Door.lnk Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2AB.tmp\Gay\Sweet Young Boys.lnk Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2AB.tmp\Gay\Ultimate Stud.lnk Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2AB.tmp\Hardcore\Porn Buster.lnk Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2AB.tmp\Hardcore\Real Hardcore.lnk Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2AB.tmp\Hardcore\Yvon's Training.lnk Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2AB.tmp\Latin\XXXSalsa.lnk Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2AB.tmp\Reality\In the VIP.lnk Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2AB.tmp\Voyeur\My Naughty Nanny.lnk Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2AC.tmp\Daily Pictures\In the VIP.lnk Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq32.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq41.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq43.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq45.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq47.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq49.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq4B.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq4D.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq4F.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq58.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq8.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqA.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqAF.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqB5.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqB7.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqB9.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqBB.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqBD.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqBF.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqC1.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqC3.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqC5.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqC7.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqC9.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqCB.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqCE.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqCF.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqD0.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqD1.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqD2.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqD3.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqD4.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqD5.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqD6.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqD7.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqD8.tmp\Frequently Asked Questions.url Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqD8.tmp\Home.url Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqD9.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqDA.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqdb.dat Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqDB.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqDC.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqDD.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqDE.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqDF.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqE0.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqE1.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqE2.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqE3.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqE4.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqE5.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqE6.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqE7.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqE8.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqE9.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqEB.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqEF.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqF1.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqF3.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqF4.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqF5.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqF6.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqF7.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqF8.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqF9.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqFB.tmp Object is locked skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppqsdb.dat Object is locked skipped

C:\System Volume Information\catalog.wci\00010006.ci Object is locked skipped

C:\System Volume Information\catalog.wci\CiCL0001.000 Object is locked skipped

C:\System Volume Information\catalog.wci\CiSL0001.000 Object is locked skipped

C:\System Volume Information\catalog.wci\CiSP0000.000 Object is locked skipped

C:\System Volume Information\catalog.wci\INDEX.000 Object is locked skipped

C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP501\change.log Object is locked skipped

C:\WINDOWS\$NtUninstallQ329115$\reg00003 Object is locked skipped

C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

C:\WINDOWS\SchedLgU.Txt Object is locked skipped

C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped

C:\WINDOWS\Sti_Trace.log Object is locked skipped

C:\WINDOWS\SYSTEM32\CatRoot2\edb.log Object is locked skipped

C:\WINDOWS\SYSTEM32\CatRoot2\tmp.edb Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\AppEvent.Evt Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\Internet.evt Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SAM Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SecEvent.Evt Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SECURITY Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SysEvent.Evt Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM Object is locked skipped

C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG Object is locked skipped

C:\WINDOWS\SYSTEM32\H323LOG.TXT Object is locked skipped

C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.BTR Object is locked skipped

C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.MAP Object is locked skipped

C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING.VER Object is locked skipped

C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING1.MAP Object is locked skipped

C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING2.MAP Object is locked skipped

C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.DATA Object is locked skipped

C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.MAP Object is locked skipped

C:\WINDOWS\WIADEBUG.LOG Object is locked skipped

C:\WINDOWS\WIASERVC.LOG Object is locked skipped

C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.

I was not able to save the online scan to my desktop. The program would not let me save it there so I saved it in Word and pasted it here.

Thank you,

Tanya
tanyasm
Regular Member
 
Posts: 52
Joined: November 24th, 2005, 12:37 am

Unread postby Linkmaster » January 13th, 2007, 8:07 am

Sorry for the delay, Tanya !

Your logs seem to be fine !!

I now have etrust installed and I do not like that program


If you do not like the eTrust suite, uninstall all parts of it.
You can also uninstall Yahoo AV as well, if you want
(below I have listed a few suggestions)

once I booted my computer into safe mode the ATF Icon was not on my desktop

ATF does not have an install. Lets see if we can find it
Go to Start, Search
Click on "All Files and Folders"
In the "All or part of the file name" box type :

ATF

In the "Look in" box make sure it is pointing to "Local Hard Drives (C:, etc.)"
Click on Search
Look in the right pane, and see where it is, You can move it to your Desktop

Empty the contents of this folder :

C:\Program Files\Yahoo!\YPSR\Quarantine

Then run ATF Cleaner

Just one more thing :
**Turn off System Restore**
On the Desktop, right-click My Computer
Click Properties
Click the System Restore tab.
Check "Turn off System Restore"
Click Apply, then click OK and Reboot

**Turn ON System Restore**
On the Desktop, right-click My Computer
Click Properties
Click the System Restore tab.
UN-Check "Turn off System Restore"
Click Apply, then click OK and Reboot

How is your system running now ??

Here are a few recommendations for protecting your system and reducing your risk of infection again !!

** Windows Update **
It is very important to keep your system up to date with the latest Critical Updates to avoid unnecessary security risks
Visit Microsoft's Windows Update page at the very least monthly to check for updates !!

** Make Your Internet Explorer More Secure **
This can be done by following these simple instructions :
From within Internet Explorer click on the Tools menu and then click on Options
Click once on the Security tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialize and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub-frames across different domains to Prompt
Change the Allow paste operations via script to Disable
When all these settings have been made, click on the OK button
If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.

** Real Time Prevention **
SpywareBlaster© by Javacool Software :
*Prevent the installation of ActiveX-based spyware, adware, browser hijackers, dialers, and other potentially unwanted pests
*Block spyware/tracking cookies in Internet Explorer and Mozilla/Firefox.
*Restrict the actions of potentially dangerous sites in Internet Explorer.
*Consumes no system resources

*Download, run, check for updates, download updates, select all, protect against checked. All done
*Check for updates every couple of weeks. If you have any errors running the program like a missing file see the link at the bottom of the javacool page
IESpyad© by EHowes : This will add several hundred Restricted Sites to the Restricted Site Zone in IE.

** File Cleaners (temp, prefetch, cookie, etc) **
2000/XP Only
ATF (Atribune Temp File) Cleaner© by Atribune
All Windows
CCleaner© by CCleaner.com

** Spyware Scanners **
Some FREE Spyware Scanners for Home use, that will detect and remove trojans, dialers, malware, browser hijackers, tracking components and other forms of Spyware :
SUPERAntiSpyware Home© by SUPERAntiSpyware.com
Ad-aware SE© by Lavasoft
Spybot S&D© by Safer-Networking

** Good Free Antivirus Programs **
AVG© by Grisoft
AntiVir© by H+BEDV Datentechnik GmbH
Avast© by ALWIL Software
NOTE:Remember always have just 1 antivirus program running at a time. Having more than one running causes a conflict between the programs !! You can use one as a backup to run manually

** Firewalls **
If you have an "always on" internet connection, such as DSL or Cable, I recommend a Firewall.
A firewall will make your pc invisible to the outside world and will filter the outgoing and incoming traffic on your pc.
For a good idea of how vulnerable your system(s) are go to GRC
Scroll down to "Shields Up" Click on "Proceed" Then click on "Common Ports"to scan your ports.
Free Personal Firewalls :
Sunbelt Kerio Personal Firewall© by Sunbelt
Jetico Personal Firewall© by Jetico, Inc.
Comodo Personal Firewall© by Comodo Group (XP & 2000 only)

** Install Java **
Java Runtime Environment© Sun Microsystems. It's much more secure than Microsoft's Java Virtual Machine

Always keep your Antivirus & Spyware Removal Tools current with the latest definitions and updates !!

Following these recommendations will help reduce your risk of future infections !!

Do you have any questions??
User avatar
Linkmaster
MRU Honors Grad Emeritus
 
Posts: 822
Joined: October 7th, 2005, 5:57 am
Location: Arkansas, USA

Unread postby NonSuch » January 22nd, 2007, 2:07 am

This topic is now closed. If you wish it reopened, please send us an email to 'admin at malwareremoval.com' with a link to your thread.

You can help support this site from this link :
Donations For Malware Removal

Please do not contact us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
User avatar
NonSuch
Administrator
Administrator
 
Posts: 27301
Joined: February 23rd, 2005, 7:08 am
Location: California
Advertisement
Register to Remove


Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: No registered users and 53 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware