Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

need help removing smitfraud and others

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

need help removing smitfraud and others

Unread postby jsmith052277 » April 19th, 2008, 2:00 pm

hijackthis log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:54:13 PM, on 4/19/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Real\Update_OB\RealOneMessageCenter.exe
C:\Program Files\InterMute\SpySubtract\SpySub.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Java\jre1.6.0_03\bin\jucheck.exe
C:\WINDOWS\AGRSMMSG.exe
c:\windows\system\hpsysdrv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [SSC_UserPrompt] c:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [IS CfgWiz] c:\Program Files\Norton Internet Security\cfgwiz.exe /GUID {257BBC47-1B26-432e-9F84-188603799DD3} /MODE CfgWiz /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [URLLSTCK.exe] c:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DW4] "C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\sslaunch.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} (Imikimi_activex_plugin Control) - http://imikimi.com/download/imikimi_plugin_0.5.1.cab
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: IS Service (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

--
End of file - 10573 bytes
jsmith052277
Regular Member
 
Posts: 21
Joined: April 19th, 2008, 1:57 pm
Advertisement
Register to Remove

Re: need help removing smitfraud and others

Unread postby Bio-Hazard » April 20th, 2008, 4:59 am

Welcome to the MWR forums. My name is Bio-Hazard. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research. Please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues this may or may not solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • If you don't know or understand something please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • It is important that you reply to this thread. Do not start a new topic.

Note: I am still in training here at Malware Removal, however I will be working under the direct supervision of one of our Malware Experts. Any recommendations will first be approved before being given to you. Because of this, there may be a short delay in getting our responses to you, however be assured that we will be working diligently on your problem.



Uninstall list

Make an uninstall list using HijackThis. To access the Uninstall Manager you would do the following:

  • Start HijackThis
  • Click on the Config button
  • Click on the Misc Tools button
  • Click on the Open Uninstall Manager button.
  • Click on the Save list... button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here on your next reply.
User avatar
Bio-Hazard
MRU Master Emeritus
 
Posts: 4078
Joined: May 10th, 2007, 8:28 am
Location: Cornwall, UK

Re: need help removing smitfraud and others

Unread postby jsmith052277 » April 20th, 2008, 11:35 am

Adobe Acrobat - Reader 6.0.2 Update
Adobe Flash Player ActiveX
Adobe Reader 6.0.1
Apple Mobile Device Support
Apple Software Update
Blackhawk Striker 2 from Compaq (remove only)
Blasterball 2 from Compaq (remove only)
Blasterball 2 Holidays from Compaq (remove only)
Blasterball 2 Remix from Compaq (remove only)
Bonjour
Bounce Symphony from Compaq (remove only)
CC_ccProxyExt
ccCommon
ccPxyCore
Compaq Connections
Compaq Organize
Crystal Maze from Compaq (remove only)
Easy Internet Sign-up
Final Drive Nitro from Compaq (remove only)
Google Toolbar for Internet Explorer
Help and Support Additions
HijackThis 2.0.2
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows XP (KB915865)
HP Boot Optimizer
HP Imaging Device Functions 9.0
HP Photosmart Cameras 9.0
HP Photosmart Essential 2.01
HP Solution Center 9.0
HP Update
Imikimi Plugin
J2SE Runtime Environment 5.0
Java(TM) 6 Update 3
Lexibox Deluxe from Compaq (remove only)
LiveReg (Symantec Corporation)
LiveUpdate 2.5 (Symantec Corporation)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Standard Edition 2003
Microsoft Plus! Dancer LE
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft Works
MSRedist
MSXML 4.0 SP2 (KB936181)
MySpaceIM
Napster for Windows Media Player
Norton AntiSpam
Norton AntiVirus 2005
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security 2005 (Symantec Corporation)
Norton Security Center
Norton WMI Update
Norton WMI Update
Overball from Compaq (remove only)
PC-Doctor for Windows
Phoenix Assault from Compaq (remove only)
Polar Bowler from Compaq (remove only)
Polar Golfer from Compaq (remove only)
Python 2.2 pywin32 extensions (build 203)
Python 2.2.3
QuickTime
RealPlayer
Remove Adobe Photoshop Album 2.0 Starter Edition installer
Remove Microsoft Money 2005 installer
Remove Quicken New User Edition installer
Remove WeatherBug installer
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB941693)
Security Update for Windows XP (KB943055)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944533)
Security Update for Windows XP (KB944653)
Security Update for Windows XP (KB945553)
Security Update for Windows XP (KB946026)
Security Update for Windows XP (KB948590)
Security Update for Windows XP (KB948881)
Shooting Stars Pool from Compaq (remove only)
SiS VGA Utilities
Slyder from Compaq (remove only)
Sonic Express Labeler
Sonic RecordNow Audio
Sonic RecordNow Copy
Sonic RecordNow Data
Sonic Update Manager
SPBBC
SpySubtract
Super Granny from Compaq (remove only)
SymNet
The Weather Channel Desktop
Tradewinds from Compaq (remove only)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB930916)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update for Windows XP (KB942840)
Weather Services
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Format Runtime
Windows Media Player 10
Windows XP Hotfix - KB867282
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB883667
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888239
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
jsmith052277
Regular Member
 
Posts: 21
Joined: April 19th, 2008, 1:57 pm

Re: need help removing smitfraud and others

Unread postby Bio-Hazard » April 20th, 2008, 1:49 pm

Remove bad HijackThis entries

  • Run HijackThis
  • Click on the Scan button
  • Put a check beside all of the items listed below (if present):

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE


  • Close all open windows and browsers/email etc...
  • Click on the Fix Checked button
  • When completed close the application.

REBOOT AFTER WHEN YOU HAVE COMPLETED ALL THESE STEPS




ATF-Cleaner

Please download ATF Cleaner by Atribune.

  • Save it to your desktop
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.

    If you use Firefox browser
  • Click Firefox at the top and choose: Select All
  • Click the Empty Selected button.

    NOTE: If you would like to keep your saved passwords
    please click No at the prompt.


    If you use Opera browser
  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.

    NOTE: If you would like to keep your saved passwords
    please click No at the prompt.

  • Click Exit on the Main menu to close the program.

For Technical Support double-click the e-mail address located at the bottom of each menu.


Malwarebytes' Anti-Malware

  • Please download Malwarebytes' Anti-Malware and save it to a convenient location.
  • Double click on mbam-setup.exe to install it.
  • Before clicking the Finish button, make sure that these 2 boxes are checked (ticked):
      Update Malwarebytes' Anti-Malware
      Launch Malwarebytes' Anti-Malware
  • Malwarebytes' Anti-Malware will now check for updates. If your firewall prompts, please allow it. If you can't update it, select the Update tab. Under Update Mirror, select one of the websites and click on Check for Updates.
  • Select the Scanner tab. Click on Perform full scan, then click on Scan.
  • Leave the default options as it is and click on Start Scan.
  • When done, you will be prompted. Click OK, then click on Show Results.
  • Checked (ticked) all items and click on Remove Selected.
  • After it has removed the items, Notepad will open. Please post this log in your next reply. You can also find the log in the Logs tab. The bottom most log is the latest.



Logs/Information to Post in Reply

Please post the following logs/Information in your reply

  • Malwarebytes' Anti-Malware
  • A fresh HijackThis Log ( after all the above has been done)
User avatar
Bio-Hazard
MRU Master Emeritus
 
Posts: 4078
Joined: May 10th, 2007, 8:28 am
Location: Cornwall, UK

Re: need help removing smitfraud and others

Unread postby jsmith052277 » April 21st, 2008, 7:17 am

Malwarebytes' Anti-Malware 1.11
Database version: 663

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 152728
Time elapsed: 58 minute(s), 48 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 54
Files Infected: 135

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\Software\The Weather Channel (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Weather Services (Adware.Hotbar) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\DW4 (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cpls\wxfw.dll (Adware.Hotbar) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Program Files\Outerinfo (Adware.Outerinfo) -> Quarantined and deleted successfully.
C:\Program Files\Outerinfo\FF (Adware.Outerinfo) -> Quarantined and deleted successfully.
C:\Program Files\Outerinfo\FF\components (Adware.Outerinfo) -> Quarantined and deleted successfully.
C:\Program Files\Starware408 (Adware.Starware) -> Quarantined and deleted successfully.
C:\Program Files\Starware408\bin (Adware.Starware) -> Quarantined and deleted successfully.
C:\Program Files\Screensavers.com (Adware.Comet) -> Quarantined and deleted successfully.
C:\Program Files\Screensavers.com\ActiveDesktop (Adware.Comet) -> Quarantined and deleted successfully.
C:\Program Files\Screensavers.com\SSSInstaller (Adware.Comet) -> Quarantined and deleted successfully.
C:\Program Files\Screensavers.com\ActiveDesktop\bin (Adware.Comet) -> Quarantined and deleted successfully.
C:\Program Files\Screensavers.com\SSSInstaller\bin (Adware.Comet) -> Quarantined and deleted successfully.
C:\Program Files\Insider (Adware.DnsInsider) -> Quarantined and deleted successfully.
C:\Program Files\QdrDrive (Adware.AdBand) -> Quarantined and deleted successfully.
C:\Program Files\Router (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Program Files\ISM (Adware.ISM) -> Quarantined and deleted successfully.
C:\Program Files\QdrModule (Adware.ISM) -> Quarantined and deleted successfully.
C:\Program Files\QdrPack (Adware.ISM) -> Quarantined and deleted successfully.
C:\Documents and Settings\Little Ray\Application Data\DriveCleaner Free (Rogue.DriveCleaner) -> Quarantined and deleted successfully.
C:\Documents and Settings\Little Ray\Application Data\DriveCleaner Free\Logs (Rogue.DriveCleaner) -> Quarantined and deleted successfully.
C:\Documents and Settings\Alex\Application Data\DriveCleaner Free (Rogue.DriveCleaner) -> Quarantined and deleted successfully.
C:\Documents and Settings\Alex\Application Data\DriveCleaner Free\Logs (Rogue.DriveCleaner) -> Quarantined and deleted successfully.
C:\Documents and Settings\abby and alex\Application Data\DriveCleaner Free (Rogue.DriveCleaner) -> Quarantined and deleted successfully.
C:\Documents and Settings\abby and alex\Application Data\DriveCleaner Free\Logs (Rogue.DriveCleaner) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware408 (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware408\buttons (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware408\contexts (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware408\images (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware408\SimpleUpdate (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Little Ray\Application Data\Starware408 (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Little Ray\Application Data\Starware408\Button_5 (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Little Ray\Application Data\Starware408\Button_6 (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Little Ray\Application Data\Starware408\Button_7 (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Little Ray\Application Data\Starware408\Video_Vault (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Little Ray\Application Data\Starware408\Watch_Videos (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Big Ray\Application Data\Starware408 (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Big Ray\Application Data\Starware408\Button_5 (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Big Ray\Application Data\Starware408\Button_6 (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Big Ray\Application Data\Starware408\Button_7 (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Big Ray\Application Data\Starware408\Video_Vault (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Big Ray\Application Data\Starware408\Watch_Videos (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Alex\Application Data\Starware408 (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Alex\Application Data\Starware408\Button_5 (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Alex\Application Data\Starware408\Button_6 (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Alex\Application Data\Starware408\Button_7 (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Alex\Application Data\Starware408\Video_Vault (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Alex\Application Data\Starware408\Watch_Videos (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\abby and alex\Application Data\Starware408 (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\abby and alex\Application Data\Starware408\Button_5 (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\abby and alex\Application Data\Starware408\Button_6 (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\abby and alex\Application Data\Starware408\Button_7 (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\abby and alex\Application Data\Starware408\Video_Vault (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\abby and alex\Application Data\Starware408\Watch_Videos (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\abby and alex\Application Data\Starware408\Button_6\images (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\abby and alex\Application Data\Starware408\Button_6\images\active (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\abby and alex\Application Data\Starware408\Button_6\images\default (Adware.Starware) -> Quarantined and deleted successfully.

Files Infected:
C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Program Files\Imikimi\uninstall.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Program Files\ISM\ism.exe (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\MSN\horylycaw77798 .exe (Adware.TTC) -> Quarantined and deleted successfully.
C:\Program Files\QdrDrive\QdrDrive9.dll (Adware.SearchAid) -> Quarantined and deleted successfully.
C:\Program Files\QdrDrive\qdrloader.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\QdrModule\QdrModule11 .exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\QdrPack\QdrPack11 .exe (Adware.ISMonitor) -> Quarantined and deleted successfully.
C:\Program Files\Router\Router .exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Program Files\Router\UnInstall.exe (Trojan.Delf) -> Quarantined and deleted successfully.
C:\Program Files\Screensavers.com\ActiveDesktop\bin\ActiveDesktopExe.exe (Adware.Comet) -> Quarantined and deleted successfully.
C:\Program Files\Screensavers.com\SSSInstaller\bin\screensavers.exe (Adware.Comet) -> Quarantined and deleted successfully.
C:\Program Files\Screensavers.com\SSSInstaller\bin\sinstaller3.exe (Adware.Comet) -> Quarantined and deleted successfully.
C:\Program Files\Screensavers.com\SSSInstaller\bin\SSSInstaller.dll (Adware.Comet) -> Quarantined and deleted successfully.
C:\Program Files\The Weather Channel FW\Framework\TheWeatherChannelNE.exe (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Program Files\The Weather Channel FW\Framework\TheWeatherChannelQC.exe (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Program Files\The Weather Channel FW\Framework\TheWeatherChannelqx.exe (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Program Files\The Weather Channel FW\Framework\TheWeatherChannelSlnchr.exe (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Program Files\The Weather Channel FW\Framework\TheWeatherChannelUpdate.exe (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Program Files\The Weather Channel FW\Framework\WiseInstallUtility.dll (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Program Files\The Weather Channel FW\Framework\wxfw.dll (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP58\A0009709.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\b103.exe (Trojan.DownLoader) -> Quarantined and deleted successfully.
C:\WINDOWS\b104.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\b138.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\b147.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\b151.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\mrofinu72.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\IA\asappsrv.dll (AdWare.CommAd) -> Quarantined and deleted successfully.
C:\WINDOWS\IA\command.exe (AdWare.CommAd) -> Quarantined and deleted successfully.
C:\Program Files\Starware408\bin\Starware408.dll (Adware.Starware) -> Quarantined and deleted successfully.
C:\Program Files\Screensavers.com\SSSUninst.exe (Adware.Comet) -> Quarantined and deleted successfully.
C:\Program Files\Insider\Insider.exe (Adware.DnsInsider) -> Quarantined and deleted successfully.
C:\Program Files\Insider\UnInstall.exe (Adware.DnsInsider) -> Quarantined and deleted successfully.
C:\Program Files\QdrDrive\QdrDrive8.dll (Adware.AdBand) -> Quarantined and deleted successfully.
C:\Program Files\Router\Router.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Program Files\ISM\Uninstall.exe (Adware.ISM) -> Quarantined and deleted successfully.
C:\Program Files\QdrModule\dic.gz (Adware.ISM) -> Quarantined and deleted successfully.
C:\Program Files\QdrModule\kwd.gz (Adware.ISM) -> Quarantined and deleted successfully.
C:\Program Files\QdrModule\QdrModule11.exe (Adware.ISM) -> Quarantined and deleted successfully.
C:\Program Files\QdrModule\QdrModule9.exe (Adware.ISM) -> Quarantined and deleted successfully.
C:\Program Files\QdrPack\dicts.gz (Adware.ISM) -> Quarantined and deleted successfully.
C:\Program Files\QdrPack\QdrPack11.exe (Adware.ISM) -> Quarantined and deleted successfully.
C:\Program Files\QdrPack\QdrPack9.exe (Adware.ISM) -> Quarantined and deleted successfully.
C:\Program Files\QdrPack\trgts.gz (Adware.ISM) -> Quarantined and deleted successfully.
C:\Documents and Settings\Little Ray\Application Data\DriveCleaner Free\Logs\update.log (Rogue.DriveCleaner) -> Quarantined and deleted successfully.
C:\Documents and Settings\Alex\Application Data\DriveCleaner Free\Logs\update.log (Rogue.DriveCleaner) -> Quarantined and deleted successfully.
C:\Documents and Settings\abby and alex\Application Data\DriveCleaner Free\Logs\update.log (Rogue.DriveCleaner) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware408\buttons\1223_button_1b_def.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware408\buttons\1223_button_1b_over.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware408\buttons\1229_button_1b_def.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware408\buttons\1229_button_1b_over.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware408\buttons\Button_50.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware408\buttons\Button_60.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware408\buttons\Button_70.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware408\buttons\FindIt.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware408\buttons\FindItHot.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware408\buttons\findithotxp.png (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware408\buttons\finditxp.png (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware408\buttons\logo.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware408\buttons\logoxp.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware408\buttons\Weather.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware408\buttons\WeatherHot.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware408\buttons\weatherhotxp.png (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware408\buttons\weatherxp.png (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware408\contexts\error.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware408\contexts\Related.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware408\contexts\Travel.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware408\images\clear.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware408\images\cloudy.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware408\images\foggy.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware408\images\mcloud.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware408\images\na.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware408\images\nclear.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware408\images\ncloudy.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware408\images\nfoggy.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware408\images\nmcloud.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware408\images\npcloud.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware408\images\nrain.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware408\images\pcloud.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware408\images\rain.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware408\images\walertXP.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware408\SimpleUpdate\ProductMessagingConfig.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware408\SimpleUpdate\ProductMessagingConfig.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware408\SimpleUpdate\SimpleUpdateConfig.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware408\SimpleUpdate\SimpleUpdateConfig.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware408\SimpleUpdate\TimerManagerConfig.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Starware408\SimpleUpdate\TimerManagerConfig.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Little Ray\Application Data\Starware408\Button_5\Button_5Options.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Little Ray\Application Data\Starware408\Button_5\Button_5Options.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Little Ray\Application Data\Starware408\Button_6\Button_6Options.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Little Ray\Application Data\Starware408\Button_6\Button_6Options.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Little Ray\Application Data\Starware408\Button_7\Button_7Options.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Little Ray\Application Data\Starware408\Button_7\Button_7Options.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Little Ray\Application Data\Starware408\Video_Vault\Video_VaultOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Little Ray\Application Data\Starware408\Video_Vault\Video_VaultOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Little Ray\Application Data\Starware408\Watch_Videos\Watch_VideosOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Little Ray\Application Data\Starware408\Watch_Videos\Watch_VideosOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Big Ray\Application Data\Starware408\Button_5\Button_5Options.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Big Ray\Application Data\Starware408\Button_5\Button_5Options.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Big Ray\Application Data\Starware408\Button_6\Button_6Options.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Big Ray\Application Data\Starware408\Button_6\Button_6Options.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Big Ray\Application Data\Starware408\Button_7\Button_7Options.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Big Ray\Application Data\Starware408\Button_7\Button_7Options.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Big Ray\Application Data\Starware408\Video_Vault\Video_VaultOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Big Ray\Application Data\Starware408\Video_Vault\Video_VaultOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Big Ray\Application Data\Starware408\Watch_Videos\Watch_VideosOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Big Ray\Application Data\Starware408\Watch_Videos\Watch_VideosOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Alex\Application Data\Starware408\Button_5\Button_5Options.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Alex\Application Data\Starware408\Button_5\Button_5Options.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Alex\Application Data\Starware408\Button_6\Button_6Options.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Alex\Application Data\Starware408\Button_6\Button_6Options.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Alex\Application Data\Starware408\Button_7\Button_7Options.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Alex\Application Data\Starware408\Button_7\Button_7Options.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Alex\Application Data\Starware408\Video_Vault\Video_VaultOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Alex\Application Data\Starware408\Video_Vault\Video_VaultOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Alex\Application Data\Starware408\Watch_Videos\Watch_VideosOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\Alex\Application Data\Starware408\Watch_Videos\Watch_VideosOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\abby and alex\Application Data\Starware408\Button_5\Button_5Options.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\abby and alex\Application Data\Starware408\Button_5\Button_5Options.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\abby and alex\Application Data\Starware408\Button_6\Button_6Options.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\abby and alex\Application Data\Starware408\Button_6\Button_6Options.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\abby and alex\Application Data\Starware408\Button_6\images\active\Button_60.bmp (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\abby and alex\Application Data\Starware408\Button_7\Button_7Options.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\abby and alex\Application Data\Starware408\Button_7\Button_7Options.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\abby and alex\Application Data\Starware408\Video_Vault\Video_VaultOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\abby and alex\Application Data\Starware408\Video_Vault\Video_VaultOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\abby and alex\Application Data\Starware408\Watch_Videos\Watch_VideosOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
C:\Documents and Settings\abby and alex\Application Data\Starware408\Watch_Videos\Watch_VideosOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\jkhfg.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\b111.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\b148.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Alex\Desktop\Online Security Guide.lnk (Rogue.Link) -> Quarantined and deleted successfully.
C:\Documents and Settings\abby and alex\Desktop\Online Security Guide.lnk (Rogue.Link) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk (Rogue.Link) -> Quarantined and deleted successfully.








Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:17:02 AM, on 4/21/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\InterMute\SpySubtract\SpySub.exe
c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\AGRSMMSG.exe
c:\windows\system\hpsysdrv.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [SSC_UserPrompt] c:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [IS CfgWiz] c:\Program Files\Norton Internet Security\cfgwiz.exe /GUID {257BBC47-1B26-432e-9F84-188603799DD3} /MODE CfgWiz /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [URLLSTCK.exe] c:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\sslaunch.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} (Imikimi_activex_plugin Control) - http://imikimi.com/download/imikimi_plugin_0.5.1.cab
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: IS Service (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

--
End of file - 9755 bytes
jsmith052277
Regular Member
 
Posts: 21
Joined: April 19th, 2008, 1:57 pm

Re: need help removing smitfraud and others

Unread postby Bio-Hazard » April 21st, 2008, 2:25 pm

Update Java Runtime:

You are using an old version of Java. Sun's Java is sometimes updated in order to eliminate the exploitation of vulnerabilities in an existing version. For this reason it's extremely important that you keep the program up to date and also remove the older more vulnerable versions from your system. The most current version of Sun Java is: Java Runtime Environment Version 6 Update 5.
  • Go to http://java.sun.com/javase/downloads/index.jsp
  • Click on the link named Java Runtime Environment (JRE) 6 Update 5
  • Click on the radio button to Accept License Agreement
  • Click on Windows Offline Installation Multi-language and save the downloaded file to your hard disk
  • Go to Start => Control Panel => Add or Remove Programs
  • Uninstall all old versions of Java (Java 2 Runtime Environment JRE or JSE)
  • Reboot your computer
  • Delete the folder C:\Program Files\Java if present
  • Install the new version by running the newly-downloaded file and follow the on-screen instructions.
  • Reboot your computer


Kaspersky Online Scan

With the exception of Internet Explorer, which must be used for this scan, keep ALL programs closed
Please do an online scan with Kaspersky Online Scanner. You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75%. Once the licence accepted, reset to 100%.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings
  • In the scan settings make sure that the following are selected:
    o Scan using the following Anti-Virus database:
    + Extended (If available otherwise Standard)
    o Scan Options:
    + Scan Archives
    + Scan Mail Bases
  • Click OK
  • Now under select a target to scan select My Computer
  • The scan will take a while so be patient and let it run.
  • Please do not use your computer while the scan is running. Once the scan is complete it will display if your system has been infected.
  • Click the Save Report As... button (see red arrow below)

    Image
  • In the Save as... prompt, select Desktop
  • In the File name box, name the file KasScan-ddmmyy (or similar)
  • In the Save as type prompt, select Text file (see below)

    Image
  • Copy and paste the report in your next post.

Note: It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and to speed up scan time.Please don't go surfing while your resident protection is disabled!Once scan is finished remember to re-enable resident antivirus protection along with whatever antispyware application you use.



Logs/Information to Post in Reply

Please post the following logs/Information in your reply

  • Kaspersky Log
  • A fresh HijackThis Log ( after all the above has been done)
  • How are things running now ?
User avatar
Bio-Hazard
MRU Master Emeritus
 
Posts: 4078
Joined: May 10th, 2007, 8:28 am
Location: Cornwall, UK

Re: need help removing smitfraud and others

Unread postby jsmith052277 » April 23rd, 2008, 8:08 pm

KASPERSKY ONLINE SCANNER REPORT
Wednesday, April 23, 2008 8:04:37 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 23/04/2008
Kaspersky Anti-Virus database records: 722306
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\

Scan Statistics:
Total number of scanned objects: 110332
Number of viruses found: 10
Number of infected objects: 22
Number of suspicious objects: 4
Duration of the scan process: 01:44:27

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Alex\Local Settings\Temp\jkhfc.dll Infected: Packed.Win32.Monder.gen skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\12fc5213d9182dc4358fe6f9197ab5d1_078767bd-db6d-468a-b80d-16f488788c99 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle.zip/Yazzle1552OinUninstaller.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle2.zip/Yazzle1552OinUninstaller.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle2.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Confid.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Content.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Privacy.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Restrict.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\WebHist.log Object is locked skipped
C:\Documents and Settings\Big Ray\My Documents\My Videos\videos.exe Infected: not-a-virus:AdWare.Win32.Comet.bq skipped
C:\Documents and Settings\Compaq_Owner\Application Data\InterMute\SpySubtract\tmp\3 Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\QUAR1.37265 Infected: not-a-virus:AdWare.Win32.CommAd.a skipped
C:\Documents and Settings\Compaq_Owner\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\QUAR1.86696 Infected: not-a-virus:AdWare.Win32.CommAd.a skipped
C:\Documents and Settings\Compaq_Owner\Application Data\MySpace\IM\Logs\MySpaceIM-20080421-210017.log Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\History\History.IE5\MSHist012008042220080423\index.dat Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\JETEC65.tmp Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\~DF5E04.tmp Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Compaq_Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Compaq_Owner\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Compaq_Owner\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\2007-03-11 2223\01 full_bb1b4c8863dc6f18726d9678df20c767.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\2007-03-11 2223\AlbumArtSmall.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\2007-03-11 2223\desktop.ini Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\2007-03-11 2223\Folder.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\desktop.ini Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\inspirational.RMP Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Thumbs.db Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-15-28 AM)\01 Track 1.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-15-28 AM)\02 Track 2.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-15-28 AM)\03 Track 3.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-15-28 AM)\04 Track 4.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-15-28 AM)\05 Track 5.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-15-28 AM)\06 Track 6.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-15-28 AM)\07 Track 7.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-15-28 AM)\08 Track 8.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-17-09 PM)\01 push comes to shove.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-17-09 PM)\02 what i was tryin to do.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-17-09 PM)\04 i feel bad.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-17-09 PM)\05 my wish.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-17-09 PM)\06 in pieces.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-17-09 PM)\08 i've seen what u can do.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-17-09 PM)\13 he ain't the leavin kind.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-17-09 PM)\14 life is a highway.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-17-09 PM)\AlbumArtSmall.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-17-09 PM)\AlbumArt_{1B428191-174E-4D08-AD47-73B5855FC938}_Large.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-17-09 PM)\AlbumArt_{1B428191-174E-4D08-AD47-73B5855FC938}_Small.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-17-09 PM)\desktop.ini Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-17-09 PM)\Folder.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-17-09 PM)\Thumbs.db Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-21-18 AM)\01 Track 1.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-21-18 AM)\02 Track 2.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-21-18 AM)\03 Track 3.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-21-18 AM)\04 Track 4.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-21-18 AM)\05 Track 5.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-21-18 AM)\06 Track 6.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-28-36 AM)\01 3.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-28-36 AM)\02 3.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-28-36 AM)\03 3.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-28-36 AM)\04 3.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-28-36 AM)\05 3.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-28-36 AM)\06 3.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-33-14 AM)\01 4.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-33-14 AM)\02 4.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-33-14 AM)\03 4.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-33-14 AM)\04 4.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-33-14 AM)\05 4.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-33-14 AM)\06 4.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-33-14 AM)\07 4.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-40-00 AM)\01 5.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-40-00 AM)\02 5.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-40-00 AM)\03 5.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-40-00 AM)\04 5.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-40-00 AM)\05 5.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-40-00 AM)\06 5.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-40-00 AM)\07 5.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-47-35 AM)\01 6.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-47-35 AM)\02 6.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-47-35 AM)\03 6.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-47-35 AM)\04 6.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-47-35 AM)\05 6.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 11-47-35 AM)\06 6.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 12-04-44 AM)\02 hold on to me.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 12-04-44 AM)\07 i couldn't dream of love better than this.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 12-04-44 AM)\AlbumArtSmall.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 12-04-44 AM)\AlbumArt_{96EC356F-19C3-49F4-A5C2-0AD0CF917B76}_Large.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 12-04-44 AM)\AlbumArt_{96EC356F-19C3-49F4-A5C2-0AD0CF917B76}_Small.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 12-04-44 AM)\desktop.ini Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 12-04-44 AM)\Folder.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 12-04-44 AM)\Thumbs.db Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 12-13-20 AM)\01 you win again.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 12-13-20 AM)\03 i can't stop loving you.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 12-13-20 AM)\05 i started loving you again.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 12-13-20 AM)\18 help me make it through the night.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 12-13-20 AM)\AlbumArtSmall.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 12-13-20 AM)\AlbumArt_{A73E5E38-CE98-44E1-97C6-50A47AD44F5F}_Large.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 12-13-20 AM)\AlbumArt_{A73E5E38-CE98-44E1-97C6-50A47AD44F5F}_Small.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 12-13-20 AM)\desktop.ini Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 12-13-20 AM)\Folder.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 12-13-20 AM)\Thumbs.db Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 12-29-37 AM)\04 jesus take the wheel.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 12-29-37 AM)\08 i guess its gonna have to hurt.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 12-29-37 AM)\09 i just can't live a lie.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 12-29-37 AM)\12 whenever you remember.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 12-29-37 AM)\AlbumArtSmall.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 12-29-37 AM)\AlbumArt_{9805E048-C781-4D3B-806A-B6FEB1983DFB}_Large.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 12-29-37 AM)\AlbumArt_{9805E048-C781-4D3B-806A-B6FEB1983DFB}_Small.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 12-29-37 AM)\desktop.ini Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 12-29-37 AM)\Folder.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 12-29-37 AM)\Thumbs.db Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 12-48-26 AM)\04 i love the way you love me.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 12-48-26 AM)\09 i can love you like that.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 12-48-26 AM)\12 i swear.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 12-48-26 AM)\AlbumArtSmall.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 12-48-26 AM)\AlbumArt_{41BBF64B-57A6-4308-8ECB-7FC9422807AF}_Large.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 12-48-26 AM)\AlbumArt_{41BBF64B-57A6-4308-8ECB-7FC9422807AF}_Small.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 12-48-26 AM)\desktop.ini Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 12-48-26 AM)\Folder.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-10-2007 12-48-26 AM)\Thumbs.db Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-11-2007 4-15-37 PM)\01 thunderstruck.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-11-2007 4-15-37 PM)\03 back in black.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-11-2007 4-15-37 PM)\11 dirty deeds done dirt cheap.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-11-2007 4-15-37 PM)\AlbumArtSmall.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-11-2007 4-15-37 PM)\AlbumArt_{EF13E03D-B86A-45D7-B022-80217A231F8F}_Large.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-11-2007 4-15-37 PM)\AlbumArt_{EF13E03D-B86A-45D7-B022-80217A231F8F}_Small.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-11-2007 4-15-37 PM)\desktop.ini Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-11-2007 4-15-37 PM)\Folder.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-11-2007 4-15-37 PM)\Thumbs.db Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-11-2007 4-26-18 PM)\01 hells bells.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-11-2007 4-26-18 PM)\05 you shook me all night long.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-11-2007 4-26-18 PM)\09 highway to hell.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-11-2007 4-26-18 PM)\11 for those about to rock.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-11-2007 4-26-18 PM)\AlbumArtSmall.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-11-2007 4-26-18 PM)\AlbumArt_{9505F1B2-9A93-4F8D-B790-9EF2A42606BC}_Large.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-11-2007 4-26-18 PM)\AlbumArt_{9505F1B2-9A93-4F8D-B790-9EF2A42606BC}_Small.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-11-2007 4-26-18 PM)\desktop.ini Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-11-2007 4-26-18 PM)\Folder.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-11-2007 4-26-18 PM)\Thumbs.db Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-16-2007 11-40-50 PM)\01 Track 1.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-16-2007 11-40-50 PM)\02 Track 2.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-16-2007 11-40-50 PM)\03 Track 3.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-16-2007 11-40-50 PM)\04 Track 4.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-16-2007 11-40-50 PM)\05 Track 5.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-16-2007 11-40-50 PM)\06 Track 6.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-16-2007 11-40-50 PM)\07 Track 7.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-16-2007 11-40-50 PM)\08 Track 8.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-16-2007 11-40-50 PM)\09 Track 9.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-16-2007 11-40-50 PM)\10 Track 10.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-16-2007 11-40-50 PM)\11 Track 11.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-16-2007 11-40-50 PM)\12 Track 12.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-16-2007 11-40-50 PM)\13 Track 13.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-16-2007 11-40-50 PM)\14 Track 14.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-16-2007 11-40-50 PM)\15 Track 15.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-16-2007 11-40-50 PM)\16 Track 16.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-16-2007 11-40-50 PM)\AlbumArtSmall.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-16-2007 11-40-50 PM)\AlbumArt_{E7414437-050C-49CA-A1AF-8F1328DDF010}_Large.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-16-2007 11-40-50 PM)\AlbumArt_{E7414437-050C-49CA-A1AF-8F1328DDF010}_Small.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-16-2007 11-40-50 PM)\desktop.ini Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-16-2007 11-40-50 PM)\Folder.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-16-2007 11-40-50 PM)\Thumbs.db Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-8-2007 4-23-05 PM)\01 Track 1.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-8-2007 4-23-05 PM)\02 Track 2.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-8-2007 4-23-05 PM)\03 Track 3.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-8-2007 4-23-05 PM)\04 Track 4.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-8-2007 4-23-05 PM)\05 Track 5.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-8-2007 4-23-05 PM)\06 Track 6.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-8-2007 4-23-05 PM)\07 Track 7.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-8-2007 4-23-05 PM)\08 Track 8.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-8-2007 4-23-05 PM)\09 Track 9.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-8-2007 4-23-05 PM)\10 Track 10.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-8-2007 4-23-05 PM)\AlbumArtSmall.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-8-2007 4-23-05 PM)\AlbumArt_{99C58B32-6474-4210-B597-F5B7F59EAD6C}_Large.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-8-2007 4-23-05 PM)\AlbumArt_{99C58B32-6474-4210-B597-F5B7F59EAD6C}_Small.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-8-2007 4-23-05 PM)\desktop.ini Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-8-2007 4-23-05 PM)\Folder.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-8-2007 4-29-11 PM)\01 Track 1.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-8-2007 4-29-11 PM)\02 Track 2.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-8-2007 4-29-11 PM)\03 Track 3.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-8-2007 4-29-11 PM)\04 Track 4.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-8-2007 4-29-11 PM)\05 Track 5.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-8-2007 4-29-11 PM)\06 Track 6.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-8-2007 4-29-11 PM)\07 Track 7.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-8-2007 4-29-11 PM)\08 Track 8.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-8-2007 4-29-11 PM)\09 Track 9.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-8-2007 4-29-11 PM)\10 Track 10.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-8-2007 4-29-11 PM)\11 Track 11.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-8-2007 4-29-11 PM)\12 Track 12.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-8-2007 4-29-11 PM)\13 Track 13.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-8-2007 4-29-11 PM)\14 Track 14.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-8-2007 4-29-11 PM)\15 Track 15.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-8-2007 4-29-11 PM)\AlbumArtSmall.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-8-2007 4-29-11 PM)\AlbumArt_{4DA44FE0-6FCF-456B-A278-C4257FA8A84F}_Large.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-8-2007 4-29-11 PM)\AlbumArt_{4DA44FE0-6FCF-456B-A278-C4257FA8A84F}_Small.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-8-2007 4-29-11 PM)\desktop.ini Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-8-2007 4-29-11 PM)\Folder.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-9-2007 11-04-11 PM)\03 Track 3.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-9-2007 11-04-11 PM)\AlbumArtSmall.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-9-2007 11-04-11 PM)\AlbumArt_{44E96F5D-5A74-42FF-A7AF-393E62E79441}_Large.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-9-2007 11-04-11 PM)\AlbumArt_{44E96F5D-5A74-42FF-A7AF-393E62E79441}_Small.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-9-2007 11-04-11 PM)\desktop.ini Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-9-2007 11-04-11 PM)\Folder.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-9-2007 11-14-10 PM)\04 breathe.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-9-2007 11-14-10 PM)\05 lets make love.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-9-2007 11-14-10 PM)\08 if i'm not in love with you.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-9-2007 11-14-10 PM)\11 wait for me.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-9-2007 11-14-10 PM)\AlbumArtSmall.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-9-2007 11-14-10 PM)\AlbumArt_{52F8228C-885B-4A74-8343-4A9C9EA772CC}_Large.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-9-2007 11-14-10 PM)\AlbumArt_{52F8228C-885B-4A74-8343-4A9C9EA772CC}_Small.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-9-2007 11-14-10 PM)\desktop.ini Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-9-2007 11-14-10 PM)\Folder.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-9-2007 11-33-26 PM)\01 cowboy in me.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-9-2007 11-33-26 PM)\03 i quess u get used to somebody.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-9-2007 11-33-26 PM)\08 take me away from here.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-9-2007 11-33-26 PM)\11 angry all the time.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-9-2007 11-33-26 PM)\13 i don't know why they say grown men don't cry.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-9-2007 11-33-26 PM)\AlbumArtSmall.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-9-2007 11-33-26 PM)\AlbumArt_{1E3A6D54-5B47-48E4-9DAC-9A8FF16CD471}_Large.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-9-2007 11-33-26 PM)\AlbumArt_{1E3A6D54-5B47-48E4-9DAC-9A8FF16CD471}_Small.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-9-2007 11-33-26 PM)\desktop.ini Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-9-2007 11-33-26 PM)\Folder.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-9-2007 11-50-23 PM)\03 i was born the day you left me.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-9-2007 11-50-23 PM)\07 tell me that you live for love.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-9-2007 11-50-23 PM)\08 been waiting all my life.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-9-2007 11-50-23 PM)\11 i'm moving on.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-9-2007 11-50-23 PM)\AlbumArtSmall.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-9-2007 11-50-23 PM)\AlbumArt_{6C859385-82D4-4703-9078-60C8822E76C4}_Large.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-9-2007 11-50-23 PM)\AlbumArt_{6C859385-82D4-4703-9078-60C8822E76C4}_Small.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-9-2007 11-50-23 PM)\desktop.ini Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-9-2007 11-50-23 PM)\Folder.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (2-9-2007 11-50-23 PM)\Thumbs.db Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (3-21-2007 6-41-39 PM)\01 Track 1.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (3-21-2007 6-41-39 PM)\02 Track 2.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (3-21-2007 6-41-39 PM)\03 Track 3.wma Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (3-21-2007 6-41-39 PM)\AlbumArtSmall.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (3-21-2007 6-41-39 PM)\desktop.ini Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (3-21-2007 6-41-39 PM)\Folder.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Music\Unknown Artist\Unknown Album (3-21-2007 6-41-39 PM)\Thumbs.db Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\04-manning-action-2.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\050104d2.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\07-001.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\07-002.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\07-003.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\07-004.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\07-005.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\07-006.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\07-007.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\07-008.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\07-009.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\07-010.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\1017051344_l.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\1041282755_l.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\1042545784_l.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\1064961246_l.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\10thSig.gif Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\2007-02-12\IMG001.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\2007-02-12\IMG003.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\2007-02-12\IMG004.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\2007-02-12\IMG005.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\2007-02-12\IMG009.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\2007-02-12\IMG015.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\2007-02-12\IMG016.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\2007-02-12\IMG018.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\2007-02-12\IMG023.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\2007-02-12\IMG025.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\2007-02-12\IMG026.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\2007-02-12\IMG027.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\2007-02-12\Thumbs.db Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\2007-02-12\tracy.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\2007-07-18\IMG003.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\2007-07-18\IMG004.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\2007-07-18\IMG005.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\2007-07-18\IMG006.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\2007-07-18\IMG007.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\2007-07-18\IMG008.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\2007-07-18\IMG009.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\2007-07-18\IMG010.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\2007-07-18\IMG011.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\2007-07-18\IMG012.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\2007-07-18\IMG013.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\2007-07-18\IMG014.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\2007-07-18\IMG015.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\2007-07-18\IMG016.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\2007-07-18\IMG018.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\2007-07-18\IMG019.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\2007-07-18\IMG022.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\2007-07-18\IMG023.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\2007-07-18\IMG024.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\2007-07-18\IMG025.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\2007-07-18\Thumbs.db Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\270631258_l.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\29%20Sunset%20and%20crosses.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\2pac.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\2pac2-1.gif Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\2pac20moving20letters.gif Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\2pacanime.gif Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\39.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\3CROSSES.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\3yxshlv1.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\42201.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\52.gif Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\639023031_l.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\831034901_m.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\831061673_m.gif Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\831063053_m.gif Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\870960371_l.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\899251551_l.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\99091110.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\a&s.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\addthanks.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\all.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\angel_light.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\ant.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\antdeezy.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\Anthony.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\atl.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\a_daughter.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\a_son.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\b.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\ba.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\baba.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\baby pac.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\banb2.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\bandstar.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\bear.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\beast.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\blood hands.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\bloods.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\bush_flipping_finger.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\butterfly-tm.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\CAG0GEZW.gif Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\CAG0GEZW.png Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\cat6.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\cb5265eaeee59ddce50c83e2673bbadb.gif Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\cbi.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\couch.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\crack.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\crew.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\cross.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\crosses.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\crosses2.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\crosses4.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\cwall01v.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\cwall02v.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\cwall03v.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\cwall04v.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\cwall05v.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\cwall06v.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\cwall07v.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\cwall08v.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\cwall09v.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\cwall10v.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\cwall11v.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\cwall12v.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\cwall13v.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\cwall14v.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\cwall15v.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\cwall16v.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\cwall17v.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\cwall18v.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\cwall20v.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\cwall21v.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\cwall22v.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\cwall23v.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\cwall24v.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\da boys.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\db_big102.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\dem.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\demon4by6.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\Desktop.ini Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\devin.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\dey.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\diplomatjimmy.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\Dixie_Girl.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\door.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\fats.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\gemini Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\gettin high.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\glowmo.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\gngster.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\hatin.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\hug00036.gif Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\im.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\J's.gif Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\J's.png Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\jesus wept.bmp Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\jesus%20runyon2.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\jesus.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\Jesus1.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\jesus105.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\JesusCrying.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\jesus_flare.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\jesus_second_coming.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\jsjdc4.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\jszn2f.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\jszn2f1.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\jszn2fk.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\jszp09.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\jszp09b.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\jszp09h.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\jszp09i.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\jszp09w.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\jt1jsk.gif Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\jt1mdl.gif Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\jt1mx4.gif Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\jt2dg1.gif Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\jt2f7d.gif Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\jt2vxz.gif Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\jt5u04.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\kisses.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\kses.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\lasttime2pacwasalive.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\LEAN WIT IT.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\Letter to mommy.bmp Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\Lightning.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\lightning_010.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\lightning_1344_small.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\lightning_1345.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\lightning_1357_small.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\lightning_1368_small.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\lips.gif Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\look at all that money.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\love hurts.gif Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\l_02dcc5ccf467d29d7addcd923827ad29.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\l_0e66d5e502e8eaf2503606b1211040d3.gif Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\l_1284943adb57a219eeef139850c8eb5f.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\l_de49ff8365e350d03acc5dfd0cecfb59.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\me.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\MIDWEST.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\miss00011.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\miss00012.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\miss00016.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\miss00031.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\MJ-en.gif Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\MOB-6.gif Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\money and liquor.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\money_art_000.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\money_art_001.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\ms bama.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\music-2pac-scroll1.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\music-2pac-scroll2.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\music-2pac-scroll3.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\music-2pac-scroll4.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\music-2pac-scroll5.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\music-2pac-scroll6.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\muzuq.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\my baby girl.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\myspace-codes-posters080.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\mz.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\m_14125cd42e895d12a8451ee2836ff1d2.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\m_18ad4d1f0e4b0901e53b3258f9c44499.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\m_27d42496c908cdb45f13407ff8eb3e0b.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\m_2c83ae6d9909e85e050679262717e1dd.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\m_35413e24d3df39ef0afa33c67e98e84a.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\m_3bb882e96676cc190cb8d5307c9062bd.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\m_43aa54d796b13d5214149c3584ed4bcd.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\m_87e295b3e740c72fe2a0af5396697554.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\m_95ce04b06a21e666f298ffc1931d3567.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\m_a234f9f05f4b72c9cfd54a1574f664ab.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\m_b7a413a869291357cd036a32f5d953b7.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\m_d6a66e5d9ab87d2aecf6a8c8ff60ef4d.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\m_e2a490baeb18967ae6a27a8ac172130f.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\m_e9f60d589a3d47d4b7dff619bf7a6f17.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\m_ebd5306626f87c2bae1724ef96828f13.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\m_ebf6b157d94dd364e28884527f3d4553.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\no makeup.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\o baby.gif Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\old folgies.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\pac & bone.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\pac & snoop.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\pac camo.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\pac money.gif Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\pacmovin.gif Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\pic030407_2.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\pool.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\poster-jesus-resurrection-16.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\poster35.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\Pride.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\ps36-06v.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\ps41-13v.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\ps50-01v.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\ps51-10v.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\ps65-08.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\ps68-04.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\ps68-34.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\ps71-19.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\ps91-05.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\rashad.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\Red_Rum.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\rip pac.gif Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\s07_788.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\Sample Pictures.lnk Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\sex.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\sexual.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\sexy.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\shad and ant.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\shad.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\shaw 1.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\shaw 2.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\shaw 3.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\shaw 4.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\shaw 5.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\shaw and ant.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\shay.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\sin.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\smky.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\spiderman-black-costume.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\t&s.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\tall_n_sexy.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\thats me.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\The_Ultimate_Makaveli_Animation.gif Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\thonlygod1.gif Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\thpacsmkinitup7hf0hj.gif Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\thug life.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\Thumbs.db Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\th_2pac.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\th_2pac2.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\th_2pacbg.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\th_2pacchain.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\th_2pacpray.gif Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\th_meditating.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\th_tiger14.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\th_tracy.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\th_tracy3.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\th_tracy4.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\th_tracy5.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\th_tupac-photo-tupac-6200105.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\th_tupac-sketch.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\th_tupac.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\th_Tupac_Shakur.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\top hat.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\treal.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\tupac.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\tupac_back.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\untitled-3.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\untitled.bmp Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\warnabrotha.bmp Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\west side.jpg Object is locked skipped
C:\Documents and Settings\Tracy\My Documents\My Pictures\westcoast.gif Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\AntiSpam\Log\Spam.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPPolicy.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPStart.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPStop.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\tmp619d.tmp\ESRDEF.999 Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\tmp619d.tmp\TCDEFS.998 Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\tmp619d.tmp\TCSCAN7.997 Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\tmp619d.tmp\TCSCAN8.996 Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\tmp619d.tmp\TCSCAN9.995 Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\tmp619d.tmp\TINF.994 Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\tmp619d.tmp\TINFL.993 Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\tmp619d.tmp\TSCAN1.992 Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\tmp619d.tmp\V.990 Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\tmp619d.tmp\V.991 Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\tmp619d.tmp\VIRSCAN.989 Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\tmp619d.tmp\VIRSCAN1.988 Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\tmp619d.tmp\VIRSCAN2.987 Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\tmp619d.tmp\VIRSCAN3.986 Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\tmp619d.tmp\VIRSCAN4.985 Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\tmp619d.tmp\VIRSCAN5.984 Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\tmp619d.tmp\VIRSCAN6.983 Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\tmp619d.tmp\VIRSCAN7.982 Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\tmp619d.tmp\VIRSCAN8.981 Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\tmp619d.tmp\VIRSCAN9.980 Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\tmp619d.tmp\VIRSCANT.979 Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\tmp619d.tmp\WHATSNEW.978 Object is locked skipped
C:\Program Files\Common Files\Міcrosoft\nоpdb.exe Infected: not-a-virus:AdWare.Win32.PurityScan.gq skipped
C:\Program Files\Compaq Connections\6750491\Users\Default\Data\chandir.dat Object is locked skipped
C:\Program Files\Compaq Connections\6750491\Users\Default\Data\chandir.idx Object is locked skipped
C:\Program Files\Compaq Connections\6750491\Users\Default\Data\chn.dat Object is locked skipped
C:\Program Files\Compaq Connections\6750491\Users\Default\Data\chn.idx Object is locked skipped
C:\Program Files\Compaq Connections\6750491\Users\Default\Data\D0000000.FCS Object is locked skipped
C:\Program Files\Compaq Connections\6750491\Users\Default\Data\inuse.txt Object is locked skipped
C:\Program Files\Compaq Connections\6750491\Users\Default\Data\L0000006.FCS Object is locked skipped
C:\Program Files\Compaq Connections\6750491\Users\Default\Data\main.log Object is locked skipped
C:\Program Files\Compaq Connections\6750491\Users\Default\Data\prs.dat Object is locked skipped
C:\Program Files\Compaq Connections\6750491\Users\Default\Data\prs.idx Object is locked skipped
C:\Program Files\Compaq Connections\6750491\Users\Default\Data\prs_die.dat Object is locked skipped
C:\Program Files\Compaq Connections\6750491\Users\Default\Data\prs_die.idx Object is locked skipped
C:\Program Files\Compaq Connections\6750491\Users\Default\Data\prs_dnd.dat Object is locked skipped
C:\Program Files\Compaq Connections\6750491\Users\Default\Data\prs_dnd.idx Object is locked skipped
C:\Program Files\Compaq Connections\6750491\Users\Default\Data\prs_ext.dat Object is locked skipped
C:\Program Files\Compaq Connections\6750491\Users\Default\Data\prs_ext.idx Object is locked skipped
C:\Program Files\Compaq Connections\6750491\Users\Default\Data\prs_rcv.dat Object is locked skipped
C:\Program Files\Compaq Connections\6750491\Users\Default\Data\prs_rcv.idx Object is locked skipped
C:\Program Files\Compaq Connections\6750491\Users\Default\Data\storydb.dat Object is locked skipped
C:\Program Files\Compaq Connections\6750491\Users\Default\Data\storydb.idx Object is locked skipped
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe Object is locked skipped
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe Object is locked skipped
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe Object is locked skipped
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe Object is locked skipped
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe Object is locked skipped
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe Object is locked skipped
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe Object is locked skipped
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe Object is locked skipped
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe Object is locked skipped
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe Object is locked skipped
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe Object is locked skipped
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe Object is locked skipped
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe Object is locked skipped
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe Object is locked skipped
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe Object is locked skipped
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe Object is locked skipped
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe Object is locked skipped
C:\Program Files\Morpheus\mymorpheusToolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\Program Files\MSN\horylycaw77798.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\AVApp.log Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\AVError.log Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\AVVirus.log Object is locked skipped
C:\Program Files\QuickTime\QTTask .exe Object is locked skipped
C:\Program Files\QuickTime\QTTask .exe Object is locked skipped
C:\Program Files\QuickTime\QTTask .exe Object is locked skipped
C:\Program Files\QuickTime\QTTask .exe Object is locked skipped
C:\Program Files\QuickTime\QTTask .exe Object is locked skipped
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Program Files\SymNetDrv\SNDMon.exe Object is locked skipped
C:\Program Files\WildTangent\LFS\Scripts\GameData.log Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc10.lnk Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc11.lnk Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc166.lnk Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc167.lnk Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc168.lnk Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc169.lnk Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc170.lnk Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc171\60 day trial - Office 2003.lnk Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc171\Compaq Organize.lnk Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc171\Documentation.lnk Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc171\Easy Internet Sign-up.lnk Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc171\Help and Support.lnk Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc171\HP Extended Service Plans.lnk Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc171\Norton Internet Security.lnk Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc171\RealPlayer.lnk Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc171\Register with HP.url Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc171\Software Repair Wizard.lnk Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc18.jpg Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc30.url Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc35\All Users\localStorage\common.cls Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc35\All Users\profile.dat Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc35\data\mith\localStorage\common.cls Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc35\data\mith\profile.dat Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc35\data\tnbrat1977\localStorage\common.cls Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc35\data\tnbrat1977\profile.dat Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc35\data\tnbratt1977\localStorage\common.cls Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc35\data\tnbratt1977\profile.dat Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc35\data\tnbratt77\localStorage\common.cls Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc35\data\tnbratt77\profile.dat Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc36\caches\bart\1\0201D2243F Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc36\caches\bart\1\0201D29F62 Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc36\caches\bart\1\0201D29F72 Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc36\caches\bart\1\2B00002AB8 Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc36\caches\bart\1\2B00002B31 Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc36\caches\bart\1\2B00002B40 Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc36\caches\bart\1024\2B000001B7 Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc36\caches\bart\129\0201D215F1 Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc36\caches\bart\129\0201E05D26 Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc36\caches\bart\129\0201E075C4 Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc36\caches\bart\129\2B0000144F Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc36\caches\bart\131\0201D20DA9 Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc36\caches\bart\5\207265696E646565725F736E6F77 Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc36\caches\bart\96\0201D20DA9 Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc36\caches\users\tnbrat1977\buddyicon Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc36\caches\users\tnbrat1977\feedbag Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc36\caches\users\tnbratt1977\buddyicon Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc36\caches\users\tnbratt77\buddyicon Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc37.mp3 Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc38.mp3 Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc39.lnk Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc40.lnk Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc41.lnk Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc42.url Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc43.lnk Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc44.lnk Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc5.lnk Object is locked skipped
C:\RECYCLER\S-1-5-21-1172433556-4105764488-3237526379-1009\Dc8.lnk Object is locked skipped
C:\RECYCLER\S-1-5-21-1668557505-1773809857-3584175554-1009\Dc1.zip Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP20\A0005557.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP20\A0005558.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP58\A0009706.dll Infected: Packed.Win32.Monder.gen skipped
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP58\A0009735.exe/data0004 Infected: Trojan-Clicker.Win32.Small.jf skipped
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP58\A0009735.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP58\A0009826.exe Infected: not-a-virus:AdWare.Win32.Comet.bq skipped
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP59\A0010033.dll Infected: not-a-virus:AdWare.Win32.CommAd.a skipped
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP59\A0010034.exe Infected: not-a-virus:AdWare.Win32.CommAd.a skipped
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP63\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\mrofinu72.exe.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{3C1BB0ED-D0DF-4DAA-8C01-D293B1A1F26A}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
C:\WINDOWS\ѕуmbols\iexplore .exe Infected: Trojan-Downloader.Win32.PurityScan.fe skipped
C:\WINDOWS\ѕуmbols\iexplore.exe Infected: Trojan-Downloader.Win32.PurityScan.fe skipped
D:\I386\Apps\APP18456\src\HPSummer2005.exe/WISE0016.BIN Infected: not-a-virus:AdWare.Win32.MyWay.j skipped
D:\I386\Apps\APP18456\src\HPSummer2005.exe WiseSFX: infected - 1 skipped
D:\I386\Apps\APP18456\src\HPSummer2005.exe WiseSFXDropper: infected - 1 skipped

Scan process completed.




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:07:57 PM, on 4/23/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\InterMute\SpySubtract\SpySub.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\AGRSMMSG.exe
c:\windows\system\hpsysdrv.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [SSC_UserPrompt] c:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [IS CfgWiz] c:\Program Files\Norton Internet Security\cfgwiz.exe /GUID {257BBC47-1B26-432e-9F84-188603799DD3} /MODE CfgWiz /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [URLLSTCK.exe] c:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\sslaunch.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partne ... nicode.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} (Imikimi_activex_plugin Control) - http://imikimi.com/download/imikimi_plugin_0.5.1.cab
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: IS Service (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

--
End of file - 10119 bytes
jsmith052277
Regular Member
 
Posts: 21
Joined: April 19th, 2008, 1:57 pm

Re: need help removing smitfraud and others

Unread postby jsmith052277 » April 23rd, 2008, 9:40 pm

things are getting better! thank you so much for all of your help!
jsmith052277
Regular Member
 
Posts: 21
Joined: April 19th, 2008, 1:57 pm

Re: need help removing smitfraud and others

Unread postby Bio-Hazard » April 25th, 2008, 1:24 am

Hello!

Is your D drive a flash drive or permenant drive?


OiUninstaller

Download and run this uninstaller: http://www.outerinfo.com/OiUninstaller.exe
Here is a tutorial if needed.


USE HOSTS EXPERT TO UPDATE MVPS HOSTS FILE

Download HostsXpert and unzip it to your computer, somewhere where you can find it.
  • Run HostsXpert
  • If Hosts file is Read Only, click on Make Writeable, otherwise move on to next stage.
  • Click Download button.
  • Click MVPs Hosts
  • Click Merge File
  • Press OK to download latest MVPs update and merge it with your Hosts.
  • When finished click File Handling
  • Click Make Read Only to secure your Hosts file.
  • Exit HostsXpert.



Show All Files And Folders Windows XP

  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View Tab.
  • Under the Hidden files and folders heading select Show hidden files and folders.
  • Uncheck Hide file extensions for known file types
  • Uncheck the Hide protected operating system files (recommended) option.
  • Click Apply to confirm.
  • Click OK.



Delete bad files and folders

Using Windows Explore by right-clicking the start button and left clicking Explore navigate to and find the following files and folders: if found, delete them (some may not be present after previous steps):

NOTE: DO NOT delete C:\Program Files\Common Files\Microsoft Shared\

    Folders:
    C:\WINDOWS\??mbols
    C:\Program Files\Common Files\??crosoft
    C:\Program Files\Morpheus


    Files:
    C:\WINDOWS\mrofinu72.exe.tmp
    C:\Documents and Settings\Alex\Local Settings\Temp\jkhfc.dll
    C:\Program Files\MSN\horylycaw77798.exe
    C:\Documents and Settings\Big Ray\My Documents\My Videos\videos.exe




Download and Run ComboFix

We will begin with ComboFix.exe. Please visit this webpage for download links, and instructions for running the tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix


Please ensure you read this guide carefully and install the Recovery Console first.

The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

Once installed, you should see a blue screen prompt that says:

The Recovery Console was successfully installed.

Please continue as follows:

  1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

  2. Click Yes to allow ComboFix to continue scanning for malware.

When the tool is finished, it will produce a report for you.

Please include the following reports for further review, and so we may continue cleansing the system:

C:\ComboFix.txt
New HijackThis log.




Logs/Information to Post in Reply

Please post the following logs/Information in your reply

  • Combofix Log
  • A fresh HijackThis Log ( after all the above has been done)
User avatar
Bio-Hazard
MRU Master Emeritus
 
Posts: 4078
Joined: May 10th, 2007, 8:28 am
Location: Cornwall, UK

Re: need help removing smitfraud and others

Unread postby jsmith052277 » April 25th, 2008, 8:06 pm

Im not sure about the drive D or permanent drive. Im not that computer literate!! LOL!! How do I figure that out?


This website will not open for me "http://www.outerinfo.com/OiUninstaller.exe"!!

What do I do?
jsmith052277
Regular Member
 
Posts: 21
Joined: April 19th, 2008, 1:57 pm

Re: need help removing smitfraud and others

Unread postby Bio-Hazard » April 26th, 2008, 10:17 am

jsmith052277 wrote:Im not sure about the drive D or permanent drive.


Is this D drive inside your computer case so that it always connected to the computer or is it something that you connect to the computer yourself through usb slot?


jsmith052277 wrote:This website will not open for me "http://www.outerinfo.com/OiUninstaller.exe"!!


Do you get any error messages? What happens when you click on that link?

Did you already install Hostexpert?


OiUninstaller

  • Click on the tutorial link, Here
  • It should take you to page called Uninstall Outerinfo
  • On the page where it says: " This situation can be corrected by downloading and running the stand-alone uninstaller available here<<<<<< Click this
  • Then follow the instructions on that page


After that follow my instructions from my last post
User avatar
Bio-Hazard
MRU Master Emeritus
 
Posts: 4078
Joined: May 10th, 2007, 8:28 am
Location: Cornwall, UK

Re: need help removing smitfraud and others

Unread postby jsmith052277 » April 26th, 2008, 7:31 pm

This is what comes up when I try to go to that link or the tutorial, and NO I haven't downloaded anything or done anything else yet. I wanted to get your ok first!!


Internet Explorer cannot display the webpage

Most likely causes:
You are not connected to the Internet.
The website is encountering problems.
There might be a typing error in the address.

What you can try:
Check your Internet connection. Try visiting another website to make sure you are connected.

Retype the address.

Go back to the previous page.

More information

This problem can be caused by a variety of issues, including:

Internet connectivity has been lost.
The website is temporarily unavailable.
The Domain Name Server (DNS) is not reachable.
The Domain Name Server (DNS) does not have a listing for the website's domain.
If this is an HTTPS (secure) address, click tools, click Internet Options, click Advanced, and check to be sure the SSL and TLS protocols are enabled under the security section.

For offline users

You can still view subscribed feeds and some recently viewed webpages.
To view subscribed feeds

Click the Favorites Center button , click Feeds, and then click the feed you want to view.

To view recently visited webpages (might not work on all pages)

Click Tools , and then click Work Offline.
Click the Favorites Center button , click History, and then click the page you want to view.


The internet is working, so i don't understand what is going on with it
jsmith052277
Regular Member
 
Posts: 21
Joined: April 19th, 2008, 1:57 pm

Re: need help removing smitfraud and others

Unread postby jsmith052277 » April 26th, 2008, 7:34 pm

The D Drive is inside!!
jsmith052277
Regular Member
 
Posts: 21
Joined: April 19th, 2008, 1:57 pm

Re: need help removing smitfraud and others

Unread postby Bio-Hazard » April 27th, 2008, 4:10 pm

USE HOSTSXPERT TO DISABLE THE HOSTS FILE
Download HostsXpert and unzip it to your computer, somewhere you can find it,
  • There will now be a new HOSTSXPERT folder where you unzipped the file. Double click the folder, click on HostsXpert.exe
  • Double click on HostsXpert.exe
  • Click on Make Writeable.
  • Click on Restore MS HOSTS
  • Exit HostsXpert.


Hopefully now you have access to the internet site to donwload that uninstaller.


OiUninstaller

  • Click on the tutorial link, Here
  • It should take you to page called Uninstall Outerinfo
  • On the page where it says: " This situation can be corrected by downloading and running the stand-alone uninstaller available here<<<<<< Click this
  • Then follow the instructions on that page





    Show All Files And Folders Windows XP

    • Click Start.
    • Open My Computer.
    • Select the Tools menu and click Folder Options.
    • Select the View Tab.
    • Under the Hidden files and folders heading select Show hidden files and folders.
    • Uncheck Hide file extensions for known file types
    • Uncheck the Hide protected operating system files (recommended) option.
    • Click Apply to confirm.
    • Click OK.



    Delete bad files and folders

    Using Windows Explore by right-clicking the start button and left clicking Explore navigate to and find the following files and folders: if found, delete them (some may not be present after previous steps):

    NOTE: DO NOT delete C:\Program Files\Common Files\Microsoft Shared\

      Folders:
      C:\WINDOWS\??mbols
      C:\Program Files\Common Files\??crosoft
      C:\Program Files\Morpheus
      C:\Program Files\Yazzle

      Files:
      C:\WINDOWS\mrofinu72.exe.tmp
      C:\Documents and Settings\Alex\Local Settings\Temp\jkhfc.dll
      C:\Program Files\MSN\horylycaw77798.exe
      C:\Documents and Settings\Big Ray\My Documents\My Videos\videos.exe
      D:\I386\Apps\APP18456\src\HPSummer2005.exe


    Logs/Information to Post in Reply

    Please post the following logs/Information in your reply

    • A fresh HijackThis Log ( after all the above has been done)
User avatar
Bio-Hazard
MRU Master Emeritus
 
Posts: 4078
Joined: May 10th, 2007, 8:28 am
Location: Cornwall, UK

Re: need help removing smitfraud and others

Unread postby jsmith052277 » April 27th, 2008, 10:14 pm

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:13:56 PM, on 4/27/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\InterMute\SpySubtract\SpySub.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\AGRSMMSG.exe
c:\windows\system\hpsysdrv.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [SSC_UserPrompt] c:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [IS CfgWiz] c:\Program Files\Norton Internet Security\cfgwiz.exe /GUID {257BBC47-1B26-432e-9F84-188603799DD3} /MODE CfgWiz /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [URLLSTCK.exe] c:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\sslaunch.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partne ... nicode.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} (Imikimi_activex_plugin Control) - http://imikimi.com/download/imikimi_plugin_0.5.1.cab
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: IS Service (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

--
End of file - 10120 bytes
jsmith052277
Regular Member
 
Posts: 21
Joined: April 19th, 2008, 1:57 pm
Advertisement
Register to Remove

Next

  • Similar Topics
    Replies
    Views
    Last post

Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: No registered users and 18 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware